CCSP Cloud Platform and Infrastructure Security Practice Question
A company stores sensitive backups in cloud object storage. The security policy requires that backups be recoverable even if the primary cloud region suffers a catastrophic outage, and that the backup data remain encrypted with keys the company controls throughout replication. Which configuration best satisfies both requirements?
⚠ Common exam trap
The trap here is focusing only on where the ciphertext is replicated while forgetting that the decryption keys must also survive the same regional failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cross-region replication with customer-managed keys replicated to the destination region
The scenario imposes two independent requirements: survive a regional outage and keep encryption keys under company control throughout replication. Cross-region replication satisfies the first, and customer-managed keys replicated to the destination region satisfy the second. Client-side encryption with keys confined to the source region fails because a regional outage would strand the keys, leaving replicated ciphertext unrecoverable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Single-region storage with versioning and object lock enabled
Why it's wrong here
Versioning and object lock protect against accidental deletion and ransomware tampering within a region, which is valuable, but they do nothing for a regional outage. If the entire region becomes unavailable, the backups are inaccessible regardless of versioning. This option addresses integrity and retention, not the geographic resilience the scenario explicitly demands.
- ✗
Cross-region replication with client-side encryption using keys held only in the source region
Why it's wrong here
Client-side encryption gives strong key custody, but if the keys exist only in the source region, a regional failure that takes down the key store also renders the replicated ciphertext undecryptable. The backups would survive physically yet be useless in recovery. Key material must be available in or recoverable from the destination region to meet the outage requirement.
- ✓
Cross-region replication with customer-managed keys replicated to the destination region
Why this is correct
Replicating objects to a second region protects against a regional outage, and using customer-managed keys that are also replicated to the destination region ensures the company retains cryptographic control and can decrypt in the secondary region without provider key custody. This combination satisfies both durability and key ownership requirements, and it is the standard pattern for regulated backup architectures.
- ✗
Cross-region replication with provider-managed encryption keys in both regions
Why it's wrong here
Cross-region replication addresses the availability requirement, but provider-managed keys leave the company without independent cryptographic control and may not be usable across regions without provider involvement. If the provider's key infrastructure in the primary region is unavailable, recovery in the secondary region could be impeded. This option solves durability but fails the key custody requirement.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.