ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your SaaS development team will store customer personally identifiable information (PII) in a multitenant database hosted on a public IaaS provider. Corporate policy states that cloud-provider personnel must be technically prevented from viewing customer data, while the application itself must retain full read/write capability. Which cryptographic design decision best satisfies this requirement with the least operational complexity?

  • Apply volume-level encryption on the virtual machine disks using provider-supplied keys

  • Rely on TLS for all database connections and disable at-rest encryption to avoid key-management overhead

  • Enable the provider's server-side encryption service with provider-managed keys

  • Encrypt data on the client before transmission using keys stored in an on-premises Hardware Security Module integrated with a cloud KMS

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot