CCSP Cloud Data Security Practice Question
A global enterprise is designing a cloud storage architecture with cross-region replication for disaster recovery. They must ensure that data replicated to a secondary region is encrypted with keys managed by the customer, and that those keys are stored in the secondary region's key management service (KMS). Which THREE capabilities must be enabled?
⚠ Common exam trap
The trap is selecting default encryption or client-side encryption as sufficient; candidates must recognize that customer-managed keys in the secondary region require explicit permissions and cross-region replication configuration, not just any encryption method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Permission for the replication service to use the secondary region's key
Option D (Cross-region replication) is required because the scenario explicitly demands that data be replicated to a secondary region for disaster recovery, which is the core mechanism that copies objects across regions. Option E (Customer-managed encryption keys in the secondary region) is correct because the requirement states the replicated data must be encrypted with customer-managed keys that reside in the secondary region's KMS, satisfying the customer-controlled key mandate. Option C (Permission for the replication service to use the secondary region's key) is correct because the replication service must be authorized to encrypt the replicated objects with that secondary-region customer-managed key; without the appropriate KMS key policy/grant, replication would fail to apply the required encryption. Option A (Default encryption with provider keys) does not belong because provider-managed keys do not meet the customer-managed key requirement. Option B (Client-side encryption before upload) does not belong because client-side encryption is performed before the data reaches the storage service and would not use the secondary region's KMS-managed customer keys as specified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Default encryption with provider keys
Why it's wrong here
Default encryption with provider keys cannot satisfy the requirement that customer-managed keys reside in the secondary region's KMS, because the provider controls key generation and storage. It is tempting as baseline at-rest encryption, and would suffice where regulatory control over key custody is not mandated.
- ✗
Client-side encryption before upload
Why it's wrong here
Client-side encryption happens before upload, so the provider's secondary-region KMS never holds or applies the keys, breaking the residency requirement. It is tempting because it gives the customer sole key control, which is correct when the provider must never see plaintext or keys at all.
- ✓
Permission for the replication service to use the secondary region's key
Why this is correct
Replication must be granted explicit permission to encrypt with the customer-managed key held in the secondary region's KMS; without that authorisation, cross-region writes fail because the destination key cannot be used. This satisfies the stem's constraint that replicated data be encrypted under customer-managed keys stored in the secondary region.
- ✓
Cross-region replication
Why this is correct
Cross-region replication copies objects to the secondary region, enabling the customer-managed keys held in that region's KMS to encrypt the replicated data. It is the capability that actually moves data across regions to satisfy the disaster recovery design.
- ✓
Customer-managed encryption keys in the secondary region
Why this is correct
Customer-managed encryption keys in the secondary region satisfy the explicit requirement that replicated data be encrypted with customer-controlled keys stored in that region's KMS, rather than provider-managed keys. This is the axis distinguishing customer-managed from default provider-managed encryption.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.