CCSP Cloud Data Security Practice Question
A cloud security architect is designing a data retention and deletion strategy for a SaaS application hosted in a public cloud. The organization must ensure that data is securely deleted when no longer needed, and that deletion is verifiable. Which two practices should be implemented? (Choose two.)
⚠ Common exam trap
The trap here is assuming that overwriting data with zeros is a valid secure deletion method in the cloud, when cloud storage abstraction makes it ineffective and unverifiable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use cryptographic erasure by destroying the encryption keys associated with the data.
Cryptographic erasure destroys keys to make data unrecoverable, and automated retention policies with logging provide verifiable deletion. Together, they ensure data is securely deleted and that deletion can be audited. These practices are well-suited to cloud environments where physical media control is absent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use cryptographic erasure by destroying the encryption keys associated with the data.
Why this is correct
Cryptographic erasure renders data unrecoverable by destroying the keys used to encrypt it. This is effective in cloud environments where physical media destruction is not possible. It provides a verifiable method of deletion because once keys are destroyed, the ciphertext cannot be decrypted, meeting the requirement for secure and verifiable deletion.
- ✗
Rely on the cloud provider's standard data deletion process as specified in their SLA.
Why it's wrong here
Provider standard deletion may not be verifiable by the customer and may not meet specific regulatory requirements for secure deletion. The organization needs to ensure deletion is verifiable, which typically requires customer-controlled mechanisms or audit evidence. Relying solely on the provider's process does not provide the necessary assurance.
- ✓
Implement a data retention policy that automatically deletes data after a set period and logs the deletion events.
Why this is correct
An automated retention policy ensures data is deleted according to schedule, and logging deletion events provides an audit trail for verification. This practice directly supports verifiable deletion by creating records that can be reviewed. It also enforces consistent data lifecycle management, which is essential for compliance.
- ✗
Overwrite data with zeros before deletion to ensure it cannot be recovered.
Why it's wrong here
In cloud environments, overwriting data with zeros is not reliable because the underlying storage may be virtualized, replicated, or on shared media. The customer typically does not have direct access to physical blocks. Cryptographic erasure or provider-specific secure deletion APIs are more appropriate and verifiable.
- ✗
Store all data in a single cloud region to simplify deletion.
Why it's wrong here
Storing data in a single region does not inherently ensure secure or verifiable deletion. It may simplify some aspects of data management, but deletion still requires proper mechanisms. This practice does not address the core requirements of secure deletion and verifiability, and could introduce other risks like regional outages.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.