Courseiva
mediumMultiple Select

CCSP Practice Question: A cloud security team is implementing a data…

A cloud security team is implementing a data discovery and classification program for their SaaS applications. Which TWO statements accurately describe best practices for data classification in the cloud?

⚠ Common exam trap

CCSP often tests the misconception that the cloud provider is responsible for classifying customer data, when in fact classification is a customer responsibility, and that tokenization alone can replace classification, which is false.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Automated tools can scan cloud storage and apply classification labels based on content inspection.

Option C is correct because automated discovery tools (such as CASB or native cloud DLP scanners) can crawl SaaS storage, inspect content using pattern matching, regex, keywords, and ML classifiers, and then apply classification labels (e.g., Public, Confidential, PII) at scale, which is essential in large cloud environments where manual labeling is impractical. Option D is correct because DLP policies consume classification labels and content inspection results to monitor and control data in motion (email, uploads, API traffic) and at rest (SaaS repositories), enforcing rules such as blocking exfiltration of labeled sensitive data, thereby operationalizing the classification scheme. Option A is not correct because manual user classification is inconsistent, error-prone, and unscalable in large cloud environments, so automated methods are preferred. Option B is not correct because tokenization is a data protection technique that substitutes sensitive values with tokens; it still requires identifying and classifying the sensitive data first, so it cannot replace classification. Option E is not correct because classification labels are typically applied by the data owner or via automated tools under the organization's governance, not by the cloud service provider, since the provider does not know the business context or sensitivity of the customer's data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manual classification by users is more accurate than automated methods in large-scale cloud environments.

    Why it's wrong here

    Manual labelling cannot scale to SaaS data volumes and is inconsistent across users, whereas automated discovery tools apply policy-driven classification continuously. It tempts because human judgement suits small, high-value datasets where context matters, but large cloud environments require automation as the primary mechanism.

  • ✗

    Tokenization can replace data classification by eliminating the need to identify sensitive data.

    Why it's wrong here

    Tokenisation substitutes sensitive values with surrogates but still requires classification to know which fields are sensitive and which vault or policy applies. It is tempting because tokenised data looks de-identified, and would be correct for reducing breach scope, yet it complements rather than replaces classification.

  • ✓

    Automated tools can scan cloud storage and apply classification labels based on content inspection.

    Why this is correct

    Automated scanning satisfies the discovery requirement by inspecting object content and metadata across SaaS storage, then applying labels consistently at scale. This removes the manual effort and inconsistency that make human-only classification impractical for large cloud data volumes.

  • ✓

    Data loss prevention (DLP) policies can enforce classification by monitoring and controlling data in motion and at rest.

    Why this is correct

    DLP enforces the classification scheme by inspecting data in motion and at rest, blocking or alerting on policy violations. This closes the gap between labelling data and actually protecting it, satisfying the program's requirement that classification drives enforceable controls.

  • ✗

    Data classification labels must be applied by the cloud service provider to ensure consistency.

    Why it's wrong here

    Classification labels are applied by the data owner or classification tooling, not the provider, since the provider lacks business context to judge sensitivity. It tempts because providers do enforce infrastructure-level controls, but data classification responsibility stays with the customer under shared responsibility.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.