exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 439 discussion

Actual exam question from ISC's CCSP
Question #: 439
Topic #: 1
[All CCSP Questions]

Cryptographic keys for encrypted data stored in the cloud should be ________________ .

  • A. Not stored with the cloud provider.
  • B. Generated with redundancy
  • C. At least 128 bits long
  • D. Split into groups
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Cryptographic keys should not be stored along with the data they secure, regardless of key length. We don't split crypto keys or generate redundant keys (doing so would violate the principle of secrecy necessary for keys to serve their purpose).

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MaciekMT
1 month, 3 weeks ago
Selected Answer: A
For strong cloud security, cryptographic keys should not be stored with the cloud provider that holds the encrypted data. This practice, known as separation of duties, prevents a single entity from having both the keys and the encrypted data, reducing the risk of unauthorized access. Instead, organizations should use client-side key management or external Key Management Systems (KMS). Why Not the Others? B. Generated with redundancy → While key backups are important, redundancy alone does not ensure security if the key is compromised. C. At least 128 bits long → While 128-bit encryption is a minimum, modern security standards recommend 256-bit encryption for higher security. D. Split into groups → Key splitting (Shamir’s Secret Sharing) can be a useful security method but is not a strict requirement for cloud encryption.
upvoted 1 times
...
stack120566
8 months, 1 week ago
i agree that keys should not be stored with the data wthat they protect. But saying that they should not be stored wth the cloud provider is not true. Azure and other cloud providers offer key vaults. The vaults are seperate and distinct from the data that is protected They off integrations where the keys can be accessed from applications. In azure's case the appliications can be configured with permiison to read the key, certiificate. This offers means of enhancing security by creating a secure way of accessing keys, certificates, passwords or other secret without directly without exposing keys in code. This is a very usual feature in PaaS
upvoted 2 times
...
akg001
2 years, 4 months ago
Selected Answer: A
A. Not stored with the cloud provider.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago