Courseiva
easyMultiple Choice

CCSP Practice Question: A company must ensure that cloud storage data is…

A company must ensure that cloud storage data is retained even if authorized users attempt to delete it, to comply with a legal hold. Which configuration is most effective?

⚠ Common exam trap

ISC2 often tests the misconception that versioning alone provides legal hold protection, but versioning only preserves previous versions and does not block deletion of the current version or all versions via a lifecycle policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable immutable storage (WORM) on the bucket

Immutable storage (WORM) on a bucket prevents any object from being deleted or overwritten for a specified retention period, even by authorized users or the root account. This directly enforces legal hold requirements by making data tamper-proof and deletion-proof at the storage layer, regardless of user permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement data classification labels

    Why it's wrong here

    Classification labels only tag data so policy can be applied; they neither block deletion nor preserve a copy, so an authorised delete still succeeds. Labels tempt because they underpin governance programmes, and would be correct if the question asked how to identify data subject to retention rules.

  • ✓

    Enable immutable storage (WORM) on the bucket

    Why this is correct

    WORM immutability enforces retention at the storage layer, so objects cannot be overwritten or deleted until the retention period expires, even by privileged users. This satisfies the legal hold requirement, unlike IAM policies or soft delete, which authorised users can still circumvent or reverse.

  • ✗

    Enable versioning on the storage bucket

    Why it's wrong here

    Versioning keeps prior object versions after an overwrite or delete, but a user holding delete permission can still remove versions or the bucket itself. It tempts because it recovers accidental deletions, and would be correct if the requirement were rollback rather than enforced legal hold.

  • ✗

    Encrypt data with customer-managed keys

    Why it's wrong here

    Customer-managed keys control who can decrypt data, not whether an object can be deleted; an authorised user with delete permission still removes it. Encryption tempts because it dominates cloud data-protection discussions, and it would be correct if the requirement were cryptographic control over data at rest.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.