CCSP Cloud Data Security Practice Question
An organization uses cloud storage and wants to protect against accidental deletion of objects. They also want to be able to recover previous versions of objects in case of unintended modifications. Which feature should they enable?
⚠ Common exam trap
The trap is confusing versioning with backup or replication; candidates might choose access logs or bucket policies thinking they enable recovery, but only versioning retains previous object versions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Versioning
Versioning is the cloud storage feature that retains multiple variants of an object, allowing recovery from accidental deletion or modification. When versioning is enabled, overwriting or deleting an object creates a new version or a delete marker, and previous versions remain accessible. This directly meets the requirement to recover previous versions and protect against accidental deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Bucket policies
Why it's wrong here
Bucket policies govern who may perform which API actions on the bucket; they do not retain prior object copies, so an overwrite or delete still destroys the only version. They are tempting because they are the standard access-control mechanism, and would be correct for restricting public or cross-account access.
- ✗
Access logs
Why it's wrong here
Access logs record requests made against the bucket for auditing and forensics; they store no object data, so deleted or overwritten content cannot be reconstructed from them. They are tempting because they are the usual visibility feature, and would be correct when the requirement is tracing who accessed or modified objects.
- ✓
Versioning
Why this is correct
Versioning retains prior and deleted object states within the same bucket, letting you recover overwritten or removed objects without separate backups. It directly addresses both accidental deletion and unintended modification by preserving each object's earlier versions for restoration.
- ✗
Server-side encryption
Why it's wrong here
Server-side encryption protects object confidentiality at rest by encrypting stored data; it neither prevents deletion nor preserves earlier copies, so overwritten content is unrecoverable. It is tempting because encryption is a common storage safeguard, and would be correct when the requirement is protecting data at rest from unauthorised disclosure.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.