Courseiva
Cloud Data Security →hardMultiple Choice

CCSP Cloud Data Security Practice Question

A multinational corporation uses a cloud-based data warehouse. The security team must ensure that data is irreversibly destroyed when it is no longer needed, even across backups and replicas. The cloud provider offers a cryptographic erase feature. What is the MOST important consideration when relying on cryptographic erase?

⚠ Common exam trap

The trap here is focusing on the encryption algorithm or physical media destruction instead of the secure destruction of the encryption keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The keys used for encryption must be securely destroyed and not recoverable.

Cryptographic erase relies on destroying the encryption keys so that data becomes permanently unrecoverable. The critical factor is ensuring that all copies of the keys are destroyed and cannot be restored from backups or escrow. Without key destruction, the data remains accessible. Other options are either irrelevant or address different sanitization methods.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The data must be overwritten with random patterns before key destruction.

    Why it's wrong here

    Overwriting is a physical sanitization method, but cryptographic erase does not require it. The point of cryptographic erase is to avoid overwriting by making the data unreadable through key loss. Overwriting would be redundant and may not be possible in cloud environments where the customer lacks physical access.

  • ✗

    The encryption algorithm must be AES-256.

    Why it's wrong here

    AES-256 is a strong standard, but the effectiveness of cryptographic erase depends on key destruction, not the algorithm's strength. Even a strong algorithm is useless if the key remains accessible. The scenario requires irreversible destruction, which is achieved by destroying the key, not by choosing a specific algorithm.

  • ✗

    The cloud provider must certify that all storage media are physically destroyed.

    Why it's wrong here

    Physical destruction is not necessary with cryptographic erase. The provider may reuse media after key destruction. Requiring physical destruction would be impractical and costly, and it is not the basis of cryptographic erase. The focus should be on key management, not media disposal.

  • ✓

    The keys used for encryption must be securely destroyed and not recoverable.

    Why this is correct

    Cryptographic erase works by destroying the encryption keys, rendering the data unreadable. If keys are backed up or escrowed, the data can be recovered, violating the requirement. Therefore, ensuring key destruction and non-recoverability is paramount. This includes removing all copies of the key from backups, HSMs, and key management systems.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.