Courseiva
Cloud Data Security →hardMultiple Choice

CCSP Cloud Data Security Practice Question

A financial services company stores sensitive data in a cloud provider's object storage. The security team wants to enforce that all data is encrypted at rest using keys that the company controls, and that the cloud provider cannot access the plaintext keys. Which cloud data security control should they implement?

⚠ Common exam trap

The trap here is believing that server-side encryption with customer-provided keys (SSE-C) gives the customer sole control, when the provider still handles the key in plaintext.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client-side encryption where the company encrypts data before uploading and manages its own keys outside the cloud provider's infrastructure.

Client-side encryption is the only option that guarantees the cloud provider never has access to plaintext keys, because encryption and key management occur entirely within the company's environment. Server-side options, even with customer-provided keys or HSMs, involve the provider in key handling, which introduces potential access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Server-side encryption with provider-managed keys (SSE-CMK) where the provider generates and stores the keys in its own KMS.

    Why it's wrong here

    With provider-managed keys, the cloud provider generates and stores the keys, and may have access to them for administrative purposes. This does not meet the requirement that the provider cannot access the plaintext keys. The company needs to control the keys, not the provider.

  • ✗

    Server-side encryption with a hardware security module (HSM) where the provider manages the HSM and the keys are stored in the provider's key store.

    Why it's wrong here

    Even if an HSM is used, if the provider manages the HSM and the keys are stored in the provider's key store, the provider may have administrative access to the keys. This does not ensure that the provider cannot access the plaintext keys, as required.

  • ✗

    Server-side encryption with customer-provided keys (SSE-C) where the company supplies the key with each request but the provider stores it temporarily.

    Why it's wrong here

    SSE-C allows the customer to provide the encryption key, but the provider must handle the key in plaintext to perform encryption and decryption. This means the provider can access the key during operations, which violates the requirement that the provider cannot access plaintext keys.

  • ✓

    Client-side encryption where the company encrypts data before uploading and manages its own keys outside the cloud provider's infrastructure.

    Why this is correct

    Client-side encryption ensures that data is encrypted before it reaches the cloud provider, and the company retains sole control of the keys. The provider only stores ciphertext and cannot access plaintext keys, satisfying the requirement for exclusive control and preventing provider access.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.