CCSP Cloud Data Security Practice Question
A company uses a cloud key management service with customer-managed keys to encrypt data in a cloud storage bucket. The security team wants to ensure that if a key is compromised, they can revoke the cloud service's ability to decrypt the data immediately. What should they do?
⚠ Common exam trap
CCSP often tests the difference between key rotation, deletion, and disabling — candidates pick rotation or deletion thinking they revoke access, but only disabling or revoking permissions immediately stops decryption without destroying the key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable the key in the cloud key management service or revoke the key's access permissions for the cloud service.
Disabling the customer-managed key or revoking the cloud service's permissions to use it immediately prevents the service from performing cryptographic operations with that key, effectively cutting off decryption. This is a reversible, fast action that preserves the key material for potential recovery. It directly addresses the requirement to revoke the cloud service's ability to decrypt data immediately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rotate the key to a new version.
Why it's wrong here
Rotation creates a new key version for future encryption; existing ciphertext remains decryptable with the old version, so the compromised key still works. It is tempting because rotation limits a key's lifetime, but it is the right choice for scheduled hygiene, not for immediate revocation, which requires disabling the key version.
- ✗
Delete the key permanently from the cloud key management service.
Why it's wrong here
Permanent deletion is irreversible and typically scheduled, so it cannot deliver immediate, controlled revocation and risks destroying data permanently. It is tempting as the ultimate kill switch, but disabling the key version is the correct choice because it halts decryption at once while remaining reversible.
- ✗
Regenerate the key material by importing a new key.
Why it's wrong here
Importing new key material creates a separate key; it does not revoke the compromised key's ability to decrypt existing ciphertext, so immediate decryption prevention fails. It is tempting because key rotation is a genuine hygiene practise, and would be correct for limiting exposure of future data rather than revoking a specific key.
- ✓
Disable the key in the cloud key management service or revoke the key's access permissions for the cloud service.
Why this is correct
Disabling the customer-managed key or revoking the cloud service's grant removes its ability to unwrap the data encryption key, immediately halting decryption. This satisfies the requirement for instant revocation of the service's decryption capability if the key is compromised.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.