CCSP Cloud Data Security Practice Question
A multinational corporation uses a cloud-based data warehouse. The security team must enforce a policy that prevents any user from exporting query results containing more than 100 personally identifiable information (PII) records to an external IP address. Which cloud data security control is MOST appropriate?
⚠ Common exam trap
Test-takers frequently confuse access control with data loss prevention; bucket policies and row-level security govern access to data but do not inspect or limit the volume of data being exported.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a cloud access security broker (CASB) with data loss prevention (DLP) policies that inspect outbound traffic for PII and block transfers exceeding the threshold.
A CASB with DLP is designed to inspect data in motion, recognize sensitive information like PII, and enforce policies based on content and volume. It can block or alert on transfers that exceed the defined threshold to external IP addresses, providing the inline enforcement needed to prevent data exfiltration. Other controls either lack content inspection or cannot block the transfer in real time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply row-level security in the data warehouse to limit the number of PII records each user can query.
Why it's wrong here
Row-level security restricts which rows a user can access based on attributes, but it does not limit the number of records returned or control where the results are sent. A user could still export many records if they have access to them. This control does not address the volume threshold or external IP destination.
- ✗
Enable database activity monitoring (DAM) on the data warehouse to log all queries and alert on large result sets.
Why it's wrong here
DAM provides auditing and alerting but does not actively block the export. It would detect the violation after it occurs, which does not satisfy the requirement to prevent the export. While useful for compliance, it lacks the inline enforcement needed to stop data exfiltration in real time.
- ✗
Configure cloud storage bucket policies to deny access from external IP ranges.
Why it's wrong here
Bucket policies control access to stored objects, not query results exported from a data warehouse. They cannot inspect the content or volume of query results in transit. This control would not prevent a user with legitimate access from exporting PII through the data warehouse's query interface, so it fails to enforce the specific policy.
- ✓
Implement a cloud access security broker (CASB) with data loss prevention (DLP) policies that inspect outbound traffic for PII and block transfers exceeding the threshold.
Why this is correct
A CASB with DLP can inspect data in transit, identify PII patterns, and enforce policies based on content and volume. It can block or alert on exports that exceed the defined threshold to external IPs, directly addressing the requirement. This is the most appropriate control because it operates at the data level and can be applied across cloud services.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.