Courseiva
hardMultiple ChoiceObjective-mapped

CCSP Practice Question: A company uses a hybrid cloud architecture with…

A company uses a hybrid cloud architecture with on-premises key management and cloud services. They need to ensure that encryption keys used for cloud data are never exposed to the cloud provider. Which key management approach best meets this requirement?

⚠ Common exam trap

ISC2 often tests the misconception that a cloud-based HSM (Option D) is equivalent to on-premises key control, but the trap is that any key stored in the cloud provider's infrastructure is still accessible to the provider, whereas BYOK with an on-premises HSM ensures the provider never has access to the plaintext key material.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a BYOK solution with an on-premises HSM and key caching

A Bring Your Own Key (BYOK) solution with an on-premises Hardware Security Module (HSM) allows the company to generate and store encryption keys locally, then securely transfer them to the cloud for use without exposing the raw key material to the cloud provider. Key caching ensures that the cloud service can perform operations without the provider ever having persistent access to the plaintext keys, meeting the requirement that keys are never exposed to the cloud provider.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use the cloud provider's native key management service

    Why it's wrong here

    Provider manages keys, so they have access.

  • Store keys in a cloud key vault with access logs

    Why it's wrong here

    Provider still controls the vault infrastructure.

  • Use a BYOK solution with an on-premises HSM and key caching

    Why this is correct

    BYOK allows key generation and lifetime outside the cloud.

  • Deploy a cloud-based HSM and store keys only there

    Why it's wrong here

    HSM is still in provider's environment.

About these practice questions

One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.