A cloud security architect is designing a data retention and deletion strategy for a SaaS application hosted in a public cloud. The organization must ensure that data is securely deleted when no longer needed, and that deletion is verifiable. Which two practices should be implemented? (Choose two.)
Cryptographic erasure renders data unrecoverable by destroying the keys used to encrypt it. This is effective in cloud environments where physical media destruction is not possible. It provides a verifiable method of deletion because once keys are destroyed, the ciphertext cannot be decrypted, meeting the requirement for secure and verifiable deletion.
Why this answer
Cryptographic erasure destroys keys to make data unrecoverable, and automated retention policies with logging provide verifiable deletion. Together, they ensure data is securely deleted and that deletion can be audited. These practices are well-suited to cloud environments where physical media control is absent.
Exam trap
The trap here is assuming that overwriting data with zeros is a valid secure deletion method in the cloud, when cloud storage abstraction makes it ineffective and unverifiable.