CCSP Cloud Data Security Practice Question
A company wants to use a cloud KMS to encrypt data but requires that the encryption key never leaves their on-premises hardware security module (HSM) due to compliance. Which key management model should they adopt?
⚠ Common exam trap
CCSP often tests the distinction between BYOK (import your key into the cloud KMS) and HYOK (key never leaves your premises), so candidates who assume 'bring your own key' means the key stays on-premises pick BYOK incorrectly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hold Your Own Key (HYOK)
HYOK (Hold Your Own Key) is the only model where the encryption key material is generated, stored, and used exclusively within the customer's on-premises HSM and never exported to the cloud provider. The cloud KMS is used only to wrap or reference the key, satisfying compliance mandates that keys must remain under customer physical control. CMEK, CSEK, and BYOK all involve the key material being imported into or generated within the cloud provider's infrastructure at some point.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Customer-Managed Encryption Key (CMEK)
Why it's wrong here
CMEK keys are generated and stored inside the cloud provider's KMS, so the key material resides in provider infrastructure rather than the on-premises HSM. It is tempting because CMEK gives the customer control over key rotation and lifecycle, and would be correct where compliance permits provider-hosted key material.
- ✗
Customer-Supplied Encryption Key (CSEK)
Why it's wrong here
CSEKs are supplied per request and held only transiently by the provider, but they are not stored in, generated by, or bound to the on-premises HSM, so no persistent HSM-resident key exists. CSEK is tempting because the customer originates the key, and would suit encrypting objects with externally generated keys passed at request time.
- ✓
Hold Your Own Key (HYOK)
Why this is correct
Hold Your Own Key keeps cryptographic material inside the customer's on-premises HSM, so encryption and decryption occur locally and only ciphertext reaches the cloud KMS. This satisfies the compliance constraint that the key never leaves the HSM, unlike cloud-hosted models where key material resides in the provider's infrastructure.
- ✗
Bring Your Own Key (BYOK)
Why it's wrong here
BYOK imports a copy of the customer's key into the provider's KMS, so key material leaves the on-premises HSM and is stored in provider infrastructure. It is tempting because the customer generates the key and retains an escrowed copy, and would be correct where the requirement is customer-originated keys rather than keys that never leave the HSM.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.