Courseiva
Cloud Data Security →mediumMultiple Select

CCSP Cloud Data Security Practice Question

A company stores sensitive data in cloud object storage and wants to protect against ransomware attacks that could encrypt or delete objects. Which TWO measures should they implement? (Choose two.)

⚠ Common exam trap

Candidates often mistakenly choose cross-region replication or lifecycle policies as ransomware defenses, not realizing that replication alone does not prevent deletion/encryption, and lifecycle policies could actually delete data. The correct approach combines immutable storage to prevent modification and versioning to allow recovery of prior states.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement immutable storage (e.g., Object Lock)

Option B (immutable storage such as Object Lock) is correct because it enforces WORM (write once, read many) protection, preventing objects from being modified or deleted for a defined retention period even by compromised or malicious accounts, which directly blocks ransomware encryption or deletion. Option D (object versioning) is correct because it preserves prior versions of each object, so if ransomware overwrites or encrypts the current version, the previous clean versions remain recoverable. Option A (cross-region replication) only copies data to another region and would replicate corrupted or encrypted objects too, so it does not protect against ransomware. Option C (signed URLs) merely grants time-limited access to specific objects and does not prevent an attacker with valid credentials from encrypting or deleting data. Option E (short object lifetimes via lifecycle policies) actually deletes objects sooner, which increases data loss risk rather than protecting against ransomware.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use cross-region replication

    Why it's wrong here

    Cross-region replication copies objects to another region but propagates encrypted or deleted versions if the source is compromised, so it does not protect against ransomware. It is tempting for durability and regional outage recovery, where it is the correct choice.

  • ✓

    Implement immutable storage (e.g., Object Lock)

    Why this is correct

    Object Lock enforces WORM protection at the object level, preventing overwrite or deletion for a defined retention period — even by compromised credentials or malicious insiders. This directly satisfies the ransomware constraint, since encrypted or deleted objects cannot be altered until retention expires, enabling clean recovery.

  • ✗

    Configure signed URLs for access

    Why it's wrong here

    Signed URLs grant time-limited access to specific objects; they do not prevent an attacker with valid credentials from encrypting or deleting objects. They are tempting for secure temporary sharing with external parties, which is their actual purpose, not ransomware protection.

  • ✓

    Enable object versioning

    Why this is correct

    Object versioning preserves every prior iteration of an object, so ransomware encryption or deletion writes a new version rather than destroying the original. Recovery simply restores the last clean version, satisfying the stem's requirement to protect stored objects against encryption or deletion without relying on separate backups.

  • ✗

    Set short object lifetimes using lifecycle policies

    Why it's wrong here

    Short lifetimes delete objects automatically, which accelerates data loss during a ransomware event rather than protecting against it. Lifecycle policies are tempting for cost management and compliance retention limits, where they are correct, but they do not preserve recoverable copies.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.