Courseiva
easyMultiple ChoiceObjective-mapped

CCSP Practice Question: A cloud security architect is implementing a data…

A cloud security architect is implementing a data classification scheme. They need to ensure that data labeled 'confidential' is automatically encrypted when stored in cloud storage. Which approach best achieves this?

⚠ Common exam trap

ISC2 often tests the misconception that DLP tools can enforce encryption at the point of upload, when in fact DLP is typically a post-storage or in-transit scanning mechanism, not a storage-layer encryption enforcer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure cloud storage bucket policies to enforce encryption for objects with a 'confidential' tag

Cloud storage bucket policies can be configured to enforce server-side encryption for objects that carry a specific metadata tag (e.g., 'confidential'). This approach automates encryption at the point of storage without requiring separate buckets or manual intervention, ensuring that all tagged data is encrypted as a condition of the write operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use a separate storage bucket for confidential data with default encryption enabled

    Why it's wrong here

    Requires users to know which bucket to use, not automatic.

  • Deploy a data loss prevention (DLP) tool to scan and encrypt on upload

    Why it's wrong here

    DLP is for detection, not enforcement of encryption.

  • Configure cloud storage bucket policies to enforce encryption for objects with a 'confidential' tag

    Why this is correct

    Automated enforcement based on classification labels.

  • Train users to manually encrypt files before uploading

    Why it's wrong here

    Manual process is not reliable for compliance.

About these practice questions

One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.