CCSP Cloud Platform and Infrastructure Security Practice Question
A healthcare cloud tenant must ensure that when a physical host is decommissioned, residual data in storage cannot be reconstructed. The provider offers self-encrypting drives. Which property most directly guarantees that cryptographic erasure is effective?
⚠ Common exam trap
The trap here is conflating physical sanitization methods like overwriting or shredding with cryptographic erasure, which is defined by destruction of the key rather than the data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The media encryption key is wrapped by a key-encryption key that is destroyed on decommission
Cryptographic erasure depends entirely on the irrecoverability of the key material protecting the drive. Only destroying the wrapping key that protects the media encryption key ensures that ciphertext on retired media can never be decrypted, which is precisely the guarantee a healthcare tenant needs for decommissioned storage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The media encryption key is wrapped by a key-encryption key that is destroyed on decommission
Why this is correct
Cryptographic erasure works by destroying the key that protects the media encryption key, rendering all ciphertext on the drive permanently undecryptable. If the key-encryption key is reliably destroyed and never escrowed elsewhere, the data becomes unrecoverable even if the platters are later read, which is the property the tenant needs contractually guaranteed.
- ✗
The drive firmware performs a multi-pass overwrite of all sectors
Why it's wrong here
Overwriting is a sanitization method, not cryptographic erasure, and self-encrypting drives do not typically rewrite every sector on decommission. More importantly, overwrite quality depends on firmware behavior the tenant cannot verify, and wear-leveling or remapped sectors may be skipped, so this does not provide the strong, verifiable guarantee the scenario requires.
- ✗
The drive is physically shredded at an approved destruction facility
Why it's wrong here
Shredding is the strongest physical sanitization, but the scenario specifically asks about cryptographic erasure, and in cloud environments tenants rarely receive custody of individual drives for physical destruction. This answer sidesteps the actual question about key destruction and is generally impractical for provider-managed storage.
- ✗
The storage array keeps redundant copies of the data on mirrored volumes
Why it's wrong here
Mirroring improves availability, not sanitization. Redundant copies actually widen the attack surface because every replica holds the same ciphertext and must be covered by the same key-destruction process. If any mirror retains an unwrapped key or a cached copy, cryptographic erasure fails, so this property undermines rather than guarantees the outcome.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.