ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your company stores terabytes of customer backups in a cloud object store using an envelope encryption scheme: each object is encrypted with a unique data encryption key (DEK) that is wrapped by a customer-managed key-encrypting key (KEK) in the provider's KMS. Compliance now mandates annual key rotation, but downtime and large-scale data re-encryption must be avoided. Which approach best satisfies these constraints?
Export the current KEK, delete it from the KMS, and import a new KEK containing identical key material.
Generate a new KEK annually, unwrap each stored DEK, then wrap it with the new KEK while leaving the ciphertext untouched.
Extend the existing KEK's expiration date in the KMS so that re-encryption is unnecessary.
Create fresh DEKs for every object and re-encrypt all backups, keeping the original KEK in use.
With envelope encryption, rotating the KEK does not require decrypting and re-encrypting the underlying ciphertext. Instead, the DEKs are simply unwrapped with the old KEK and immediately rewrapped (re-encrypted) with the new KEK. The objects remain encrypted with their original DEKs, so no bulk data movement or service outage occurs.
Generating new DEKs for every object forces full re-encryption of all data, defeating the performance goal. Extending the existing KEK's validity avoids work but fails the explicit rotation requirement. Importing a KEK with identical key material is not a true rotation and violates most key-management standards.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is envelope encryption in cloud storage?
Open an interactive chat with Bash
Why doesn't rotating the KEK require re-encryption of the underlying data?
Open an interactive chat with Bash
What happens if compliance mandates DEK rotation instead of KEK rotation?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .