CCSP Cloud Data Security Practice Question
A financial services company stores regulated transaction logs in a cloud object storage bucket. The security team must ensure that even the cloud provider's administrators cannot access the plaintext data, and that the company can immediately revoke access for a compromised internal user without re-encrypting all objects. Which approach BEST meets these requirements?
⚠ Common exam trap
The trap here is assuming that server-side encryption with customer-managed keys in the cloud KMS prevents provider administrators from accessing plaintext, when in fact the provider still controls the underlying key infrastructure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use client-side encryption where the company retains sole control of the keys in an on-premises HSM and issues short-lived data keys to authorized users.
Client-side encryption with keys held exclusively by the customer in an on-premises HSM ensures that the cloud provider never has access to the plaintext or the key material, which is essential when even provider administrators must be excluded. Short-lived data keys enable immediate revocation of a compromised user without re-encrypting the entire data set, meeting both the confidentiality and agility requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable provider-managed server-side encryption with a customer-managed key stored in the cloud provider's KMS.
Why it's wrong here
Provider-managed keys in the cloud KMS leave key material accessible to the provider's administrative plane, so provider administrators could potentially access plaintext. Also, revoking an internal user's access would require changing the key policy, which may not immediately prevent decryption of already-encrypted objects. This fails the requirement that even provider admins cannot access plaintext.
- ✗
Implement server-side encryption with provider-managed keys and enable bucket versioning and object lock.
Why it's wrong here
Provider-managed keys mean the provider controls the key material, so provider administrators can access plaintext. Bucket versioning and object lock protect against deletion or modification but do nothing to prevent decryption by the provider or to enable immediate revocation of a user's access. This approach does not satisfy the confidentiality or revocation requirements.
- ✗
Apply server-side encryption with customer-provided keys (SSE-C) and store the keys in the cloud provider's secret manager.
Why it's wrong here
SSE-C requires the customer to provide the key with each request, but storing those keys in the provider's secret manager reintroduces provider access to key material. This undermines the requirement that provider administrators cannot access plaintext. Additionally, revoking a user's access would not automatically invalidate the key, so immediate revocation is not achieved.
- ✓
Use client-side encryption where the company retains sole control of the keys in an on-premises HSM and issues short-lived data keys to authorized users.
Why this is correct
Client-side encryption with keys held exclusively in an on-premises HSM ensures the cloud provider never possesses the key material, so provider administrators cannot decrypt the data. Issuing short-lived data keys allows immediate revocation for a compromised user without re-encrypting all objects, satisfying both requirements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.