CCSP Cloud Data Security Practice Question
A financial services company is migrating a customer analytics platform to a public cloud IaaS environment. The security team must ensure that sensitive data at rest in the cloud provider's block storage volumes is encrypted and that the company retains sole control over the encryption keys, even from the cloud provider. Which approach BEST meets these requirements?
⚠ Common exam trap
The trap here is assuming that customer-managed keys in the cloud provider's KMS give the same level of control as keys held entirely outside the provider's environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement client-side encryption before writing data to the block storage volumes, managing keys in an on-premises HSM.
Client-side encryption with keys stored in an on-premises HSM ensures that data is encrypted before it leaves the company's control and that the cloud provider never has access to the encryption keys. This provides the strongest level of key control and meets both the encryption at rest and sole key control requirements. Provider-managed or customer-managed keys in the cloud still involve the provider in key management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable cloud provider volume encryption with customer-managed keys stored in the provider's KMS.
Why it's wrong here
Customer-managed keys in the provider's KMS still reside within the provider's infrastructure. Although the customer manages key policies, the provider has underlying access to the key material and could potentially decrypt data. This does not meet the requirement of sole control, especially against the provider itself.
- ✓
Implement client-side encryption before writing data to the block storage volumes, managing keys in an on-premises HSM.
Why this is correct
Client-side encryption encrypts data before it reaches the cloud, and storing keys in an on-premises HSM ensures the company retains exclusive control. The cloud provider only sees ciphertext and never has access to the plaintext or the keys. This satisfies both encryption at rest and sole key control requirements.
- ✗
Use the cloud provider's native volume encryption with provider-managed keys.
Why it's wrong here
Provider-managed keys are generated and stored by the cloud provider, meaning the provider has access to the keys and can potentially decrypt the data. This does not give the company sole control over the keys, which is a critical requirement here. While it provides encryption at rest, it fails the key control mandate for sensitive financial data.
- ✗
Use transport-layer encryption (TLS) for all data written to the block storage volumes.
Why it's wrong here
TLS protects data in transit, not data at rest. Once data is written to the block storage volumes, it is stored unencrypted unless additional encryption is applied. This approach fails to meet the encryption-at-rest requirement and does not address key control at all.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.