ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization stores sensitive customer data in a public cloud object storage service that supports several encryption modes. Compliance mandates that cryptographic keys must never persist within the provider's environment, yet developers prefer to rely on native server-side encryption so they can keep existing workflows unchanged. Which key management option best satisfies both the compliance requirement and the operational preference?

  • Rely on the provider's default server-side encryption with provider-managed keys stored in a multi-tenant key management service

  • Generate a customer master key in the provider's dedicated hardware security module service and grant the storage service access to it for encryption

  • Configure server-side encryption with customer-provided keys supplied on every request, allowing the provider to encrypt objects without storing the key

  • Implement client-side encryption in the application and store the data-encryption keys in the cloud provider's managed key management service

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot