Courseiva
Cloud Data Security →hardMultiple Choice

CCSP Cloud Data Security Practice Question

A multinational corporation uses a cloud-based data warehouse. The security team must enforce a policy that prevents any user from exporting query results containing more than 100 personally identifiable information (PII) records to an external IP address. Which cloud data security control is MOST appropriate?

⚠ Common exam trap

Test-takers frequently confuse access control with data loss prevention; bucket policies and row-level security govern access to data but do not inspect or limit the volume of data being exported.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a cloud access security broker (CASB) with data loss prevention (DLP) policies that inspect outbound traffic for PII and block transfers exceeding the threshold.

A CASB with DLP is designed to inspect data in motion, recognize sensitive information like PII, and enforce policies based on content and volume. It can block or alert on transfers that exceed the defined threshold to external IP addresses, providing the inline enforcement needed to prevent data exfiltration. Other controls either lack content inspection or cannot block the transfer in real time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply row-level security in the data warehouse to limit the number of PII records each user can query.

    Why it's wrong here

    Row-level security restricts which rows a user can access based on attributes, but it does not limit the number of records returned or control where the results are sent. A user could still export many records if they have access to them. This control does not address the volume threshold or external IP destination.

  • ✗

    Enable database activity monitoring (DAM) on the data warehouse to log all queries and alert on large result sets.

    Why it's wrong here

    DAM provides auditing and alerting but does not actively block the export. It would detect the violation after it occurs, which does not satisfy the requirement to prevent the export. While useful for compliance, it lacks the inline enforcement needed to stop data exfiltration in real time.

  • ✗

    Configure cloud storage bucket policies to deny access from external IP ranges.

    Why it's wrong here

    Bucket policies control access to stored objects, not query results exported from a data warehouse. They cannot inspect the content or volume of query results in transit. This control would not prevent a user with legitimate access from exporting PII through the data warehouse's query interface, so it fails to enforce the specific policy.

  • ✓

    Implement a cloud access security broker (CASB) with data loss prevention (DLP) policies that inspect outbound traffic for PII and block transfers exceeding the threshold.

    Why this is correct

    A CASB with DLP can inspect data in transit, identify PII patterns, and enforce policies based on content and volume. It can block or alert on exports that exceed the defined threshold to external IPs, directly addressing the requirement. This is the most appropriate control because it operates at the data level and can be applied across cloud services.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.