Courseiva
Cloud Data Security →hardMultiple Choice

CCSP Cloud Data Security Practice Question

A healthcare organization stores patient data in a cloud database. Regulatory requirements mandate that data must be encrypted at rest using FIPS 140-2 validated cryptographic modules. The organization wants to use the cloud provider's managed encryption service. Which aspect should they verify to ensure compliance?

⚠ Common exam trap

Test-takers frequently confuse algorithm strength (AES-256) or general security certifications (ISO 27001) with FIPS 140-2 validation of the cryptographic module itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

That the encryption service's cryptographic module has a current FIPS 140-2 validation certificate.

FIPS 140-2 validation is a requirement for cryptographic modules used by federal agencies and often mandated by regulations like HIPAA. To comply, the organization must confirm that the specific cryptographic module used by the cloud service has a valid FIPS 140-2 certificate. This ensures the module meets stringent security standards for design and implementation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    That the database uses AES-256 encryption.

    Why it's wrong here

    AES-256 is a strong algorithm, but the requirement is about FIPS 140-2 validated modules, not the algorithm alone. An implementation of AES-256 could be non-compliant if the module is not validated. The organization must verify the module's validation, not just the algorithm.

  • ✗

    That the cloud provider's encryption service uses FIPS 140-2 validated hardware security modules (HSMs) for key storage.

    Why it's wrong here

    While HSMs are often used, FIPS 140-2 validation applies to the cryptographic module itself, not just the HSM. The service might use validated HSMs but still employ non-validated software modules for encryption. Verifying only HSM validation does not guarantee overall compliance with the requirement.

  • ✗

    That the cloud provider is certified under ISO/IEC 27001.

    Why it's wrong here

    ISO/IEC 27001 is an information security management system certification, not a cryptographic validation. It does not ensure that encryption modules are FIPS 140-2 validated. While it indicates good security practices, it does not meet the specific regulatory mandate for FIPS 140-2 validated modules.

  • ✓

    That the encryption service's cryptographic module has a current FIPS 140-2 validation certificate.

    Why this is correct

    FIPS 140-2 validation is specific to the cryptographic module. The organization must ensure that the module used for encryption has a valid certificate from a NIST-accredited lab. This directly confirms that the encryption meets the regulatory requirement. The certificate should cover the exact module version and configuration used.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.