mediumMultiple Choice
CCSP Practice Question: Uses cloud object storage for backup data and…
An organization uses cloud object storage for backup data and requires that once written, data cannot be modified or deleted for a specified retention period. Which feature should they enable?
⚠ Common exam trap
ISC2 often tests the misconception that bucket versioning alone provides data immutability, but versioning only protects against accidental overwrites by preserving old versions, not against intentional deletion or modification of the current version.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Object lock with write-once-read-many (WORM) protection
Object lock with WORM protection is the correct feature because it enforces a retention policy that prevents any user, including the root account, from modifying or deleting objects until the retention period expires. This is specifically designed for compliance requirements such as SEC 17a-4(f) and ensures data immutability at the object level, which bucket versioning, encryption, or lifecycle rules cannot guarantee.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Bucket versioning
Why it's wrong here
Bucket versioning preserves prior object versions when overwrites or deletions occur, so an attacker or rogue administrator can still delete the current object; it does not enforce immutability. It is tempting because versioning supports recovery from accidental overwrites and ransomware, and would suit a scenario needing rollback rather than guaranteed retention.
- ✓
Object lock with write-once-read-many (WORM) protection
Why this is correct
Object lock enforces WORM semantics at the storage layer, preventing overwrite or deletion of an object version until its retention period expires, even by privileged users. This satisfies the immutability-for-a-specified-period constraint that ordinary versioning or lifecycle policies cannot guarantee.
- ✗
Encryption at rest with customer-managed keys
Why it's wrong here
Encryption at rest with customer-managed keys protects confidentiality, not immutability; it cannot prevent overwriting or deletion during the retention period. It is tempting because customer-managed keys give control over data access and cryptographic erasure, and would be the right choice when the requirement is key custody or regulatory control over encryption, rather than write-once retention.
- ✗
Lifecycle management to expire objects old objects
Why it's wrong here
Lifecycle management deletes or transitions objects once an age threshold passes, which actively removes data rather than preventing alteration; it cannot enforce write-once retention. It is the right tool for cost control, such as expiring stale backups after 90 days, but here the requirement is immutability for a set period, which object lock or a retention policy provides.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.