CCSP Cloud Data Security Practice Question
A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that any modification to a log file is detectable and that the original content cannot be repudiated. Which mechanism should they implement?
⚠ Common exam trap
The trap here is assuming that encryption or hashing alone provides non-repudiation, when only a digital signature binds the signer's identity to the data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use digital signatures with a private key to sign each log file.
Digital signatures use asymmetric cryptography to bind the signer's identity to the data. When a log file is signed, any alteration invalidates the signature, and the signer cannot deny signing. This satisfies both integrity and non-repudiation requirements. Encryption alone provides confidentiality but not tamper evidence, while hashing without a signature lacks non-repudiation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use digital signatures with a private key to sign each log file.
Why this is correct
Digital signatures provide integrity, authentication, and non-repudiation. If the private key is securely held by the log producer, any modification to the log file will invalidate the signature, and the signer cannot deny having signed it. This directly meets the requirements for tamper detection and non-repudiation.
- ✗
Apply a cryptographic hash (e.g., SHA-256) to each log file and store the hash separately.
Why it's wrong here
Hashing provides integrity verification, but storing the hash separately does not prevent an attacker from modifying both the log and the hash if they gain access to the hash store. Without a digital signature or a trusted timestamp, non-repudiation is not achieved. This is insufficient for the stated requirements.
- ✗
Enable object versioning and configure a lifecycle policy to retain all versions.
Why it's wrong here
Object versioning preserves previous versions of an object, which helps with recovery but does not detect unauthorized modifications to the current version. An attacker could modify the current version, and unless someone compares versions, the change may go unnoticed. Versioning alone does not provide non-repudiation.
- ✗
Enable server-side encryption with customer-provided keys (SSE-C).
Why it's wrong here
SSE-C provides confidentiality by encrypting objects with keys supplied by the customer, but it does not provide integrity verification or non-repudiation. An attacker with write access could still alter the object and re-encrypt it, and the change would not be detectable. This does not meet the requirement for tamper detection.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.