CCSP Cloud Data Security Practice Question
A cloud architect is designing a data retention solution for a SaaS application hosted with a cloud provider. The organization must ensure that customer data is irretrievably destroyed at the end of its retention period, even though the data is stored in a multi-tenant object storage service with underlying solid-state drives. Which approach best satisfies this requirement?
⚠ Common exam trap
The trap here is assuming that a standard delete operation or lifecycle expiration physically erases data from cloud storage media.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use crypto-shredding: encrypt each customer's data with a unique data encryption key and destroy the key when retention expires.
Crypto-shredding is the most reliable method for irretrievable destruction in multi-tenant cloud storage because it makes data unreadable by destroying the key. Physical destruction or overwriting is impractical when the provider controls the media and may keep replicas. Destroying a unique key per customer ensures that even residual ciphertext cannot be decrypted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Issue a delete command to the object storage API and rely on the provider's background garbage collection to erase the data blocks.
Why it's wrong here
A delete command typically removes metadata and marks blocks for reuse, but the underlying data may persist until overwritten. Provider garbage collection is not guaranteed to sanitize all replicas or backups within the required timeframe, so it cannot ensure irretrievable destruction for compliance.
- ✗
Overwrite the objects with random data before deleting them, then request a certificate of media destruction from the provider.
Why it's wrong here
Overwriting in a multi-tenant object store is not reliable because the provider abstracts the physical media and may maintain immutable replicas or snapshots. Cloud providers generally will not issue media destruction certificates for logical objects, so this approach does not guarantee destruction.
- ✓
Use crypto-shredding: encrypt each customer's data with a unique data encryption key and destroy the key when retention expires.
Why this is correct
Crypto-shredding renders data unrecoverable by deleting the encryption key. In a multi-tenant cloud object store, physical destruction of specific data is not feasible, but destroying the unique key makes the ciphertext useless. This meets the irretrievable destruction requirement without relying on provider media sanitization.
- ✗
Move the data to an infrequent access storage tier and configure a lifecycle policy to expire it after the retention period.
Why it's wrong here
Lifecycle expiration deletes the object reference but does not sanitize the underlying storage media. Data may remain in backups or replicas, and the provider controls physical destruction. This does not meet the requirement for irretrievable destruction of customer data.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.