CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud security team is evaluating controls for protecting data in a PaaS database service. The database must support tenant isolation, and the team wants to prevent one tenant's queries from accessing another tenant's rows. Which TWO controls BEST achieve row-level tenant isolation? (Choose two.)
⚠ Common exam trap
The trap here is treating encryption at rest or application-side filtering as tenant isolation, when only database-enforced controls such as row-level security or schema-scoped privileges actually prevent cross-tenant row access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use separate database schemas per tenant with distinct database roles and grant only schema-scoped privileges.
Row-level security policies and schema-per-tenant with role-scoped grants both enforce isolation inside the database engine, so cross-tenant access is blocked regardless of application behavior. TDE, application-side filtering, and auditing do not prevent a query from reaching another tenant's rows, making them insufficient as primary isolation controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable database auditing and alert on queries that return more than a threshold number of rows.
Why it's wrong here
Auditing detects suspicious activity after the fact but does not prevent cross-tenant reads. An attacker or buggy query can exfiltrate data before alerts trigger, and volume thresholds do not map to tenant boundaries, so this is a detective, not preventive, control.
- ✓
Use separate database schemas per tenant with distinct database roles and grant only schema-scoped privileges.
Why this is correct
Schema-per-tenant with role-scoped grants limits each tenant's session to its own schema, providing a strong boundary. Combined with row-level policies or as an alternative, it prevents cross-tenant access at the privilege layer and reduces the blast radius of a compromised application credential.
- ✓
Implement row-level security policies in the database engine that filter rows based on the authenticated tenant identity.
Why this is correct
Row-level security enforces filtering at the engine level using the session's tenant identity, so even a crafted query cannot return another tenant's rows. This is the canonical database-native control for multi-tenant row isolation and works regardless of application bugs in query construction.
- ✗
Enable transparent data encryption on the database so that rows are encrypted at rest with a service-managed key.
Why it's wrong here
TDE protects data at rest against media theft but does not differentiate tenants at query time. Once the database is running, all tenants' rows are decrypted for queries, so a query with access to the connection can read any row. It does not provide row-level isolation.
- ✗
Configure the application to append a tenant_id filter to every generated SQL statement.
Why it's wrong here
Application-side filtering is fragile because a single missed or bypassed query path exposes cross-tenant data. It relies entirely on developer discipline and does not enforce isolation at the data layer, so it fails as a primary control for row-level tenant isolation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.