Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A company wants to enforce data classification in its cloud environment. They need to automatically identify and label sensitive data such as credit card numbers in cloud storage. Which service should they use?

⚠ Common exam trap

The trap is that candidates may choose Cloud KMS thinking 'protecting sensitive data' means encryption — but the question specifically asks for automatic identification and labeling of data content, which is DLP's unique classification capability, not encryption or access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud DLP

Cloud DLP (Data Loss Prevention) is designed to automatically discover, classify, and label sensitive data such as credit card numbers, social security numbers, and personally identifiable information in cloud storage and other services. It uses built-in and custom infoType detectors (including regex and checksum validation for credit cards) to identify and tag sensitive content, directly fulfilling the requirement to automatically identify and label sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud KMS

    Why it's wrong here

    Cloud KMS performs cryptographic key generation, storage, rotation and encryption operations; it does not scan stored objects, detect patterns such as card numbers, or apply classification labels. It is tempting because KMS underpins data protection, and would be correct where the requirement is managing encryption keys rather than discovering sensitive content.

  • ✓

    Cloud DLP

    Why this is correct

    Cloud DLP scans storage repositories and uses pattern matching and checksums to detect credit card numbers, then applies classification labels automatically. This directly satisfies the requirement to identify and label sensitive data at scale, which manual tagging or generic encryption services cannot achieve.

  • ✗

    Cloud Audit Logs

    Why it's wrong here

    Cloud Audit Logs record administrative and data-access activity for compliance and forensics; they neither inspect object contents nor assign classification labels. They are tempting because audit trails support data-governance programmes, and would be correct where the requirement is evidencing who accessed which resource and when.

  • ✗

    Cloud IAM

    Why it's wrong here

    Cloud IAM governs identities and permissions over resources; it neither inspects object contents nor applies classification labels to credit card numbers. It is tempting because IAM does control access to storage, but the requirement is automated data discovery and labelling, which needs a dedicated data classification or DLP service.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.