Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A company stores sensitive backups in cloud object storage. The security policy requires that backups be recoverable even if the primary cloud region suffers a catastrophic outage, and that the backup data remain encrypted with keys the company controls throughout replication. Which configuration best satisfies both requirements?

⚠ Common exam trap

The trap here is focusing only on where the ciphertext is replicated while forgetting that the decryption keys must also survive the same regional failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cross-region replication with customer-managed keys replicated to the destination region

The scenario imposes two independent requirements: survive a regional outage and keep encryption keys under company control throughout replication. Cross-region replication satisfies the first, and customer-managed keys replicated to the destination region satisfy the second. Client-side encryption with keys confined to the source region fails because a regional outage would strand the keys, leaving replicated ciphertext unrecoverable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Single-region storage with versioning and object lock enabled

    Why it's wrong here

    Versioning and object lock protect against accidental deletion and ransomware tampering within a region, which is valuable, but they do nothing for a regional outage. If the entire region becomes unavailable, the backups are inaccessible regardless of versioning. This option addresses integrity and retention, not the geographic resilience the scenario explicitly demands.

  • ✗

    Cross-region replication with client-side encryption using keys held only in the source region

    Why it's wrong here

    Client-side encryption gives strong key custody, but if the keys exist only in the source region, a regional failure that takes down the key store also renders the replicated ciphertext undecryptable. The backups would survive physically yet be useless in recovery. Key material must be available in or recoverable from the destination region to meet the outage requirement.

  • ✓

    Cross-region replication with customer-managed keys replicated to the destination region

    Why this is correct

    Replicating objects to a second region protects against a regional outage, and using customer-managed keys that are also replicated to the destination region ensures the company retains cryptographic control and can decrypt in the secondary region without provider key custody. This combination satisfies both durability and key ownership requirements, and it is the standard pattern for regulated backup architectures.

  • ✗

    Cross-region replication with provider-managed encryption keys in both regions

    Why it's wrong here

    Cross-region replication addresses the availability requirement, but provider-managed keys leave the company without independent cryptographic control and may not be usable across regions without provider involvement. If the provider's key infrastructure in the primary region is unavailable, recovery in the secondary region could be impeded. This option solves durability but fails the key custody requirement.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.