hardMultiple Select
CISSP Practice Question: Protect data at rest in a cloud storage system
A company needs to protect data at rest in a cloud storage system. Which THREE encryption methods are appropriate for this purpose?
⚠ Common exam trap
Candidates often confuse hashing with encryption, or fail to recognize that stream ciphers without authentication (like RC4) are highly vulnerable to bit-flipping attacks and are completely inappropriate for securing data at rest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Client-side encryption with key management
Client-side encryption with key management (B) is correct because encrypting data before it leaves the client and managing keys via a KMS or HSM ensures data at rest in the cloud storage is protected and keys are controlled separately from the data. AES-256 in GCM mode (D) is correct because AES-256 provides strong symmetric encryption for data at rest while GCM supplies authenticated encryption (confidentiality plus integrity/authenticity), making it suitable for stored objects. Envelope encryption (E) is correct because it encrypts data with a data encryption key (DEK) and then encrypts that DEK with a master key (KEK) held in a KMS/HSM, which is the standard approach for protecting data at rest at scale in cloud storage. MD5 hashing (C) is not an encryption method—it is a broken cryptographic hash used for integrity checks, not confidentiality—and a stream cipher without authentication such as RC4 (A) is inappropriate because RC4 is deprecated/insecure and lacks authentication, so it does not properly protect data at rest.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Stream cipher without authentication (e.g., RC4)
Why it's wrong here
Stream ciphers, such as RC4, when implemented without an accompanying Message Authentication Code (MAC) or other integrity mechanism, only provide confidentiality and are critically vulnerable to bit-flipping attacks. An attacker can predictably alter specific bits in the ciphertext, which translates to controlled changes in the plaintext upon decryption, without detection. This lack of integrity protection makes them unsuitable for securing data at rest in cloud storage, as the authenticity and non-tampering of the data cannot be guaranteed.
- ✓
Client-side encryption with key management
Why this is correct
Client-side encryption is a highly effective method for protecting data at rest in the cloud because it ensures that data is encrypted on the client's system *before* it is transmitted to or stored by the cloud provider. This approach guarantees that the cloud provider only ever receives encrypted data and has no access to the plaintext or the encryption keys. Robust key management, encompassing secure generation, storage, rotation, and revocation of these client-controlled keys, is absolutely essential to maintain the overall security posture and prevent unauthorized data access.
- ✗
MD5 hashing
Why it's wrong here
MD5 is a cryptographic hash function, not an encryption algorithm, meaning its primary purpose is to generate a fixed-size digest for data integrity verification, not to transform data into an unreadable format that can be decrypted. While it can detect accidental data alteration, MD5 does not provide confidentiality; the original data cannot be recovered from its hash. Moreover, MD5 is considered cryptographically broken due to known collision vulnerabilities, rendering it unsuitable for even integrity checks in security-critical applications, let alone protecting data confidentiality.
- ✓
AES-256 in GCM mode
Why this is correct
AES-256 in Galois/Counter Mode (GCM) is an industry-standard authenticated encryption with associated data (AEAD) cipher, making it an excellent choice for protecting data at rest in cloud environments. AES-256 provides robust confidentiality through its 256-bit key, while GCM mode simultaneously ensures data integrity and authenticity by generating a Message Authentication Code (MAC) for the ciphertext. This combined approach guarantees that the data remains confidential and detects any unauthorized modifications, which is critical for secure cloud storage.
- ✓
Envelope encryption
Why this is correct
Envelope encryption is a highly scalable and secure method for protecting large volumes of data, particularly well-suited for cloud storage environments. It utilizes a two-tier key hierarchy: a unique Data Encryption Key (DEK) is used to encrypt the actual data, and this DEK itself is then encrypted (or "wrapped") by a Key Encryption Key (KEK). The KEK, which is typically managed by a Hardware Security Module (HSM) or a Key Management Service (KMS), protects many DEKs, allowing for efficient key rotation and management without the need to re-encrypt all stored data.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.