CCSP Cloud Data Security Practice Question
A multinational corporation stores trade secrets in a cloud object storage bucket. The security team wants to ensure that even if the cloud provider's internal systems are compromised, the data remains confidential. They also need to maintain the ability to revoke access to specific data objects without affecting other objects. Which combination of techniques should they implement?
⚠ Common exam trap
A common mix-up: candidates confuse server-side encryption with customer-provided keys (SSE-C) as equivalent to client-side encryption; SSE-C still exposes keys to the provider during processing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client-side encryption with per-object keys and a key management system that supports granular key revocation.
Client-side encryption with per-object keys ensures that data is encrypted before it reaches the cloud, so a provider compromise does not expose plaintext. Per-object keys allow revoking access to a specific object by revoking its key, without affecting other objects. This provides both confidentiality against provider compromise and granular revocation, which are the core requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transport-layer encryption (TLS) and identity-based access policies.
Why it's wrong here
TLS only protects data in transit; data at rest remains unencrypted and vulnerable to provider-side compromise. Identity-based policies control who can access objects but do not encrypt data. This combination does not provide confidentiality against a compromised provider or enable granular revocation based on encryption keys.
- ✓
Client-side encryption with per-object keys and a key management system that supports granular key revocation.
Why this is correct
Client-side encryption ensures data is encrypted before reaching the cloud, so provider compromise does not expose plaintext. Using per-object keys allows revoking access to a specific object by revoking its key, without impacting other objects. A key management system that supports granular revocation enables this fine-grained control, meeting both confidentiality and selective revocation requirements.
- ✗
Server-side encryption with customer-provided keys (SSE-C) and object-level ACLs.
Why it's wrong here
SSE-C requires the customer to provide the encryption key with each request, and the provider uses it to encrypt/decrypt but does not store it. However, the provider still handles the key during the operation, and a compromise of provider systems during processing could expose the key. Also, SSE-C does not inherently support per-object key revocation without re-encrypting all objects with a new key.
- ✗
Server-side encryption with provider-managed keys and bucket-level access policies.
Why it's wrong here
Server-side encryption with provider-managed keys means the cloud provider holds the keys and can decrypt data, so a compromise of provider systems could expose the trade secrets. Bucket-level policies control access but do not protect against provider-side compromise. This approach fails the confidentiality requirement against the provider itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.