CCSP Cloud Data Security Practice Question
A healthcare organization stores patient data in a cloud database. Regulatory requirements mandate that data must be encrypted at rest using FIPS 140-2 validated cryptographic modules. The organization wants to use the cloud provider's managed encryption service. Which aspect should they verify to ensure compliance?
⚠ Common exam trap
Test-takers frequently confuse algorithm strength (AES-256) or general security certifications (ISO 27001) with FIPS 140-2 validation of the cryptographic module itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
That the encryption service's cryptographic module has a current FIPS 140-2 validation certificate.
FIPS 140-2 validation is a requirement for cryptographic modules used by federal agencies and often mandated by regulations like HIPAA. To comply, the organization must confirm that the specific cryptographic module used by the cloud service has a valid FIPS 140-2 certificate. This ensures the module meets stringent security standards for design and implementation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
That the database uses AES-256 encryption.
Why it's wrong here
AES-256 is a strong algorithm, but the requirement is about FIPS 140-2 validated modules, not the algorithm alone. An implementation of AES-256 could be non-compliant if the module is not validated. The organization must verify the module's validation, not just the algorithm.
- ✗
That the cloud provider's encryption service uses FIPS 140-2 validated hardware security modules (HSMs) for key storage.
Why it's wrong here
While HSMs are often used, FIPS 140-2 validation applies to the cryptographic module itself, not just the HSM. The service might use validated HSMs but still employ non-validated software modules for encryption. Verifying only HSM validation does not guarantee overall compliance with the requirement.
- ✗
That the cloud provider is certified under ISO/IEC 27001.
Why it's wrong here
ISO/IEC 27001 is an information security management system certification, not a cryptographic validation. It does not ensure that encryption modules are FIPS 140-2 validated. While it indicates good security practices, it does not meet the specific regulatory mandate for FIPS 140-2 validated modules.
- ✓
That the encryption service's cryptographic module has a current FIPS 140-2 validation certificate.
Why this is correct
FIPS 140-2 validation is specific to the cryptographic module. The organization must ensure that the module used for encryption has a valid certificate from a NIST-accredited lab. This directly confirms that the encryption meets the regulatory requirement. The certificate should cover the exact module version and configuration used.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.