nerdexam
Isaca

CCAK · Question #106

When migrating to a cloud environment, which of the following should be the PRIMARY driver for the use of encryption?

The correct answer is A. Cloud Service Provider encryption capabilities. When migrating to a cloud environment, the CSP's encryption capabilities serve as the primary practical driver because they define the technical boundaries of what encryption mechanisms, algorithms, and key management options are actually available and supported. No matter how…

Cloud Data Governance

Question

When migrating to a cloud environment, which of the following should be the PRIMARY driver for the use of encryption?

Options

  • ACloud Service Provider encryption capabilities
  • BThe presence of PII
  • COrganizational security policies
  • DCost-benefit analysis

How the community answered

(47 responses)
  • A
    74% (35)
  • B
    15% (7)
  • C
    6% (3)
  • D
    4% (2)

Explanation

When migrating to a cloud environment, the CSP's encryption capabilities serve as the primary practical driver because they define the technical boundaries of what encryption mechanisms, algorithms, and key management options are actually available and supported. No matter how strong an organization's policies or how sensitive its PII, the encryption strategy must operate within what the chosen CSP can technically support. While organizational security policies (C) and PII presence (B) are important considerations, they cannot override the fundamental constraint of what the CSP makes possible. Note: some frameworks argue organizational policy should be primary, but in cloud migration context, CSP capabilities gate everything else.

Topics

#Cloud encryption#Data protection#Cloud Service Provider capabilities#Cloud security strategy

Community Discussion

No community discussion yet for this question.

Full CCAK Practice