Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Encryption at rest Practice Question

A financial services company stores customer transaction data in a cloud object storage bucket. The company requires that all data be encrypted at rest using keys that it generates and manages on-premises, with the cloud provider having no access to the keys. Which encryption approach should the company use?

⚠ Common exam trap

CCSP often tests the distinction between BYOK/CMK (provider still holds key material in its KMS) and true client-side encryption (customer retains sole key custody) — candidates who equate 'customer-managed' with 'provider cannot access' pick the wrong answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client-side encryption with customer-owned keys

Client-side encryption with customer-owned keys means the company encrypts data before uploading it to cloud storage, and the keys never leave the company's on-premises environment. The cloud provider stores only ciphertext and has no access to the plaintext or the keys, satisfying the requirement that the provider cannot access the keys.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Server-side encryption with AES-256

    Why it's wrong here

    Server-side AES-256 uses provider-managed keys, so the cloud provider holds and can access the key material, failing the on-premises control requirement. Customer-managed keys held externally, such as HYOK or external key store, meet it. SSE is tempting because it encrypts at rest.

  • ✓

    Client-side encryption with customer-owned keys

    Why this is correct

    Encrypting data before it leaves the organisation means the provider stores only ciphertext, and keys generated and retained on-premises are never exposed to the cloud service. This satisfies the requirement that the provider has no access to keys, unlike provider-managed or customer-managed keys held in the cloud.

  • ✗

    Server-side encryption with bring your own key (BYOK) to cloud KMS

    Why it's wrong here

    BYOK involves importing your key into the cloud KMS. While the key originates from the customer, once imported, the cloud provider manages its lifecycle and may have access to it. This does not guarantee no provider access.

  • ✗

    Server-side encryption with customer-managed keys (CMK) in cloud KMS

    Why it's wrong here

    Customer-managed keys in cloud KMS are generated and held by the provider's HSM, so the provider retains the technical capability to access them, failing the on-premises key custody requirement. It is tempting because CMK suits scenarios needing key rotation and audit control while accepting provider-hosted key material.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.