Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A healthcare organization is storing patient records in a cloud object storage service. They must encrypt data at rest with keys they control and rotate regularly, but they do not want to manage the encryption process themselves. Which encryption option should they use?

⚠ Common exam trap

CCSP often tests the distinction between key control and encryption process management, and candidates may confuse CMEK with CSEK or client-side encryption, incorrectly assuming that controlling keys means managing the encryption process.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer-managed encryption keys (CMEK)

Customer-managed encryption keys (CMEK) allow the organization to control the encryption keys (including rotation) while the cloud provider manages the encryption/decryption process. This meets the requirement of using keys they control without managing the encryption process itself. CMEK is supported by major cloud providers (e.g., AWS KMS, Azure Key Vault, Google Cloud KMS) and integrates with object storage services. The organization retains control over key lifecycle but delegates cryptographic operations to the provider.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Server-side encryption with cloud provider default keys

    Why it's wrong here

    Provider default keys are generated and held by the cloud provider, so the organisation neither controls nor rotates them, failing the key-ownership requirement. It is tempting because it removes all key management overhead, and would be correct if the requirement were merely encryption at rest with no customer control.

  • ✓

    Customer-managed encryption keys (CMEK)

    Why this is correct

    Customer-managed encryption keys let the organisation retain sole control over key material and rotation schedules, while the cloud provider performs the actual cryptographic operations. This satisfies the stem's dual constraint: keys the healthcare organisation controls, without managing the encryption process itself.

  • ✗

    Customer-supplied encryption keys (CSEK)

    Why it's wrong here

    CSEK requires the customer to supply the key with every request and to handle rotation and storage themselves, which is exactly the management burden the scenario excludes. It is tempting because the customer fully controls the key material, and would be correct if they accepted that operational responsibility.

  • ✗

    Client-side encryption

    Why it's wrong here

    Client-side encryption means the organisation encrypts data before upload and manages keys and rotation entirely itself, contradicting the requirement to avoid managing the encryption process. It is tempting because it gives the strongest key control, and would be correct if the provider were untrusted or had to see only ciphertext.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.