Courseiva
Cloud Data Security →mediumMultiple Select

CCSP Cloud Data Security Practice Question

A cloud security architect is designing a data loss prevention (DLP) strategy for a cloud environment that stores sensitive customer data. Which TWO techniques should be implemented to proactively identify and protect sensitive data? (Select TWO.)

⚠ Common exam trap

CCSP often tests the distinction between preventive access controls (bucket policies, versioning) and proactive data-centric controls (DLP scanning, de-identification) — candidates pick access controls that do not actually identify or transform sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

De-identification transforms

Option B (de-identification transforms) is correct because techniques such as tokenization, masking, pseudonymization, and generalization remove or obscure personally identifiable information (PII) so that sensitive customer data is protected even when accessed or processed, directly supporting a proactive DLP strategy. Option C (automated DLP scanning for sensitive data) is correct because continuous automated discovery and classification of sensitive data (e.g., using pattern matching, regex, and ML-based classifiers) lets the organization proactively locate and tag PII across storage and data flows so protection controls can be applied. Option A (cross-region replication) is not a DLP control; it improves durability and availability but can actually widen the data exposure footprint. Option D (bucket policies blocking all public access) is a useful access control, but it is reactive perimeter hardening rather than a technique for identifying sensitive data. Option E (enabling object versioning) supports recovery and immutability but does nothing to discover, classify, or de-identify sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cross-region replication

    Why it's wrong here

    Cross-region replication copies objects between geographic locations for durability and disaster recovery; it neither inspects content nor classifies sensitive customer data, so it cannot proactively identify anything. It is tempting because replication does protect data availability, and it would be the right choice when the requirement is resilience or latency rather than discovery and protection.

  • ✓

    De-identification transforms

    Why this is correct

    De-identification transforms (tokenisation, masking, generalisation) remove or replace direct identifiers so stored records no longer expose customer identities, satisfying the requirement to protect sensitive data at rest. Unlike detection-only controls, they proactively reduce the data's sensitivity before exposure, limiting breach impact and supporting privacy compliance.

  • ✓

    Automated DLP scanning for sensitive data

    Why this is correct

    Automated DLP scanning inspects stored objects against pattern and classifier rules, discovering sensitive customer data such as card numbers or personal identifiers. This proactive detection satisfies the requirement to identify sensitive data before exfiltration or misuse occurs.

  • ✗

    Bucket policies blocking all public access

    Why it's wrong here

    Bucket policies blocking public access are preventive access controls, not discovery or classification of sensitive data. They are tempting because public exposure is a genuine DLP concern, and such policies would be correct for hardening storage against anonymous reads, but they neither identify nor label sensitive content.

  • ✗

    Enabling object versioning

    Why it's wrong here

    Object versioning preserves prior object states against overwrite or deletion; it performs no sensitive-data discovery or protection. It tempts because versioning supports recovery after destructive incidents, and it would be the right choice for resilience against ransomware or accidental deletion, not for proactive DLP identification.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.