Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A healthcare organization runs a regulated workload on a public cloud. The security team must ensure that data stored in object storage remains unreadable to the cloud provider's staff even if they have physical access to the storage media. Which approach best meets this requirement?

⚠ Common exam trap

The trap here is treating any server-side encryption option as equivalent to customer-controlled encryption, when only client-side encryption with customer-held keys removes the provider from the trust boundary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Encrypt data client-side before upload and retain sole custody of the keys

When the requirement is that the cloud provider itself must be unable to read the data, the customer must control encryption end to end. Encrypting client-side before upload and keeping keys outside the provider's reach guarantees that only ciphertext ever reaches provider infrastructure. Server-side options, whether provider-managed or customer-provided per request, still involve provider systems handling keys or plaintext at some point.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable server-side encryption with provider-managed keys

    Why it's wrong here

    Provider-managed server-side encryption protects data at rest against media theft, but the provider holds and can access the keys, so provider personnel with sufficient privilege could theoretically decrypt the objects. This does not satisfy a requirement that the provider itself be unable to read the data. The customer gains convenience but surrenders the cryptographic control that the scenario explicitly demands.

  • ✗

    Rely on transport-layer encryption using TLS for all uploads and downloads

    Why it's wrong here

    TLS protects data in transit between the client and the storage endpoint, but once the object lands in the bucket it is stored in whatever form the provider uses at rest. Transport encryption does nothing to prevent provider staff from reading stored objects. Treating TLS as a data-at-rest control is a fundamental category error and leaves the regulated data exposed to the provider.

  • ✗

    Enable server-side encryption with customer-provided keys that the provider does not retain

    Why it's wrong here

    Customer-provided keys are supplied per request, and while the provider does not store them long term, they are present in memory during processing and the provider can technically access plaintext during the operation. This still leaves a window where provider systems handle the key material. It is stronger than provider-managed keys but does not fully guarantee that provider staff can never read the data.

  • ✓

    Encrypt data client-side before upload and retain sole custody of the keys

    Why this is correct

    Client-side encryption performed before the data leaves the customer's environment ensures the provider only ever receives ciphertext. Because the customer never shares the keys, provider personnel cannot decrypt the objects even with full physical access to storage media. This is the classic approach for meeting requirements that the cloud provider itself must be unable to read regulated data, and it directly satisfies the stated constraint.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.