CCSP Cloud Data Security Practice Question
A cloud architect is implementing data loss prevention (DLP) for a data lake containing PII. They want to automatically detect and transform sensitive data like Social Security numbers and medical record numbers. Which THREE actions should they take? (Choose three.)
⚠ Common exam trap
The trap is that versioning and replication are common 'best practice' options that sound security-relevant, but they address durability and availability — not detection, classification, or transformation of sensitive data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply de-identification transforms such as masking or tokenization
Option C is correct because the cloud DLP API (e.g., Google Cloud DLP / Sensitive Data Protection) is the service that inspects data lake content and identifies predefined infoTypes such as US_SOCIAL_SECURITY_NUMBER and medical record numbers, which is the required detection step. Option A is correct because de-identification transforms like masking, tokenization, or format-preserving encryption are exactly the mechanisms DLP provides to irreversibly or reversibly transform the detected PII before it is stored or shared. Option D is correct because automated classification labels derived from DLP findings let the architect tag and govern the data lake objects by sensitivity level, enabling downstream policy enforcement and audit. Option B is not correct because bucket versioning only preserves object versions for recovery and does not detect or transform PII. Option E is not correct because cross-region replication addresses durability and availability, not data loss prevention or sensitive-data transformation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Apply de-identification transforms such as masking or tokenization
Why this is correct
Masking and tokenisation replace or substitute sensitive values so the data lake retains analytical utility while Social Security and medical record numbers are no longer exposed. This directly satisfies the stem's requirement to transform detected sensitive data, complementing scanning and classification rather than duplicating them.
- ✗
Enable bucket versioning
Why it's wrong here
Versioning retains multiple object revisions for recovery; it neither detects PII patterns nor transforms values, so it fails the detection and transformation requirement. It is tempting because versioning supports data durability and ransomware recovery, and would be correct where the requirement is preserving prior object states rather than masking sensitive content.
- ✓
Use cloud DLP API to scan for sensitive data types
Why this is correct
The cloud DLP API inspects data at rest in the lake, matching built-in infoTypes such as US Social Security numbers and medical record numbers. This satisfies the stem's detection requirement, providing the findings that drive subsequent de-identification and automated classification labelling.
- ✓
Configure automated classification labels based on DLP findings
Why this is correct
Automated classification labels derived from DLP findings tag each object by sensitivity, enabling policy-driven protection and audit reporting across the data lake. This satisfies the stem's need to act on detected PII systematically, complementing scanning and transformation rather than replacing either.
- ✗
Set up cross-region replication for durability
Why it's wrong here
Cross-region replication copies objects to another region for durability and availability; it performs no pattern detection or transformation of Social Security or medical record numbers. It is tempting because replication underpins resilience and disaster recovery, and would be correct where the requirement is geographic redundancy rather than automated sensitive-data handling.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.