ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is migrating protected health information (PHI) to a public-cloud analytics platform. The data is already encrypted in transit and at rest, but it must be decrypted while queries run in the virtual machines. To improve security specifically during the use phase of the cloud data lifecycle-without forcing major application changes-which additional control should you recommend?
Use confidential computing with hardware-based trusted execution environments to keep data encrypted during processing.
Implement client-side field-level encryption before uploading PHI to the cloud storage service.
Enable object versioning and write-once-read-many (WORM) storage on the cloud data lake.
Configure automated cryptographic erasure of encryption keys once the retention period ends.
The use phase of the cloud data lifecycle covers the moment when information is processed in memory. Traditional TLS protects data in transit, and storage encryption or WORM targets the store/archive phases. Crypto-shredding addresses the dispose phase. To protect data while it is actively being processed, the most effective option is confidential computing using hardware-based trusted execution environments (TEEs). A TEE keeps data and code isolated and encrypted in memory, reducing exposure even if the underlying hypervisor or operating system is compromised, and it can usually be adopted without modifying application logic significantly. Therefore, selecting confidential computing with TEEs is the correct choice.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is confidential computing?
Open an interactive chat with Bash
How does a Trusted Execution Environment (TEE) improve cloud security?
Open an interactive chat with Bash
Why is data encryption at rest, in transit, and in use important?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .