Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A company is implementing a data classification policy for cloud storage. They want to label objects with tags indicating the sensitivity level (e.g., 'Confidential'). Which benefit does tagging resources with classification labels provide?

⚠ Common exam trap

The trap here is conflating classification tagging with encryption or cost optimization — candidates often assume that labeling data 'Confidential' automatically encrypts it, when in fact tags only enable policy enforcement and visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It allows enforcement of data handling policies based on sensitivity

Tags applied to cloud resources act as metadata that policy engines, DLP tools, and automation can evaluate at runtime. By labeling objects as 'Confidential', 'Internal', or 'Public', organizations can attach conditional policies (e.g., deny public access, require encryption, restrict cross-region replication) that enforce handling rules based on the classification. This is the primary governance benefit of classification tagging.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It provides client-side encryption keys

    Why it's wrong here

    Tags are metadata labels; they do not generate, store or manage client-side encryption keys, which come from a KMS or customer-managed key system. Tagging is tempting here because classification often drives key selection policies, but the label itself only records sensitivity, enabling policy enforcement and audit rather than supplying cryptographic material.

  • ✗

    It automatically encrypts data at rest

    Why it's wrong here

    Tags are metadata and do not perform encryption; encryption at rest is applied by the storage service or customer-managed keys regardless of labels. Tagging is tempting because classification frequently triggers encryption policy, but the tag only records sensitivity for policy evaluation, auditing and access decisions rather than executing the cryptographic operation itself.

  • ✗

    It reduces storage costs by moving data to cheaper tiers

    Why it's wrong here

    Tags are metadata and do not move objects between storage classes; lifecycle rules or autoclass perform tiering based on age or access patterns. Tagging is tempting because lifecycle policies can reference classification labels, but the label alone only records sensitivity for policy, audit and access decisions, not cost reduction.

  • ✓

    It allows enforcement of data handling policies based on sensitivity

    Why this is correct

    Classification tags attach sensitivity metadata to objects, enabling policy engines to enforce handling rules such as encryption, access restrictions and retention automatically. This satisfies the stem's requirement that labelling drives enforcement of data handling policies based on sensitivity.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.