CCSP Cloud Data Security Practice Question
A security architect is designing a multi-cloud data protection strategy. They need to give a third-party auditor time-limited, read-only access to a specific file in a cloud storage bucket. Which access control method is most appropriate?
⚠ Common exam trap
The trap is confusing network-level access (VPN) or identity-level access (IAM/ACL) with object-level temporary delegation; candidates often pick IAM because it sounds most 'secure,' missing that pre-signed URLs are the canonical least-privilege answer for third-party single-object access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Pre-signed URL with an expiration time
A pre-signed URL is a time-limited, cryptographically signed URL that grants temporary access to a specific object without requiring the auditor to have an identity in the cloud provider's IAM system. It is generated by a principal with permission to the object and embeds an expiration timestamp and signature, making it ideal for granting an external third party scoped, read-only, time-bound access to a single file. This satisfies least privilege and avoids creating persistent identities or network paths.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud VPN connection for the auditor
Why it's wrong here
A VPN only secures the transport path between the auditor's network and the cloud environment; it grants no identity-based permission to the object itself. It is tempting because VPNs are the standard mechanism for encrypted remote connectivity, and would be correct if the requirement were protecting data in transit for an ongoing site-to-site link.
- ✗
Bucket ACL granting read access to the auditor's cloud account
Why it's wrong here
Bucket ACLs grant access at bucket or object scope to a cloud account, with no native expiry, so time-limited read-only access to one file cannot be enforced. They are tempting because ACLs are the classic object-storage permission primitive, and would suit granting persistent read access to a trusted partner's account.
- ✗
IAM policy granting read access to the auditor's user
Why it's wrong here
An IAM policy bound to the auditor's user grants standing read permission rather than time-limited access, and broad storage read permissions expose other objects in the bucket. IAM policies are tempting because they are the standard cloud authorisation mechanism, and would be correct for durable role-based access within your own tenant.
- ✓
Pre-signed URL with an expiration time
Why this is correct
A pre-signed URL embeds temporary credentials and an expiry directly into the link, granting read-only access to one specific object without creating an identity or sharing bucket keys. This satisfies the auditor's time-limited, single-file requirement, unlike broader role-based or bucket-level permissions.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.