CCSP Cloud Data Security Practice Question
A company uses a cloud key management service (KMS) with an HSM-backed key for encrypting sensitive data. They want to ensure that the key is automatically rotated every 90 days and that older key versions are retained for decryption of previously encrypted data. Which KMS feature should be configured?
⚠ Common exam trap
CCSP often tests the misconception that key rotation requires re-encrypting all data or that old key versions are automatically deleted, leading candidates to choose key destruction or revocation instead of version retention.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automatic key rotation with version retention
Automatic key rotation with version retention is the correct KMS feature because it enables the system to generate a new cryptographic key version on a defined schedule (e.g., every 90 days) while preserving all previous versions. The old versions remain available for decrypting data that was encrypted under them, ensuring backward compatibility. This directly satisfies both requirements: automatic rotation and retention of older key versions for decryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automatic key rotation with version retention
Why this is correct
Automatic key rotation with version retention satisfies both constraints: it rotates the HSM-backed key on the 90-day schedule while preserving prior key versions, so data encrypted under earlier versions remains decryptable. Rotation alone would render old ciphertext unreadable without retained versions.
- ✗
Key aliasing
Why it's wrong here
Key aliasing provides a stable friendly name pointing to a key, decoupling applications from key identifiers; it neither schedules rotation nor preserves prior versions. Rotation configuration with version retention is required here. Aliasing would be correct when applications must reference a key by a constant name across rotations.
- ✗
Key destruction schedule
Why it's wrong here
A destruction schedule permanently deletes key material after a set period, which would make data encrypted under those versions unrecoverable and directly contradicts retaining older versions for decryption. Rotation with version retention is needed. Destruction scheduling would be correct when regulatory policy requires keys to be irrevocably deleted after a defined lifetime.
- ✗
Key revocation policy
Why it's wrong here
Revocation invalidates a key so ciphertext becomes undecryptable, which directly contradicts retaining older versions for decryption. It is tempting because revocation is a genuine KMS control, but its purpose is emergency compromise response — disabling a leaked key — not scheduled rotation with version retention.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.