Courseiva

CCNA Cloud Data Security Questions

45 of 120 questions · Page 2/2 · Cloud Data Security · Answers revealed

76
MCQmedium

An organization wants to share a large file from a cloud storage bucket with an external partner for a limited time. They need to ensure that the partner can only access the specific file and that the access expires automatically. Which method should they use?

A.Make the bucket public
B.Create a new cloud provider user account for the partner and attach a custom policy to the bucket
C.Use cross-region replication
D.Use a pre-signed URL
AnswerD

A pre-signed URL embeds temporary credentials in the link itself, granting time-limited access to one specific object without exposing bucket permissions or requiring the partner to hold Microsoft Entra ID credentials. The expiry parameter satisfies the automatic revocation constraint, while scoping to a single object meets the least-privilege requirement for external sharing.

Why this answer

A pre-signed URL provides temporary access to a specific object in a cloud storage bucket, with an expiration time. It grants the external partner permission to download the file without needing a cloud account, and access automatically expires. This meets the requirements of limited-time, specific-file access.

Exam trap

The trap is overlooking the need for automatic expiration and specific file access. Candidates might choose making the bucket public for simplicity, but that fails security and expiration requirements.

How to eliminate wrong answers

Option A is wrong because making the bucket public grants access to all objects indefinitely, violating the requirement for limited time and specific file. Option B is wrong because creating a new user account is more complex, may not automatically expire, and grants broader access than needed. Option C is wrong because cross-region replication copies data to another region but does not provide temporary access to an external partner.

77
Multi-Selectmedium

A cloud security architect is designing a data loss prevention (DLP) strategy for a cloud environment that stores sensitive customer data. Which TWO techniques should be implemented to proactively identify and protect sensitive data? (Select TWO.)

Select 2 answers
A.Cross-region replication
B.De-identification transforms
C.Automated DLP scanning for sensitive data
D.Bucket policies blocking all public access
E.Enabling object versioning
AnswersB, C

De-identification transforms (tokenisation, masking, generalisation) remove or replace direct identifiers so stored records no longer expose customer identities, satisfying the requirement to protect sensitive data at rest. Unlike detection-only controls, they proactively reduce the data's sensitivity before exposure, limiting breach impact and supporting privacy compliance.

Why this answer

Option B (de-identification transforms) is correct because techniques such as tokenization, masking, pseudonymization, and generalization remove or obscure personally identifiable information (PII) so that sensitive customer data is protected even when accessed or processed, directly supporting a proactive DLP strategy. Option C (automated DLP scanning for sensitive data) is correct because continuous automated discovery and classification of sensitive data (e.g., using pattern matching, regex, and ML-based classifiers) lets the organization proactively locate and tag PII across storage and data flows so protection controls can be applied. Option A (cross-region replication) is not a DLP control; it improves durability and availability but can actually widen the data exposure footprint.

Option D (bucket policies blocking all public access) is a useful access control, but it is reactive perimeter hardening rather than a technique for identifying sensitive data. Option E (enabling object versioning) supports recovery and immutability but does nothing to discover, classify, or de-identify sensitive data.

Exam trap

CCSP often tests the distinction between preventive access controls (bucket policies, versioning) and proactive data-centric controls (DLP scanning, de-identification) — candidates pick access controls that do not actually identify or transform sensitive data.

78
MCQmedium

A cloud security architect is designing a data retention strategy for a SaaS application hosted on a public cloud. The application stores user-generated content in a multi-tenant database. Regulatory requirements mandate that user data be permanently deleted upon request within 30 days. The architect needs to ensure that backups and replicas also honor the deletion. Which approach BEST ensures compliance with the deletion requirement?

A.Use a database that supports per-user encryption keys and crypto-shredding by deleting the keys upon user request.
B.Implement soft delete by marking records as deleted and filtering them out in the application, while retaining them in the database for audit purposes.
C.Configure the database to automatically purge records older than 30 days using a time-to-live (TTL) setting.
D.Schedule a nightly job that runs a DELETE SQL statement to remove user records from the primary database and all replicas.
AnswerA

Crypto-shredding involves encrypting each user's data with a unique key and then deleting the key when deletion is requested. This renders the data irrecoverable, even in backups and replicas, because the ciphertext cannot be decrypted. It effectively achieves permanent deletion without having to locate and erase every copy. This is a robust method for complying with deletion requirements in distributed systems.

Why this answer

Crypto-shredding is the most effective way to ensure permanent deletion in a multi-tenant cloud environment with backups and replicas. By encrypting each user's data with a unique key and deleting the key, the data becomes irrecoverable everywhere it exists, including backups. This satisfies the 30-day deletion requirement without needing to track and erase every copy, which is impractical in distributed systems with immutable backups.

Other methods leave data remnants in backups or fail to permanently erase data.

Exam trap

The trap here is assuming that deleting records from the primary database and replicas is sufficient, when backups and immutable storage often retain data beyond the deletion window.

79
MCQmedium

A multinational corporation is using a cloud-based data warehouse to analyze customer data. The data includes personally identifiable information (PII) from various countries. The security team needs to ensure that data is anonymized before analysis to comply with privacy regulations. Which technique should they use?

A.Tokenization
B.Data masking
C.Encryption with customer-managed keys
D.Generalization and suppression
AnswerD

Generalization replaces specific values with broader categories, and suppression removes certain data fields. These techniques are core to anonymization frameworks like k-anonymity, making it difficult to re-identify individuals. They align with privacy regulations that require anonymization for data analysis.

Why this answer

Generalization and suppression are anonymization techniques that reduce data granularity and remove identifiers, making re-identification difficult. Tokenization and masking are reversible or not fully anonymizing, and encryption does not anonymize. These techniques help comply with privacy regulations by ensuring data cannot be linked to individuals.

Exam trap

The trap here is equating de-identification techniques like masking or tokenization with true anonymization, which requires irreversibility.

80
MCQmedium

A cloud architect is designing a data retention solution for a SaaS application hosted with a cloud provider. The organization must ensure that customer data is irretrievably destroyed at the end of its retention period, even though the data is stored in a multi-tenant object storage service with underlying solid-state drives. Which approach best satisfies this requirement?

A.Issue a delete command to the object storage API and rely on the provider's background garbage collection to erase the data blocks.
B.Overwrite the objects with random data before deleting them, then request a certificate of media destruction from the provider.
C.Use crypto-shredding: encrypt each customer's data with a unique data encryption key and destroy the key when retention expires.
D.Move the data to an infrequent access storage tier and configure a lifecycle policy to expire it after the retention period.
AnswerC

Crypto-shredding renders data unrecoverable by deleting the encryption key. In a multi-tenant cloud object store, physical destruction of specific data is not feasible, but destroying the unique key makes the ciphertext useless. This meets the irretrievable destruction requirement without relying on provider media sanitization.

Why this answer

Crypto-shredding is the most reliable method for irretrievable destruction in multi-tenant cloud storage because it makes data unreadable by destroying the key. Physical destruction or overwriting is impractical when the provider controls the media and may keep replicas. Destroying a unique key per customer ensures that even residual ciphertext cannot be decrypted.

Exam trap

The trap here is assuming that a standard delete operation or lifecycle expiration physically erases data from cloud storage media.

81
MCQmedium

A cloud security analyst is reviewing data flows for a web application that stores session tokens in a cloud database. The tokens are considered sensitive and must be protected both at rest and in transit. The database supports encryption at rest using provider-managed keys, and the application connects over a private network link. Which additional control best protects the session tokens from being exposed in the event of a database snapshot being copied to another region?

A.Restrict snapshot sharing to the same region using a bucket policy that denies cross-region replication.
B.Configure the application to hash session tokens before storing them so the database never contains the original token values.
C.Enable database audit logging to record every query that accesses the session token table and alert on unusual access patterns.
D.Enable customer-managed keys for the database encryption so snapshots copied to another region remain encrypted under keys the organization controls.
AnswerD

Customer-managed keys ensure that snapshots retain encryption tied to the organization's key policy, so a copied snapshot cannot be decrypted without access to those keys. This protects the session tokens even if the snapshot leaves the original region. Provider-managed keys may still protect the snapshot, but the organization has less control over access and revocation.

Why this answer

Customer-managed keys are the best additional control because they keep snapshot encryption under the organization's key policy, so a snapshot copied to another region remains unreadable without those keys. Audit logging, hashing, and bucket policies either detect rather than prevent, break application functionality, or can be bypassed by privileged actions.

Exam trap

The trap here is assuming that provider-managed encryption or a regional policy is sufficient, when the scenario requires that a copied snapshot remain protected under keys the organization can control and revoke.

82
MCQeasy

A startup is deploying a new cloud application that stores user profile pictures in an object storage bucket. The security team wants to ensure that data at rest is encrypted and that the encryption keys are managed by the cloud provider with minimal operational overhead. Which encryption option should they choose?

A.Server-side encryption with customer-provided keys (SSE-C).
B.Server-side encryption with provider-managed keys (SSE-S3 or equivalent).
C.Client-side encryption with keys stored in an on-premises hardware security module (HSM).
D.Server-side encryption with customer-managed keys in the cloud KMS (SSE-KMS).
AnswerB

Server-side encryption with provider-managed keys automatically encrypts data at rest and the cloud provider handles all key management, including rotation and storage. This meets the requirement for encryption at rest with minimal operational overhead, as the startup does not need to manage any keys. It is the simplest and most appropriate choice for this scenario.

Why this answer

Server-side encryption with provider-managed keys automatically encrypts data at rest and the cloud provider handles all aspects of key management, including generation, rotation, and storage. This requires no effort from the startup, perfectly aligning with the goal of minimal operational overhead while ensuring data at rest is encrypted.

Exam trap

The trap here is assuming that customer-managed keys in the cloud KMS require no overhead; in reality, they still involve key management tasks, whereas provider-managed keys are fully handled by the provider.

83
MCQhard

A multinational corporation uses a cloud-based data warehouse to store aggregated analytics data. The data includes anonymized user behavior logs that, when combined with a separate dataset of user identifiers, could re-identify individuals. The security team wants to implement a data masking technique that preserves the statistical properties of the data for analytics while preventing re-identification. Which technique BEST meets these requirements?

A.Data generalization that replaces specific values with broader categories, such as age ranges instead of exact ages.
B.Differential privacy that adds controlled noise to query results or data values to protect individual privacy.
C.Format-preserving encryption that encrypts user identifiers while maintaining their original format.
D.Tokenization that replaces user identifiers with randomly generated tokens stored in a secure vault.
AnswerB

Differential privacy adds mathematical noise to data or query results, ensuring that the inclusion or exclusion of any single individual does not significantly affect the output. This preserves aggregate statistical properties while preventing re-identification. It is specifically designed for analytics scenarios where utility must be maintained. Unlike masking or tokenization, it provides a quantifiable privacy guarantee, making it the best fit for this requirement.

Why this answer

Differential privacy is the only technique that provides a formal privacy guarantee while allowing accurate statistical analysis. It works by injecting noise calibrated to the sensitivity of the data, ensuring that individual records cannot be distinguished. This preserves the overall distribution and correlations, which are essential for analytics.

Other techniques either destroy statistical utility or provide weaker privacy guarantees that can be compromised through auxiliary data.

Exam trap

The trap here is confusing data masking techniques that preserve format or referential integrity with those that preserve statistical properties, which is a unique characteristic of differential privacy.

84
MCQeasy

A company wants to enforce data classification in its cloud environment. They need to automatically identify and label sensitive data such as credit card numbers in cloud storage. Which service should they use?

A.Cloud KMS
B.Cloud DLP
C.Cloud Audit Logs
D.Cloud IAM
AnswerB

Cloud DLP scans storage repositories and uses pattern matching and checksums to detect credit card numbers, then applies classification labels automatically. This directly satisfies the requirement to identify and label sensitive data at scale, which manual tagging or generic encryption services cannot achieve.

Why this answer

Cloud DLP (Data Loss Prevention) is designed to automatically discover, classify, and label sensitive data such as credit card numbers, social security numbers, and personally identifiable information in cloud storage and other services. It uses built-in and custom infoType detectors (including regex and checksum validation for credit cards) to identify and tag sensitive content, directly fulfilling the requirement to automatically identify and label sensitive data.

Exam trap

The trap is that candidates may choose Cloud KMS thinking 'protecting sensitive data' means encryption — but the question specifically asks for automatic identification and labeling of data content, which is DLP's unique classification capability, not encryption or access control.

How to eliminate wrong answers

Option A (Cloud KMS) is wrong because Key Management Service handles cryptographic key creation, rotation, and usage — it protects data via encryption but does not inspect or classify content. Option C (Cloud Audit Logs) is wrong because audit logs record API activity and administrative actions for compliance and forensics, not data content classification. Option D (Cloud IAM) is wrong because Identity and Access Management controls who can access resources via roles and policies, but it does not scan or label data based on sensitivity.

85
MCQmedium

A cloud security architect is designing a data retention policy for a cloud-based document management system. The policy must ensure that documents are automatically deleted after a specified retention period, and that deletion is verifiable and irreversible. Which cloud-native feature should be implemented to meet these requirements?

A.Bucket versioning with a retention policy.
B.Client-side encryption with key deletion after the retention period.
C.Manual deletion by administrators on a scheduled basis.
D.Object lifecycle management policies with expiration actions.
AnswerD

Object lifecycle management policies allow administrators to define rules that automatically delete objects after a specified period. These policies are enforced by the cloud provider, and deletion is typically permanent and irreversible (unless versioning or soft delete is enabled). The provider logs lifecycle actions, providing verifiability. This meets the requirements for automatic, verifiable, and irreversible deletion.

Why this answer

Object lifecycle management policies are cloud-native features that automatically transition or delete objects based on age or other criteria. They are enforced by the provider, ensuring consistent application, and typically log actions for audit. When configured to delete after a retention period, they provide automatic, verifiable, and irreversible removal of data, meeting the policy requirements.

Exam trap

The trap here is confusing crypto-shredding (key deletion) with actual data deletion; key deletion leaves the encrypted data in place and may not satisfy legal retention requirements.

86
MCQmedium

A cloud storage bucket is configured with versioning enabled. A ransomware attack encrypts all objects in the bucket. How can the organization recover the original data?

A.Use the cloud provider's backup service to restore the bucket
B.Replicate data from the cross-region replica
C.Use the cloud provider's ransomware recovery service
D.Restore from previous versions of the objects
AnswerD

Versioning retains prior copies of each object, so overwritten or encrypted current versions can be replaced by restoring an earlier, unencrypted version. This recovers the original data without paying a ransom or relying on provider intervention.

Why this answer

Object versioning retains every prior version of an object, so when ransomware overwrites or encrypts the current version, the original unencrypted versions remain accessible. Recovery is performed by restoring the previous version (or promoting it to current) via the object versioning API or console.

Exam trap

The trap is reaching for a dedicated 'backup' or 'replication' answer when the question explicitly states versioning is enabled — versioning itself is the recovery mechanism.

How to eliminate wrong answers

Option A is wrong because the question specifies versioning is enabled — the recovery mechanism is versioning itself, not a separate provider backup service (which may not exist or may not be configured). Option B is wrong because cross-region replication would replicate the encrypted/overwritten objects too, unless replication of delete markers or versioning semantics is carefully configured; it is not the primary recovery path here. Option C is wrong because there is no generic 'ransomware recovery service' in cloud object storage — this is a fabricated option.

87
MCQhard

A multinational corporation uses a cloud-based data warehouse. The security team must ensure that data is irreversibly destroyed when it is no longer needed, even across backups and replicas. The cloud provider offers a cryptographic erase feature. What is the MOST important consideration when relying on cryptographic erase?

A.The data must be overwritten with random patterns before key destruction.
B.The encryption algorithm must be AES-256.
C.The cloud provider must certify that all storage media are physically destroyed.
D.The keys used for encryption must be securely destroyed and not recoverable.
AnswerD

Cryptographic erase works by destroying the encryption keys, rendering the data unreadable. If keys are backed up or escrowed, the data can be recovered, violating the requirement. Therefore, ensuring key destruction and non-recoverability is paramount. This includes removing all copies of the key from backups, HSMs, and key management systems.

Why this answer

Cryptographic erase relies on destroying the encryption keys so that data becomes permanently unrecoverable. The critical factor is ensuring that all copies of the keys are destroyed and cannot be restored from backups or escrow. Without key destruction, the data remains accessible.

Other options are either irrelevant or address different sanitization methods.

Exam trap

The trap here is focusing on the encryption algorithm or physical media destruction instead of the secure destruction of the encryption keys.

88
MCQeasy

Which of the following is the primary benefit of using client-side encryption for data stored in the cloud?

A.Automatic key rotation
B.Maximum control over encryption keys
C.Simplified key management
D.Reduced latency for data access
AnswerB

Client-side encryption means data is encrypted before it leaves the organisation, so the cloud provider never holds the plaintext or the keys. That gives maximum control over key management, unlike server-side options where the provider participates.

Why this answer

Client-side encryption means the data is encrypted before it is sent to the cloud, and the customer retains full control over the encryption keys. This gives the customer maximum control over key management, including key generation, rotation, and storage, ensuring that the cloud provider never has access to the plaintext data or the keys.

Exam trap

CCSP often tests the misconception that client-side encryption simplifies key management or provides automatic rotation, when in fact it increases customer responsibility and control.

How to eliminate wrong answers

Option A is wrong because automatic key rotation is a feature that can be provided by cloud key management services (e.g., AWS KMS, Azure Key Vault) and is not exclusive to client-side encryption; in fact, client-side encryption often requires manual key rotation. Option C is wrong because simplified key management is typically a benefit of server-side encryption where the cloud provider manages keys; client-side encryption increases key management complexity. Option D is wrong because reduced latency is not a primary benefit; client-side encryption can add latency due to encryption/decryption overhead on the client side.

89
MCQmedium

A cloud engineer must ensure that data written to a cloud block storage volume is encrypted at rest using keys the organization controls, while allowing the provider to perform snapshots. The organization wants to avoid re-encrypting data in the application and wants minimal performance impact. Which approach BEST meets these requirements?

A.Enable volume encryption using a customer-managed key stored in a cloud key management service, integrated with the block storage service.
B.Store the volume on encrypted hardware and document the provider's physical controls in the risk register.
C.Use provider-managed encryption with provider-owned keys and rely on the provider's compliance attestations.
D.Implement application-level encryption before writing blocks, managing keys in an on-premises HSM.
AnswerA

Volume-level encryption with a customer-managed key encrypts data at rest transparently to the application, so no application changes are needed. The organization controls the key lifecycle in the cloud KMS, and the provider can still take snapshots because encryption is handled at the storage layer. Performance impact is minimal since encryption is offloaded to the storage infrastructure.

Why this answer

Volume encryption with a customer-managed key in a cloud KMS satisfies both the at-rest encryption mandate and the key-control requirement while remaining transparent to the application. The provider can still snapshot the volume because encryption occurs at the storage layer, and performance impact is minimal. Application-level encryption and provider-managed keys fail one or more stated constraints.

Exam trap

The trap here is equating provider-managed encryption with customer-controlled keys, when only customer-managed keys in a KMS give the organization lifecycle control.

90
MCQeasy

An organization is moving sensitive customer data to the cloud and must ensure that data is encrypted before being sent to the cloud provider. They want to maintain full control over the encryption keys and not rely on the cloud provider for any key management. Which approach should they use?

A.VPN encryption
B.Server-side encryption with AWS KMS
C.Transparent Data Encryption (TDE)
D.Client-side encryption
AnswerD

Client-side encryption encrypts data before transmission, so plaintext never reaches the provider. Because the organisation generates and retains its own keys, the cloud provider performs no key management, satisfying the requirement for full customer control.

Why this answer

Client-side encryption means the organization encrypts data before it ever leaves their environment, so the cloud provider only ever receives ciphertext and never has access to the plaintext or the keys. This satisfies both requirements: data is encrypted prior to transmission and the customer retains full control of key management (often via their own HSM or KMS). Because the provider never holds the keys, it cannot decrypt the data even if compelled or breached.

Exam trap

CCSP often tests the distinction between encryption in transit (VPN/TLS), server-side encryption (provider-managed keys), and client-side encryption (customer-managed keys) — candidates frequently pick server-side encryption with KMS assuming 'customer-managed key' equals 'full customer control,' when the provider still performs the cryptographic operations.

How to eliminate wrong answers

Option A is wrong because VPN encryption only protects data in transit between endpoints and terminates at the cloud edge, leaving data at rest unencrypted and under provider control. Option B is wrong because server-side encryption with AWS KMS means the cloud provider performs encryption and manages keys (even with customer-managed keys, the provider's infrastructure handles the cryptographic operations), which violates the requirement to not rely on the provider for key management. Option C is wrong because Transparent Data Encryption encrypts data at rest at the database layer, typically with keys managed by the database or platform, and does not encrypt data before it is sent to the cloud.

91
Multi-Selecthard

A cloud security team is implementing a data discovery and classification solution for a multi-cloud environment. They need to identify and classify data stored in object storage buckets across AWS, Azure, and Google Cloud. The solution must automatically detect sensitive data such as personally identifiable information (PII) and protected health information (PHI). Which TWO capabilities are MOST critical for the solution to effectively classify data across these platforms? (Choose two.)

Select 2 answers
A.Integration with a SIEM to forward all classification events for real-time alerting.
B.The ability to automatically remediate misclassified data by moving it to a secure bucket.
C.The ability to enforce encryption at rest using provider-managed keys on all discovered buckets.
D.Prebuilt or customizable pattern recognition for PII and PHI, such as regular expressions and machine learning models.
E.Support for native API integration with each cloud provider's storage service to enumerate and sample objects.
AnswersD, E

Effective classification requires the ability to identify sensitive data patterns. Prebuilt or customizable detectors for PII and PHI enable the solution to recognize formats like Social Security numbers, credit card numbers, and medical record identifiers. Machine learning models can improve accuracy by learning from context. Without these, the solution cannot accurately classify data, especially across diverse data types and languages.

Why this answer

The two most critical capabilities for multi-cloud data discovery and classification are the ability to access data via native APIs and the ability to recognize sensitive data patterns. Native API integration enables the solution to enumerate and sample objects across different cloud storage services. Pattern recognition, including regular expressions and machine learning, allows accurate identification of PII and PHI.

Together, these enable effective classification. Other options are either post-classification actions or unrelated security controls.

Exam trap

The trap here is selecting operational or remediation features, such as SIEM integration or auto-remediation, as critical for classification, when the core requirements are data access and pattern detection.

92
MCQhard

A financial services firm stores transaction logs in a cloud object storage bucket. Regulations require that deleted records be irrecoverable within 24 hours, even from provider-managed replicas and backups. The security team must select a deletion method that meets this requirement without relying on provider assurances. Which approach BEST satisfies the requirement?

A.Use cryptographic erasure by destroying the customer-managed key that encrypts the objects, rendering all copies undecipherable.
B.Enable bucket versioning and delete the current object versions, relying on the provider's lifecycle policy to purge noncurrent versions after 30 days.
C.Issue a delete request for each object and then open a support ticket asking the provider to confirm removal from all replicas and backups.
D.Move the objects to a colder storage class with a short retention period, then allow the provider to expire them automatically.
AnswerA

Cryptographic erasure destroys the key material, making every encrypted copy—including provider replicas and backups—unreadable without needing to locate each copy. Because the firm controls the customer-managed key, it does not rely on provider deletion guarantees. This meets the 24-hour irrecoverability requirement even when physical copies persist, and is a recognized cloud data destruction technique.

Why this answer

Cryptographic erasure is the only listed method that makes all copies—including provider-managed replicas and backups—unreadable by destroying the customer-controlled key. It avoids dependence on provider deletion timelines and assurances, so it can satisfy a strict 24-hour irrecoverability mandate. Versioning, delete requests, and storage-class changes leave recoverable copies or rely on provider processes.

Exam trap

The trap here is assuming that a delete request or lifecycle expiration removes every provider-held copy, when replicas and backups persist independently of the logical object.

93
MCQmedium

A financial services company must comply with a regulation that requires encryption keys used for cloud services to be generated and stored on-premises in a Hardware Security Module (HSM). The cloud provider must not have any access to the keys. Which key management approach should the company adopt?

A.Cloud KMS with HSM-backed keys
B.Customer-Managed Encryption Keys (CMEK)
C.Bring Your Own Key (BYOK)
D.Hold Your Own Key (HYOK)
AnswerD

Hold Your Own Key keeps key generation and storage inside the customer's on-premises HSM, so the cloud provider never gains access to plaintext keys. This directly satisfies the regulation's mandate that keys remain on-premises and inaccessible to the provider, unlike cloud-hosted alternatives where the provider retains custodial control.

Why this answer

HYOK (Hold Your Own Key) is the only approach where the customer generates and stores the encryption keys entirely on-premises in their own HSM, and the cloud provider never has access to the plaintext keys. The cloud provider only receives encrypted data or wrapped keys, so it cannot decrypt the data. This satisfies the regulation's requirement that keys be generated and stored on-premises and that the provider have zero access.

In contrast, CMEK and BYOK still involve the cloud provider's key management infrastructure, which means the provider has some level of access or control.

Exam trap

CCSP often tests the distinction between key management models where the cloud provider still has access to keys (CMEK, BYOK) versus models where the customer retains exclusive control (HYOK), and candidates frequently confuse BYOK with HYOK, assuming that importing your own key means the provider has no access.

How to eliminate wrong answers

Option A is wrong because Cloud KMS with HSM-backed keys stores keys in the cloud provider's HSM, so the provider has access to the keys and they are not generated or stored on-premises. Option B is wrong because Customer-Managed Encryption Keys (CMEK) still reside in the cloud provider's KMS, meaning the provider has access to the key material and can potentially use it, violating the zero-access requirement. Option C is wrong because Bring Your Own Key (BYOK) allows you to import your own key material into the cloud provider's KMS, but once imported, the provider has access to the key and it is stored in the cloud, not exclusively on-premises.

94
MCQhard

A multinational corporation uses a cloud-based data warehouse. The security team must enforce a policy that prevents any user from exporting query results containing more than 100 personally identifiable information (PII) records to an external IP address. Which cloud data security control is MOST appropriate?

A.Apply row-level security in the data warehouse to limit the number of PII records each user can query.
B.Enable database activity monitoring (DAM) on the data warehouse to log all queries and alert on large result sets.
C.Configure cloud storage bucket policies to deny access from external IP ranges.
D.Implement a cloud access security broker (CASB) with data loss prevention (DLP) policies that inspect outbound traffic for PII and block transfers exceeding the threshold.
AnswerD

A CASB with DLP can inspect data in transit, identify PII patterns, and enforce policies based on content and volume. It can block or alert on exports that exceed the defined threshold to external IPs, directly addressing the requirement. This is the most appropriate control because it operates at the data level and can be applied across cloud services.

Why this answer

A CASB with DLP is designed to inspect data in motion, recognize sensitive information like PII, and enforce policies based on content and volume. It can block or alert on transfers that exceed the defined threshold to external IP addresses, providing the inline enforcement needed to prevent data exfiltration. Other controls either lack content inspection or cannot block the transfer in real time.

Exam trap

The trap here is confusing access control with data loss prevention; bucket policies and row-level security govern access to data but do not inspect or limit the volume of data being exported.

95
MCQhard

A multinational corporation uses a cloud-based data warehouse to analyze customer data across regions. The company must comply with GDPR, which restricts cross-border data transfers. The security architect needs to ensure that data subjects' personal data remains within the EU region and is not replicated to other regions. Which cloud data security control should be implemented?

A.Use of a cloud access security broker (CASB) to monitor data flows
B.Tokenization of all personal data before storing in the cloud data warehouse
C.Encryption of data at rest with customer-managed keys stored in the EU
D.Data residency policies enforced through cloud provider's region lock feature
AnswerD

Data residency policies enforced through the cloud provider's region lock feature allow the organization to restrict data storage and processing to a specific geographic region. This ensures that personal data remains within the EU, complying with GDPR's cross-border transfer restrictions. It is a direct control that prevents replication to other regions.

Why this answer

GDPR requires that personal data of EU subjects not be transferred to countries without adequate protection unless specific safeguards are in place. To ensure data remains within the EU, the organization should use the cloud provider's region lock or data residency feature, which restricts data storage and processing to a chosen region. This preventive control directly addresses the requirement.

Exam trap

The trap here is confusing encryption or tokenization with data residency; both protect data but do not prevent cross-border replication, which is the core GDPR concern.

96
MCQeasy

A cloud security analyst is reviewing access logs and notices that a pre-signed URL for an object was used after its expiration time. What should be the outcome of such an access attempt?

A.The request is redirected to a new URL automatically
B.The request is allowed because the URL was generated with valid credentials
C.The request is denied with an access denied error
D.The request is logged but still granted
AnswerC

A pre-signed URL carries a cryptographic signature embedding its expiry timestamp. Once that time passes, the storage service validates the signature and rejects the request, returning an access denied error rather than serving the object.

Why this answer

Pre-signed URLs embed an expiration timestamp (the X-Amz-Expires parameter, capped at 7 days for SigV4) that the storage service validates on every request. Once the current time exceeds that expiry, the signature is treated as invalid and the service returns HTTP 403 AccessDenied. The credentials used to generate the URL are irrelevant at access time — only the signed expiry governs validity.

Exam trap

The trap here is assuming that valid credentials or an active IAM identity can override an expired pre-signed URL — candidates conflate credential validity with signature validity and pick the 'allowed' option.

How to eliminate wrong answers

Option A is wrong because pre-signed URLs are static signed strings; the storage service has no mechanism to redirect an expired request to a freshly signed URL — that would defeat the security purpose of expiration. Option B is wrong because the validity of the generating credentials does not extend the URL's life; the embedded expiration is authoritative and is checked independently of whether the signer's keys are still active. Option D is wrong because logging an event does not imply granting access — an expired signature fails validation before any authorization decision, so the request is rejected, not merely audited.

97
Multi-Selecthard

A cloud security architect is designing a data retention and deletion strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a database service and object storage. Regulations require that customer data be permanently deleted upon request, including from backups and disaster recovery sites. Which TWO controls are MOST critical to ensure compliance? (Choose two.)

Select 2 answers
A.Maintain an immutable audit log of all deletion requests and actions taken.
B.Use a centralized key management system with automated key rotation every 30 days.
C.Ensure that the cloud provider's backup and disaster recovery processes include mechanisms to propagate deletions to all copies.
D.Implement cryptographic erase by destroying the encryption keys associated with the customer's data.
E.Enable versioning on object storage buckets to prevent accidental deletion.
AnswersC, D

Backups and DR sites often retain data separately, so deletions must be propagated to them. Without this, data could persist indefinitely. This control is critical to ensure that deletion requests are honored across all storage locations, including offsite replicas, meeting the regulatory requirement.

Why this answer

To ensure permanent deletion across backups and DR sites, cryptographic erase (destroying keys) and propagating deletions to all copies are critical. Key rotation and audit logs do not delete data, and versioning can retain data. These two controls together ensure that data is irrecoverable and removed from all storage locations.

Exam trap

The trap here is assuming that key rotation or audit logging can substitute for actual data deletion, when they only provide security or evidence, not removal.

98
MCQhard

A multinational corporation must comply with GDPR and local data residency laws. They are designing a cloud storage architecture that will store customer data in the EU region. However, to improve disaster recovery, they want to replicate data to a secondary region outside the EU. Which approach meets compliance requirements?

A.Use cross-region replication to a non-EU region but apply client-side encryption before upload
B.Use same-region replication within the EU and disable cross-region replication
C.Use cross-region replication to a US region and encrypt data with SSE-S3
D.Use cross-region replication to a non-EU region and rely on a Data Processing Agreement (DPA)
AnswerB

Keeping replication within the EU and disabling cross-region replication prevents customer data leaving the jurisdiction, satisfying GDPR and local data residency rules. Disaster recovery is still provided through same-region replication, so compliance is met without unlawful transfer.

Why this answer

GDPR and data residency laws restrict transferring EU personal data to non-EU regions without an adequate legal mechanism, and cross-region replication to a non-EU region constitutes such a transfer. Keeping replication within the EU (same-region or intra-EU) and disabling cross-region replication to non-EU locations satisfies residency while still providing redundancy. This is the only option that avoids an unlawful transfer entirely.

Exam trap

The trap is believing that encryption (client-side or SSE) or a DPA legally sanitizes a cross-border transfer — candidates pick encryption as a compliance shortcut when the regulation actually restricts the location of processing, not just its confidentiality.

How to eliminate wrong answers

Option A is wrong because client-side encryption does not change the fact that personal data is being stored and processed in a non-EU region — GDPR governs the transfer and processing location, not just the ciphertext's readability. Option C is wrong because SSE-S3 is provider-managed encryption at rest and provides no legal basis for transferring EU personal data to a US region; the data is still transferred and processed outside the EU. Option D is wrong because a DPA alone does not authorize unrestricted transfers to non-EU regions — you still need a valid transfer mechanism (SCCs, adequacy decision, BCRs) and the DPA does not override data residency statutes.

99
MCQhard

A multinational corporation uses a cloud-based data lake to store aggregated analytics data. The security team needs to ensure that data subjects can exercise their right to erasure under GDPR, even when data is replicated across multiple cloud regions and stored in immutable backups. Which strategy best addresses this requirement?

A.Store all personal data in a single cloud region to simplify deletion and avoid cross-region replication issues.
B.Use crypto-shredding by encrypting each data subject's records with a unique key and destroying that key upon erasure request.
C.Anonymize the data by removing direct identifiers, then consider the erasure request fulfilled.
D.Implement a centralized deletion workflow that removes the data from all primary storage and waits for backup retention periods to expire.
AnswerB

Crypto-shredding makes data unrecoverable by destroying the unique encryption key, even if ciphertext remains in backups or replicas. This effectively satisfies the right to erasure because the data cannot be decrypted. It works across regions and immutable backups without needing to physically delete every copy.

Why this answer

Crypto-shredding is the most effective way to satisfy erasure requests when data is replicated and backed up immutably. By destroying the unique key for a data subject, the ciphertext becomes useless, achieving erasure without needing to locate and delete every copy. This approach is scalable and works across regions.

Exam trap

The trap here is assuming that deleting data from primary storage fulfills erasure, ignoring immutable backups and cross-region replicas.

100
MCQhard

A multinational corporation uses a cloud-based data warehouse. The security team must ensure that data remains encrypted at rest and that encryption keys are automatically rotated every 90 days without manual intervention. The keys must be stored in a hardware security module (HSM) and be auditable. Which solution meets these requirements?

A.Use a cloud KMS with automatic key rotation enabled and HSM-backed keys.
B.Implement application-level encryption with keys stored in a local hardware security module (HSM) and rotate them manually every 90 days.
C.Store encryption keys in a third-party secrets manager and rotate them using a scheduled script.
D.Use provider-managed encryption keys and rely on the provider's default rotation schedule.
AnswerA

A cloud KMS with automatic rotation and HSM-backed keys provides automated key rotation at defined intervals, stores keys in HSMs, and generates audit logs. This directly meets the requirements for automatic 90-day rotation, HSM storage, and auditability without manual effort.

Why this answer

A cloud KMS with automatic rotation and HSM-backed keys provides automated, policy-driven key rotation at specified intervals, ensures keys are stored in hardware security modules, and generates audit logs. This satisfies all requirements: encryption at rest, automatic 90-day rotation, HSM storage, and auditability.

Exam trap

The trap here is assuming that any key management service with rotation capabilities will automatically meet HSM and audit requirements, when in fact not all KMS offerings are HSM-backed or provide the necessary audit detail.

101
MCQmedium

A financial services firm stores sensitive customer data in an object storage bucket. The security team wants to prevent the cloud provider's administrators from accessing the plaintext data, even though the provider manages the underlying infrastructure. The firm also needs to retain full control over the encryption keys and the ability to revoke access immediately. Which approach best meets these requirements?

A.Implement client-side encryption where the firm generates and stores keys in its own on-premises HSM.
B.Use provider-managed encryption with customer-managed keys stored in the provider's KMS.
C.Use a cloud access security broker (CASB) to encrypt data before it reaches the bucket.
D.Enable server-side encryption with provider-managed keys and enforce TLS for all data transfers.
AnswerA

Client-side encryption with keys held in an on-premises HSM ensures the cloud provider never has access to the plaintext or the keys. The firm retains exclusive control and can revoke access by simply not providing the key. This directly satisfies the requirement to prevent provider administrators from accessing plaintext data.

Why this answer

Client-side encryption with keys stored in an on-premises HSM ensures that the cloud provider never possesses the keys or the plaintext. This gives the firm exclusive control and the ability to revoke access instantly by withholding the key. Other methods leave key management with the provider or do not fully prevent provider access.

Exam trap

The trap here is assuming that using a cloud KMS with customer-managed keys prevents provider access, when in fact the provider still controls the infrastructure and may have privileged access to keys.

102
MCQhard

A cloud security team is implementing a data loss prevention (DLP) solution for a cloud storage environment. They need to detect and prevent the exfiltration of sensitive data, including personally identifiable information (PII) and intellectual property, in real time. The solution must also provide granular reporting on policy violations. Which approach is most effective?

A.Use a cloud-native DLP service that integrates with the cloud storage API and inspects data at rest and in transit.
B.Rely on the cloud provider's built-in encryption and access controls to prevent data exfiltration.
C.Deploy endpoint DLP agents on all user devices to monitor data transfers.
D.Implement a network-based DLP appliance at the perimeter to inspect all traffic leaving the cloud.
AnswerA

A cloud-native DLP service integrated with the storage API can inspect data in real time as it is accessed or moved, and can enforce policies to block exfiltration. It provides granular reporting and is designed for the cloud environment. This meets the requirements for real-time detection and prevention of sensitive data loss.

Why this answer

A cloud-native DLP service integrated with the storage API can inspect data in real time, enforce policies to block exfiltration, and provide granular reporting. It is designed for cloud environments and can monitor both data at rest and in transit within the cloud, making it the most effective solution for detecting and preventing sensitive data loss.

Exam trap

The trap here is assuming that perimeter or endpoint DLP tools are sufficient for cloud storage, when they often miss internal cloud data flows and API-based access.

103
MCQmedium

A company has enabled object versioning on its cloud storage bucket to protect against accidental deletion. A ransomware attack encrypts all objects and creates new versions. To recover the data, the company needs to restore the previous unencrypted versions. What is the most efficient recovery method?

A.Delete the current versions or use the previous versions directly
B.Use the object lifecycle policy to delete current versions
C.Request the cloud provider to restore from their backups
D.Restore from a backup stored in a different region
AnswerA

Because versioning preserved the pre-ransomware copies, the unencrypted objects still exist as prior versions. Deleting the current encrypted versions or promoting the previous versions restores data directly, avoiding full backup restoration and satisfying the efficient recovery requirement.

Why this answer

With object versioning enabled, the previous unencrypted versions of the objects still exist in the bucket as noncurrent versions, so the most efficient recovery is to delete the current (encrypted) versions or simply access the previous versions directly. This avoids any external restore process and leverages the versioning feature exactly as designed. The recovery is fast, in-place, and requires no provider intervention or cross-region transfer.

Exam trap

CCSP often tests whether candidates understand that versioning preserves prior objects in place — many pick backup or provider restore options, missing that the previous versions are directly accessible.

How to eliminate wrong answers

Option B is wrong because a lifecycle policy is used to automate deletion or transition of versions over time — it is not a recovery mechanism and would not restore data. Option C is wrong because the cloud provider does not maintain customer-accessible backups of object versions; the provider's responsibility ends at durability of the storage layer, and requesting a restore is not a supported recovery path. Option D is wrong because restoring from a cross-region backup is slower, costlier, and unnecessary when versioning already preserves the prior objects in the same bucket.

104
MCQeasy

A cloud security administrator is configuring encryption for a new cloud storage bucket that will hold archived logs. The logs are not highly sensitive but must be encrypted at rest to meet a compliance requirement. The administrator wants to minimize operational overhead and does not need to manage keys. Which encryption option is MOST appropriate?

A.Server-side encryption with customer-managed keys stored in a cloud KMS.
B.Server-side encryption with customer-provided keys (SSE-C) supplied with each API request.
C.Client-side encryption with keys stored on-premises in a hardware security module (HSM).
D.Server-side encryption with provider-managed keys (SSE-S3 or equivalent).
AnswerD

Server-side encryption with provider-managed keys automatically encrypts data at rest and handles key management, rotation, and storage. It requires no customer action and imposes minimal operational overhead. Since the logs are not highly sensitive and the requirement is simply encryption at rest, this option meets the compliance need without additional complexity. It is the default and most cost-effective approach for such scenarios.

Why this answer

For non-sensitive data with a simple encryption-at-rest requirement and a desire to minimize operational overhead, provider-managed server-side encryption is the most appropriate. It is automatic, requires no key management, and meets compliance. Customer-managed or client-side options add unnecessary complexity and cost without providing additional value for this use case.

Exam trap

The trap here is over-engineering the solution by assuming that any encryption requirement necessitates customer-managed or client-side keys, when provider-managed keys are sufficient for low-sensitivity data.

105
MCQeasy

A healthcare organization is storing patient records in a cloud object storage service. They must encrypt data at rest with keys they control and rotate regularly, but they do not want to manage the encryption process themselves. Which encryption option should they use?

A.Server-side encryption with cloud provider default keys
B.Customer-managed encryption keys (CMEK)
C.Customer-supplied encryption keys (CSEK)
D.Client-side encryption
AnswerB

Customer-managed encryption keys let the organisation retain sole control over key material and rotation schedules, while the cloud provider performs the actual cryptographic operations. This satisfies the stem's dual constraint: keys the healthcare organisation controls, without managing the encryption process itself.

Why this answer

Customer-managed encryption keys (CMEK) allow the organization to control the encryption keys (including rotation) while the cloud provider manages the encryption/decryption process. This meets the requirement of using keys they control without managing the encryption process itself. CMEK is supported by major cloud providers (e.g., AWS KMS, Azure Key Vault, Google Cloud KMS) and integrates with object storage services.

The organization retains control over key lifecycle but delegates cryptographic operations to the provider.

Exam trap

CCSP often tests the distinction between key control and encryption process management, and candidates may confuse CMEK with CSEK or client-side encryption, incorrectly assuming that controlling keys means managing the encryption process.

How to eliminate wrong answers

Option A is wrong because provider default keys are fully managed by the cloud provider, so the organization does not control the keys or their rotation. Option C is wrong because customer-supplied encryption keys (CSEK) require the organization to supply and manage the keys entirely, including rotation, which means they are managing the encryption process. Option D is wrong because client-side encryption requires the organization to encrypt data before uploading, thus managing the encryption process themselves.

106
MCQmedium

A cloud security team is implementing a data loss prevention (DLP) solution for data stored in a cloud object storage service. They need to detect and prevent the upload of files containing personally identifiable information (PII). The DLP solution must inspect file contents in near real-time as objects are uploaded. Which approach is MOST effective?

A.Enable bucket logging and periodically scan logs for PII patterns.
B.Implement client-side encryption so that PII is encrypted before upload.
C.Use a cloud-native DLP service integrated with the storage service to scan objects on upload.
D.Configure a web application firewall (WAF) to inspect uploads for PII.
AnswerC

A cloud-native DLP service can be configured to trigger on object creation events, inspect contents for PII, and take actions such as blocking or alerting. This provides near real-time detection and prevention. Integration with the storage service enables automatic scanning without manual intervention.

Why this answer

A cloud-native DLP service integrated with the storage service can automatically scan objects as they are uploaded, detect PII, and enforce policies in near real-time. Other options either do not inspect content, prevent inspection, or use inappropriate tools. Thus, the integrated DLP service is the most effective approach.

Exam trap

The trap here is thinking that encryption or logging can substitute for content inspection when the requirement is to detect PII in files.

107
MCQhard

An organization uses a cloud-based data analytics platform with data stored in a data warehouse. The security team discovers that some tables contain unencrypted personally identifiable information (PII). They need to automatically scan the data warehouse for PII and apply pseudonymization to protect sensitive columns. Which cloud service should be used?

A.Cloud Storage bucket policies
B.Cloud Access Security Broker (CASB)
C.Cloud Data Loss Prevention (DLP) API
D.Cloud Key Management Service (KMS)
AnswerC

The Cloud DLP API inspects data at rest, using infoType detectors to identify PII such as names, emails and national identifiers, then applies de-identification transforms like pseudonymisation via crypto-based tokenisation or format-preserving encryption directly to matched columns.

Why this answer

Cloud Data Loss Prevention (DLP) API is designed to discover, classify, and protect sensitive data such as PII across cloud storage and data warehouses. It can automatically scan tables, identify PII using built-in infoType detectors, and apply de-identification transformations like pseudonymization (e.g., replacing values with surrogate tokens) directly. This matches the requirement to automatically scan and pseudonymize sensitive columns without manual intervention.

Exam trap

CCSP often tests the confusion between encryption (KMS) and pseudonymization (DLP), or between access control (bucket policies) and data inspection (DLP), causing candidates to pick KMS or CASB when the question explicitly asks for automatic PII scanning and pseudonymization.

How to eliminate wrong answers

Option A is wrong because Cloud Storage bucket policies control access to objects (IAM and ACLs) but do not inspect data content for PII or perform pseudonymization. Option B is wrong because a CASB provides visibility and policy enforcement for cloud service usage (e.g., shadow IT, access control) but does not natively scan data warehouse tables for PII or apply column-level pseudonymization. Option D is wrong because Cloud KMS manages encryption keys for data at rest or in transit; it does not discover PII or perform pseudonymization—it only encrypts data, which is not the same as pseudonymization.

108
MCQmedium

A financial services company stores regulated transaction logs in a cloud object storage bucket. The security team must ensure that even the cloud provider's administrators cannot access the plaintext data, and that the company can immediately revoke access for a compromised internal user without re-encrypting all objects. Which approach BEST meets these requirements?

A.Enable provider-managed server-side encryption with a customer-managed key stored in the cloud provider's KMS.
B.Implement server-side encryption with provider-managed keys and enable bucket versioning and object lock.
C.Apply server-side encryption with customer-provided keys (SSE-C) and store the keys in the cloud provider's secret manager.
D.Use client-side encryption where the company retains sole control of the keys in an on-premises HSM and issues short-lived data keys to authorized users.
AnswerD

Client-side encryption with keys held exclusively in an on-premises HSM ensures the cloud provider never possesses the key material, so provider administrators cannot decrypt the data. Issuing short-lived data keys allows immediate revocation for a compromised user without re-encrypting all objects, satisfying both requirements.

Why this answer

Client-side encryption with keys held exclusively by the customer in an on-premises HSM ensures that the cloud provider never has access to the plaintext or the key material, which is essential when even provider administrators must be excluded. Short-lived data keys enable immediate revocation of a compromised user without re-encrypting the entire data set, meeting both the confidentiality and agility requirements.

Exam trap

The trap here is assuming that server-side encryption with customer-managed keys in the cloud KMS prevents provider administrators from accessing plaintext, when in fact the provider still controls the underlying key infrastructure.

109
MCQhard

A company uses a cloud key management service (KMS) with an HSM-backed key for encrypting sensitive data. They want to ensure that the key is automatically rotated every 90 days and that older key versions are retained for decryption of previously encrypted data. Which KMS feature should be configured?

A.Automatic key rotation with version retention
B.Key aliasing
C.Key destruction schedule
D.Key revocation policy
AnswerA

Automatic key rotation with version retention satisfies both constraints: it rotates the HSM-backed key on the 90-day schedule while preserving prior key versions, so data encrypted under earlier versions remains decryptable. Rotation alone would render old ciphertext unreadable without retained versions.

Why this answer

Automatic key rotation with version retention is the correct KMS feature because it enables the system to generate a new cryptographic key version on a defined schedule (e.g., every 90 days) while preserving all previous versions. The old versions remain available for decrypting data that was encrypted under them, ensuring backward compatibility. This directly satisfies both requirements: automatic rotation and retention of older key versions for decryption.

Exam trap

CCSP often tests the misconception that key rotation requires re-encrypting all data or that old key versions are automatically deleted, leading candidates to choose key destruction or revocation instead of version retention.

How to eliminate wrong answers

Option B is wrong because key aliasing is simply a human-friendly name that points to a key, and it does not perform rotation or retain old versions for decryption. Option C is wrong because a key destruction schedule permanently deletes key material after a set period, which would make previously encrypted data unrecoverable and directly contradicts the need to retain older versions. Option D is wrong because a key revocation policy disables or revokes a key, preventing its use for both encryption and decryption, which again conflicts with the requirement to decrypt older data.

110
Multi-Selecteasy

A cloud security team needs to ensure that all data in transit between on-premises systems and the cloud is encrypted. Which TWO options should they consider? (Choose two.)

Select 2 answers
A.Set up a VPN between on-premises and cloud
B.Use signed URLs for access
C.Enable bucket versioning
D.Enable server-side encryption with CMEK
E.Use TLS 1.2+ for all API calls
AnswersA, E

An IPsec VPN encrypts all traffic traversing the tunnel between on-premises gateways and cloud networks, covering every protocol rather than individual sessions. This satisfies the requirement that all data in transit be encrypted, since the tunnel provides blanket protection regardless of application.

Why this answer

Option A is correct because a VPN (typically IPsec or SSL/TLS-based) creates an encrypted tunnel over the public internet between on-premises networks and the cloud, protecting all data in transit at the network layer. Option E is correct because enforcing TLS 1.2 or higher on all API calls encrypts application-layer traffic end-to-end, ensuring data in transit between clients and cloud services is protected with strong ciphers. Option B is incorrect because signed URLs only grant time-limited access to specific resources; they do not encrypt the data in transit.

Option C is incorrect because bucket versioning preserves object versions for recovery and durability, not encryption. Option D is incorrect because server-side encryption with CMEK protects data at rest, not data in transit.

Exam trap

CCSP often tests the distinction between encryption in transit and at rest, and candidates may mistakenly select server-side encryption with CMEK (which is for data at rest) or signed URLs (which are for access control) when asked about data in transit.

111
MCQhard

A cloud security architect is designing a key management strategy for a hybrid cloud environment. The organization requires that encryption keys never leave their on-premises hardware security module (HSM) due to strict regulatory mandates, yet cloud services must be able to perform encryption operations on data at rest. Which key management approach meets these requirements?

A.Customer-managed encryption keys (CMEK)
B.Hold Your Own Key (HYOK)
C.Cloud provider default encryption
D.Bring Your Own Key (BYOK)
AnswerB

HYOK retains key material within the customer's on-premises HSM, with cryptographic operations performed locally or via a proxy, so keys never leave the HSM. This satisfies the regulatory mandate while still permitting encryption of cloud data at rest.

Why this answer

HYOK (Hold Your Own Key) keeps the master key material inside the customer's on-premises HSM and never exports it to the cloud provider. The cloud service sends cryptographic operations (encrypt/decrypt) to the on-prem HSM via a secure channel, so keys never leave the customer's control while still enabling encryption of cloud data at rest. This satisfies the regulatory mandate that keys remain on-premises.

Exam trap

The trap is conflating BYOK with HYOK — both involve 'your own key,' but only HYOK keeps the key physically on-premises. Candidates who skim the question miss the phrase 'keys never leave their on-premises HSM.'

How to eliminate wrong answers

Option A is wrong because CMEK (Customer-Managed Encryption Keys) still stores key material in the cloud provider's KMS/HSM — the customer manages the key lifecycle but the key resides in the provider's infrastructure, violating the 'never leave on-prem' requirement. Option C is wrong because provider default encryption uses provider-managed keys entirely, giving the customer no control over key custody at all. Option D is wrong because BYOK imports customer-generated key material into the cloud provider's KMS, so after import the key lives in the provider's HSM — it does not stay on-premises.

112
Multi-Selectmedium

A cloud security architect is designing a key management strategy to meet regulatory requirements for key separation and tamper evidence. Which TWO of the following are benefits of using hardware security modules (HSMs) backing a cloud KMS? (Select TWO.)

Select 2 answers
A.Compliance with FIPS 140-2 Level 3 or higher
B.Eliminates the need for customer-managed keys
C.Reduced latency for encryption operations
D.Automatic key rotation without customer intervention
E.Tamper-resistant key storage that prevents key extraction
AnswersA, E

HSMs validated to FIPS 140-2 Level 3 or higher provide physical tamper evidence and identity-based authentication, directly satisfying the stem's tamper-evidence requirement. Level 3's tamper-response mechanisms destroy keys on intrusion attempts, unlike software-based key stores. This certification also underpins key separation by enforcing cryptographic boundaries between tenants and roles within Microsoft Entra ID-integrated KMS deployments.

Why this answer

Option A is correct because HSMs backing a cloud KMS are validated to FIPS 140-2 (or FIPS 140-3) Level 3 or higher, which requires physical tamper resistance, identity-based authentication, and role separation — directly satisfying the regulatory key-separation and tamper-evidence requirements described. Option E is correct because HSM hardware is tamper-resistant and tamper-evident: keys are generated and used inside the cryptographic boundary and cannot be extracted in plaintext, with mechanisms that zeroize keys and leave evidence if the module is physically breached. Option B is wrong because HSMs protect keys but do not remove the need for customer-managed keys — in fact, customer-managed keys are often used with HSM-backed KMS to meet separation-of-duties requirements.

Option C is wrong because HSM-backed operations typically add network and hardware round-trip latency compared with software-only key stores, not reduce it. Option D is wrong because automatic key rotation is a KMS policy feature, not an inherent benefit of HSM backing, and many regulations still require customer-controlled or explicitly configured rotation.

Exam trap

The trap is selecting plausible-sounding but incorrect benefits like 'reduced latency' or 'automatic rotation.' Candidates must distinguish inherent HSM properties (tamper resistance, FIPS validation) from KMS policy features (rotation) and from performance claims that are usually false.

113
MCQmedium

A data classification scheme for a cloud environment defines labels such as Public, Internal, Confidential, and Restricted. Which label should be applied to data that, if disclosed, would cause severe damage to the organization and is subject to regulatory fines?

A.Restricted
B.Public
C.Confidential
D.Internal
AnswerA

Restricted fits because the stem demands the highest sensitivity tier for severe damage plus regulatory penalties. Unlike Confidential, which covers unauthorised disclosure causing damage, Restricted is reserved for data whose compromise triggers legal sanctions, so it satisfies the classification scheme's top-level handling, encryption and access-control requirements.

Why this answer

The Restricted label is reserved for the most sensitive data whose unauthorized disclosure would cause severe damage and trigger regulatory penalties. Data classification schemes typically escalate from Public → Internal → Confidential → Restricted, with Restricted representing the highest tier requiring the strictest controls (encryption, least privilege, audit logging). Because the question specifies 'severe damage' plus 'regulatory fines,' this maps directly to the top classification tier.

Exam trap

CCSP often tests the distinction between Confidential and Restricted, luring candidates who assume 'confidential' means maximum sensitivity when the exam expects Restricted for severe-damage, regulator-fined data.

How to eliminate wrong answers

Option B is wrong because Public data is intended for open disclosure and carries no confidentiality requirement, so it cannot describe data whose exposure causes severe damage. Option C is wrong because Confidential typically covers sensitive internal data whose disclosure causes moderate harm, but it sits below Restricted in most schemes and does not imply the highest protection tier. Option D is wrong because Internal merely denotes data not meant for external release but with low sensitivity, far below the severe-damage threshold described.

114
MCQeasy

A cloud security team is reviewing access controls for a storage bucket containing sensitive data. They want to ensure that only authorized users can access the data and that access is logged for auditing. Which cloud-native mechanism should they implement?

A.Encryption at rest with key rotation
B.Network Access Control Lists (ACLs) with flow logs
C.Identity and Access Management (IAM) policies with logging enabled
D.Storage bucket policies with versioning enabled
AnswerC

IAM policies define who can access resources, and enabling logging (e.g., cloud audit logs) records access attempts. This combination ensures both access control and auditability, directly meeting the scenario's requirements. It is a fundamental cloud security practice.

Why this answer

IAM policies with logging enabled provide both access control and auditability by defining permissions and recording access events. Network ACLs, bucket policies without logging, and encryption do not fully satisfy the requirement to control and log user access to the data.

Exam trap

The trap here is confusing data protection mechanisms like encryption with access control and auditing, which are separate concerns.

115
MCQmedium

A security architect is designing a multi-cloud data protection strategy. They need to give a third-party auditor time-limited, read-only access to a specific file in a cloud storage bucket. Which access control method is most appropriate?

A.Cloud VPN connection for the auditor
B.Bucket ACL granting read access to the auditor's cloud account
C.IAM policy granting read access to the auditor's user
D.Pre-signed URL with an expiration time
AnswerD

A pre-signed URL embeds temporary credentials and an expiry directly into the link, granting read-only access to one specific object without creating an identity or sharing bucket keys. This satisfies the auditor's time-limited, single-file requirement, unlike broader role-based or bucket-level permissions.

Why this answer

A pre-signed URL is a time-limited, cryptographically signed URL that grants temporary access to a specific object without requiring the auditor to have an identity in the cloud provider's IAM system. It is generated by a principal with permission to the object and embeds an expiration timestamp and signature, making it ideal for granting an external third party scoped, read-only, time-bound access to a single file. This satisfies least privilege and avoids creating persistent identities or network paths.

Exam trap

The trap is confusing network-level access (VPN) or identity-level access (IAM/ACL) with object-level temporary delegation; candidates often pick IAM because it sounds most 'secure,' missing that pre-signed URLs are the canonical least-privilege answer for third-party single-object access.

How to eliminate wrong answers

Option A is wrong because a Cloud VPN connection grants network-level access to the VPC, not object-level access to a specific file, and it is heavyweight and persistent rather than time-limited. Option B is wrong because a bucket ACL granting read to the auditor's cloud account gives access to the entire bucket, not a single file, and persists until explicitly revoked. Option C is wrong because an IAM policy granting read to the auditor's user requires creating or federating an identity in your cloud account, which is more complex and broader than necessary for a one-off audit.

116
Multi-Selecthard

A cloud data architect is designing a tokenization solution for a payment processing platform hosted in a public cloud. The platform must store primary account numbers (PANs) while minimizing PCI DSS scope and preventing raw PAN exposure in application logs and analytics pipelines. Which TWO design elements are most critical to achieve these goals? (Choose two.)

Select 2 answers
A.Use a format-preserving token that replaces the PAN with a value of similar length and character set, stored in a separate token vault with strict access controls.
B.Apply the tokenization at the point of data capture, before the PAN enters application logs, message queues, or analytics pipelines.
C.Ensure the tokenization service is deployed in the same network subnet as the analytics platform to reduce latency for token lookups.
D.Use reversible encryption with a shared symmetric key for the PAN and store the key in the application configuration file for operational simplicity.
E.Store the token-to-PAN mapping in the same database as the tokenized transaction records to simplify joins and reporting.
AnswersA, B

A format-preserving token maintains the data format so existing applications and databases can process it without schema changes, while the token vault isolates the mapping to the original PAN. Strict access controls on the vault limit exposure and reduce PCI DSS scope because most systems handle only tokens. This design directly minimizes raw PAN propagation into logs and analytics.

Why this answer

Tokenization at the point of capture and a format-preserving token stored in an isolated vault are the two critical elements. Early tokenization keeps raw PANs out of logs, queues, and analytics, while format preservation allows existing systems to process tokens without redesign. The vault separation ensures that even if downstream systems are compromised, the original PANs remain protected.

Exam trap

The trap here is treating tokenization as simply encrypting data, when the essential design is early substitution plus isolation of the token-to-PAN mapping from the systems that process tokens.

117
MCQmedium

A cloud architect is designing a data classification scheme for a SaaS provider. The provider handles customer data that includes public marketing materials, internal policies, and sensitive customer financial records. Which classification level should be assigned to customer financial records to enforce the highest level of protection?

A.Internal
B.Public
C.Restricted
D.Confidential
AnswerC

Restricted is the highest classification tier, reserved for data whose disclosure causes severe harm, such as customer financial records. Assigning it satisfies the stem's requirement to enforce the strongest protection, exceeding Confidential or Internal levels used for policies and marketing material.

Why this answer

Customer financial records represent the most sensitive data class in the scenario, requiring the highest protection tier, which is Restricted. Restricted classification enforces strict access controls, encryption, and monitoring appropriate for regulated financial data. Since the question explicitly asks for the highest level of protection, Restricted is the correct mapping.

Exam trap

CCSP often tests the tier hierarchy by presenting Confidential as a plausible 'high' answer, trapping candidates who forget that Restricted is the top classification for regulated, severe-impact data.

How to eliminate wrong answers

Option A is wrong because Internal is a low-sensitivity label for data not intended for public release but not requiring strong protection, far below financial records. Option B is wrong because Public data is deliberately open and requires no confidentiality controls. Option D is wrong because Confidential is a mid-to-high tier that covers sensitive business data but is not the top classification; the question demands the highest protection level, which is Restricted.

118
MCQeasy

An organization uses cloud storage and wants to protect against accidental deletion of objects. They also want to be able to recover previous versions of objects in case of unintended modifications. Which feature should they enable?

A.Bucket policies
B.Access logs
C.Versioning
D.Server-side encryption
AnswerC

Versioning retains prior and deleted object states within the same bucket, letting you recover overwritten or removed objects without separate backups. It directly addresses both accidental deletion and unintended modification by preserving each object's earlier versions for restoration.

Why this answer

Versioning is the cloud storage feature that retains multiple variants of an object, allowing recovery from accidental deletion or modification. When versioning is enabled, overwriting or deleting an object creates a new version or a delete marker, and previous versions remain accessible. This directly meets the requirement to recover previous versions and protect against accidental deletion.

Exam trap

The trap is confusing versioning with backup or replication; candidates might choose access logs or bucket policies thinking they enable recovery, but only versioning retains previous object versions.

How to eliminate wrong answers

Option A is wrong because bucket policies define access permissions, not data retention or version recovery. Option B is wrong because access logs record requests made to the bucket, which is useful for auditing but does not enable recovery of deleted or modified objects. Option C is correct.

Option D is wrong because server-side encryption protects data confidentiality at rest, but does not provide versioning or recovery capabilities.

119
MCQhard

A financial services company stores sensitive data in a cloud provider's object storage. The security team wants to enforce that all data is encrypted at rest using keys that the company controls, and that the cloud provider cannot access the plaintext keys. Which cloud data security control should they implement?

A.Server-side encryption with provider-managed keys (SSE-CMK) where the provider generates and stores the keys in its own KMS.
B.Server-side encryption with a hardware security module (HSM) where the provider manages the HSM and the keys are stored in the provider's key store.
C.Server-side encryption with customer-provided keys (SSE-C) where the company supplies the key with each request but the provider stores it temporarily.
D.Client-side encryption where the company encrypts data before uploading and manages its own keys outside the cloud provider's infrastructure.
AnswerD

Client-side encryption ensures that data is encrypted before it reaches the cloud provider, and the company retains sole control of the keys. The provider only stores ciphertext and cannot access plaintext keys, satisfying the requirement for exclusive control and preventing provider access.

Why this answer

Client-side encryption is the only option that guarantees the cloud provider never has access to plaintext keys, because encryption and key management occur entirely within the company's environment. Server-side options, even with customer-provided keys or HSMs, involve the provider in key handling, which introduces potential access.

Exam trap

The trap here is believing that server-side encryption with customer-provided keys (SSE-C) gives the customer sole control, when the provider still handles the key in plaintext.

120
MCQmedium

A financial services company is migrating a customer analytics platform to a public cloud IaaS environment. The security team must ensure that sensitive data at rest in the cloud provider's block storage volumes is encrypted and that the company retains sole control over the encryption keys, even from the cloud provider. Which approach BEST meets these requirements?

A.Enable cloud provider volume encryption with customer-managed keys stored in the provider's KMS.
B.Implement client-side encryption before writing data to the block storage volumes, managing keys in an on-premises HSM.
C.Use the cloud provider's native volume encryption with provider-managed keys.
D.Use transport-layer encryption (TLS) for all data written to the block storage volumes.
AnswerB

Client-side encryption encrypts data before it reaches the cloud, and storing keys in an on-premises HSM ensures the company retains exclusive control. The cloud provider only sees ciphertext and never has access to the plaintext or the keys. This satisfies both encryption at rest and sole key control requirements.

Why this answer

Client-side encryption with keys stored in an on-premises HSM ensures that data is encrypted before it leaves the company's control and that the cloud provider never has access to the encryption keys. This provides the strongest level of key control and meets both the encryption at rest and sole key control requirements. Provider-managed or customer-managed keys in the cloud still involve the provider in key management.

Exam trap

The trap here is assuming that customer-managed keys in the cloud provider's KMS give the same level of control as keys held entirely outside the provider's environment.

← PreviousPage 2 of 2 · 120 questions total

Ready to test yourself?

Try a timed practice session using only Cloud Data Security questions.