CCSP Cloud Data Security Practice Question
A cloud security team is reviewing access controls for a storage bucket containing sensitive data. They want to ensure that only authorized users can access the data and that access is logged for auditing. Which cloud-native mechanism should they implement?
⚠ Common exam trap
Watch out — candidates often confuse data protection mechanisms like encryption with access control and auditing, which are separate concerns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identity and Access Management (IAM) policies with logging enabled
IAM policies with logging enabled provide both access control and auditability by defining permissions and recording access events. Network ACLs, bucket policies without logging, and encryption do not fully satisfy the requirement to control and log user access to the data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encryption at rest with key rotation
Why it's wrong here
Encryption at rest protects data confidentiality but does not control access or provide audit logs. Key rotation is a key management practice, not an access control mechanism. This option does not meet the need for authorized access and logging.
- ✗
Network Access Control Lists (ACLs) with flow logs
Why it's wrong here
Network ACLs control traffic at the subnet level, not user access to storage buckets. Flow logs capture network traffic but do not provide user-level access control or detailed audit trails for data access. This option addresses network security, not identity-based access.
- ✓
Identity and Access Management (IAM) policies with logging enabled
Why this is correct
IAM policies define who can access resources, and enabling logging (e.g., cloud audit logs) records access attempts. This combination ensures both access control and auditability, directly meeting the scenario's requirements. It is a fundamental cloud security practice.
- ✗
Storage bucket policies with versioning enabled
Why it's wrong here
Bucket policies can control access, but versioning is for data recovery and does not provide audit logging of access. Without logging, the team cannot audit who accessed the data. This option partially addresses access control but misses the auditing requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.