Courseiva
Cloud Data Security →hardMultiple Select

CCSP Cloud Data Security Practice Question

A cloud security architect is designing a data retention and deletion strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a database service and object storage. Regulations require that customer data be permanently deleted upon request, including from backups and disaster recovery sites. Which TWO controls are MOST critical to ensure compliance? (Choose two.)

⚠ Common exam trap

The trap here is assuming that key rotation or audit logging can substitute for actual data deletion, when they only provide security or evidence, not removal.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure that the cloud provider's backup and disaster recovery processes include mechanisms to propagate deletions to all copies.

To ensure permanent deletion across backups and DR sites, cryptographic erase (destroying keys) and propagating deletions to all copies are critical. Key rotation and audit logs do not delete data, and versioning can retain data. These two controls together ensure that data is irrecoverable and removed from all storage locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Maintain an immutable audit log of all deletion requests and actions taken.

    Why it's wrong here

    Audit logs provide evidence of deletion but do not ensure that data is actually deleted from all locations. They are important for compliance reporting but are not a deletion mechanism. Without a technical control to remove data, logs alone cannot satisfy the requirement for permanent deletion.

  • ✗

    Use a centralized key management system with automated key rotation every 30 days.

    Why it's wrong here

    Key rotation limits the amount of data encrypted with a single key but does not delete data. Rotated keys are retained to decrypt old data, so the data remains recoverable. This does not achieve permanent deletion upon request. It is a security best practice but not a deletion control.

  • ✓

    Ensure that the cloud provider's backup and disaster recovery processes include mechanisms to propagate deletions to all copies.

    Why this is correct

    Backups and DR sites often retain data separately, so deletions must be propagated to them. Without this, data could persist indefinitely. This control is critical to ensure that deletion requests are honored across all storage locations, including offsite replicas, meeting the regulatory requirement.

  • ✓

    Implement cryptographic erase by destroying the encryption keys associated with the customer's data.

    Why this is correct

    Cryptographic erase ensures that data becomes unreadable by destroying the keys, which is effective even for backups and replicas if the keys are not backed up. This is critical for permanent deletion across all copies. It meets the requirement by making data irrecoverable without needing to physically locate and delete every copy.

  • ✗

    Enable versioning on object storage buckets to prevent accidental deletion.

    Why it's wrong here

    Versioning retains multiple versions of objects, which can hinder permanent deletion. It is designed to prevent data loss, not to facilitate deletion. In fact, versioning would require additional steps to delete all versions, complicating compliance with deletion requests. It is counterproductive for this scenario.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.