CCSP Cloud Platform and Infrastructure Security Practice Question
A financial services company runs a critical workload on AWS. The security team must ensure that all data at rest in Amazon S3 is encrypted with keys that the company controls and that the keys are stored in a hardware security module (HSM) separate from the cloud provider's default HSM. The company also requires the ability to immediately revoke access to the keys. Which solution meets these requirements?
⚠ Common exam trap
Test-takers frequently confuse customer managed keys in AWS KMS with customer-controlled HSMs; a custom key store is required to use your own CloudHSM cluster, not just any KMS key.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use S3 server-side encryption with AWS KMS custom key store backed by AWS CloudHSM (SSE-KMS with custom key store).
The requirement is for customer-controlled keys stored in a dedicated HSM separate from the cloud provider's default HSM, with immediate revocation. AWS KMS custom key store backed by AWS CloudHSM provides exactly this: you control the HSM cluster, and you can revoke access by disassociating the key or deleting it. Other options either use provider-managed HSMs or lack HSM separation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use S3 server-side encryption with AWS KMS custom key store backed by AWS CloudHSM (SSE-KMS with custom key store).
Why this is correct
A KMS custom key store allows you to use AWS CloudHSM clusters that you control, providing a dedicated HSM separate from the default AWS KMS HSMs. You can immediately revoke access by removing the key from the custom key store or deleting the key. This satisfies both the separate HSM and immediate revocation requirements.
- ✗
Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3).
Why it's wrong here
SSE-S3 uses keys fully managed by AWS, and the company has no control over the keys or the HSMs. This fails the requirement for customer-controlled keys and separate HSM. It also does not provide immediate revocation because the company cannot delete or disable the keys.
- ✗
Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).
Why it's wrong here
SSE-KMS uses AWS KMS customer managed keys, which are stored in AWS-managed HSMs. While the company controls the key policy, the HSM is not separate from the cloud provider's default infrastructure. The requirement for a separate HSM is not met, and immediate revocation is possible but the HSM separation is lacking.
- ✗
Use S3 client-side encryption with a customer-provided key stored in AWS Secrets Manager.
Why it's wrong here
Client-side encryption with a key in Secrets Manager gives the company control over the key material, but Secrets Manager is not an HSM. The key is not stored in a dedicated HSM separate from the cloud provider's default HSM. Immediate revocation is possible by deleting the secret, but the HSM requirement is not satisfied.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.