CCSP Cloud Data Security Practice Question
An organization is moving sensitive customer data to the cloud and must ensure that data is encrypted before being sent to the cloud provider. They want to maintain full control over the encryption keys and not rely on the cloud provider for any key management. Which approach should they use?
⚠ Common exam trap
CCSP often tests the distinction between encryption in transit (VPN/TLS), server-side encryption (provider-managed keys), and client-side encryption (customer-managed keys) — candidates frequently pick server-side encryption with KMS assuming 'customer-managed key' equals 'full customer control,' when the provider still performs the cryptographic operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client-side encryption
Client-side encryption means the organization encrypts data before it ever leaves their environment, so the cloud provider only ever receives ciphertext and never has access to the plaintext or the keys. This satisfies both requirements: data is encrypted prior to transmission and the customer retains full control of key management (often via their own HSM or KMS). Because the provider never holds the keys, it cannot decrypt the data even if compelled or breached.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPN encryption
Why it's wrong here
VPN encryption protects data in transit over the network, but the data is decrypted at the provider's endpoint and stored under the provider's keys, so it fails the requirement for client-side encryption with customer-controlled keys. It is tempting because VPNs are correct for securing data in transit between sites.
- ✗
Server-side encryption with AWS KMS
Why it's wrong here
Server-side encryption with AWS KMS encrypts after the data reaches the provider, and key management remains with the provider, contradicting the requirement for encryption before transmission and full customer key control. It is tempting because KMS is correct when provider-managed keys and at-rest encryption suffice.
- ✗
Transparent Data Encryption (TDE)
Why it's wrong here
Transparent Data Encryption encrypts database files at rest on the server, after data has already been transmitted and stored, so it does not encrypt before sending or give the customer exclusive key control. It is tempting because TDE is correct for protecting database files at rest without application changes.
- ✓
Client-side encryption
Why this is correct
Client-side encryption encrypts data before transmission, so plaintext never reaches the provider. Because the organisation generates and retains its own keys, the cloud provider performs no key management, satisfying the requirement for full customer control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.