Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A small business is migrating its customer database to a cloud-based database service. The security team wants to ensure that data is encrypted at rest using keys that the business controls, but they do not want to manage the underlying hardware security modules. Which cloud key management option should they choose?

⚠ Common exam trap

A common mix-up: candidates confuse customer-managed keys with provider-managed keys; only customer-managed keys give the business control, but they still rely on the provider's HSM.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer-managed keys stored in a cloud KMS.

Customer-managed keys in a cloud KMS provide the business with control over key lifecycle and access policies while the cloud provider handles the HSM infrastructure. This balances control with operational simplicity, making it ideal for organizations that want key control without managing hardware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Client-side encryption with keys stored on-premises.

    Why it's wrong here

    Client-side encryption with on-premises keys gives full control but requires managing the keys and encryption/decryption outside the cloud database, which may not integrate seamlessly. It also adds operational complexity and may not support all database features. The scenario specifically seeks to avoid managing HSMs, but on-premises key management may still require HSMs.

  • ✗

    Provider-managed keys with automatic rotation.

    Why it's wrong here

    Provider-managed keys mean the cloud provider controls the keys, not the business. While convenient, this does not meet the requirement for customer control over keys. The business cannot enforce its own key policies or revoke access independently. This option fails the control requirement.

  • ✗

    Bring your own key (BYOK) using a third-party key management service.

    Why it's wrong here

    BYOK with a third-party KMS can provide control, but it adds another vendor and integration complexity. The business wants to avoid managing HSMs; a third-party KMS might still require managing that service. A cloud KMS with customer-managed keys is simpler and directly integrated with the cloud database service.

  • ✓

    Customer-managed keys stored in a cloud KMS.

    Why this is correct

    Customer-managed keys in a cloud KMS allow the business to control key lifecycle and permissions while the provider manages the HSM infrastructure. This meets the requirement for customer-controlled keys without the burden of managing hardware. It also integrates with cloud database services for encryption at rest.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.