CCSP Cloud Data Security Practice Question
A healthcare organization is storing patient records in a cloud object storage service. They must encrypt data at rest with keys they control and rotate regularly, but they do not want to manage the encryption process themselves. Which encryption option should they use?
⚠ Common exam trap
CCSP often tests the distinction between key control and encryption process management, and candidates may confuse CMEK with CSEK or client-side encryption, incorrectly assuming that controlling keys means managing the encryption process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer-managed encryption keys (CMEK)
Customer-managed encryption keys (CMEK) allow the organization to control the encryption keys (including rotation) while the cloud provider manages the encryption/decryption process. This meets the requirement of using keys they control without managing the encryption process itself. CMEK is supported by major cloud providers (e.g., AWS KMS, Azure Key Vault, Google Cloud KMS) and integrates with object storage services. The organization retains control over key lifecycle but delegates cryptographic operations to the provider.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Server-side encryption with cloud provider default keys
Why it's wrong here
Provider default keys are generated and held by the cloud provider, so the organisation neither controls nor rotates them, failing the key-ownership requirement. It is tempting because it removes all key management overhead, and would be correct if the requirement were merely encryption at rest with no customer control.
- ✓
Customer-managed encryption keys (CMEK)
Why this is correct
Customer-managed encryption keys let the organisation retain sole control over key material and rotation schedules, while the cloud provider performs the actual cryptographic operations. This satisfies the stem's dual constraint: keys the healthcare organisation controls, without managing the encryption process itself.
- ✗
Customer-supplied encryption keys (CSEK)
Why it's wrong here
CSEK requires the customer to supply the key with every request and to handle rotation and storage themselves, which is exactly the management burden the scenario excludes. It is tempting because the customer fully controls the key material, and would be correct if they accepted that operational responsibility.
- ✗
Client-side encryption
Why it's wrong here
Client-side encryption means the organisation encrypts data before upload and manages keys and rotation entirely itself, contradicting the requirement to avoid managing the encryption process. It is tempting because it gives the strongest key control, and would be correct if the provider were untrusted or had to see only ciphertext.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.