ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A hospital is migrating a database that contains protected health information (PHI) to an IaaS provider. Compliance policy requires that the cloud operator must never be able to read the data, and internal auditors insist on a clear separation of duties for cryptographic key administration. Which design choice BEST meets both requirements while keeping management overhead low?
Use the provider's KMS but allow joint key custody, giving both cloud administrators and the customer security team full access to the keys.
Rely on the provider's default storage-level encryption service and let the provider manage the master keys.
Encrypt the data on-premises and store the customer-owned keys in an on-premises HSM that is integrated with the application via KMIP.
Hash personally identifying columns at the application layer but leave the rest of the database in plaintext.
Client-side (also called customer-controlled) encryption ensures that data are encrypted before they reach the provider's storage layer, so the cloud operator cannot view plaintext. Housing the customer-owned keys in an on-premises hardware security module (HSM) that exposes KMIP interfaces allows the security team to retain exclusive control of the keys, satisfying separation-of-duties and regulatory mandates. Provider-managed keys, keys stored alongside the data, or relying only on hashing fail to prevent provider access or do not protect the full data set.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is KMIP and why is it important for cryptographic key management?
Open an interactive chat with Bash
What is an HSM and how does it enhance security?
Open an interactive chat with Bash
What is client-side encryption, and how does it protect data in the cloud?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .