Courseiva
Cloud Data Security →hardMultiple Choice

CCSP Cloud Data Security Practice Question

A company uses a cloud key management service (KMS) with an HSM-backed key for encrypting sensitive data. They want to ensure that the key is automatically rotated every 90 days and that older key versions are retained for decryption of previously encrypted data. Which KMS feature should be configured?

⚠ Common exam trap

CCSP often tests the misconception that key rotation requires re-encrypting all data or that old key versions are automatically deleted, leading candidates to choose key destruction or revocation instead of version retention.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automatic key rotation with version retention

Automatic key rotation with version retention is the correct KMS feature because it enables the system to generate a new cryptographic key version on a defined schedule (e.g., every 90 days) while preserving all previous versions. The old versions remain available for decrypting data that was encrypted under them, ensuring backward compatibility. This directly satisfies both requirements: automatic rotation and retention of older key versions for decryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Automatic key rotation with version retention

    Why this is correct

    Automatic key rotation with version retention satisfies both constraints: it rotates the HSM-backed key on the 90-day schedule while preserving prior key versions, so data encrypted under earlier versions remains decryptable. Rotation alone would render old ciphertext unreadable without retained versions.

  • ✗

    Key aliasing

    Why it's wrong here

    Key aliasing provides a stable friendly name pointing to a key, decoupling applications from key identifiers; it neither schedules rotation nor preserves prior versions. Rotation configuration with version retention is required here. Aliasing would be correct when applications must reference a key by a constant name across rotations.

  • ✗

    Key destruction schedule

    Why it's wrong here

    A destruction schedule permanently deletes key material after a set period, which would make data encrypted under those versions unrecoverable and directly contradicts retaining older versions for decryption. Rotation with version retention is needed. Destruction scheduling would be correct when regulatory policy requires keys to be irrevocably deleted after a defined lifetime.

  • ✗

    Key revocation policy

    Why it's wrong here

    Revocation invalidates a key so ciphertext becomes undecryptable, which directly contradicts retaining older versions for decryption. It is tempting because revocation is a genuine KMS control, but its purpose is emergency compromise response — disabling a leaked key — not scheduled rotation with version retention.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.