Courseiva
Cloud Data Security →hardMultiple Choice

CCSP Cloud Data Security Practice Question

A financial services company stores regulated data in a cloud object storage bucket and uses a cloud key management service (KMS) with customer-managed keys. An auditor asks how the company ensures that data remains protected if a malicious insider with KMS administrator rights attempts to export key material. Which KMS capability should the security team describe?

⚠ Common exam trap

Watch out — candidates often confuse detective or access controls such as logging and MFA with the preventive guarantee that key material cannot be exported from a validated HSM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The KMS uses hardware security modules that are validated to FIPS 140-2 or FIPS 140-3 and are configured to prevent key material from being exported in plaintext.

HSM-backed KMS with FIPS validation is the correct capability because these modules are designed to keep key material inside the hardware boundary and prevent plaintext export, even by administrators. MFA, audit logging, and rotation are useful controls but do not stop an insider from extracting usable key material through legitimate administrative interfaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The KMS uses hardware security modules that are validated to FIPS 140-2 or FIPS 140-3 and are configured to prevent key material from being exported in plaintext.

    Why this is correct

    HSM-backed KMS implementations are designed so that key material never leaves the HSM in plaintext, even for administrators. FIPS validation provides assurance that the cryptographic module enforces this boundary. This directly answers the auditor's concern about an insider exporting keys, because administrative rights do not translate into the ability to extract raw key bytes.

  • ✗

    The KMS automatically rotates customer-managed keys every 90 days, which limits the usefulness of any exported key material.

    Why it's wrong here

    Rotation limits the window of exposure for a compromised key, but it does not prevent an administrator from exporting the current key version and decrypting existing data. Until rotation completes and old versions are disabled or deleted, exported material remains usable. The scenario specifically asks about preventing export, so rotation is a mitigating, not preventive, control.

  • ✗

    The KMS logs all key usage to an immutable audit trail, so any export attempt by an insider would be detected after the fact.

    Why it's wrong here

    Audit logging is valuable for detection and forensics, but it does not prevent key material from being exported. An insider could still exfiltrate keys before the logs are reviewed, and the damage would already be done. The scenario asks how data remains protected, which requires a preventive control rather than a detective one.

  • ✗

    The KMS enforces multi-factor authentication for all administrative actions, which prevents an insider from exporting key material.

    Why it's wrong here

    Multi-factor authentication strengthens identity verification but does not by itself prevent an authorized administrator from using legitimate KMS APIs to export or misuse keys. If the KMS supports key export, MFA alone will not stop an insider who has valid credentials. The auditor's question is about key material extraction, so a stronger technical control is required.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.