easyMultiple Choice
ISC2 CC Practice Question: A small business uses a cloud file storage…
A small business uses a cloud file storage service that allows sharing links. An employee mistakenly shared a folder containing customer data via a public link. The business wants to prevent such incidents in the future without blocking legitimate sharing. Which access control method should they implement?
⚠ Common exam trap
The trap is choosing encryption or watermarking as a preventive measure: candidates may think encrypting files prevents unauthorized access, but encryption does not stop someone with the link from accessing the decrypted content if the service handles decryption; authentication is the direct control for link access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require authentication for shared links
Requiring authentication for shared links ensures that only authorized users can access the shared content, preventing public exposure of sensitive data while still allowing legitimate sharing with specific individuals. This balances security with the need to share files externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable all external sharing
Why it's wrong here
Disabling external sharing removes the capability entirely, so legitimate sharing with partners and clients also stops, failing the stem's requirement to keep it. It is tempting because it guarantees no public link can ever leak data, and it would be correct where regulatory or contractual rules forbid any external sharing at all.
- ✓
Require authentication for shared links
Why this is correct
Requiring authentication for shared links forces recipients to sign in, typically via Microsoft Entra ID, before accessing files. This satisfies the constraint of preventing anonymous public exposure while preserving legitimate external sharing, since links still work for authenticated users. Anonymous access, the root cause of the leak, is eliminated without disabling sharing entirely.
- ✗
Use watermarking on documents
Why it's wrong here
Watermarking overlays visible or invisible marks on documents to trace leaks and deter screenshots; it does not govern whether a sharing link is public or restricted, so the folder could still be shared externally. It fits forensic tracing after distribution, not link-scope control.
- ✗
Encrypt all files
Why it's wrong here
Encrypting files protects confidentiality if storage or links are compromised, but a public link still grants access to anyone holding it, and authorised recipients can decrypt. It suits data-at-rest protection, whereas the requirement is restricting how sharing links are scoped and permissioned.
Go deeper
Related to this question
Learn chapter
Access Control Fundamentals
Key term
Exposure
Exposure is the measure of potential loss or harm to an organization's assets when a vulnerability is exploited by a threat, often expressed as the window of time or degree of access an attacker has.
Key term
Folder
A folder is a logical container used to organize and group digital files, resources, or cloud-based assets within a system or platform.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.