mediumMultiple Choice
CCSP Practice Question: Migrating sensitive customer data to the cloud
A company is migrating sensitive customer data to the cloud. They need to classify data according to the organization's data classification policy, which includes public, internal, confidential, and restricted categories. Which of the following is the MOST important step to ensure data classification is effective in the cloud?
⚠ Common exam trap
ISC2 often tests the misconception that encryption alone is sufficient for data classification, but encryption is a protection mechanism, not a classification or enforcement mechanism; the trap is confusing security controls with data governance processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate classification labels with DLP and access control policies
Integrating classification labels with DLP and access control policies ensures that the classification scheme is enforced automatically, not just documented. This allows the cloud infrastructure to apply appropriate protections (e.g., blocking unauthorized access or preventing data exfiltration) based on the label, making classification actionable and effective in a dynamic cloud environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign a data custodian to manually tag data objects
Why it's wrong here
Manual tagging by a custodian does not scale or stay consistent across cloud data volumes, so labels drift and classification becomes unreliable. It is tempting because custodians own data handling, but automated discovery and labelling is required to apply policy consistently at cloud scale.
- ✗
Implement encryption for all data at rest and in transit
Why it's wrong here
Encryption protects data confidentiality but does not itself assign or enforce classification labels, so it cannot make classification effective. It is tempting because encryption is a core cloud data protection control, and would be the answer if the requirement were protecting data rather than classifying it.
- ✓
Integrate classification labels with DLP and access control policies
Why this is correct
Classification labels only deliver value when enforced; integrating them with DLP and access control policies ensures restricted and confidential data is actually protected in the cloud. Labels alone, without enforcement, leave sensitive data exposed regardless of how accurately it is categorised.
- ✗
Store each classification level in separate cloud regions
Why it's wrong here
Regional storage is a residency and availability decision; it neither labels data nor ties handling rules to classification categories. It is tempting because segregation sounds like tiering, but classification effectiveness depends on consistent labelling and policy mapping, not geographic placement of objects.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.