CCSP Cloud Data Security Practice Question
An organization is required to use client-side encryption for all data uploaded to a cloud storage service to ensure that the cloud provider has no access to plaintext. However, they also need to allow the cloud provider to perform server-side operations like indexing and search on the encrypted data. Which technology can address this conflict?
⚠ Common exam trap
CCSP often tests the distinction between encryption technologies that enable computation versus those that enable search — candidates may confuse homomorphic encryption (computation) with searchable encryption (search/indexing).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Searchable encryption
Searchable encryption allows data to remain encrypted at rest while still supporting server-side operations such as keyword search and indexing over the ciphertext. It enables the cloud provider to perform searches without decrypting the data, satisfying both the client-side encryption requirement and the need for server-side search functionality. This directly resolves the conflict described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Format-preserving encryption
Why it's wrong here
Format-preserving encryption keeps ciphertext in the original data format, but the provider still cannot search or index plaintext values without decrypting them. It is tempting because it suits databases needing encrypted fields that retain length and type, not server-side search over encrypted content.
- ✓
Searchable encryption
Why this is correct
Searchable encryption lets the provider index and query ciphertext without decrypting it, preserving client-side key custody. It resolves the conflict by enabling server-side search operations over encrypted objects while the provider never gains plaintext access, satisfying both the no-plaintext constraint and the indexing requirement.
- ✗
Tokenization
Why it's wrong here
Tokenization substitutes sensitive values with non-sensitive tokens stored in a separate vault; the provider cannot index or search the original plaintext, so it fails the requirement. It is tempting because tokenisation protects data at rest from provider access, but it does not preserve searchable structure the way searchable encryption or homomorphic techniques do.
- ✗
Homomorphic encryption
Why it's wrong here
Homomorphic encryption permits computation on ciphertext, but practical schemes support limited arithmetic operations, not general keyword indexing and search across arbitrary stored documents. It is tempting because it is the canonical answer for computing on encrypted data, and would be correct for specific analytic functions rather than text search.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.