CCSP · domain
Cloud Data Security
Cloud Data Security covers how data is classified, protected, retained, and discovered across IaaS, PaaS, and SaaS. For CCSP you must reason about encryption at rest and in transit, key ownership models (BYOK, HYOK, CSEK), tokenization, masking, DLP, and data residency controls, then pick the control that actually satisfies a stated requirement.
Focused practice
Practice Cloud Data Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Cloud Data Security
Be able to map a stated data protection requirement to the exact control: key custody model, scoped time-bound access, or region restriction. The single most important thing is identifying who owns and can revoke the encryption key, since that decides most answers.
Selecting customer-managed vs provider-managed keys, including Cloud KMS, Cloud HSM, and CSEK on GCP or SSE-KMS and SSE-C on AWS S3
Using pre-signed URLs or SAS tokens for time-limited, scoped access to a single object
Enforcing data residency with region-pinned buckets, VPC Service Controls, or organization policy constraints
Applying DLP API, Macie, or Sensitive Data Protection to discover, classify, and mask regulated data
Watch out for
Common Cloud Data Security exam traps
- ▸Confusing encryption at rest with encryption in transit, or assuming default SSE gives the customer control over key lifecycle and revocation.
- ▸Choosing a broad IAM role or bucket policy when the scenario demands access limited to one object and expiring automatically.
- ▸Treating replication or multi-region storage as compliant with residency rules when copies leave the mandated jurisdiction.
Question index
All Cloud Data Security questions (120)
Click any question to see the full explanation, or start a practice session above.
A cloud security architect is designing a data retention and deletion strategy for a SaaS application hosted in a public cloud. The organization must ensure that data is securely deleted when no longer needed, and that deletion is verifiable. Which two practices should be implemented? (Choose two.)
Medium2A multinational corporation must comply with GDPR and store EU customer data only within the European Union. Which cloud storage security measure directly addresses this requirement?
Hard3A company is required to encrypt all data in transit between its on-premises data center and its cloud environment. They have a hybrid cloud setup and need a secure tunnel for all traffic. Which solution should they implement?
Medium4A healthcare company stores medical images in a cloud object storage bucket. The images are accessed by radiologists via a web application. The security team wants to ensure that data is encrypted in transit and that the encryption keys are not accessible to the cloud provider. Which solution should they implement?
Medium5A global e-commerce company must store customer payment data in a specific geographic region to comply with local data residency laws. Which cloud configuration ensures that data never leaves the required region?
Medium6Which phase of the cloud data lifecycle involves making data available for processing by applications and users?
Easy7A company uses a cloud key management service with customer-managed keys to encrypt data in a cloud storage bucket. The security team wants to ensure that if a key is compromised, they can revoke the cloud service's ability to decrypt the data immediately. What should they do?
Hard8A DevOps team is deploying an application that will store encryption keys in a cloud KMS. The security policy requires that keys be stored in a hardware security module (HSM) and that key material never leaves the HSM boundary. Which key management option should they choose?
Medium9A cloud security team is reviewing data retention for a software-as-a-service application hosted in a public cloud. Legal counsel requires that customer data be deleted permanently when a subscription ends, and that deletion be demonstrable to auditors. The cloud provider's storage system uses log-structured storage and maintains replicas across multiple availability zones. Which action best supports demonstrable, permanent deletion?
Medium10A security team is setting up a DLP solution to scan cloud storage for credit card numbers. They want to automatically mask the detected credit card numbers so that only the last four digits are visible. Which DLP de-identification transform should they use?
Medium11A multinational corporation uses a cloud DLP service to scan data stored in cloud storage and a cloud data warehouse for personally identifiable information (PII). The DLP scan identifies credit card numbers in a dataset. According to the cloud data lifecycle, at which stage should the DLP scan ideally be performed to minimize exposure?
Hard12A multinational corporation stores trade secrets in a cloud object storage bucket. The security team wants to ensure that even if the cloud provider's internal systems are compromised, the data remains confidential. They also need to maintain the ability to revoke access to specific data objects without affecting other objects. Which combination of techniques should they implement?
Hard13A startup is using a cloud-based SaaS CRM to store customer contact information. The security policy requires that data be encrypted both in transit and at rest. The SaaS provider states that it encrypts data in transit using TLS and at rest using AES-256. What should the startup do to verify these claims?
Easy14Which of the following is the correct order of phases in the cloud data lifecycle?
Easy15A company is required by a data sovereignty law to ensure that all data generated by its EU customers is stored and processed within the EU. The company uses a cloud provider with data centers in multiple regions. Which cloud storage configuration should they implement?
Medium16An organization wants to classify data in the cloud and assign labels such as 'Public', 'Internal', 'Confidential', and 'Restricted'. What is the primary purpose of this classification scheme?
Easy17A financial services firm stores sensitive customer records in a cloud object storage bucket. The security team wants to ensure that even if the cloud provider's internal staff or a compromised administrative account attempts to access the data, they cannot read it. The firm already uses provider-managed encryption at rest. Which additional control BEST achieves this requirement?
Medium18A cloud security manager is implementing data discovery and classification for a multi-cloud environment. The organization needs to automatically identify and tag sensitive data such as personally identifiable information (PII) and protected health information (PHI) across cloud storage services. Which two capabilities are essential for an effective data classification solution? (Choose two.)
Medium19A multinational corporation must store customer data in specific geographic regions to comply with data sovereignty laws. Which cloud storage feature should they configure to ensure data does not leave a designated region?
Medium20An organization uses cloud object storage with versioning enabled. After a ransomware attack, they discover that many objects were encrypted by the attacker. How does versioning help in this scenario?
Medium21A cloud security manager is implementing a data retention policy for a SaaS CRM that stores customer contact records. Regulations require that records be irreversibly destroyed after seven years, but the SaaS provider's recycle bin retains deleted records for 30 days and backups persist for 90 days. Which cloud data disposal approach best satisfies the regulatory requirement?
Medium22A financial services company is implementing a data loss prevention (DLP) solution to protect sensitive data in cloud storage. They need to identify and classify data containing personally identifiable information (PII) such as credit card numbers and social security numbers. Which three capabilities should the DLP solution provide? (Choose three.)
Hard23Which phase of the cloud data lifecycle involves the removal of data in a manner that ensures it cannot be reconstructed, typically using techniques like cryptographic erasure or degaussing?
Easy24A company is implementing a data classification policy for cloud storage. They want to label objects with tags indicating the sensitivity level (e.g., 'Confidential'). Which benefit does tagging resources with classification labels provide?
Easy25A cloud data governance team is defining controls for data remanence in a multi-tenant public cloud environment. They must address both logical and physical media reuse concerns. Which TWO practices are MOST appropriate for managing data remanence risk? (Choose two.)
Medium26A healthcare company stores patient records in a cloud storage bucket. They need to encrypt the data at rest using encryption keys that they manage themselves, but they want to generate the keys within the cloud provider's key management service. Which encryption option should they choose?
Easy27A cloud architect is implementing data loss prevention (DLP) for a data lake containing PII. They want to automatically detect and transform sensitive data like Social Security numbers and medical record numbers. Which THREE actions should they take? (Choose three.)
Hard28A security engineer needs to provide temporary access to a specific object in a cloud storage bucket for a third-party auditor, without granting them any other permissions. The access should expire automatically after 24 hours. Which method should the engineer use?
Easy29A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that if an attacker gains access to the bucket, the data cannot be read. They also want to prevent the cloud provider from accessing the plaintext. Which approach best meets these requirements?
Medium30A company is planning to implement data classification for its cloud environment. Which TWO components are essential for an effective data classification scheme? (Select TWO.)
Easy31A company is migrating its on-premises database to a cloud-based managed database service. The security policy requires that data at rest be encrypted and that the company retain control over key rotation. Which cloud service should they use to meet these requirements?
Easy32A company is migrating its on-premises database to a cloud-based database-as-a-service (DBaaS) offering. The security team wants to ensure that the data remains encrypted at rest and that they retain control over the encryption keys. Which cloud data security concept should they implement?
Easy33A healthcare organization stores patient data in a cloud database. Regulatory requirements mandate that data must be encrypted at rest using FIPS 140-2 validated cryptographic modules. The organization wants to use the cloud provider's managed encryption service. Which aspect should they verify to ensure compliance?
Hard34A financial services company is migrating sensitive customer data to the cloud. They require that encryption keys be generated and stored on-premises in their own hardware security module (HSM), with the cloud provider never having access to the plaintext keys. Which key management model should they implement?
Easy35A cloud security team is evaluating DLP techniques to protect sensitive data in a cloud data warehouse. They want to replace sensitive values with realistic but fictitious data for non-production environments while preserving referential integrity. Which TWO de-identification techniques are suitable?
Medium36A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that data is protected at rest but does not want to manage encryption keys themselves. They also need to prove to auditors that encryption is enabled. Which cloud provider feature should they use?
Medium37A data governance team is developing a classification scheme for cloud-stored data. They want to label data based on sensitivity, from least to most restrictive. Which of the following is a typical classification category for highly sensitive data that could cause severe damage if disclosed?
Easy38A cloud security engineer needs to protect a storage bucket from accidental deletion and ransomware attacks. Which two features should be enabled together for maximum protection?
Medium39A company is using a cloud provider's key management service (KMS) with HSM-backed keys. They want to ensure that key material is automatically replaced periodically to limit the impact of a potential key compromise. Which KMS feature should they configure?
Medium40A multinational corporation must ensure that customer data from the European Union is stored and processed only within EU regions to comply with GDPR. They are using a cloud provider with data centers globally. What is the primary mechanism to enforce this requirement?
Medium41An organization is implementing a data loss prevention (DLP) solution to protect sensitive data in cloud storage. Which TWO of the following are capabilities of a cloud DLP service? (Select TWO.)
Medium42A company is deploying a cloud application that processes customers' personal data. They need to ensure data in transit is protected. Which THREE of the following are appropriate controls for data in transit? (Select THREE.)
Easy43An organization wants to protect its cloud storage data from ransomware attacks that might encrypt or delete objects. The security team decides to enable a feature that maintains previous versions of objects when changes are made. Which feature is being described?
Medium44A cloud security administrator is configuring access to a cloud storage bucket that contains regulated data. The administrator needs to ensure that data is encrypted at rest using keys that are automatically rotated every 90 days. Which cloud service feature should the administrator use?
Easy45A global enterprise is designing a cloud storage architecture with cross-region replication for disaster recovery. They must ensure that data replicated to a secondary region is encrypted with keys managed by the customer, and that those keys are stored in the secondary region's key management service (KMS). Which THREE capabilities must be enabled?
Hard46A cloud security team is implementing data loss prevention (DLP) for sensitive data in a cloud data warehouse. They need to detect and classify Social Security numbers (SSNs) stored in tables. Which cloud service capability is most appropriate for this task?
Medium47A cloud security team is implementing data loss prevention for a data lake that stores customer support logs. They need to redact credit card numbers from the logs before they are used for analytics. Which DLP de-identification technique should be applied?
Medium48A financial services company stores regulated data in a cloud object storage bucket and uses a cloud key management service (KMS) with customer-managed keys. An auditor asks how the company ensures that data remains protected if a malicious insider with KMS administrator rights attempts to export key material. Which KMS capability should the security team describe?
Hard49A cloud security architect is designing a data retention and deletion strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a combination of object storage, block storage, and a managed database. Regulatory requirements mandate that data be irrecoverably deleted upon customer request. Which TWO of the following measures are MOST effective to ensure secure data disposal in the cloud? (Choose two.)
Hard50A multinational corporation must comply with data residency requirements that mandate certain data must remain within the European Union. Additionally, the company needs to ensure high availability and disaster recovery for this data. Which TWO measures should be implemented? (Select TWO.)
Hard51A healthcare organization stores electronic protected health information (ePHI) in a cloud environment. They need to implement data discovery and classification to meet HIPAA requirements. Which two techniques are most appropriate for identifying ePHI in unstructured data stored in cloud object storage? (Choose two.)
Hard52A financial institution is implementing a data classification scheme for their cloud environment. They have data that, if exposed, could cause severe damage to the organization and is subject to strict regulatory requirements. Which classification level should be applied to this data?
Medium53A cloud security administrator is configuring access to a cloud object storage bucket that contains regulated data. The requirement is that only identities with an explicit business need can read objects, and that access decisions are evaluated centrally with fine-grained conditions such as department and time of day. Which capability BEST addresses this requirement?
Easy54When data is in transit between an on-premises data center and a cloud service, which of the following is the minimum encryption standard recommended by security best practices?
Easy55A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that any modification to a log file is detectable and that the original content cannot be repudiated. Which mechanism should they implement?
Medium56A cloud administrator is configuring a new object storage bucket that will hold internal project files. The organization's policy states that data must be encrypted at rest, but the team wants the cloud provider to handle all key management with no additional operational overhead. Which configuration meets this policy with the least administrative effort?
Easy57A small business is migrating its customer database to a cloud-based database service. The security team wants to ensure that data is encrypted at rest using keys that the business controls, but they do not want to manage the underlying hardware security modules. Which cloud key management option should they choose?
Easy58A small business uses a cloud provider's default server-side encryption (SSE) to encrypt data at rest in their cloud storage. They are concerned about key management overhead. Which statement best describes the key management responsibility for SSE?
Easy59A cloud security team is implementing data discovery and classification for a multi-cloud environment. They need to identify sensitive data such as personally identifiable information (PII) and protected health information (PHI) across structured and unstructured data stores. Which TWO approaches are MOST effective for accurate and scalable data discovery in this scenario? (Choose two.)
Hard60A cloud architect is designing a data lifecycle policy for a SaaS application. According to the cloud data lifecycle, which phase immediately follows the 'Share' phase?
Hard61A company wants to use a cloud KMS to encrypt data but requires that the encryption key never leaves their on-premises hardware security module (HSM) due to compliance. Which key management model should they adopt?
Medium62A cloud security team is implementing data loss prevention (DLP) for a SaaS application that stores sensitive documents. They need to detect and prevent unauthorized sharing of documents containing personally identifiable information (PII). Which two cloud data security controls should be implemented? (Choose two.)
Medium63Which of the following is the most granular method to grant time-limited access to a specific object in a cloud storage bucket without requiring the requester to have cloud provider credentials?
Easy64A company uses a cloud KMS to manage encryption keys for its cloud storage buckets. The security team wants to ensure that keys are rotated automatically every 90 days and that access to keys is restricted based on user roles. Which key management feature should they configure?
Medium65A cloud security team is implementing a data classification scheme for objects stored in a cloud environment. They need to ensure that classification labels persist with the data, travel with it when copied or moved between services, and can be used to enforce access and DLP policies automatically. Which approach BEST achieves these outcomes?
Hard66An organization is required to use client-side encryption for all data uploaded to a cloud storage service to ensure that the cloud provider has no access to plaintext. However, they also need to allow the cloud provider to perform server-side operations like indexing and search on the encrypted data. Which technology can address this conflict?
Hard67A company uses a cloud KMS service with an HSM backing for key storage. The security policy requires that keys be rotated automatically every 90 days and that old keys be retained for at least one year to decrypt archived data. Which key management feature should be configured to meet these requirements?
Hard68A financial services company uses a cloud DLP API to scan data stored in Cloud Storage and BigQuery. They need to reduce the risk of exposing credit card numbers in reports by replacing the first 12 digits with asterisks while preserving the last four. Which de-identification technique should they apply?
Medium69A cloud architect is designing a data classification strategy for a multi-cloud environment. The strategy must automatically tag resources with classification labels and enforce access controls based on those labels. Which THREE components are essential for this automated classification and enforcement?
Medium70A cloud engineer is configuring a storage bucket that will hold publicly accessible marketing images. The security policy requires that data at rest be encrypted, but the images are not sensitive and the team wants to minimize operational overhead. Which cloud storage encryption option is most appropriate?
Easy71A financial services company stores customer transaction data in a cloud object storage bucket. The company requires that all data be encrypted at rest using keys that it generates and manages on-premises, with the cloud provider having no access to the keys. Which encryption approach should the company use?
Easy72A company stores sensitive data in cloud object storage and wants to protect against ransomware attacks that could encrypt or delete objects. Which TWO measures should they implement? (Choose two.)
Medium73A cloud security architect is designing a data retention and destruction strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a mix of block storage, object storage, and a managed database. Regulatory requirements mandate that data be irrecoverably destroyed upon customer offboarding, and that the destruction be verifiable. Which TWO of the following practices BEST support these requirements? (Choose two.)
Hard74An organization must implement encryption for data in transit between its on-premises data center and a cloud provider. The data is sensitive and the organization requires a dedicated, encrypted tunnel. Which solution should be used?
Hard75A financial services company stores customer transaction data in a cloud object storage service. The security team wants to ensure that if a malicious insider gains access to the storage bucket, they cannot read the data. Which encryption approach provides the highest level of protection against the cloud provider and insiders?
Medium76An organization wants to share a large file from a cloud storage bucket with an external partner for a limited time. They need to ensure that the partner can only access the specific file and that the access expires automatically. Which method should they use?
Medium77A cloud security architect is designing a data loss prevention (DLP) strategy for a cloud environment that stores sensitive customer data. Which TWO techniques should be implemented to proactively identify and protect sensitive data? (Select TWO.)
Medium78A cloud security architect is designing a data retention strategy for a SaaS application hosted on a public cloud. The application stores user-generated content in a multi-tenant database. Regulatory requirements mandate that user data be permanently deleted upon request within 30 days. The architect needs to ensure that backups and replicas also honor the deletion. Which approach BEST ensures compliance with the deletion requirement?
Medium79A multinational corporation is using a cloud-based data warehouse to analyze customer data. The data includes personally identifiable information (PII) from various countries. The security team needs to ensure that data is anonymized before analysis to comply with privacy regulations. Which technique should they use?
Medium80A cloud architect is designing a data retention solution for a SaaS application hosted with a cloud provider. The organization must ensure that customer data is irretrievably destroyed at the end of its retention period, even though the data is stored in a multi-tenant object storage service with underlying solid-state drives. Which approach best satisfies this requirement?
Medium81A cloud security analyst is reviewing data flows for a web application that stores session tokens in a cloud database. The tokens are considered sensitive and must be protected both at rest and in transit. The database supports encryption at rest using provider-managed keys, and the application connects over a private network link. Which additional control best protects the session tokens from being exposed in the event of a database snapshot being copied to another region?
Medium82A startup is deploying a new cloud application that stores user profile pictures in an object storage bucket. The security team wants to ensure that data at rest is encrypted and that the encryption keys are managed by the cloud provider with minimal operational overhead. Which encryption option should they choose?
Easy83A multinational corporation uses a cloud-based data warehouse to store aggregated analytics data. The data includes anonymized user behavior logs that, when combined with a separate dataset of user identifiers, could re-identify individuals. The security team wants to implement a data masking technique that preserves the statistical properties of the data for analytics while preventing re-identification. Which technique BEST meets these requirements?
Hard84A company wants to enforce data classification in its cloud environment. They need to automatically identify and label sensitive data such as credit card numbers in cloud storage. Which service should they use?
Easy85A cloud security architect is designing a data retention policy for a cloud-based document management system. The policy must ensure that documents are automatically deleted after a specified retention period, and that deletion is verifiable and irreversible. Which cloud-native feature should be implemented to meet these requirements?
Medium86A cloud storage bucket is configured with versioning enabled. A ransomware attack encrypts all objects in the bucket. How can the organization recover the original data?
Medium87A multinational corporation uses a cloud-based data warehouse. The security team must ensure that data is irreversibly destroyed when it is no longer needed, even across backups and replicas. The cloud provider offers a cryptographic erase feature. What is the MOST important consideration when relying on cryptographic erase?
Hard88Which of the following is the primary benefit of using client-side encryption for data stored in the cloud?
Easy89A cloud engineer must ensure that data written to a cloud block storage volume is encrypted at rest using keys the organization controls, while allowing the provider to perform snapshots. The organization wants to avoid re-encrypting data in the application and wants minimal performance impact. Which approach BEST meets these requirements?
Medium90An organization is moving sensitive customer data to the cloud and must ensure that data is encrypted before being sent to the cloud provider. They want to maintain full control over the encryption keys and not rely on the cloud provider for any key management. Which approach should they use?
Easy91A cloud security team is implementing a data discovery and classification solution for a multi-cloud environment. They need to identify and classify data stored in object storage buckets across AWS, Azure, and Google Cloud. The solution must automatically detect sensitive data such as personally identifiable information (PII) and protected health information (PHI). Which TWO capabilities are MOST critical for the solution to effectively classify data across these platforms? (Choose two.)
Hard92A financial services firm stores transaction logs in a cloud object storage bucket. Regulations require that deleted records be irrecoverable within 24 hours, even from provider-managed replicas and backups. The security team must select a deletion method that meets this requirement without relying on provider assurances. Which approach BEST satisfies the requirement?
Hard93A financial services company must comply with a regulation that requires encryption keys used for cloud services to be generated and stored on-premises in a Hardware Security Module (HSM). The cloud provider must not have any access to the keys. Which key management approach should the company adopt?
Medium94A multinational corporation uses a cloud-based data warehouse. The security team must enforce a policy that prevents any user from exporting query results containing more than 100 personally identifiable information (PII) records to an external IP address. Which cloud data security control is MOST appropriate?
Hard95A multinational corporation uses a cloud-based data warehouse to analyze customer data across regions. The company must comply with GDPR, which restricts cross-border data transfers. The security architect needs to ensure that data subjects' personal data remains within the EU region and is not replicated to other regions. Which cloud data security control should be implemented?
Hard96A cloud security analyst is reviewing access logs and notices that a pre-signed URL for an object was used after its expiration time. What should be the outcome of such an access attempt?
Easy97A cloud security architect is designing a data retention and deletion strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a database service and object storage. Regulations require that customer data be permanently deleted upon request, including from backups and disaster recovery sites. Which TWO controls are MOST critical to ensure compliance? (Choose two.)
Hard98A multinational corporation must comply with GDPR and local data residency laws. They are designing a cloud storage architecture that will store customer data in the EU region. However, to improve disaster recovery, they want to replicate data to a secondary region outside the EU. Which approach meets compliance requirements?
Hard99A multinational corporation uses a cloud-based data lake to store aggregated analytics data. The security team needs to ensure that data subjects can exercise their right to erasure under GDPR, even when data is replicated across multiple cloud regions and stored in immutable backups. Which strategy best addresses this requirement?
Hard100A multinational corporation uses a cloud-based data warehouse. The security team must ensure that data remains encrypted at rest and that encryption keys are automatically rotated every 90 days without manual intervention. The keys must be stored in a hardware security module (HSM) and be auditable. Which solution meets these requirements?
Hard101A financial services firm stores sensitive customer data in an object storage bucket. The security team wants to prevent the cloud provider's administrators from accessing the plaintext data, even though the provider manages the underlying infrastructure. The firm also needs to retain full control over the encryption keys and the ability to revoke access immediately. Which approach best meets these requirements?
Medium102A cloud security team is implementing a data loss prevention (DLP) solution for a cloud storage environment. They need to detect and prevent the exfiltration of sensitive data, including personally identifiable information (PII) and intellectual property, in real time. The solution must also provide granular reporting on policy violations. Which approach is most effective?
Hard103A company has enabled object versioning on its cloud storage bucket to protect against accidental deletion. A ransomware attack encrypts all objects and creates new versions. To recover the data, the company needs to restore the previous unencrypted versions. What is the most efficient recovery method?
Medium104A cloud security administrator is configuring encryption for a new cloud storage bucket that will hold archived logs. The logs are not highly sensitive but must be encrypted at rest to meet a compliance requirement. The administrator wants to minimize operational overhead and does not need to manage keys. Which encryption option is MOST appropriate?
Easy105A healthcare organization is storing patient records in a cloud object storage service. They must encrypt data at rest with keys they control and rotate regularly, but they do not want to manage the encryption process themselves. Which encryption option should they use?
Easy106A cloud security team is implementing a data loss prevention (DLP) solution for data stored in a cloud object storage service. They need to detect and prevent the upload of files containing personally identifiable information (PII). The DLP solution must inspect file contents in near real-time as objects are uploaded. Which approach is MOST effective?
Medium107An organization uses a cloud-based data analytics platform with data stored in a data warehouse. The security team discovers that some tables contain unencrypted personally identifiable information (PII). They need to automatically scan the data warehouse for PII and apply pseudonymization to protect sensitive columns. Which cloud service should be used?
Hard108A financial services company stores regulated transaction logs in a cloud object storage bucket. The security team must ensure that even the cloud provider's administrators cannot access the plaintext data, and that the company can immediately revoke access for a compromised internal user without re-encrypting all objects. Which approach BEST meets these requirements?
Medium109A company uses a cloud key management service (KMS) with an HSM-backed key for encrypting sensitive data. They want to ensure that the key is automatically rotated every 90 days and that older key versions are retained for decryption of previously encrypted data. Which KMS feature should be configured?
Hard110A cloud security team needs to ensure that all data in transit between on-premises systems and the cloud is encrypted. Which TWO options should they consider? (Choose two.)
Easy111A cloud security architect is designing a key management strategy for a hybrid cloud environment. The organization requires that encryption keys never leave their on-premises hardware security module (HSM) due to strict regulatory mandates, yet cloud services must be able to perform encryption operations on data at rest. Which key management approach meets these requirements?
Hard112A cloud security architect is designing a key management strategy to meet regulatory requirements for key separation and tamper evidence. Which TWO of the following are benefits of using hardware security modules (HSMs) backing a cloud KMS? (Select TWO.)
Medium113A data classification scheme for a cloud environment defines labels such as Public, Internal, Confidential, and Restricted. Which label should be applied to data that, if disclosed, would cause severe damage to the organization and is subject to regulatory fines?
Medium114A cloud security team is reviewing access controls for a storage bucket containing sensitive data. They want to ensure that only authorized users can access the data and that access is logged for auditing. Which cloud-native mechanism should they implement?
Easy115A security architect is designing a multi-cloud data protection strategy. They need to give a third-party auditor time-limited, read-only access to a specific file in a cloud storage bucket. Which access control method is most appropriate?
Medium116A cloud data architect is designing a tokenization solution for a payment processing platform hosted in a public cloud. The platform must store primary account numbers (PANs) while minimizing PCI DSS scope and preventing raw PAN exposure in application logs and analytics pipelines. Which TWO design elements are most critical to achieve these goals? (Choose two.)
Hard117A cloud architect is designing a data classification scheme for a SaaS provider. The provider handles customer data that includes public marketing materials, internal policies, and sensitive customer financial records. Which classification level should be assigned to customer financial records to enforce the highest level of protection?
Medium118An organization uses cloud storage and wants to protect against accidental deletion of objects. They also want to be able to recover previous versions of objects in case of unintended modifications. Which feature should they enable?
Easy119A financial services company stores sensitive data in a cloud provider's object storage. The security team wants to enforce that all data is encrypted at rest using keys that the company controls, and that the cloud provider cannot access the plaintext keys. Which cloud data security control should they implement?
Hard120A financial services company is migrating a customer analytics platform to a public cloud IaaS environment. The security team must ensure that sensitive data at rest in the cloud provider's block storage volumes is encrypted and that the company retains sole control over the encryption keys, even from the cloud provider. Which approach BEST meets these requirements?
MediumOther domains
All CCSP exam domains
Frequently asked questions
- What does the Cloud Data Security domain cover on the CCSP exam?
- Be able to map a stated data protection requirement to the exact control: key custody model, scoped time-bound access, or region restriction. The single most important thing is identifying who owns and can revoke the encryption key, since that decides most answers.
- How many questions are in this domain?
- This page lists all 120 Cloud Data Security questions in the CCSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Cloud Data Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.