CCSP Cloud Data Security Practice Question
A cloud security analyst is reviewing data flows for a web application that stores session tokens in a cloud database. The tokens are considered sensitive and must be protected both at rest and in transit. The database supports encryption at rest using provider-managed keys, and the application connects over a private network link. Which additional control best protects the session tokens from being exposed in the event of a database snapshot being copied to another region?
⚠ Common exam trap
The trap here is assuming that provider-managed encryption or a regional policy is sufficient, when the scenario requires that a copied snapshot remain protected under keys the organization can control and revoke.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable customer-managed keys for the database encryption so snapshots copied to another region remain encrypted under keys the organization controls.
Customer-managed keys are the best additional control because they keep snapshot encryption under the organization's key policy, so a snapshot copied to another region remains unreadable without those keys. Audit logging, hashing, and bucket policies either detect rather than prevent, break application functionality, or can be bypassed by privileged actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Restrict snapshot sharing to the same region using a bucket policy that denies cross-region replication.
Why it's wrong here
A bucket policy can limit replication, but it does not protect the snapshot if it is copied through other means such as manual export or administrative action. The scenario specifically contemplates a snapshot being copied to another region, so the control must protect the data itself. Encryption with customer-controlled keys is more robust than relying solely on policy restrictions.
- ✗
Configure the application to hash session tokens before storing them so the database never contains the original token values.
Why it's wrong here
Hashing session tokens would break session validation because the application needs the original token to compare against the client's presented value. A hash is one-way, so the server could not reconstruct or verify the session state reliably unless it also stores a lookup mechanism. This approach is impractical for session management and does not address snapshot exposure directly.
- ✗
Enable database audit logging to record every query that accesses the session token table and alert on unusual access patterns.
Why it's wrong here
Audit logging detects and records access but does not prevent a copied snapshot from being read. If an attacker obtains the snapshot, the tokens remain exposed regardless of logging. The scenario asks for protection in the event of snapshot copying, which requires a preventive encryption control rather than a detective monitoring control.
- ✓
Enable customer-managed keys for the database encryption so snapshots copied to another region remain encrypted under keys the organization controls.
Why this is correct
Customer-managed keys ensure that snapshots retain encryption tied to the organization's key policy, so a copied snapshot cannot be decrypted without access to those keys. This protects the session tokens even if the snapshot leaves the original region. Provider-managed keys may still protect the snapshot, but the organization has less control over access and revocation.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.