Courseiva
Cloud Data Security →hardMultiple Choice

CCSP Cloud Data Security Practice Question

An organization is required to use client-side encryption for all data uploaded to a cloud storage service to ensure that the cloud provider has no access to plaintext. However, they also need to allow the cloud provider to perform server-side operations like indexing and search on the encrypted data. Which technology can address this conflict?

⚠ Common exam trap

CCSP often tests the distinction between encryption technologies that enable computation versus those that enable search — candidates may confuse homomorphic encryption (computation) with searchable encryption (search/indexing).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Searchable encryption

Searchable encryption allows data to remain encrypted at rest while still supporting server-side operations such as keyword search and indexing over the ciphertext. It enables the cloud provider to perform searches without decrypting the data, satisfying both the client-side encryption requirement and the need for server-side search functionality. This directly resolves the conflict described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Format-preserving encryption

    Why it's wrong here

    Format-preserving encryption keeps ciphertext in the original data format, but the provider still cannot search or index plaintext values without decrypting them. It is tempting because it suits databases needing encrypted fields that retain length and type, not server-side search over encrypted content.

  • ✓

    Searchable encryption

    Why this is correct

    Searchable encryption lets the provider index and query ciphertext without decrypting it, preserving client-side key custody. It resolves the conflict by enabling server-side search operations over encrypted objects while the provider never gains plaintext access, satisfying both the no-plaintext constraint and the indexing requirement.

  • ✗

    Tokenization

    Why it's wrong here

    Tokenization substitutes sensitive values with non-sensitive tokens stored in a separate vault; the provider cannot index or search the original plaintext, so it fails the requirement. It is tempting because tokenisation protects data at rest from provider access, but it does not preserve searchable structure the way searchable encryption or homomorphic techniques do.

  • ✗

    Homomorphic encryption

    Why it's wrong here

    Homomorphic encryption permits computation on ciphertext, but practical schemes support limited arithmetic operations, not general keyword indexing and search across arbitrary stored documents. It is tempting because it is the canonical answer for computing on encrypted data, and would be correct for specific analytic functions rather than text search.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.