Courseiva
Cloud Data Security →mediumMultiple Choice

CCSP Cloud Data Security Practice Question

A company wants to use a cloud KMS to encrypt data but requires that the encryption key never leaves their on-premises hardware security module (HSM) due to compliance. Which key management model should they adopt?

⚠ Common exam trap

CCSP often tests the distinction between BYOK (import your key into the cloud KMS) and HYOK (key never leaves your premises), so candidates who assume 'bring your own key' means the key stays on-premises pick BYOK incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Hold Your Own Key (HYOK)

HYOK (Hold Your Own Key) is the only model where the encryption key material is generated, stored, and used exclusively within the customer's on-premises HSM and never exported to the cloud provider. The cloud KMS is used only to wrap or reference the key, satisfying compliance mandates that keys must remain under customer physical control. CMEK, CSEK, and BYOK all involve the key material being imported into or generated within the cloud provider's infrastructure at some point.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Customer-Managed Encryption Key (CMEK)

    Why it's wrong here

    CMEK keys are generated and stored inside the cloud provider's KMS, so the key material resides in provider infrastructure rather than the on-premises HSM. It is tempting because CMEK gives the customer control over key rotation and lifecycle, and would be correct where compliance permits provider-hosted key material.

  • ✗

    Customer-Supplied Encryption Key (CSEK)

    Why it's wrong here

    CSEKs are supplied per request and held only transiently by the provider, but they are not stored in, generated by, or bound to the on-premises HSM, so no persistent HSM-resident key exists. CSEK is tempting because the customer originates the key, and would suit encrypting objects with externally generated keys passed at request time.

  • ✓

    Hold Your Own Key (HYOK)

    Why this is correct

    Hold Your Own Key keeps cryptographic material inside the customer's on-premises HSM, so encryption and decryption occur locally and only ciphertext reaches the cloud KMS. This satisfies the compliance constraint that the key never leaves the HSM, unlike cloud-hosted models where key material resides in the provider's infrastructure.

  • ✗

    Bring Your Own Key (BYOK)

    Why it's wrong here

    BYOK imports a copy of the customer's key into the provider's KMS, so key material leaves the on-premises HSM and is stored in provider infrastructure. It is tempting because the customer generates the key and retains an escrowed copy, and would be correct where the requirement is customer-originated keys rather than keys that never leave the HSM.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.