ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your company stores terabytes of customer backups in a cloud object store using an envelope encryption scheme: each object is encrypted with a unique data encryption key (DEK) that is wrapped by a customer-managed key-encrypting key (KEK) in the provider's KMS. Compliance now mandates annual key rotation, but downtime and large-scale data re-encryption must be avoided. Which approach best satisfies these constraints?

  • Export the current KEK, delete it from the KMS, and import a new KEK containing identical key material.

  • Generate a new KEK annually, unwrap each stored DEK, then wrap it with the new KEK while leaving the ciphertext untouched.

  • Extend the existing KEK's expiration date in the KMS so that re-encryption is unnecessary.

  • Create fresh DEKs for every object and re-encrypt all backups, keeping the original KEK in use.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot