Courseiva
mediumMultiple Choice

CCSP Practice Question: Uses cloud object storage for backup data and…

An organization uses cloud object storage for backup data and requires that once written, data cannot be modified or deleted for a specified retention period. Which feature should they enable?

⚠ Common exam trap

ISC2 often tests the misconception that bucket versioning alone provides data immutability, but versioning only protects against accidental overwrites by preserving old versions, not against intentional deletion or modification of the current version.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Object lock with write-once-read-many (WORM) protection

Object lock with WORM protection is the correct feature because it enforces a retention policy that prevents any user, including the root account, from modifying or deleting objects until the retention period expires. This is specifically designed for compliance requirements such as SEC 17a-4(f) and ensures data immutability at the object level, which bucket versioning, encryption, or lifecycle rules cannot guarantee.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Bucket versioning

    Why it's wrong here

    Bucket versioning preserves prior object versions when overwrites or deletions occur, so an attacker or rogue administrator can still delete the current object; it does not enforce immutability. It is tempting because versioning supports recovery from accidental overwrites and ransomware, and would suit a scenario needing rollback rather than guaranteed retention.

  • ✓

    Object lock with write-once-read-many (WORM) protection

    Why this is correct

    Object lock enforces WORM semantics at the storage layer, preventing overwrite or deletion of an object version until its retention period expires, even by privileged users. This satisfies the immutability-for-a-specified-period constraint that ordinary versioning or lifecycle policies cannot guarantee.

  • ✗

    Encryption at rest with customer-managed keys

    Why it's wrong here

    Encryption at rest with customer-managed keys protects confidentiality, not immutability; it cannot prevent overwriting or deletion during the retention period. It is tempting because customer-managed keys give control over data access and cryptographic erasure, and would be the right choice when the requirement is key custody or regulatory control over encryption, rather than write-once retention.

  • ✗

    Lifecycle management to expire objects old objects

    Why it's wrong here

    Lifecycle management deletes or transitions objects once an age threshold passes, which actively removes data rather than preventing alteration; it cannot enforce write-once retention. It is the right tool for cost control, such as expiring stale backups after 90 days, but here the requirement is immutability for a set period, which object lock or a retention policy provides.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.