Courseiva
easyMultiple Choice

ISC2 CC Practice Question: A small business uses a cloud file storage…

A small business uses a cloud file storage service that allows sharing links. An employee mistakenly shared a folder containing customer data via a public link. The business wants to prevent such incidents in the future without blocking legitimate sharing. Which access control method should they implement?

⚠ Common exam trap

The trap is choosing encryption or watermarking as a preventive measure: candidates may think encrypting files prevents unauthorized access, but encryption does not stop someone with the link from accessing the decrypted content if the service handles decryption; authentication is the direct control for link access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Require authentication for shared links

Requiring authentication for shared links ensures that only authorized users can access the shared content, preventing public exposure of sensitive data while still allowing legitimate sharing with specific individuals. This balances security with the need to share files externally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable all external sharing

    Why it's wrong here

    Disabling external sharing removes the capability entirely, so legitimate sharing with partners and clients also stops, failing the stem's requirement to keep it. It is tempting because it guarantees no public link can ever leak data, and it would be correct where regulatory or contractual rules forbid any external sharing at all.

  • ✓

    Require authentication for shared links

    Why this is correct

    Requiring authentication for shared links forces recipients to sign in, typically via Microsoft Entra ID, before accessing files. This satisfies the constraint of preventing anonymous public exposure while preserving legitimate external sharing, since links still work for authenticated users. Anonymous access, the root cause of the leak, is eliminated without disabling sharing entirely.

  • ✗

    Use watermarking on documents

    Why it's wrong here

    Watermarking overlays visible or invisible marks on documents to trace leaks and deter screenshots; it does not govern whether a sharing link is public or restricted, so the folder could still be shared externally. It fits forensic tracing after distribution, not link-scope control.

  • ✗

    Encrypt all files

    Why it's wrong here

    Encrypting files protects confidentiality if storage or links are compromised, but a public link still grants access to anyone holding it, and authorised recipients can decrypt. It suits data-at-rest protection, whereas the requirement is restricting how sharing links are scoped and permissioned.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.