Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A financial services firm runs regulated workloads on Microsoft Azure. Auditors require that disk encryption keys for IaaS virtual machines remain under the firm's exclusive control, that the keys never leave a hardware security module, and that the firm can revoke access to the keys at any time, rendering the disks unreadable. The firm does not want Microsoft to be able to decrypt the disks without an explicit grant. Which Azure disk encryption configuration meets these requirements?

⚠ Common exam trap

The trap here is treating any customer-managed key as equivalent to a hardware security module-backed key, when software-protected keys do not meet a strict HSM custody requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Disk Encryption with BitLocker keys wrapped by a customer key held in Azure Key Vault Managed HSM

The auditors require customer-exclusive key custody in a hardware security module plus the ability to revoke access and render disks unreadable. Azure Key Vault Managed HSM supplies single-tenant, hardware-backed key storage, and Azure Disk Encryption wraps the volume keys with a customer key from that HSM. Disabling or revoking the key-encryption key effectively crypto-shreds the disks, which platform-managed or software-protected keys cannot achieve.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Disk Encryption with BitLocker keys wrapped by a customer key held in Azure Key Vault Managed HSM

    Why this is correct

    Azure Key Vault Managed HSM provides a single-tenant, FIPS 140-2 Level 3 validated hardware security module where the customer's key material never leaves the HSM boundary. Azure Disk Encryption uses BitLocker for Windows or dm-crypt for Linux and wraps the volume keys with the customer's key-encryption key. Revoking or disabling that key makes the disks unreadable, and Microsoft cannot decrypt without an explicit grant, satisfying every stated requirement.

  • ✗

    Server-side encryption with customer-managed keys stored in Azure Key Vault, using software-protected keys

    Why it's wrong here

    Customer-managed keys give the firm control over rotation and revocation, which is a meaningful improvement, but software-protected keys reside in a software HSM rather than a dedicated hardware security module with FIPS 140-2 Level 3 validation. The requirement that keys never leave a hardware security module is not satisfied. This option is close but misses the hardware-backed key custody constraint.

  • ✗

    Azure Storage Service Encryption with infrastructure encryption enabled on the managed disks

    Why it's wrong here

    Infrastructure encryption adds a second layer of platform-managed encryption at the storage cluster level, but the keys remain under Microsoft's control. The customer cannot revoke access to render disks unreadable, and the keys are not held in a customer-exclusive hardware security module. This option strengthens baseline encryption but does not deliver the key sovereignty and revocation capability the auditors require.

  • ✗

    Azure Disk Encryption with BitLocker keys stored in an Azure Key Vault that uses platform-managed keys

    Why it's wrong here

    Platform-managed keys are generated and held by Microsoft, so the customer does not have exclusive control and cannot unilaterally revoke access in a way that prevents Microsoft from decrypting. This fails the requirement that keys never leave customer-controlled HSMs and that Microsoft cannot decrypt without an explicit grant. It provides encryption at rest but not the sovereignty the auditors demand.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.