CCSP Cloud Data Security Practice Question
A cloud storage bucket is configured with versioning enabled. A ransomware attack encrypts all objects in the bucket. How can the organization recover the original data?
⚠ Common exam trap
The trap is reaching for a dedicated 'backup' or 'replication' answer when the question explicitly states versioning is enabled — versioning itself is the recovery mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore from previous versions of the objects
Object versioning retains every prior version of an object, so when ransomware overwrites or encrypts the current version, the original unencrypted versions remain accessible. Recovery is performed by restoring the previous version (or promoting it to current) via the object versioning API or console.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the cloud provider's backup service to restore the bucket
Why it's wrong here
The provider's backup service restores from its own backup copies, which may not exist or may predate the attack; versioning already retains prior object versions, so recovery uses those instead. It is tempting because backups are a legitimate recovery mechanism, and would be correct where versioning is disabled or backups are the only retained copies.
- ✗
Replicate data from the cross-region replica
Why it's wrong here
Cross-region replication copies the current, encrypted object state, so it propagates the ransomware ciphertext rather than restoring pre-attack content. It is tempting because replication provides durability and regional failover for disasters such as region outages, but it offers no historical version retrieval, which is what versioning already preserves.
- ✗
Use the cloud provider's ransomware recovery service
Why it's wrong here
No generic provider ransomware recovery service restores objects; recovery here relies on the bucket's own versioning, which retains prior unencrypted object versions. Such services are tempting because providers market dedicated ransomware detection and response offerings, but those target backup infrastructure or endpoint estate, not object-version rollback within a versioned bucket.
- ✓
Restore from previous versions of the objects
Why this is correct
Versioning retains prior copies of each object, so overwritten or encrypted current versions can be replaced by restoring an earlier, unencrypted version. This recovers the original data without paying a ransom or relying on provider intervention.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.