CCSP Cloud Platform and Infrastructure Security Practice Question
A financial services company runs a regulated workload on a public cloud. The security team must ensure that all data at rest in the cloud provider's block storage service is encrypted with keys that the company controls and can revoke immediately. The company also needs to prove to auditors that the cloud provider cannot access the plaintext data. Which approach BEST meets these requirements?
⚠ Common exam trap
Watch out — candidates often confuse customer-managed keys in the provider's KMS with true customer-controlled keys, when only client-side encryption with external key storage guarantees the provider cannot access plaintext.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement client-side encryption before writing data to block storage, using a customer-managed key stored in an external key management system.
Client-side encryption with an externally managed key ensures the cloud provider never receives plaintext and cannot access the key. The company retains full control and can revoke the key instantly, and auditors can verify that the provider has no path to the plaintext. Other options either leave key control with the provider or do not provide provable inaccessibility, failing the regulatory requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use provider-managed encryption keys with automatic rotation enabled, and rely on the provider's attestation reports for audit evidence.
Why it's wrong here
Provider-managed keys are controlled by the cloud provider, so the company cannot revoke them immediately or prove that the provider lacks access to plaintext. While rotation and attestation reports are useful, they do not give the company exclusive control over the key lifecycle. This fails the requirement for customer-controlled, immediately revocable keys and the need to demonstrate provider inability to access data.
- ✗
Use a cloud provider's key management service to generate a customer-managed key (CMK) and enable automatic rotation, while the provider manages the underlying HSM.
Why it's wrong here
A CMK in the provider's KMS gives the company control over key policies and rotation, but the provider still operates the HSM and could theoretically access the key material. Immediate revocation is possible, but proving that the provider cannot access plaintext is difficult because the provider controls the infrastructure. This does not fully meet the requirement for provable provider inaccessibility.
- ✓
Implement client-side encryption before writing data to block storage, using a customer-managed key stored in an external key management system.
Why this is correct
Client-side encryption ensures data is encrypted before it reaches the cloud provider, so the provider never sees plaintext. Storing the key in an external KMS that the company controls allows immediate revocation and provides audit evidence that the provider cannot access the key. This directly satisfies all stated requirements: customer control, immediate revocation, and provable provider inaccessibility.
- ✗
Enable server-side encryption with customer-provided keys (SSE-C), where the company supplies the key with each API request but the provider stores the encrypted data.
Why it's wrong here
SSE-C allows the company to supply the key, but the provider still performs encryption and decryption and may briefly handle the key in memory. The company cannot prove that the provider never has access to plaintext, and immediate revocation is not guaranteed because the provider may cache the key. This falls short of the requirement to demonstrate provider inaccessibility.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.