Courseiva
Cloud Data Security →mediumMultiple Choice

CCSP Cloud Data Security Practice Question

A cloud security architect is designing a data retention strategy for a SaaS application hosted on a public cloud. The application stores user-generated content in a multi-tenant database. Regulatory requirements mandate that user data be permanently deleted upon request within 30 days. The architect needs to ensure that backups and replicas also honor the deletion. Which approach BEST ensures compliance with the deletion requirement?

⚠ Common exam trap

The trap here is assuming that deleting records from the primary database and replicas is sufficient, when backups and immutable storage often retain data beyond the deletion window.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a database that supports per-user encryption keys and crypto-shredding by deleting the keys upon user request.

Crypto-shredding is the most effective way to ensure permanent deletion in a multi-tenant cloud environment with backups and replicas. By encrypting each user's data with a unique key and deleting the key, the data becomes irrecoverable everywhere it exists, including backups. This satisfies the 30-day deletion requirement without needing to track and erase every copy, which is impractical in distributed systems with immutable backups. Other methods leave data remnants in backups or fail to permanently erase data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use a database that supports per-user encryption keys and crypto-shredding by deleting the keys upon user request.

    Why this is correct

    Crypto-shredding involves encrypting each user's data with a unique key and then deleting the key when deletion is requested. This renders the data irrecoverable, even in backups and replicas, because the ciphertext cannot be decrypted. It effectively achieves permanent deletion without having to locate and erase every copy. This is a robust method for complying with deletion requirements in distributed systems.

  • ✗

    Implement soft delete by marking records as deleted and filtering them out in the application, while retaining them in the database for audit purposes.

    Why it's wrong here

    Soft delete does not permanently remove data; it merely hides it from the application. The data remains in the database and backups, violating the requirement for permanent deletion within 30 days. While it may support audit or recovery, it fails the regulatory mandate. Soft delete is not a compliant approach when data must be irrecoverably erased.

  • ✗

    Configure the database to automatically purge records older than 30 days using a time-to-live (TTL) setting.

    Why it's wrong here

    TTL settings automatically delete records after a specified period, but they are based on record age, not on user deletion requests. If a user requests deletion immediately after creating data, the TTL will not remove it until 30 days have passed, which may be acceptable, but TTL does not guarantee deletion from backups. Backups may still contain the data beyond the TTL period. TTL is useful for retention policies but not for on-demand deletion.

  • ✗

    Schedule a nightly job that runs a DELETE SQL statement to remove user records from the primary database and all replicas.

    Why it's wrong here

    Running DELETE statements removes data from the primary database and possibly replicas, but it does not address backups. Backups may retain the data for their retention period, which could exceed 30 days. Additionally, replicas may have lag, and the deletion may not propagate immediately. This approach is insufficient for ensuring permanent deletion across all copies, especially immutable backups.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.