CCSP Cloud Data Security Practice Question
A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that data is protected at rest but does not want to manage encryption keys themselves. They also need to prove to auditors that encryption is enabled. Which cloud provider feature should they use?
⚠ Common exam trap
The trap here is assuming that any encryption option satisfies the requirement, but the key management responsibility differentiates the choices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Server-side encryption with provider-managed keys (SSE-S3 or equivalent)
Server-side encryption with provider-managed keys is correct because it automatically encrypts data at rest without requiring the customer to manage keys, and it can be audited through provider configurations. Client-side and SSE-C both involve customer key management, which the firm wants to avoid. TLS is irrelevant for data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transport Layer Security (TLS) for data in transit
Why it's wrong here
TLS protects data in transit, not at rest. The scenario specifically requires protection at rest for stored transaction logs. While TLS is important, it does not address the storage encryption requirement. This option is a common misconception that confuses encryption in transit with encryption at rest.
- ✗
Client-side encryption with customer-provided keys
Why it's wrong here
Client-side encryption requires the customer to manage keys and perform encryption before uploading. This adds operational overhead and does not align with the desire to avoid key management. While it provides strong protection, it fails the scenario's requirement to not manage keys themselves.
- ✓
Server-side encryption with provider-managed keys (SSE-S3 or equivalent)
Why this is correct
This option uses encryption at rest where the cloud provider manages the keys, eliminating the customer's key management burden. Auditors can verify that encryption is enabled via provider logs or configuration settings. It meets the requirement for data protection without customer-managed keys, and is a standard feature of object storage services.
- ✗
Server-side encryption with customer-provided keys (SSE-C)
Why it's wrong here
SSE-C requires the customer to provide and manage the encryption keys, which contradicts the requirement to avoid key management. The provider uses the customer's key but does not store it, so the customer remains responsible for key lifecycle. This adds complexity and does not meet the scenario's constraints.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.