Courseiva
Cloud Data Security →mediumMultiple Choice

CCSP Cloud Data Security Practice Question

A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that data is protected at rest but does not want to manage encryption keys themselves. They also need to prove to auditors that encryption is enabled. Which cloud provider feature should they use?

⚠ Common exam trap

The trap here is assuming that any encryption option satisfies the requirement, but the key management responsibility differentiates the choices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server-side encryption with provider-managed keys (SSE-S3 or equivalent)

Server-side encryption with provider-managed keys is correct because it automatically encrypts data at rest without requiring the customer to manage keys, and it can be audited through provider configurations. Client-side and SSE-C both involve customer key management, which the firm wants to avoid. TLS is irrelevant for data at rest.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transport Layer Security (TLS) for data in transit

    Why it's wrong here

    TLS protects data in transit, not at rest. The scenario specifically requires protection at rest for stored transaction logs. While TLS is important, it does not address the storage encryption requirement. This option is a common misconception that confuses encryption in transit with encryption at rest.

  • ✗

    Client-side encryption with customer-provided keys

    Why it's wrong here

    Client-side encryption requires the customer to manage keys and perform encryption before uploading. This adds operational overhead and does not align with the desire to avoid key management. While it provides strong protection, it fails the scenario's requirement to not manage keys themselves.

  • ✓

    Server-side encryption with provider-managed keys (SSE-S3 or equivalent)

    Why this is correct

    This option uses encryption at rest where the cloud provider manages the keys, eliminating the customer's key management burden. Auditors can verify that encryption is enabled via provider logs or configuration settings. It meets the requirement for data protection without customer-managed keys, and is a standard feature of object storage services.

  • ✗

    Server-side encryption with customer-provided keys (SSE-C)

    Why it's wrong here

    SSE-C requires the customer to provide and manage the encryption keys, which contradicts the requirement to avoid key management. The provider uses the customer's key but does not store it, so the customer remains responsible for key lifecycle. This adds complexity and does not meet the scenario's constraints.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.