CCSP Cloud Data Security Practice Question
A DevOps team is deploying an application that will store encryption keys in a cloud KMS. The security policy requires that keys be stored in a hardware security module (HSM) and that key material never leaves the HSM boundary. Which key management option should they choose?
⚠ Common exam trap
CCSP often tests the distinction between BYOK (importing key material) and HSM-backed keys (where the key is generated and stored in an HSM) — candidates may assume BYOK automatically means HSM, but it does not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud KMS with HSM-backed key storage
Cloud KMS with HSM-backed key storage ensures that key material is generated and stored inside a FIPS 140-2 Level 3 validated HSM, and cryptographic operations occur within the HSM boundary. This satisfies the requirement that keys be stored in an HSM and that key material never leaves the HSM.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Customer-managed encryption keys (CMEK) with software-backed storage
Why it's wrong here
Software-backed CMEK stores key material outside an HSM, violating the requirement that keys never leave the HSM boundary. CMEK is tempting because it provides customer control over key rotation and policies, and would suit scenarios where HSM-backed key isolation is not mandated.
- ✓
Cloud KMS with HSM-backed key storage
Why this is correct
HSM-backed key storage generates and retains key material inside a validated hardware module, so cryptographic operations occur within the HSM boundary and keys are never exported. This directly satisfies the policy that key material must never leave the HSM.
- ✗
Hold your own key (HYOK) with on-premises HSM
Why it's wrong here
HYOK with an on-premises HSM keeps key material outside the cloud provider's boundary, so the cloud KMS cannot perform cryptographic operations directly; the application must call back on-premises, adding latency and defeating the managed KMS requirement. It suits regulatory mandates forbidding cloud-held keys, not this scenario.
- ✗
Bring your own key (BYOK) with key import to cloud KMS
Why it's wrong here
BYOK import places key material into the provider's KMS, where it is protected by an HSM but the customer generates and can retain a copy outside the boundary. It suits regulatory escrow or portability needs, not a policy demanding keys never leave the HSM.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.