CCSP Cloud Data Security Practice Question
A cloud security team is implementing data discovery and classification for a multi-cloud environment. They need to identify sensitive data such as personally identifiable information (PII) and protected health information (PHI) across structured and unstructured data stores. Which TWO approaches are MOST effective for accurate and scalable data discovery in this scenario? (Choose two.)
⚠ Common exam trap
The trap here is assuming that encryption eliminates the need for data discovery and classification, or that manual tagging can scale in a multi-cloud environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use cloud-native data discovery services that integrate with the provider's storage and database services.
Cloud-native discovery services offer deep integration and scalability within each provider, while third-party multi-cloud tools provide a unified, cross-provider view and consistent classification. Together, they enable accurate and scalable discovery across structured and unstructured data in a multi-cloud environment. Manual tagging and network DLP are not sufficient for comprehensive data-at-rest discovery, and encryption does not remove the need for classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use cloud-native data discovery services that integrate with the provider's storage and database services.
Why this is correct
Cloud-native discovery services are designed to work with the provider's storage and database offerings, offering deep integration, automatic scaling, and reduced operational overhead. They can scan objects, files, and databases for sensitive data patterns and often include prebuilt classifiers for PII, PHI, and other data types. This makes them highly effective for multi-cloud environments when used per provider, though cross-cloud management may require additional tooling.
- ✓
Deploy a third-party data discovery tool that supports multiple cloud providers and can scan both structured and unstructured data.
Why this is correct
A third-party tool with multi-cloud support provides a unified view and consistent classification across different providers, which is essential in a multi-cloud environment. It can scan various data stores (object storage, databases, file shares) and apply custom or industry-standard classifiers. This approach ensures scalability and accuracy by centralizing policy and reporting, though it may require additional configuration and permissions.
- ✗
Use encryption to protect all data and assume that encrypted data does not need classification.
Why it's wrong here
Encryption protects data confidentiality but does not eliminate the need for classification. Encrypted data still needs to be identified for compliance, access control, and retention purposes. Assuming encrypted data is exempt from classification is a dangerous misconception that can lead to regulatory violations. Encryption is not a substitute for discovery and classification.
- ✗
Implement network-based data loss prevention (DLP) appliances to inspect data in transit.
Why it's wrong here
Network DLP inspects data in transit, not data at rest. It cannot discover sensitive data stored in cloud storage or databases unless it is being transmitted. This approach does not provide comprehensive discovery of data at rest and is not scalable for multi-cloud storage scanning. It may complement discovery but is not a primary method.
- ✗
Rely on manual data tagging by data owners during data creation.
Why it's wrong here
Manual tagging is error-prone, inconsistent, and not scalable for large volumes of data. It depends on human diligence and may miss sensitive data, especially in unstructured formats. While tagging can complement automated discovery, it is not effective as a primary method for accurate and scalable discovery in a multi-cloud environment.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.