easyMultiple Choice
CCSP Practice Question: A company's security policy requires that all…
A company's security policy requires that all data stored in the cloud must be encrypted at rest. The cloud provider offers server-side encryption with either cloud-managed keys or customer-managed keys (CMK). Which additional control should the company implement to ensure that the CMK is not compromised and that access is auditable?
⚠ Common exam trap
ISC2 often tests the distinction between controls that protect the key itself (rotation and auditing) versus controls that protect the channel or user access (VPN, MFA, TLS), leading candidates to confuse network or identity safeguards with key management safeguards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable automatic key rotation and configure detailed audit logging for the key management service.
Enabling automatic key rotation reduces the risk of key compromise by limiting the exposure window of any single key, while detailed audit logging for the key management service (e.g., AWS CloudTrail for KMS, Azure Monitor for Key Vault) provides an immutable record of all key usage and administrative actions. This combination ensures that even if a CMK is exposed, the window of vulnerability is minimized, and any unauthorized access or misuse is detectable through logs. Without these controls, the customer-managed key could remain static for long periods, increasing risk, and access events would not be auditable, violating the policy requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable automatic key rotation and configure detailed audit logging for the key management service.
Why this is correct
Rotation limits the blast radius of a leaked CMK by shortening its cryptographic lifespan, while audit logging records every key use and policy change. Together they satisfy the stem's dual requirement that the customer-managed key stays uncompromised and that access remains auditable.
- ✗
Implement a VPN for all management traffic to the cloud provider's API.
Why it's wrong here
A VPN protects data in transit to the API but does nothing to constrain or record who uses the CMK, leaving key usage unaudited. It is tempting because encrypted tunnels are a standard control, and would be the right answer if the requirement concerned interception of management traffic rather than key governance.
- ✗
Enable multi-factor authentication (MFA) for all cloud console users.
Why it's wrong here
MFA strengthens console authentication but does not govern programmatic key usage or produce the per-operation audit trail the stem demands. It is tempting because MFA is a foundational identity control, and would be correct if the risk were credential compromise rather than unaudited CMK access.
- ✗
Use encryption in transit (TLS) for all data transfers to and from the cloud.
Why it's wrong here
TLS secures data in transit, whereas the stem concerns encryption at rest and control of the CMK itself. It is tempting because transport encryption is a universal baseline control, and would be the correct answer if the requirement addressed interception of data moving between the company and the cloud provider.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.