Courseiva

CCSP Cloud Application Security Practice Question

An organization uses a multi-cloud architecture with applications running on both AWS and Azure. They need to implement a secrets management solution that works across both platforms and supports automated rotation. Which approach best meets these requirements?

⚠ Common exam trap

The trap is assuming a single-cloud native service (AWS Secrets Manager or Azure Key Vault) can manage secrets across both clouds — only a cloud-agnostic tool like Vault natively satisfies multi-cloud rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy HashiCorp Vault as a centralized secrets manager

HashiCorp Vault is a platform-agnostic secrets management solution that runs on any cloud or on-premises environment, supports dynamic secrets, and provides automated secret rotation via leases and rotation policies. It is the only option that natively spans AWS and Azure with consistent APIs and automated rotation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy HashiCorp Vault as a centralized secrets manager

    Why this is correct

    HashiCorp Vault runs platform-agnostically, so a single control plane issues and rotates secrets for both AWS and Azure workloads. Its dynamic secrets engines and API-driven rotation satisfy the cross-platform and automated rotation constraints that native AWS Secrets Manager or Azure Key Vault cannot meet alone.

  • ✗

    Store secrets as encrypted environment variables in each environment

    Why it's wrong here

    Encrypted environment variables are static per deployment, lack a central audit trail, and cannot rotate automatically across AWS and Azure. They are tempting because they are simple and keep secrets out of source code, which suits small single-cloud workloads, but multi-cloud rotation demands a dedicated secrets manager.

  • ✗

    Use Azure Key Vault with a federation bridge to AWS

    Why it's wrong here

    Azure Key Vault is a single-cloud service; a federation bridge adds custom integration and does not natively manage AWS secrets or rotate them across both platforms. It is tempting because Key Vault offers managed rotation within Azure, which suits Azure-only estates, but cross-cloud requirements need a platform-neutral secrets manager.

  • ✗

    Use AWS Secrets Manager for all secrets

    Why it's wrong here

    AWS Secrets Manager stores and rotates secrets only within AWS; it cannot natively manage Azure Key Vault secrets, so the cross-platform rotation requirement fails. It is tempting because it excels at native AWS secret rotation via Lambda, and would be correct for an AWS-only estate.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.