easyMultiple SelectObjective-mapped
CCSP Practice Question: Wants to ensure compliance with industry…
An organization wants to ensure compliance with industry regulations by implementing data classification in the cloud. Which two actions should the organization take? (Choose two.)
⚠ Common exam trap
ISC2 often tests the misconception that encryption alone satisfies compliance requirements, but the trap here is that encryption is a control, not a classification mechanism, and without auditing and defined sensitivity levels, compliance cannot be proven.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement auditing of access to sensitive data.
Auditing access to sensitive data is a fundamental compliance requirement under regulations like GDPR, HIPAA, and PCI DSS. It provides a verifiable record of who accessed what data, when, and from where, enabling detection of unauthorized access and supporting forensic investigations. Without auditing, an organization cannot demonstrate compliance with data protection mandates that require monitoring and reporting of access to classified data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement auditing of access to sensitive data.
Why this is correct
Correct: Provides tracking and accountability.
- ✗
Store all data in a single repository for easy management.
Why it's wrong here
May not meet regulatory requirements for data segregation.
- ✓
Define data sensitivity levels and apply labels.
Why this is correct
Correct: Establishes a classification system.
- ✗
Encrypt all data regardless of classification.
Why it's wrong here
Encryption is separate from classification.
- ✗
Automatically tag all data as it is created.
Why it's wrong here
Tagging without classification may not meet compliance requirements.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.