Courseiva
easyMultiple Select

CCSP Practice Question: Wants to ensure compliance with industry…

An organization wants to ensure compliance with industry regulations by implementing data classification in the cloud. Which two actions should the organization take? (Choose two.)

⚠ Common exam trap

ISC2 often tests the misconception that encryption alone satisfies compliance requirements, but the trap here is that encryption is a control, not a classification mechanism, and without auditing and defined sensitivity levels, compliance cannot be proven.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement auditing of access to sensitive data.

Option A is correct because implementing auditing of access to sensitive data provides the traceability and accountability records required to demonstrate regulatory compliance, capturing who accessed which classified data and when. Option C is correct because data classification must begin with defined sensitivity levels (for example, Public, Internal, Confidential, Restricted) and labels applied to data so that handling, protection, and retention policies can be enforced consistently. Together, these two actions establish both the classification scheme and the monitoring needed to prove compliance. Option B is not appropriate because consolidating all data into a single repository increases blast radius and does not by itself satisfy classification or regulatory requirements. Option D is wrong because encrypting all data indiscriminately ignores classification-based handling and can be impractical or unnecessary for public data. Option E is wrong because automatically tagging all data at creation without a defined sensitivity scheme produces unreliable labels and does not establish meaningful classification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement auditing of access to sensitive data.

    Why this is correct

    Auditing access to sensitive data provides the evidentiary trail regulators require, recording who accessed which classified resource and when. This directly satisfies the compliance constraint in the stem: classification alone is static, whereas audit logging proves ongoing enforcement and supports incident investigation, demonstrating accountability to auditors.

  • ✗

    Store all data in a single repository for easy management.

    Why it's wrong here

    Consolidating everything into one repository removes the segmentation that classification exists to enforce, so differing handling requirements cannot be applied per category. A single repository is what you would choose for simplified backup or deduplication, not for regulation-driven classification.

  • ✓

    Define data sensitivity levels and apply labels.

    Why this is correct

    Defining sensitivity levels and applying labels establishes the classification schema itself, so data can be categorised consistently across cloud stores. This satisfies the compliance requirement by giving the organisation a structured basis for handling rules and controls.

  • ✗

    Encrypt all data regardless of classification.

    Why it's wrong here

    Encrypting uniformly ignores the classification outcome entirely, so controls no longer map to data sensitivity and compliance evidence cannot demonstrate tiered protection. Blanket encryption suits a scenario where all data carries equal sensitivity and no differentiated handling obligations apply.

  • ✗

    Automatically tag all data as it is created.

    Why it's wrong here

    Automatic tagging at creation applies labels without human validation, so misclassification propagates silently and audit evidence becomes unreliable. Automated tagging is the right mechanism when data volumes make manual labelling impossible and a validated taxonomy already exists to drive the rules.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.