Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A cloud security team is reviewing access controls for a storage bucket containing sensitive data. They want to ensure that only authorized users can access the data and that access is logged for auditing. Which cloud-native mechanism should they implement?

⚠ Common exam trap

Watch out — candidates often confuse data protection mechanisms like encryption with access control and auditing, which are separate concerns.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identity and Access Management (IAM) policies with logging enabled

IAM policies with logging enabled provide both access control and auditability by defining permissions and recording access events. Network ACLs, bucket policies without logging, and encryption do not fully satisfy the requirement to control and log user access to the data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encryption at rest with key rotation

    Why it's wrong here

    Encryption at rest protects data confidentiality but does not control access or provide audit logs. Key rotation is a key management practice, not an access control mechanism. This option does not meet the need for authorized access and logging.

  • ✗

    Network Access Control Lists (ACLs) with flow logs

    Why it's wrong here

    Network ACLs control traffic at the subnet level, not user access to storage buckets. Flow logs capture network traffic but do not provide user-level access control or detailed audit trails for data access. This option addresses network security, not identity-based access.

  • ✓

    Identity and Access Management (IAM) policies with logging enabled

    Why this is correct

    IAM policies define who can access resources, and enabling logging (e.g., cloud audit logs) records access attempts. This combination ensures both access control and auditability, directly meeting the scenario's requirements. It is a fundamental cloud security practice.

  • ✗

    Storage bucket policies with versioning enabled

    Why it's wrong here

    Bucket policies can control access, but versioning is for data recovery and does not provide audit logging of access. Without logging, the team cannot audit who accessed the data. This option partially addresses access control but misses the auditing requirement.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.