Courseiva
Cloud Data Security →hardMultiple Select

CCSP Cloud Data Security Practice Question

A cloud security team is implementing a data discovery and classification solution for a multi-cloud environment. They need to identify and classify data stored in object storage buckets across AWS, Azure, and Google Cloud. The solution must automatically detect sensitive data such as personally identifiable information (PII) and protected health information (PHI). Which TWO capabilities are MOST critical for the solution to effectively classify data across these platforms? (Choose two.)

⚠ Common exam trap

The trap here is selecting operational or remediation features, such as SIEM integration or auto-remediation, as critical for classification, when the core requirements are data access and pattern detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Prebuilt or customizable pattern recognition for PII and PHI, such as regular expressions and machine learning models.

The two most critical capabilities for multi-cloud data discovery and classification are the ability to access data via native APIs and the ability to recognize sensitive data patterns. Native API integration enables the solution to enumerate and sample objects across different cloud storage services. Pattern recognition, including regular expressions and machine learning, allows accurate identification of PII and PHI. Together, these enable effective classification. Other options are either post-classification actions or unrelated security controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Integration with a SIEM to forward all classification events for real-time alerting.

    Why it's wrong here

    SIEM integration is useful for monitoring and alerting on security events, but it is not critical for the core function of data discovery and classification. The classification solution must first identify and label data; forwarding events to a SIEM is a secondary operational step. While valuable, it does not enable the classification itself, so it is not one of the most critical capabilities for the stated goal.

  • ✗

    The ability to automatically remediate misclassified data by moving it to a secure bucket.

    Why it's wrong here

    Automated remediation is a response action that occurs after classification. While it can be a useful feature, it is not critical for the classification process itself. The question asks for capabilities needed to effectively classify data, not to remediate it. Remediation requires classification to be accurate, but it is not a prerequisite for discovery and classification. Therefore, it is not one of the two most critical capabilities.

  • ✗

    The ability to enforce encryption at rest using provider-managed keys on all discovered buckets.

    Why it's wrong here

    While encryption at rest is important for data protection, it is not a critical capability for data discovery and classification. The classification process needs to read and analyze data content, which may be encrypted. However, the solution itself does not need to enforce encryption; that is a separate control. This option describes a security control, not a discovery capability, and is therefore not essential for classification.

  • ✓

    Prebuilt or customizable pattern recognition for PII and PHI, such as regular expressions and machine learning models.

    Why this is correct

    Effective classification requires the ability to identify sensitive data patterns. Prebuilt or customizable detectors for PII and PHI enable the solution to recognize formats like Social Security numbers, credit card numbers, and medical record identifiers. Machine learning models can improve accuracy by learning from context. Without these, the solution cannot accurately classify data, especially across diverse data types and languages.

  • ✓

    Support for native API integration with each cloud provider's storage service to enumerate and sample objects.

    Why this is correct

    To discover and classify data across multiple clouds, the solution must be able to access and read data from each provider's object storage. Native API integration allows the tool to list buckets, enumerate objects, and retrieve samples for analysis. Without this, the solution cannot see the data and thus cannot classify it. This is a foundational requirement for any multi-cloud data discovery tool.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.