hardMultiple ChoiceObjective-mapped
CCSP Practice Question: A financial services firm is designing a cloud…
A financial services firm is designing a cloud environment that must comply with PCI DSS. The security architect proposes using a virtual private cloud (VPC) with subnets, security groups, and network ACLs. However, the compliance officer is concerned about the risk of data exposure due to misconfiguration. Which additional control would BEST address this concern?
⚠ Common exam trap
A common mix-up: candidates confuse CSPM with SIEM or DLP, thinking log analysis or data monitoring can catch configuration errors, but CSPM is the only tool specifically designed to audit and enforce cloud infrastructure configurations against compliance standards like PCI DSS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate Cloud Security Posture Management (CSPM)
CSPM tools continuously monitor cloud infrastructure configurations against compliance frameworks like PCI DSS, automatically detecting misconfigurations such as overly permissive security group rules or network ACLs that could expose cardholder data. This directly addresses the compliance officer's concern about data exposure due to misconfiguration by providing real-time visibility and remediation guidance, which is more proactive than the other options.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a Web Application Firewall (WAF)
Why it's wrong here
WAF protects web apps from attacks, not network misconfigurations.
- ✗
Implement a Security Information and Event Management (SIEM) system
Why it's wrong here
SIEM analyzes logs for threats but does not proactively prevent misconfigurations.
- ✓
Integrate Cloud Security Posture Management (CSPM)
Why this is correct
CSPM automates monitoring and remediation of misconfigurations.
- ✗
Deploy Data Loss Prevention (DLP) tools
Why it's wrong here
DLP protects data in use/motion but does not fix configuration errors.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.