Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

An organization is moving sensitive customer data to the cloud and must ensure that data is encrypted before being sent to the cloud provider. They want to maintain full control over the encryption keys and not rely on the cloud provider for any key management. Which approach should they use?

⚠ Common exam trap

CCSP often tests the distinction between encryption in transit (VPN/TLS), server-side encryption (provider-managed keys), and client-side encryption (customer-managed keys) — candidates frequently pick server-side encryption with KMS assuming 'customer-managed key' equals 'full customer control,' when the provider still performs the cryptographic operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Client-side encryption

Client-side encryption means the organization encrypts data before it ever leaves their environment, so the cloud provider only ever receives ciphertext and never has access to the plaintext or the keys. This satisfies both requirements: data is encrypted prior to transmission and the customer retains full control of key management (often via their own HSM or KMS). Because the provider never holds the keys, it cannot decrypt the data even if compelled or breached.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPN encryption

    Why it's wrong here

    VPN encryption protects data in transit over the network, but the data is decrypted at the provider's endpoint and stored under the provider's keys, so it fails the requirement for client-side encryption with customer-controlled keys. It is tempting because VPNs are correct for securing data in transit between sites.

  • ✗

    Server-side encryption with AWS KMS

    Why it's wrong here

    Server-side encryption with AWS KMS encrypts after the data reaches the provider, and key management remains with the provider, contradicting the requirement for encryption before transmission and full customer key control. It is tempting because KMS is correct when provider-managed keys and at-rest encryption suffice.

  • ✗

    Transparent Data Encryption (TDE)

    Why it's wrong here

    Transparent Data Encryption encrypts database files at rest on the server, after data has already been transmitted and stored, so it does not encrypt before sending or give the customer exclusive key control. It is tempting because TDE is correct for protecting database files at rest without application changes.

  • ✓

    Client-side encryption

    Why this is correct

    Client-side encryption encrypts data before transmission, so plaintext never reaches the provider. Because the organisation generates and retains its own keys, the cloud provider performs no key management, satisfying the requirement for full customer control.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.