CCSP Cloud Data Security Practice Question
A global enterprise is designing a cloud storage architecture with cross-region replication for disaster recovery. They must ensure that data replicated to a secondary region is encrypted with keys managed by the customer, and that those keys are stored in the secondary region's key management service (KMS). Which THREE capabilities must be enabled?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Permission for the replication service to use the secondary region's key
To meet the requirements, the customer must use customer-managed keys (CMK) in the secondary region, enable cross-region replication, and ensure the replication service has permission to use the target region's key via an appropriate access control mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Default encryption with provider keys
Why it's wrong here
Default encryption with provider keys does not meet the requirement for customer-managed keys.
- ✗
Client-side encryption before upload
Why it's wrong here
Client-side encryption before upload does not address the need for key storage in the secondary region's KMS.
- ✓
Permission for the replication service to use the secondary region's key
Why this is correct
Correct: The replication service needs permission to use the secondary region's key to encrypt replicated data.
- ✓
Cross-region replication
Why this is correct
Correct: Cross-region replication is required to copy data to the secondary region.
- ✓
Customer-managed encryption keys in the secondary region
Why this is correct
Correct: Customer-managed keys in the secondary region ensure the customer controls encryption for replicated data.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.