Courseiva
Cloud Data Security →mediumMultiple Select

CCSP Cloud Data Security Practice Question

A cloud security architect is designing a data retention and deletion strategy for a SaaS application hosted in a public cloud. The organization must ensure that data is securely deleted when no longer needed, and that deletion is verifiable. Which two practices should be implemented? (Choose two.)

⚠ Common exam trap

The trap here is assuming that overwriting data with zeros is a valid secure deletion method in the cloud, when cloud storage abstraction makes it ineffective and unverifiable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use cryptographic erasure by destroying the encryption keys associated with the data.

Cryptographic erasure destroys keys to make data unrecoverable, and automated retention policies with logging provide verifiable deletion. Together, they ensure data is securely deleted and that deletion can be audited. These practices are well-suited to cloud environments where physical media control is absent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use cryptographic erasure by destroying the encryption keys associated with the data.

    Why this is correct

    Cryptographic erasure renders data unrecoverable by destroying the keys used to encrypt it. This is effective in cloud environments where physical media destruction is not possible. It provides a verifiable method of deletion because once keys are destroyed, the ciphertext cannot be decrypted, meeting the requirement for secure and verifiable deletion.

  • ✗

    Rely on the cloud provider's standard data deletion process as specified in their SLA.

    Why it's wrong here

    Provider standard deletion may not be verifiable by the customer and may not meet specific regulatory requirements for secure deletion. The organization needs to ensure deletion is verifiable, which typically requires customer-controlled mechanisms or audit evidence. Relying solely on the provider's process does not provide the necessary assurance.

  • ✓

    Implement a data retention policy that automatically deletes data after a set period and logs the deletion events.

    Why this is correct

    An automated retention policy ensures data is deleted according to schedule, and logging deletion events provides an audit trail for verification. This practice directly supports verifiable deletion by creating records that can be reviewed. It also enforces consistent data lifecycle management, which is essential for compliance.

  • ✗

    Overwrite data with zeros before deletion to ensure it cannot be recovered.

    Why it's wrong here

    In cloud environments, overwriting data with zeros is not reliable because the underlying storage may be virtualized, replicated, or on shared media. The customer typically does not have direct access to physical blocks. Cryptographic erasure or provider-specific secure deletion APIs are more appropriate and verifiable.

  • ✗

    Store all data in a single cloud region to simplify deletion.

    Why it's wrong here

    Storing data in a single region does not inherently ensure secure or verifiable deletion. It may simplify some aspects of data management, but deletion still requires proper mechanisms. This practice does not address the core requirements of secure deletion and verifiability, and could introduce other risks like regional outages.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.