nerdexam
(ISC)2

CCSP · Question #171

A cloud data encryption situation where the cloud customer retains control of the encryption keys and the cloud provider only processes and stores the data could be considered a ____________.

The correct answer is C. Hybrid cloud deployment model. This scenario describes a shared responsibility model in cloud computing where the customer retains control over encryption keys, while the cloud provider manages data processing and storage.

Submitted by omar99· Apr 18, 2026Cloud Concepts, Architecture and Design

Question

A cloud data encryption situation where the cloud customer retains control of the encryption keys and the cloud provider only processes and stores the data could be considered a ____________.

Options

  • AThreat
  • BRisk
  • CHybrid cloud deployment model
  • DCase of infringing on the rights of the provider

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    88% (42)
  • D
    6% (3)

Why each option

This scenario describes a shared responsibility model in cloud computing where the customer retains control over encryption keys, while the cloud provider manages data processing and storage.

AThreat

This setup is a security control mechanism, not inherently a threat itself.

BRisk

This approach aims to mitigate risk by giving the customer more control, rather than being a risk itself.

CHybrid cloud deployment modelCorrect

While not a direct definition, this level of granular control over critical security components like encryption keys is often a characteristic requirement and operational model adopted by organizations implementing a hybrid cloud strategy. In hybrid environments, enterprises often extend their on-premises security postures to cloud resources, leading to a blend of customer and provider managed controls.

DCase of infringing on the rights of the provider

Cloud providers offer services like customer-managed keys (CMK) or bring-your-own-key (BYOK) specifically to allow this level of control, so it does not infringe on their rights.

Concept tested: Cloud data security and deployment models

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/encryption-overview

Topics

#Cloud Key Management#Data Encryption#Hybrid Cloud#Deployment Models

Community Discussion

No community discussion yet for this question.

Full CCSP Practice