Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A financial services company runs a critical workload on AWS. The security team must ensure that all data at rest in Amazon S3 is encrypted with keys that the company controls and that the keys are stored in a hardware security module (HSM) separate from the cloud provider's default HSM. The company also requires the ability to immediately revoke access to the keys. Which solution meets these requirements?

⚠ Common exam trap

Test-takers frequently confuse customer managed keys in AWS KMS with customer-controlled HSMs; a custom key store is required to use your own CloudHSM cluster, not just any KMS key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use S3 server-side encryption with AWS KMS custom key store backed by AWS CloudHSM (SSE-KMS with custom key store).

The requirement is for customer-controlled keys stored in a dedicated HSM separate from the cloud provider's default HSM, with immediate revocation. AWS KMS custom key store backed by AWS CloudHSM provides exactly this: you control the HSM cluster, and you can revoke access by disassociating the key or deleting it. Other options either use provider-managed HSMs or lack HSM separation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use S3 server-side encryption with AWS KMS custom key store backed by AWS CloudHSM (SSE-KMS with custom key store).

    Why this is correct

    A KMS custom key store allows you to use AWS CloudHSM clusters that you control, providing a dedicated HSM separate from the default AWS KMS HSMs. You can immediately revoke access by removing the key from the custom key store or deleting the key. This satisfies both the separate HSM and immediate revocation requirements.

  • ✗

    Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3).

    Why it's wrong here

    SSE-S3 uses keys fully managed by AWS, and the company has no control over the keys or the HSMs. This fails the requirement for customer-controlled keys and separate HSM. It also does not provide immediate revocation because the company cannot delete or disable the keys.

  • ✗

    Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).

    Why it's wrong here

    SSE-KMS uses AWS KMS customer managed keys, which are stored in AWS-managed HSMs. While the company controls the key policy, the HSM is not separate from the cloud provider's default infrastructure. The requirement for a separate HSM is not met, and immediate revocation is possible but the HSM separation is lacking.

  • ✗

    Use S3 client-side encryption with a customer-provided key stored in AWS Secrets Manager.

    Why it's wrong here

    Client-side encryption with a key in Secrets Manager gives the company control over the key material, but Secrets Manager is not an HSM. The key is not stored in a dedicated HSM separate from the cloud provider's default HSM. Immediate revocation is possible by deleting the secret, but the HSM requirement is not satisfied.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.