Courseiva
Cloud Data SecuritymediumMultiple ChoiceObjective-mapped

CCSP Cloud Data Security Practice Question

A DevOps team is deploying an application that will store encryption keys in a cloud KMS. The security policy requires that keys be stored in a hardware security module (HSM) and that key material never leaves the HSM boundary. Which key management option should they choose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cloud KMS with HSM-backed key storage

Cloud KMS with HSM-backed key storage ensures keys are generated and stored in an HSM. CMEK and BYOK typically use software-backed keys unless HSM is specified. HYOK keeps keys on-premises, not in cloud HSM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Customer-managed encryption keys (CMEK) with software-backed storage

    Why it's wrong here

    Customer-managed encryption keys (CMEK) with software-backed storage – Not HSM-backed, violates policy.

  • Cloud KMS with HSM-backed key storage

    Why this is correct

    Cloud KMS with HSM-backed key storage – Keys generated and stored in HSM, never leave boundary.

  • Hold your own key (HYOK) with on-premises HSM

    Why it's wrong here

    Hold your own key (HYOK) with on-premises HSM – Keys not in cloud HSM, does not meet cloud storage requirement.

  • Bring your own key (BYOK) with key import to cloud KMS

    Why it's wrong here

    Bring your own key (BYOK) with key import to cloud KMS – Key import may expose material during transfer, not guaranteed never leaves HSM.

About these practice questions

One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.