Courseiva
easyMultiple Choice

CCSP Practice Question: A developer accidentally uploaded a file…

A developer accidentally uploaded a file containing API credentials to a public cloud storage bucket. The cloud provider states they cannot guarantee deletion of the object. Which practice could have prevented this incident?

⚠ Common exam trap

ISC2 often tests the distinction between preventive controls (DLP) and detective/reactive controls (versioning, encryption, ACLs), leading candidates to choose bucket versioning because it allows rollback, but versioning does not prevent the initial exposure of sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data loss prevention for cloud storage

Data Loss Prevention (DLP) for cloud storage can automatically scan objects for sensitive content, such as API credentials, before or after upload. When configured with policies to block or quarantine files containing patterns like access keys, DLP prevents the data from ever being stored in a public bucket, eliminating the risk even if the provider cannot guarantee deletion. This proactive control addresses the root cause—sensitive data exposure—rather than relying on post-incident remediation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data loss prevention for cloud storage

    Why this is correct

    Data loss prevention for cloud storage inspects content and blocks uploads containing credential patterns before the object is written. This prevents the exposure entirely, unlike remediation after upload, which cannot guarantee deletion once the provider loses control.

  • ✗

    Bucket versioning

    Why it's wrong here

    Versioning preserves every object revision, including the exposed credential file, and the provider's inability to guarantee deletion means those retained versions persist; it multiplies copies rather than preventing the upload. Versioning is correct when you need recovery from accidental overwrites or deletions, not exposure prevention.

  • ✗

    Access control lists

    Why it's wrong here

    ACLs govern which principals may read or write objects, so they cannot stop an authorised developer from uploading a credential file in the first place; the exposure stems from the object's content, not its permissions. ACLs are the right control when restricting cross-account or public access to specific buckets and objects.

  • ✗

    Server-side encryption

    Why it's wrong here

    Server-side encryption protects data at rest against storage-media or provider-side compromise, but the bucket's own service decrypts transparently for any authorised reader, so the leaked credentials remain readable. Encryption is the right control when the threat is physical media theft or unauthorised low-level storage access.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.