hardMultiple Choice
CCSP Practice Question: A healthcare organization is migrating its…
A healthcare organization is migrating its electronic health record (EHR) system to a public cloud. The system stores sensitive patient data subject to HIPAA. The cloud architect has designed a multi-tier architecture with load balancers, web servers, application servers, and a PostgreSQL database. The database contains ePHI. To meet compliance, the architect plans to encrypt the database at rest using AWS RDS encryption with KMS. However, during a security review, the compliance officer notes that the database backups are stored in an S3 bucket that is not encrypted. Additionally, the application logs, which may contain patient data, are sent to CloudWatch Logs without encryption. The compliance officer insists that all data stores containing ePHI must be encrypted at rest. Which action should the architect take to ensure compliance?
⚠ Common exam trap
Candidates often assume encrypting the RDS instance automatically encrypts all associated data stores, such as backups exported to S3 and CloudWatch Logs, when in fact each service requires separate encryption configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable S3 bucket encryption for backups and enable encryption for CloudWatch Logs using KMS.
HIPAA requires encryption of ePHI at rest in all data stores. The S3 bucket containing unencrypted database backups and the CloudWatch Logs that may contain patient data both need encryption enabled via KMS to meet compliance. AWS RDS encryption protects the live database, but backups and logs are separate storage locations that must also be encrypted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable S3 bucket encryption for backups and enable encryption for CloudWatch Logs using KMS.
Why this is correct
Enabling SSE-KMS on the S3 backup bucket and KMS encryption on the CloudWatch log group closes the two unencrypted ePHI stores the compliance officer identified, satisfying the mandate that every data store holding ePHI be encrypted at rest.
- ✗
Disable automated backups and rely on point-in-time recovery.
Why it's wrong here
Disabling automated backups removes the unencrypted S3 backup copies but also eliminates recovery points, and point-in-time recovery still relies on backup storage; the requirement is encrypting every ePHI data store at rest. It is tempting as a quick way to remove the finding, yet it sacrifices resilience rather than applying SSE-KMS.
- ✗
Enable encryption on the RDS instance and use encrypted replicas.
Why it's wrong here
RDS encryption and encrypted replicas leave the unencrypted S3 backup bucket and CloudWatch Logs untouched, so ePHI still resides in unencrypted stores. It appeals because RDS encryption with KMS is the standard mechanism for encrypting the primary PostgreSQL database at rest, which is the correct action when only the database itself holds ePHI.
- ✗
Enable encryption on the S3 bucket only, since backups are the main concern.
Why it's wrong here
Encrypting only the S3 bucket leaves the CloudWatch Logs, which also contain patient data, unencrypted at rest. It is tempting because S3 server-side encryption with KMS is the correct control when backups are the sole ePHI store identified as non-compliant.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.