CCSP Cloud Data Security Practice Question
A cloud security team is implementing a data classification scheme for objects stored in a cloud environment. They need to ensure that classification labels persist with the data, travel with it when copied or moved between services, and can be used to enforce access and DLP policies automatically. Which approach BEST achieves these outcomes?
⚠ Common exam trap
The trap here is assuming that bucket-level classification or naming conventions provide object-level, portable labels, when only embedded metadata or tags travel with the data and drive automated enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Embed classification metadata as tags or object metadata that are preserved through supported copy and move operations and referenced by policy engines.
Embedding classification as tags or object metadata keeps labels attached to the data and allows them to be carried through supported copy and move operations. Policy engines and DLP services can then enforce access and handling rules automatically based on those labels. Spreadsheets, bucket-level classification, and naming conventions lack persistence, portability, and reliable automated enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store classification labels in a separate spreadsheet maintained by the data governance team and update it after each data movement.
Why it's wrong here
A manual spreadsheet is disconnected from the data, prone to staleness, and cannot enforce policies automatically. Labels would not travel with objects when copied or moved, and enforcement would depend on human processes. This approach fails the requirements for persistence, portability, and automated policy enforcement.
- ✗
Use file naming conventions that include the classification level in the object name and enforce policies based on name patterns.
Why it's wrong here
Naming conventions are fragile, easily bypassed, and not reliably preserved when objects are renamed or transformed by services. Policy enforcement based on name patterns is brittle and can produce false positives or misses. This approach does not provide durable, machine-readable labels that policy engines can trust.
- ✓
Embed classification metadata as tags or object metadata that are preserved through supported copy and move operations and referenced by policy engines.
Why this is correct
Embedding classification as tags or object metadata keeps labels attached to the data, and supported copy and move operations preserve them when configured correctly. Policy engines and DLP services can reference these labels to enforce access and handling rules automatically. This satisfies persistence, portability, and automated enforcement in a scalable way.
- ✗
Apply classification only at the storage bucket level and rely on bucket policies to enforce access.
Why it's wrong here
Bucket-level classification cannot distinguish objects with different sensitivity within the same bucket, so it lacks the granularity needed for mixed data. Labels do not travel with individual objects when moved to other buckets or services. This approach cannot support automated, object-level DLP and access enforcement across services.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.