Courseiva

CCNA Ccsp Data Security Questions

75 of 120 questions · Page 1/2 · Ccsp Data Security topic · Answers revealed

1
Multi-Selectmedium

A cloud security architect is designing a data retention and deletion strategy for a SaaS application hosted in a public cloud. The organization must ensure that data is securely deleted when no longer needed, and that deletion is verifiable. Which two practices should be implemented? (Choose two.)

Select 2 answers
A.Use cryptographic erasure by destroying the encryption keys associated with the data.
B.Rely on the cloud provider's standard data deletion process as specified in their SLA.
C.Implement a data retention policy that automatically deletes data after a set period and logs the deletion events.
D.Overwrite data with zeros before deletion to ensure it cannot be recovered.
E.Store all data in a single cloud region to simplify deletion.
AnswersA, C

Cryptographic erasure renders data unrecoverable by destroying the keys used to encrypt it. This is effective in cloud environments where physical media destruction is not possible. It provides a verifiable method of deletion because once keys are destroyed, the ciphertext cannot be decrypted, meeting the requirement for secure and verifiable deletion.

Why this answer

Cryptographic erasure destroys keys to make data unrecoverable, and automated retention policies with logging provide verifiable deletion. Together, they ensure data is securely deleted and that deletion can be audited. These practices are well-suited to cloud environments where physical media control is absent.

Exam trap

The trap here is assuming that overwriting data with zeros is a valid secure deletion method in the cloud, when cloud storage abstraction makes it ineffective and unverifiable.

2
MCQhard

A multinational corporation must comply with GDPR and store EU customer data only within the European Union. Which cloud storage security measure directly addresses this requirement?

A.Pre-signed URLs
B.Data residency configuration
C.Bucket policies with IAM conditions
D.Cross-region replication
AnswerB

Data residency configuration pins storage and processing to specific geographic regions, so EU customer data remains physically within the European Union. This directly satisfies the GDPR locality constraint, unlike encryption, access controls or tokenisation, which protect confidentiality but do not restrict where data is stored.

Why this answer

Data residency configuration lets an organization pin where cloud data is stored and processed — for example, restricting an S3 bucket, Azure region, or GCP location to EU regions so EU customer data never leaves the European Union. This directly satisfies GDPR's data-location requirement by enforcing geographic placement at the storage/service level. It is the control that maps one-to-one to the 'store EU data only in the EU' mandate.

Exam trap

CCSP often tests the confusion between access control (bucket policies, IAM, pre-signed URLs) and data placement (residency) — candidates pick a strong-sounding access control when the question is specifically about where data is stored.

How to eliminate wrong answers

Option A is wrong because pre-signed URLs only grant temporary, time-limited access to a specific object; they say nothing about where the object is stored and cannot enforce geographic boundaries. Option C is wrong because bucket policies with IAM conditions control who can access data and under what conditions (IP, MFA, time), not where the data physically resides — a permissive policy still allows storage in any region. Option D is wrong because cross-region replication deliberately copies data to other regions, which would violate the EU-only residency requirement rather than satisfy it.

3
MCQmedium

A company is required to encrypt all data in transit between its on-premises data center and its cloud environment. They have a hybrid cloud setup and need a secure tunnel for all traffic. Which solution should they implement?

A.Client-side encryption
B.Pre-signed URLs
C.VPN connection
D.TLS 1.2+ for all API calls
AnswerC

A VPN connection builds an encrypted IPsec tunnel between the on-premises gateway and the cloud endpoint, encapsulating all traffic crossing the public internet. This directly satisfies the requirement to encrypt data in transit across the hybrid link, unlike object-storage encryption or key-management services, which protect data at rest rather than the network path.

Why this answer

A VPN connection creates an encrypted IPsec tunnel between the on-premises data center and the cloud environment, securing all traffic in transit across the public internet for a hybrid setup. This satisfies the requirement for a secure tunnel for all traffic, not just API calls. Client-side encryption, pre-signed URLs, and TLS for API calls address different scopes and do not provide a site-to-site encrypted tunnel.

Exam trap

The trap is choosing TLS for API calls because it sounds like 'encryption in transit' — but the question asks for a secure tunnel for ALL traffic in a hybrid setup, which requires a site-to-site VPN, not application-layer TLS.

How to eliminate wrong answers

Option A is wrong because client-side encryption protects data before it is sent to the cloud but does not create a secure network tunnel for all traffic between sites. Option B is wrong because pre-signed URLs are time-limited access links to specific objects in object storage, not a transport encryption mechanism for hybrid connectivity. Option D is wrong because TLS 1.2+ secures individual API calls (application-layer encryption) but does not encrypt all traffic between the data center and cloud, nor does it provide a persistent tunnel for non-HTTP protocols.

4
MCQmedium

A healthcare company stores medical images in a cloud object storage bucket. The images are accessed by radiologists via a web application. The security team wants to ensure that data is encrypted in transit and that the encryption keys are not accessible to the cloud provider. Which solution should they implement?

A.Enable server-side encryption with customer-provided keys (SSE-C) and enforce HTTPS for all access.
B.Configure the bucket to use HTTPS with TLS 1.2 and enable server-side encryption with provider-managed keys.
C.Implement client-side encryption with keys stored in an on-premises HSM and enforce HTTPS for all access.
D.Use client-side encryption with keys stored in the cloud provider's KMS and enforce HTTPS for all access.
AnswerC

Client-side encryption with keys in an on-premises HSM ensures the cloud provider never has access to the keys, satisfying the key control requirement. Enforcing HTTPS encrypts data in transit. Together, these meet both requirements: data is encrypted in transit and the provider cannot access the encryption keys.

Why this answer

Client-side encryption with keys held in an on-premises HSM ensures the cloud provider never possesses the key material, so the provider cannot access the plaintext. Enforcing HTTPS encrypts data in transit, meeting both the transit encryption and key control requirements. This combination provides the necessary security for sensitive medical images.

Exam trap

The trap here is assuming that server-side encryption with customer-provided keys (SSE-C) keeps keys inaccessible to the provider, when in fact the keys are used within the provider's environment and could be exposed.

5
MCQmedium

A global e-commerce company must store customer payment data in a specific geographic region to comply with local data residency laws. Which cloud configuration ensures that data never leaves the required region?

A.Use a global load balancer to route traffic
B.Enable cross-region replication to a secondary region for disaster recovery
C.Store data in a private cloud on-premises
D.Select a specific cloud region for the storage and disable cross-region replication
AnswerD

Selecting a specific cloud region pins data at rest to that geography, and disabling cross-region replication prevents automatic copying to paired or secondary regions. This directly satisfies the data residency constraint, since no replication mechanism can move payment data outside the required jurisdiction.

Why this answer

Data residency is achieved by selecting a cloud region (e.g., 'EU-West-1') and configuring storage buckets or databases with region-specific policies. Additionally, bucket policies can explicitly deny access from outside the region, and replication features should be disabled or configured to stay within the region.

6
MCQeasy

Which phase of the cloud data lifecycle involves making data available for processing by applications and users?

A.Archive
B.Store
C.Use
D.Create
AnswerC

The Use phase covers data being made available to applications and users for processing, following Create, Store and before Share, Archive and Destroy. It is the lifecycle stage where authorised consumers actively access and work with the data.

Why this answer

The Use phase of the cloud data lifecycle is when data is made available to applications and users for processing, analysis, and consumption. It follows Create and Store, and precedes Share, Archive, and Destroy. During Use, controls like access management, encryption in use, and monitoring are applied to protect data while it is actively being processed.

Exam trap

The trap is confusing Store with Use — candidates often pick 'Store' because data must be stored before it can be used, but the question specifically asks about making data available for processing, which is the Use phase.

How to eliminate wrong answers

Option A is wrong because Archive is the phase where data is moved to long-term, low-cost storage for retention and is not actively processed. Option B is wrong because Store is the phase where data is persisted in the storage medium, not the phase where it is made available for processing. Option D is wrong because Create is the phase where new data is generated or acquired, before it is stored or used.

7
MCQhard

A company uses a cloud key management service with customer-managed keys to encrypt data in a cloud storage bucket. The security team wants to ensure that if a key is compromised, they can revoke the cloud service's ability to decrypt the data immediately. What should they do?

A.Rotate the key to a new version.
B.Delete the key permanently from the cloud key management service.
C.Regenerate the key material by importing a new key.
D.Disable the key in the cloud key management service or revoke the key's access permissions for the cloud service.
AnswerD

Disabling the customer-managed key or revoking the cloud service's grant removes its ability to unwrap the data encryption key, immediately halting decryption. This satisfies the requirement for instant revocation of the service's decryption capability if the key is compromised.

Why this answer

Disabling the customer-managed key or revoking the cloud service's permissions to use it immediately prevents the service from performing cryptographic operations with that key, effectively cutting off decryption. This is a reversible, fast action that preserves the key material for potential recovery. It directly addresses the requirement to revoke the cloud service's ability to decrypt data immediately.

Exam trap

CCSP often tests the difference between key rotation, deletion, and disabling — candidates pick rotation or deletion thinking they revoke access, but only disabling or revoking permissions immediately stops decryption without destroying the key.

How to eliminate wrong answers

Option A is wrong because rotating the key creates a new key version but does not revoke access to existing data encrypted under the old version; the service can still decrypt old ciphertext with the previous version. Option B is wrong because deleting the key permanently is destructive and irreversible after the waiting period, and it does not provide immediate revocation without risking data loss; deletion also has a mandatory waiting period in most KMS services. Option C is wrong because regenerating key material by importing a new key creates a new key or version and does not immediately revoke the cloud service's access to the existing key used for the data.

8
MCQmedium

A DevOps team is deploying an application that will store encryption keys in a cloud KMS. The security policy requires that keys be stored in a hardware security module (HSM) and that key material never leaves the HSM boundary. Which key management option should they choose?

A.Customer-managed encryption keys (CMEK) with software-backed storage
B.Cloud KMS with HSM-backed key storage
C.Hold your own key (HYOK) with on-premises HSM
D.Bring your own key (BYOK) with key import to cloud KMS
AnswerB

HSM-backed key storage generates and retains key material inside a validated hardware module, so cryptographic operations occur within the HSM boundary and keys are never exported. This directly satisfies the policy that key material must never leave the HSM.

Why this answer

Cloud KMS with HSM-backed key storage ensures that key material is generated and stored inside a FIPS 140-2 Level 3 validated HSM, and cryptographic operations occur within the HSM boundary. This satisfies the requirement that keys be stored in an HSM and that key material never leaves the HSM.

Exam trap

CCSP often tests the distinction between BYOK (importing key material) and HSM-backed keys (where the key is generated and stored in an HSM) — candidates may assume BYOK automatically means HSM, but it does not.

How to eliminate wrong answers

Option A is wrong because software-backed CMEK stores key material in software, not an HSM, violating the HSM requirement. Option C is wrong because HYOK with an on-premises HSM keeps keys outside the cloud, but the question asks for a cloud KMS option where keys are stored in an HSM — HYOK also introduces latency and operational complexity, and the key material is not in the cloud KMS. Option D is wrong because BYOK with key import allows you to bring your own key material into cloud KMS, but the imported key material may be stored in software-backed KMS unless you specifically choose HSM-backed keys; BYOK alone does not guarantee HSM storage.

9
MCQmedium

A cloud security team is reviewing data retention for a software-as-a-service application hosted in a public cloud. Legal counsel requires that customer data be deleted permanently when a subscription ends, and that deletion be demonstrable to auditors. The cloud provider's storage system uses log-structured storage and maintains replicas across multiple availability zones. Which action best supports demonstrable, permanent deletion?

A.Delete the objects through the provider's API and rely on the provider's standard garbage collection.
B.Use cryptographic erasure by destroying the customer-specific encryption key, and retain the key-destruction audit record.
C.Ask the cloud provider to issue a media-sanitization certificate for the underlying disks.
D.Overwrite the objects with random data before deleting them from the bucket.
AnswerB

Cryptographic erasure renders data unrecoverable by destroying the key that protects it, even if encrypted remnants persist on media or replicas. Because the key destruction event can be logged and attested, it produces demonstrable evidence for auditors. This method is well suited to multi-tenant, replicated cloud storage where physical media cannot be individually sanitized.

Why this answer

Cryptographic erasure destroys the key that protects a customer's data, making the ciphertext permanently unrecoverable even if remnants persist on replicated or log-structured media. The key-destruction event can be logged and attested, giving auditors the evidence legal counsel requires. API deletion, overwriting, and tenant-level media sanitization cannot guarantee or demonstrate that every copy is gone in shared cloud storage.

Exam trap

The trap here is assuming that deleting an object or overwriting it removes every replica, when shared, log-structured cloud storage may retain inaccessible blocks that only key destruction can neutralize.

10
MCQmedium

A security team is setting up a DLP solution to scan cloud storage for credit card numbers. They want to automatically mask the detected credit card numbers so that only the last four digits are visible. Which DLP de-identification transform should they use?

A.Pseudonymization
B.Bucketing
C.Tokenization
D.Masking
AnswerD

Masking replaces characters within the detected credit card number, exposing only the final four digits while obscuring the rest. This directly satisfies the requirement that only the last four digits remain visible, unlike tokenization, which substitutes the entire value with an unrelated surrogate.

Why this answer

Masking replaces sensitive values with a redacted or partially obscured version — for credit card numbers, showing only the last four digits (e.g., **** **** **** 1234) while hiding the rest. It is a de-identification transform that preserves format and usability for display/analytics without exposing the full PAN. This matches the requirement exactly: detect and automatically mask so only the last four digits remain visible.

Exam trap

CCSP often tests the distinction between reversible de-identification (tokenization, pseudonymization) and irreversible display-oriented transforms (masking) — candidates pick tokenization because it sounds more secure when the question specifically asks for partial visibility.

How to eliminate wrong answers

Option A is wrong because pseudonymization replaces identifiers with consistent artificial values (e.g., a stable token or hash) that can be re-linked to the original via a separate mapping — it does not produce a 'last four digits visible' display. Option B is wrong because bucketing groups values into ranges or categories (e.g., age bands, income brackets) to generalize data, which is not applicable to showing partial card digits. Option C is wrong because tokenization substitutes the PAN with a surrogate token stored in a vault; the token is not the last four digits and requires the vault to detokenize, so it does not meet the 'only last four visible' requirement.

11
MCQhard

A multinational corporation uses a cloud DLP service to scan data stored in cloud storage and a cloud data warehouse for personally identifiable information (PII). The DLP scan identifies credit card numbers in a dataset. According to the cloud data lifecycle, at which stage should the DLP scan ideally be performed to minimize exposure?

A.Store
B.Use
C.Create
D.Share
AnswerC

Scanning at the Create stage catches credit card numbers before the dataset is stored, classified or shared, so exposure is minimised at the point of entry. Later lifecycle stages (Store, Use, Share) would already have written PII to cloud storage and the warehouse, widening the breach surface.

Why this answer

The Create stage is where data is first generated, acquired, or entered into the cloud environment, making it the earliest point at which PII can be identified and classified. Performing DLP scanning at Create prevents sensitive data from ever being persisted, processed, or shared in unprotected form, which minimizes the exposure window across the entire cloud data lifecycle. Scanning at later stages (Store, Use, Share) means the data has already been written to storage or consumed by applications, increasing the risk and cost of remediation.

Exam trap

CCSP often tests the misconception that scanning data at rest (Store) is 'early enough' for DLP, when the lifecycle model expects controls at the earliest possible stage—Create—to truly minimize exposure.

How to eliminate wrong answers

Option A (Store) is wrong because scanning at Store only catches data after it has already been persisted to cloud storage or a warehouse, meaning the PII has already been written to disk and potentially replicated or backed up. Option B (Use) is wrong because the Use stage involves processing and analytics, so by that point the data has already been stored and may have been accessed by multiple services or users. Option D (Share) is wrong because Share is the latest possible stage, where data has already been transmitted to external or internal consumers, making any DLP finding a post-exposure incident rather than a preventive control.

12
MCQhard

A multinational corporation stores trade secrets in a cloud object storage bucket. The security team wants to ensure that even if the cloud provider's internal systems are compromised, the data remains confidential. They also need to maintain the ability to revoke access to specific data objects without affecting other objects. Which combination of techniques should they implement?

A.Transport-layer encryption (TLS) and identity-based access policies.
B.Client-side encryption with per-object keys and a key management system that supports granular key revocation.
C.Server-side encryption with customer-provided keys (SSE-C) and object-level ACLs.
D.Server-side encryption with provider-managed keys and bucket-level access policies.
AnswerB

Client-side encryption ensures data is encrypted before reaching the cloud, so provider compromise does not expose plaintext. Using per-object keys allows revoking access to a specific object by revoking its key, without impacting other objects. A key management system that supports granular revocation enables this fine-grained control, meeting both confidentiality and selective revocation requirements.

Why this answer

Client-side encryption with per-object keys ensures that data is encrypted before it reaches the cloud, so a provider compromise does not expose plaintext. Per-object keys allow revoking access to a specific object by revoking its key, without affecting other objects. This provides both confidentiality against provider compromise and granular revocation, which are the core requirements.

Exam trap

The trap here is confusing server-side encryption with customer-provided keys (SSE-C) as equivalent to client-side encryption; SSE-C still exposes keys to the provider during processing.

13
MCQeasy

A startup is using a cloud-based SaaS CRM to store customer contact information. The security policy requires that data be encrypted both in transit and at rest. The SaaS provider states that it encrypts data in transit using TLS and at rest using AES-256. What should the startup do to verify these claims?

A.Request the provider's SOC 2 Type II report and review the encryption controls.
B.Use a network sniffer to capture traffic between the startup and the SaaS provider.
C.Perform a penetration test against the SaaS provider's application.
D.Ask the provider to send the encryption keys so the startup can decrypt data.
AnswerA

A SOC 2 Type II report provides an independent auditor's opinion on the effectiveness of the provider's controls over a period, including encryption. Reviewing it verifies that the provider's claims about TLS and AES-256 are accurate and consistently applied. This is the appropriate way to gain assurance without direct access to the provider's infrastructure.

Why this answer

Independent audit reports such as SOC 2 Type II are designed to provide assurance about a service provider's controls, including encryption. They cover both in-transit and at-rest encryption and are based on evidence gathered by auditors. This is the standard method for verifying a SaaS provider's security claims without requiring direct access to their systems.

Exam trap

The trap here is thinking that technical testing like packet capture can fully verify a provider's encryption at rest, when only independent audits provide comprehensive assurance.

14
MCQeasy

Which of the following is the correct order of phases in the cloud data lifecycle?

A.Store, Create, Use, Share, Destroy, Archive
B.Create, Store, Use, Share, Archive, Destroy
C.Create, Use, Store, Share, Archive, Destroy
D.Create, Share, Store, Use, Archive, Destroy
AnswerB

This sequence matches the CSA cloud data lifecycle: data is created, stored, used, shared, archived, then destroyed. It satisfies the stem's ordering constraint by placing Destroy last, after Archive, reflecting that secure deletion is the terminal phase once retention obligations end.

Why this answer

The cloud data lifecycle follows the sequence Create, Store, Use, Share, Archive, Destroy. Data must first be created or captured, then persisted in storage, actively used or processed, shared with other parties, moved to long-term archival storage when access frequency drops, and finally securely destroyed at end of life. This ordering reflects the natural progression of data from inception through active use to eventual disposal.

Exam trap

The trap is reordering Store and Use or moving Destroy before Archive — candidates often assume data is used before it is stored, but the CCSP canonical sequence places Store immediately after Create.

How to eliminate wrong answers

Option A is wrong because it places Store before Create, which is impossible — data cannot be stored before it exists, and it also places Destroy before Archive, reversing the end-of-life sequence. Option C is wrong because it places Use before Store; while data can be used in memory immediately after creation, the lifecycle model treats storage as the phase that precedes sustained use and sharing, and the canonical CCSP ordering is Create, Store, Use, Share, Archive, Destroy. Option D is wrong because it places Share before Store and Use, which skips the persistence and active-use phases that logically precede sharing data with third parties.

15
MCQmedium

A company is required by a data sovereignty law to ensure that all data generated by its EU customers is stored and processed within the EU. The company uses a cloud provider with data centers in multiple regions. Which cloud storage configuration should they implement?

A.Enable cross-region replication to a region in the same country.
B.Select a cloud region located in the EU and disable cross-region replication.
C.Use client-side encryption for all EU data.
D.Apply data classification labels to all EU data.
AnswerB

Pinning storage to an EU region satisfies the residency requirement, since object data physically resides on EU soil. Disabling cross-region replication prevents automatic copying of objects to non-EU regions, closing the secondary path by which data could leave the jurisdiction.

Why this answer

Data sovereignty requires that data remains within a specific legal jurisdiction. By selecting a cloud region physically located in the EU and disabling cross-region replication, the company ensures that data is stored and processed only within EU borders, satisfying the legal requirement. Cross-region replication, even within the same country, could still violate the law if the replication target is outside the EU or if the law requires strict in-region processing.

Encryption and classification do not change the physical location of data, so they do not address sovereignty.

Exam trap

CCSP often tests the misconception that encryption or data classification alone can satisfy data sovereignty requirements, when in fact they do not control data location; the key is to ensure data remains within the required legal jurisdiction by selecting appropriate regions and disabling cross-region replication.

How to eliminate wrong answers

Option A is wrong because cross-region replication, even to a region in the same country, may still involve data leaving the EU if the country is not an EU member or if the replication crosses EU borders; moreover, the question specifies EU customers, so replication must be within the EU, not just the same country. Option C is wrong because client-side encryption protects data confidentiality but does not control where data is stored or processed; encrypted data can still be stored outside the EU, violating sovereignty. Option D is wrong because data classification labels are metadata used for governance and do not enforce or guarantee that data remains within a specific geographic region.

16
MCQeasy

An organization wants to classify data in the cloud and assign labels such as 'Public', 'Internal', 'Confidential', and 'Restricted'. What is the primary purpose of this classification scheme?

A.To reduce cloud storage costs by moving data to cheaper tiers
B.To enable public sharing of data
C.To comply with data localization laws
D.To apply appropriate security controls based on sensitivity
AnswerD

Labels drive protection: sensitivity tiers determine which encryption, access and handling controls apply. Classification exists precisely so that 'Restricted' data receives stricter safeguards than 'Public', satisfying the stem's requirement to classify data and assign labels. Microsoft Entra ID and similar tools then enforce those label-based controls.

Why this answer

Data classification assigns sensitivity labels so that security controls — encryption, access control, retention, DLP, and monitoring — can be applied proportionally to the data's value and risk. Labeling data as Public, Internal, Confidential, or Restricted lets the organization map each tier to a defined control baseline, ensuring the most sensitive data receives the strongest protection.

Exam trap

CCSP often tests the misconception that classification is about cost, sharing, or residency — the trap is missing that its primary purpose is to drive proportionate security controls based on sensitivity.

How to eliminate wrong answers

Option A is wrong because classification is a security/governance function, not a storage-cost optimization; tiering data to cheaper storage is a lifecycle management concern, not the purpose of sensitivity labels. Option B is wrong because classification restricts rather than enables sharing — 'Public' is one tier, but the scheme's purpose is to prevent inappropriate exposure, not promote it. Option C is wrong because data localization concerns where data resides geographically, which is a residency control, not the primary purpose of a sensitivity classification scheme.

17
MCQmedium

A financial services firm stores sensitive customer records in a cloud object storage bucket. The security team wants to ensure that even if the cloud provider's internal staff or a compromised administrative account attempts to access the data, they cannot read it. The firm already uses provider-managed encryption at rest. Which additional control BEST achieves this requirement?

A.Configure a bucket policy that denies access to all principals except a specific IAM role.
B.Enable bucket versioning and object lock to prevent unauthorized deletion.
C.Enable default encryption with a customer-provided key stored in the cloud provider's KMS.
D.Implement client-side encryption where keys are managed by the firm and never shared with the provider.
AnswerD

Client-side encryption ensures data is encrypted before it reaches the cloud, and the firm retains sole control of the keys. Even provider staff or a compromised admin cannot decrypt without the firm's keys. This directly addresses the requirement that the provider cannot read the data, unlike provider-managed encryption where the provider holds the keys.

Why this answer

The requirement is to prevent the cloud provider from reading the data. Provider-managed encryption does not meet this because the provider holds the keys. Client-side encryption with firm-controlled keys ensures the provider only sees ciphertext.

Other options address access control, integrity, or key management within the provider, but none remove the provider's ability to decrypt.

Exam trap

The trap here is assuming that provider-managed encryption at rest prevents the cloud provider from accessing data, when in fact the provider holds the keys and can decrypt.

18
Multi-Selectmedium

A cloud security manager is implementing data discovery and classification for a multi-cloud environment. The organization needs to automatically identify and tag sensitive data such as personally identifiable information (PII) and protected health information (PHI) across cloud storage services. Which two capabilities are essential for an effective data classification solution? (Choose two.)

Select 2 answers
A.Full-disk encryption of all cloud storage volumes to prevent unauthorized access to data at rest.
B.Pattern matching and regular expressions to detect structured data formats like credit card numbers and social security numbers.
C.A data loss prevention (DLP) policy that blocks all outbound traffic from cloud workloads to external networks.
D.Manual sampling of files by security analysts to determine data sensitivity based on business context.
E.Integration with cloud provider APIs to access and scan data across multiple storage services without requiring agents on every resource.
AnswersB, E

Pattern matching and regular expressions are essential for detecting structured sensitive data with known formats, such as credit card numbers and social security numbers. They enable automated scanning and tagging without manual review, which is critical for large-scale multi-cloud environments where data volume is high.

Why this answer

An effective data classification solution requires automated detection using pattern matching for structured data and API-based scanning to cover multi-cloud storage without agents. These capabilities enable scalable, consistent identification and tagging of sensitive data, which is the foundation for applying appropriate protections.

Exam trap

The trap here is confusing data protection controls like encryption or DLP blocking with the discovery and tagging capabilities that define classification.

19
MCQmedium

A multinational corporation must store customer data in specific geographic regions to comply with data sovereignty laws. Which cloud storage feature should they configure to ensure data does not leave a designated region?

A.Signed URLs
B.Cross-region replication
C.Object versioning
D.Region selection for storage buckets
AnswerD

Selecting a region for storage buckets pins object data and replicas to that geography, so customer data is written and remains within the designated jurisdiction. This directly satisfies the data sovereignty constraint that data must not leave the specified region.

Why this answer

Region selection for storage buckets allows the organization to choose the geographic region where data is stored, ensuring it does not leave the designated jurisdiction. This directly addresses data sovereignty requirements. Signed URLs, cross-region replication, and object versioning do not control the geographic location of stored data.

Exam trap

The trap is choosing cross-region replication because it sounds like a resilience feature — but replication moves data across regions, directly violating data sovereignty, whereas region selection keeps data in place.

How to eliminate wrong answers

Option A is wrong because signed URLs grant temporary access to objects but do not determine where data is stored. Option B is wrong because cross-region replication actively copies data to another region, which would violate data sovereignty by moving data outside the designated region. Option C is wrong because object versioning retains multiple versions of an object in the same region, which does not address geographic placement.

20
MCQmedium

An organization uses cloud object storage with versioning enabled. After a ransomware attack, they discover that many objects were encrypted by the attacker. How does versioning help in this scenario?

A.It allows restoration of the previous unencrypted version of each object
B.It replicates objects to a different region for disaster recovery
C.It prevents any object from being overwritten or deleted
D.It automatically encrypts all objects with customer-managed keys
AnswerA

Versioning retains prior copies of an object rather than overwriting them, so the attacker's encrypted write becomes a new version while the original unencrypted version remains intact. The analyst can restore that earlier version, recovering the data without paying a ransom.

Why this answer

Object versioning retains multiple versions of an object, so if a current version is encrypted by ransomware, the previous unencrypted version can be restored. This provides a recovery mechanism without paying a ransom. Versioning is a key data protection feature in cloud object storage.

Exam trap

The trap is confusing versioning with replication or immutability, or assuming versioning prevents deletion; the exam tests that versioning enables restoration of previous versions.

How to eliminate wrong answers

Option B is wrong because replication is a separate feature (e.g., S3 Cross-Region Replication) and not a function of versioning. Option C is wrong because versioning does not prevent overwrites or deletions; it only preserves previous versions. Option D is wrong because versioning does not automatically encrypt objects; encryption is a separate configuration.

21
MCQmedium

A cloud security manager is implementing a data retention policy for a SaaS CRM that stores customer contact records. Regulations require that records be irreversibly destroyed after seven years, but the SaaS provider's recycle bin retains deleted records for 30 days and backups persist for 90 days. Which cloud data disposal approach best satisfies the regulatory requirement?

A.Use crypto-shredding by deleting the per-tenant data encryption key and allowing key material to be destroyed after the retention period.
B.Overwrite the CRM database fields containing contact records with null values using the provider's bulk update API.
C.Configure the SaaS recycle bin to empty automatically every 30 days and rely on the provider's backup expiration after 90 days.
D.Issue a formal written request to the SaaS provider asking them to delete all customer records and confirm completion in a service report.
AnswerA

Crypto-shredding renders data unrecoverable by destroying the keys that protect it, which is effective even when residual copies exist in backups or recycle bins. In this scenario, the provider's recycle bin and backup retention windows mean logical deletion alone is insufficient, so destroying the per-tenant key after seven years ensures the records cannot be reconstructed, satisfying the irreversible destruction requirement.

Why this answer

Crypto-shredding is the most reliable cloud disposal method when data may persist in backups, replicas, or provider recycle bins. By destroying the per-tenant encryption key after the seven-year retention period, the records become cryptographically unrecoverable regardless of residual copies. Logical deletion, provider attestations, and field overwrites do not guarantee irreversible destruction in a shared-responsibility SaaS environment.

Exam trap

The trap here is assuming that deleting records through the application or asking the provider to delete them satisfies irreversible destruction, when residual backups and recycle bins can keep the data recoverable.

22
Multi-Selecthard

A financial services company is implementing a data loss prevention (DLP) solution to protect sensitive data in cloud storage. They need to identify and classify data containing personally identifiable information (PII) such as credit card numbers and social security numbers. Which three capabilities should the DLP solution provide? (Choose three.)

Select 3 answers
A.Encryption at rest using AES-256
B.Classification of data based on content
C.De-identification transforms such as masking and tokenization
D.Blocking public access to buckets
E.Automated scanning for sensitive data patterns
AnswersB, C, E

Content-based classification inspects object contents against pattern and context rules to identify PII such as card numbers and social security numbers. This is the detection foundation the DLP solution needs before it can label, report or protect sensitive data held in cloud storage.

Why this answer

Option B is correct because a DLP solution must classify data based on content, inspecting files and objects to determine whether they contain regulated data types such as PII, credit card numbers, or social security numbers. Option C is correct because de-identification transforms such as masking and tokenization are core DLP remediation capabilities that replace or obscure sensitive values so the data can be used or shared while reducing exposure. Option E is correct because automated scanning for sensitive data patterns (for example, regex or pattern matching for 16-digit card numbers and SSN formats) is how the solution discovers and inventories sensitive data across cloud storage at scale.

Option A does not belong because AES-256 encryption at rest protects confidentiality but does not identify or classify PII content. Option D does not belong because blocking public access to buckets is an access-control hardening measure, not a data identification or classification capability.

Exam trap

CCSP often tests the distinction between DLP capabilities (discovery, classification, de-identification) and general security controls (encryption, access blocking); candidates may pick encryption or access controls thinking they are part of DLP.

23
MCQeasy

Which phase of the cloud data lifecycle involves the removal of data in a manner that ensures it cannot be reconstructed, typically using techniques like cryptographic erasure or degaussing?

A.Destroy
B.Store
C.Share
D.Archive
AnswerA

Destroy is the final lifecycle phase, using cryptographic erasure (deleting the wrapping key so ciphertext is unrecoverable) or degaussing to render media magnetically unusable. This guarantees data cannot be reconstructed, satisfying the stem's irreversibility requirement rather than merely deleting pointers or access.

Why this answer

The Destroy phase of the cloud data lifecycle is specifically defined as the permanent removal of data such that it cannot be reconstructed, using methods like cryptographic erasure (destroying the encryption keys) or degaussing (magnetic erasure). Store, Share, and Archive all involve retaining data in some form. Destroy is the only phase focused on irreversible elimination.

Exam trap

The trap is confusing Archive with Destroy — candidates see 'removal' and think archiving removes data from active use, but archiving retains data, whereas Destroy ensures it cannot be reconstructed.

How to eliminate wrong answers

Option B is wrong because Store is the phase where data is persisted in cloud storage, not removed. Option C is wrong because Share is the phase where data is made accessible to other parties, which is the opposite of destruction. Option D is wrong because Archive involves moving data to long-term, lower-cost storage for retention, not eliminating it.

24
MCQeasy

A company is implementing a data classification policy for cloud storage. They want to label objects with tags indicating the sensitivity level (e.g., 'Confidential'). Which benefit does tagging resources with classification labels provide?

A.It provides client-side encryption keys
B.It automatically encrypts data at rest
C.It reduces storage costs by moving data to cheaper tiers
D.It allows enforcement of data handling policies based on sensitivity
AnswerD

Classification tags attach sensitivity metadata to objects, enabling policy engines to enforce handling rules such as encryption, access restrictions and retention automatically. This satisfies the stem's requirement that labelling drives enforcement of data handling policies based on sensitivity.

Why this answer

Tags applied to cloud resources act as metadata that policy engines, DLP tools, and automation can evaluate at runtime. By labeling objects as 'Confidential', 'Internal', or 'Public', organizations can attach conditional policies (e.g., deny public access, require encryption, restrict cross-region replication) that enforce handling rules based on the classification. This is the primary governance benefit of classification tagging.

Exam trap

The trap here is conflating classification tagging with encryption or cost optimization — candidates often assume that labeling data 'Confidential' automatically encrypts it, when in fact tags only enable policy enforcement and visibility.

How to eliminate wrong answers

Option A is wrong because tags are metadata and do not generate or store cryptographic key material — client-side encryption keys come from KMS, HSMs, or local key stores. Option B is wrong because tagging does not itself perform encryption; encryption at rest must be explicitly enabled via SSE-S3, SSE-KMS, or client-side encryption. Option C is wrong because lifecycle tiering is driven by lifecycle rules and access patterns, not by classification tags — although tags can be used as conditions in lifecycle policies, the tag alone does not reduce storage cost.

25
Multi-Selectmedium

A cloud data governance team is defining controls for data remanence in a multi-tenant public cloud environment. They must address both logical and physical media reuse concerns. Which TWO practices are MOST appropriate for managing data remanence risk? (Choose two.)

Select 2 answers
A.Implement cryptographic erasure by destroying tenant-controlled keys when data must be made unrecoverable.
B.Encrypt data with provider-managed keys and assume key rotation eliminates residual data.
C.Overwrite storage blocks with random data using a tenant-installed utility on the provider's physical hosts.
D.Rely on the provider's multi-tenancy to isolate data so remanence is not a concern.
E.Require the provider to supply audit evidence of media sanitization and secure disposal for decommissioned storage hardware.
AnswersA, E

Cryptographic erasure renders data unreadable by destroying the keys, which is effective across replicas and backups that tenants cannot directly purge. It addresses logical remanence in a multi-tenant environment where physical media is shared and managed by the provider. This gives the tenant a direct, verifiable destruction mechanism independent of provider deletion processes.

Why this answer

Managing data remanence in a public cloud requires addressing both layers: physical media sanitization, which tenants cannot perform and must verify through provider audit evidence, and logical destruction, which tenants achieve through cryptographic erasure using keys they control. Tenant-side overwriting is infeasible, isolation is not a sanitization control, and provider-managed key rotation does not destroy data.

Exam trap

The trap here is assuming that logical isolation or provider key rotation eliminates residual data, when remanence requires either verified physical sanitization or tenant-controlled cryptographic erasure.

26
MCQeasy

A healthcare company stores patient records in a cloud storage bucket. They need to encrypt the data at rest using encryption keys that they manage themselves, but they want to generate the keys within the cloud provider's key management service. Which encryption option should they choose?

A.Client-side encryption
B.Server-side encryption with Amazon S3-managed keys (SSE-S3)
C.Customer-Managed Encryption Keys (CMEK)
D.Customer-Supplied Encryption Keys (CSEK)
AnswerC

CMEK lets the provider's KMS generate and hold the key material while the customer retains control over key lifecycle and permissions, satisfying the requirement for self-managed keys generated inside the cloud KMS rather than imported or provider-owned.

Why this answer

Customer-Managed Encryption Keys (CMEK) means the cloud provider's KMS generates and stores the key material, but the customer controls the key's lifecycle — rotation, disabling, and deletion — and the key is used by the provider's service to encrypt data at rest. This matches the requirement of keys managed by the customer but generated within the provider's KMS.

Exam trap

The trap is conflating 'customer-managed' with 'customer-supplied' or 'client-side' — candidates must distinguish who generates the key (provider KMS vs. customer) from who controls its lifecycle (customer vs. provider).

How to eliminate wrong answers

Option A is wrong because client-side encryption means the customer encrypts data before uploading, managing keys entirely outside the provider's KMS — the opposite of generating keys in the provider's KMS. Option B is wrong because SSE-S3 uses keys fully managed by AWS (or the provider), giving the customer no control over key lifecycle or rotation. Option D is wrong because Customer-Supplied Encryption Keys (CSEK) require the customer to generate and supply the raw key material with each request; the provider never stores or generates it, so it fails the 'generate within the provider's KMS' requirement.

27
Multi-Selecthard

A cloud architect is implementing data loss prevention (DLP) for a data lake containing PII. They want to automatically detect and transform sensitive data like Social Security numbers and medical record numbers. Which THREE actions should they take? (Choose three.)

Select 3 answers
A.Apply de-identification transforms such as masking or tokenization
B.Enable bucket versioning
C.Use cloud DLP API to scan for sensitive data types
D.Configure automated classification labels based on DLP findings
E.Set up cross-region replication for durability
AnswersA, C, D

Masking and tokenisation replace or substitute sensitive values so the data lake retains analytical utility while Social Security and medical record numbers are no longer exposed. This directly satisfies the stem's requirement to transform detected sensitive data, complementing scanning and classification rather than duplicating them.

Why this answer

Option C is correct because the cloud DLP API (e.g., Google Cloud DLP / Sensitive Data Protection) is the service that inspects data lake content and identifies predefined infoTypes such as US_SOCIAL_SECURITY_NUMBER and medical record numbers, which is the required detection step. Option A is correct because de-identification transforms like masking, tokenization, or format-preserving encryption are exactly the mechanisms DLP provides to irreversibly or reversibly transform the detected PII before it is stored or shared. Option D is correct because automated classification labels derived from DLP findings let the architect tag and govern the data lake objects by sensitivity level, enabling downstream policy enforcement and audit.

Option B is not correct because bucket versioning only preserves object versions for recovery and does not detect or transform PII. Option E is not correct because cross-region replication addresses durability and availability, not data loss prevention or sensitive-data transformation.

Exam trap

The trap is that versioning and replication are common 'best practice' options that sound security-relevant, but they address durability and availability — not detection, classification, or transformation of sensitive data.

28
MCQeasy

A security engineer needs to provide temporary access to a specific object in a cloud storage bucket for a third-party auditor, without granting them any other permissions. The access should expire automatically after 24 hours. Which method should the engineer use?

A.Generate a time-limited signed URL for the object with a 24-hour expiration.
B.Configure a bucket access policy that allows access from the auditor's IP address.
C.Assign the auditor a cloud role with read-only access to the bucket.
D.Generate a long-term access key pair for the auditor and attach a user policy.
AnswerA

A signed URL embeds a cryptographic signature and expiry timestamp, granting temporary read access to that single object. The 24-hour expiration satisfies the automatic revocation requirement without granting the auditor broader bucket permissions or requiring an account.

Why this answer

A time-limited signed URL is generated using the object owner's credentials and embeds an expiration (e.g., 24 hours) directly in the URL. The third-party auditor can retrieve only that specific object until expiry, with no cloud identity, no IAM user, and no broader permissions. This satisfies least privilege, automatic expiry, and zero credential distribution.

Exam trap

The trap is assuming that IAM roles or bucket policies can provide automatic time-limited, per-object access — they cannot; only signed URLs (or similar presigned mechanisms) combine per-object granularity with built-in expiration and no credential requirement.

How to eliminate wrong answers

Option B is wrong because a bucket access policy tied to an IP address still requires the auditor to authenticate with cloud credentials and grants access to the bucket, not just one object, and does not auto-expire. Option C is wrong because assigning a cloud role requires creating an identity for the auditor, grants read access to the entire bucket (or more), and the role persists until explicitly removed — no automatic 24-hour expiry. Option D is wrong because long-term access keys are a persistent credential, violate least privilege, and do not expire automatically, creating a serious security risk.

29
MCQmedium

A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that if an attacker gains access to the bucket, the data cannot be read. They also want to prevent the cloud provider from accessing the plaintext. Which approach best meets these requirements?

A.Use bucket policies to restrict access to only authorized IAM roles.
B.Enable server-side encryption with provider-managed keys (SSE-S3).
C.Enable server-side encryption with customer-provided keys (SSE-C).
D.Use client-side encryption with customer-managed keys stored on-premises.
AnswerD

Client-side encryption encrypts data before it leaves the customer's environment, and keys are stored on-premises, outside the provider's control. Thus, the cloud provider only stores ciphertext and cannot decrypt without the customer's keys. If an attacker gains access to the bucket, they obtain only encrypted data, satisfying both requirements.

Why this answer

Client-side encryption with customer-managed keys ensures data is encrypted before reaching the cloud and keys never leave the customer's control. This prevents the cloud provider from accessing plaintext and protects data even if the storage bucket is compromised. Server-side options leave key management or plaintext handling with the provider, failing the requirement.

Exam trap

The trap here is assuming that server-side encryption with customer-provided keys (SSE-C) prevents the provider from accessing plaintext, when in fact the provider handles the key during encryption and decryption operations.

30
Multi-Selecteasy

A company is planning to implement data classification for its cloud environment. Which TWO components are essential for an effective data classification scheme? (Select TWO.)

Select 2 answers
A.Encryption at rest for all classified data
B.A process to tag resources with the appropriate classification labels
C.Access control policies based on classification
D.Automated DLP scanning to enforce classification
E.A classification scheme with defined labels (e.g., public, internal, confidential, restricted)
AnswersB, E

Tagging resources with classification labels is the operational mechanism that actually applies the scheme to data at scale. Without an enforced tagging process, labels remain theoretical and cannot drive protection, access, or retention controls, so the classification scheme is never realised across the cloud estate.

Why this answer

Option B is correct because an effective data classification scheme requires a repeatable process to tag resources with the appropriate classification labels, so that the assigned sensitivity level is actually recorded and travels with the data or resource for later policy enforcement. Option E is correct because classification cannot function without a defined taxonomy of labels, such as public, internal, confidential, and restricted, which establishes the categories and criteria that everything else maps to. Together, the label scheme (E) and the tagging process (B) form the foundational components of classification.

Option A is not essential to the classification scheme itself; encryption at rest is a protective control that may be applied based on classification, not a component required to classify data. Option C is also a downstream control, since access policies consume classification labels rather than define the scheme. Option D is likewise an enforcement mechanism, and automated DLP scanning depends on classification being established first rather than being essential to creating it.

Exam trap

CCSP often tests the difference between the classification scheme itself and the controls that enforce it, causing candidates to select encryption or DLP as 'essential components' when they are actually downstream controls.

31
MCQeasy

A company is migrating its on-premises database to a cloud-based managed database service. The security policy requires that data at rest be encrypted and that the company retain control over key rotation. Which cloud service should they use to meet these requirements?

A.Cloud HSM or Key Management Service (KMS) with customer-managed keys.
B.Transparent Data Encryption (TDE) with keys stored in the database.
C.Cloud provider's default encryption with provider-managed keys.
D.Client-side encryption with keys stored in a local file server.
AnswerA

Using a cloud HSM or KMS with customer-managed keys allows the company to create, rotate, and disable keys according to its own policies. The cloud provider manages the hardware but cannot access key material. This meets both encryption at rest and customer control over rotation.

Why this answer

A cloud HSM or KMS with customer-managed keys gives the company control over key lifecycle, including rotation, while still encrypting data at rest. Provider-managed keys, client-side encryption with local key storage, and TDE with in-database keys either cede rotation control or introduce operational risks that fail the policy requirement.

Exam trap

The trap here is confusing encryption at rest with key control; default provider encryption encrypts data but does not give the customer control over rotation.

32
MCQeasy

A company is migrating its on-premises database to a cloud-based database-as-a-service (DBaaS) offering. The security team wants to ensure that the data remains encrypted at rest and that they retain control over the encryption keys. Which cloud data security concept should they implement?

A.SSL/TLS encryption for data in transit between the application and the database.
B.Database auditing and logging to monitor access to sensitive data.
C.Bring Your Own Key (BYOK) integrated with the cloud provider's key management service.
D.Transparent Data Encryption (TDE) with keys managed by the cloud provider.
AnswerC

BYOK allows the company to generate and manage its own encryption keys while using the cloud provider's key management service for storage and lifecycle operations. This gives the company control over the keys and satisfies the requirement for encryption at rest with customer-controlled keys.

Why this answer

BYOK enables the company to generate and control its own encryption keys while leveraging the cloud provider's KMS for key storage and operations. This meets the need for encryption at rest with customer-controlled keys, unlike provider-managed TDE or transit encryption.

Exam trap

The trap here is equating encryption at rest with customer key control; provider-managed TDE encrypts data but does not give the customer key ownership.

33
MCQhard

A healthcare organization stores patient data in a cloud database. Regulatory requirements mandate that data must be encrypted at rest using FIPS 140-2 validated cryptographic modules. The organization wants to use the cloud provider's managed encryption service. Which aspect should they verify to ensure compliance?

A.That the database uses AES-256 encryption.
B.That the cloud provider's encryption service uses FIPS 140-2 validated hardware security modules (HSMs) for key storage.
C.That the cloud provider is certified under ISO/IEC 27001.
D.That the encryption service's cryptographic module has a current FIPS 140-2 validation certificate.
AnswerD

FIPS 140-2 validation is specific to the cryptographic module. The organization must ensure that the module used for encryption has a valid certificate from a NIST-accredited lab. This directly confirms that the encryption meets the regulatory requirement. The certificate should cover the exact module version and configuration used.

Why this answer

FIPS 140-2 validation is a requirement for cryptographic modules used by federal agencies and often mandated by regulations like HIPAA. To comply, the organization must confirm that the specific cryptographic module used by the cloud service has a valid FIPS 140-2 certificate. This ensures the module meets stringent security standards for design and implementation.

Exam trap

The trap here is confusing algorithm strength (AES-256) or general security certifications (ISO 27001) with FIPS 140-2 validation of the cryptographic module itself.

34
MCQeasy

A financial services company is migrating sensitive customer data to the cloud. They require that encryption keys be generated and stored on-premises in their own hardware security module (HSM), with the cloud provider never having access to the plaintext keys. Which key management model should they implement?

A.Customer-managed encryption keys (CMEK)
B.Bring your own key (BYOK)
C.Cloud provider default encryption (SSE-S3)
D.Hold your own key (HYOK)
AnswerD

HYOK generates and retains keys in the customer's on-premises HSM, so plaintext keys never reach the provider; the cloud only ever handles ciphertext or wrapped keys. This satisfies the requirement that the provider cannot access plaintext keys.

Why this answer

Hold your own key (HYOK) is the only model where the customer generates and stores the key material in their own HSM on-premises, and the cloud provider never has access to the plaintext key. In HYOK, encryption and decryption typically occur on the customer side or through a proxy, so the cloud provider only ever handles ciphertext. This satisfies the requirement that the provider cannot access plaintext keys.

Exam trap

CCSP often tests the confusion between BYOK and HYOK — candidates assume that importing your own key (BYOK) means the provider never sees it, but only HYOK guarantees the provider has no access to plaintext key material.

How to eliminate wrong answers

Option A is wrong because CMEK means the customer manages the key lifecycle but the key material is still generated and stored within the cloud provider's KMS, so the provider has potential access. Option B is wrong because BYOK allows the customer to import their own key into the provider's KMS, but once imported the provider's infrastructure can access the plaintext key during cryptographic operations. Option C is wrong because SSE-S3 is provider-managed encryption where the cloud provider generates, stores, and manages the keys entirely — the customer has no control and the provider has full access.

35
Multi-Selectmedium

A cloud security team is evaluating DLP techniques to protect sensitive data in a cloud data warehouse. They want to replace sensitive values with realistic but fictitious data for non-production environments while preserving referential integrity. Which TWO de-identification techniques are suitable?

Select 2 answers
A.Pseudonymization
B.Bucketing
C.Masking
D.Tokenization
E.Date shifting
AnswersA, D

Pseudonymization swaps identifiers for consistent replacement values, so the same input always maps to the same output. That determinism preserves referential integrity across related tables while producing realistic fictitious data, exactly matching the non-production requirement without exposing genuine customer values.

Why this answer

Pseudonymization (A) is correct because it replaces sensitive values with consistent artificial identifiers, so the same input always maps to the same pseudonym, which preserves referential integrity across tables and joins in non-production environments. Tokenization (D) is also correct because it substitutes sensitive data with non-sensitive tokens stored in a secure token vault, and the deterministic token-to-value mapping maintains referential integrity while providing realistic fictitious values. Bucketing (B) only generalizes values into ranges and does not produce realistic fictitious replacements or preserve exact referential links.

Masking (C) typically obscures or redacts values, often irreversibly and without guaranteeing consistent cross-table substitution, so it does not reliably preserve referential integrity. Date shifting (E) only alters date values by a consistent offset and applies solely to date fields, not to general sensitive data replacement.

Exam trap

The trap is selecting masking because it is the most commonly mentioned de-identification technique — but masking does not preserve referential integrity, whereas pseudonymization and tokenization do through consistent mapping.

36
MCQmedium

A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that data is protected at rest but does not want to manage encryption keys themselves. They also need to prove to auditors that encryption is enabled. Which cloud provider feature should they use?

A.Transport Layer Security (TLS) for data in transit
B.Client-side encryption with customer-provided keys
C.Server-side encryption with provider-managed keys (SSE-S3 or equivalent)
D.Server-side encryption with customer-provided keys (SSE-C)
AnswerC

This option uses encryption at rest where the cloud provider manages the keys, eliminating the customer's key management burden. Auditors can verify that encryption is enabled via provider logs or configuration settings. It meets the requirement for data protection without customer-managed keys, and is a standard feature of object storage services.

Why this answer

Server-side encryption with provider-managed keys is correct because it automatically encrypts data at rest without requiring the customer to manage keys, and it can be audited through provider configurations. Client-side and SSE-C both involve customer key management, which the firm wants to avoid. TLS is irrelevant for data at rest.

Exam trap

The trap here is assuming that any encryption option satisfies the requirement, but the key management responsibility differentiates the choices.

37
MCQeasy

A data governance team is developing a classification scheme for cloud-stored data. They want to label data based on sensitivity, from least to most restrictive. Which of the following is a typical classification category for highly sensitive data that could cause severe damage if disclosed?

A.Internal
B.Confidential
C.Restricted
D.Public
AnswerC

Restricted denotes the highest sensitivity tier, applied where disclosure causes severe damage such as regulatory penalty or financial loss. Classification schemes typically escalate public, internal, confidential then restricted, so restricted correctly labels the most tightly controlled data in the governance taxonomy.

Why this answer

In common classification schemes, 'Restricted' is the highest level, used for data that requires strict access control and protection.

38
MCQmedium

A cloud security engineer needs to protect a storage bucket from accidental deletion and ransomware attacks. Which two features should be enabled together for maximum protection?

A.IAM policies and MFA delete
B.Bucket versioning and object lock
C.Cross-region replication and lifecycle policies
D.Server access logging and bucket policies
AnswerB

Bucket versioning preserves every object revision, so overwritten or deleted data remains recoverable, while object lock enforces WORM retention that blocks deletion even by compromised credentials. Together they satisfy the accidental-deletion and ransomware protection requirement, since neither alone prevents malicious overwrite.

Why this answer

Versioning keeps multiple variants of an object, allowing recovery from accidental deletion or overwrite. Object lock (immutability) prevents objects from being deleted or overwritten for a specified retention period, protecting against ransomware. Combining both provides defense in depth.

39
MCQmedium

A company is using a cloud provider's key management service (KMS) with HSM-backed keys. They want to ensure that key material is automatically replaced periodically to limit the impact of a potential key compromise. Which KMS feature should they configure?

A.Key export
B.Key revocation
C.Key policies
D.Key rotation
AnswerD

Key rotation generates new cryptographic key material on a schedule, retiring the previous version while retaining it for decryption of existing ciphertext. This satisfies the requirement to limit exposure from compromise by shortening each key's useful lifespan.

Why this answer

Key rotation is the KMS feature that automatically replaces key material on a defined schedule, generating a new cryptographic key version while retaining old versions to decrypt previously encrypted data. This limits the blast radius of a compromise because ciphertext encrypted under the old key version remains protected by the new material going forward. Configuring rotation directly addresses the requirement to periodically replace key material.

Exam trap

The trap is confusing revocation with rotation — candidates pick revocation thinking it 'replaces' a compromised key, but revocation disables the key and breaks decryption, whereas rotation preserves old versions for decryption while issuing new material.

How to eliminate wrong answers

Option A is wrong because key export allows key material to leave the HSM boundary, which increases exposure risk rather than limiting the impact of compromise. Option B is wrong because revocation disables a key entirely, which would render existing ciphertext undecryptable and is a reactive response to suspected compromise, not a preventive periodic replacement. Option C is wrong because key policies define who can use or manage a key, not how often the underlying key material is replaced.

40
MCQmedium

A multinational corporation must ensure that customer data from the European Union is stored and processed only within EU regions to comply with GDPR. They are using a cloud provider with data centers globally. What is the primary mechanism to enforce this requirement?

A.Selecting cloud regions located within the EU for all services
B.Client-side encryption with keys stored in the EU
C.Using a VPN to route all traffic through an EU gateway
D.Configuring IAM policies to restrict access to EU-based administrators
AnswerA

Region selection is the foundational control: compute, storage and processing resources deployed only in EU regions keep data physically within the jurisdiction. It is the prerequisite mechanism on which replication restrictions and contractual safeguards then depend for GDPR residency.

Why this answer

The primary mechanism to enforce EU-only data residency is to select cloud regions physically located within the EU for all services that store or process the data, since data residency is fundamentally about where the data at rest and in processing resides. Region selection is a deployment-time architectural decision that determines the physical location of storage, compute, and backups. Other controls (encryption, VPN, IAM) complement but do not substitute for choosing EU regions.

Exam trap

CCSP often tests the misconception that encryption or access controls satisfy data residency, when the exam expects recognition that only physical region selection enforces where data is stored and processed.

How to eliminate wrong answers

Option B is wrong because client-side encryption with EU-stored keys protects confidentiality but does not prevent the ciphertext from being stored or processed outside the EU, so it fails the residency requirement. Option C is wrong because routing traffic through an EU VPN gateway only affects data in transit, not where data is stored or processed at rest. Option D is wrong because restricting IAM access to EU-based administrators controls who can access data, not where the data physically resides, so it does not enforce residency.

41
Multi-Selectmedium

An organization is implementing a data loss prevention (DLP) solution to protect sensitive data in cloud storage. Which TWO of the following are capabilities of a cloud DLP service? (Select TWO.)

Select 2 answers
A.Automatic encryption key rotation
C.De-identification transforms such as masking and tokenization
D.Inspection of data for sensitive information types
E.Automated backup of sensitive data
AnswersC, D

De-identification transforms such as masking and tokenisation irreversibly or reversibly obscure sensitive fields, a core DLP capability for protecting data at rest in cloud storage. They reduce exposure of regulated data while preserving usability for analytics or testing.

Why this answer

Option C is correct because cloud DLP services (such as Google Cloud DLP/Sensitive Data Protection) provide de-identification transforms including masking, tokenization, and format-preserving encryption to obfuscate sensitive values while preserving usability. Option D is correct because the core function of a cloud DLP service is inspecting data at rest or in transit to detect sensitive information types (SITs) such as credit card numbers, SSNs, and API keys using built-in or custom infoType detectors. Option A is not a DLP capability; encryption key rotation is handled by a key management service (KMS) such as Cloud KMS.

Option B is not a DLP capability; MFA enforcement is an identity and access management function (e.g., IAM, MFA policies). Option E is not a DLP capability; automated backups are provided by storage or backup services, not by DLP inspection tooling.

Exam trap

CCSP often tests whether candidates can distinguish DLP capabilities from adjacent security functions — the trap is selecting encryption key rotation or MFA enforcement as DLP features when DLP is specifically about data inspection and de-identification.

42
Multi-Selecteasy

A company is deploying a cloud application that processes customers' personal data. They need to ensure data in transit is protected. Which THREE of the following are appropriate controls for data in transit? (Select THREE.)

Select 3 answers
A.Establishing a VPN for hybrid connectivity
B.Setting data classification labels on the data
C.Enforcing HTTPS for web application access
D.Encrypting data at rest using AES-256
E.Using TLS 1.2 for all API communications
AnswersA, C, E

A VPN encrypts traffic traversing untrusted networks between on-premises infrastructure and the cloud provider, using protocols such as IPsec. This protects data in transit for hybrid connectivity, satisfying the stem's requirement to safeguard personal data moving between environments.

Why this answer

Option A is correct because a VPN (e.g., IPsec or TLS-based tunnel) encrypts traffic between on-premises networks and the cloud, protecting data in transit across hybrid connections. Option C is correct because enforcing HTTPS ensures web application traffic is encrypted with TLS, preventing eavesdropping or tampering over the network. Option E is correct because using TLS 1.2 for API communications encrypts data in transit between clients and services, providing confidentiality and integrity.

Option B is not correct because data classification labels identify sensitivity and guide handling but do not themselves encrypt or protect data in transit. Option D is not correct because AES-256 encryption at rest protects stored data, not data moving across a network.

Exam trap

The trap is mixing data-at-rest controls (AES-256) and governance controls (classification labels) with in-transit encryption; the exam tests whether you can distinguish the three data states.

43
MCQmedium

An organization wants to protect its cloud storage data from ransomware attacks that might encrypt or delete objects. The security team decides to enable a feature that maintains previous versions of objects when changes are made. Which feature is being described?

A.Object versioning
B.Access control lists
C.Cross-region replication
D.Bucket locking
AnswerA

Object versioning retains prior copies of each object whenever it is overwritten or deleted, so ransomware encryption or deletion produces a new version while the original remains recoverable. This directly satisfies the requirement to maintain previous versions of objects, enabling restoration without paying a ransom.

Why this answer

Object versioning is the feature that retains previous versions of objects when they are overwritten or deleted, allowing recovery from accidental or malicious changes such as ransomware encryption. When versioning is enabled, each PUT creates a new version, and the previous version remains accessible, so encrypted or deleted objects can be restored.

Exam trap

CCSP often tests the difference between versioning (retains history) and object lock (prevents deletion) — candidates may pick bucket locking thinking it maintains versions, but it actually enforces immutability without keeping older versions.

How to eliminate wrong answers

Option B is wrong because ACLs control access permissions on buckets and objects, not version retention — they do not protect against data modification or deletion. Option C is wrong because cross-region replication copies objects to another region for durability and compliance, but it does not maintain previous versions unless versioning is also enabled, and it does not by itself protect against ransomware overwriting the source. Option D is wrong because bucket locking (S3 Object Lock) prevents object deletion or overwriting for a specified retention period, but it does not maintain previous versions — it enforces immutability, which is a different mechanism.

44
MCQeasy

A cloud security administrator is configuring access to a cloud storage bucket that contains regulated data. The administrator needs to ensure that data is encrypted at rest using keys that are automatically rotated every 90 days. Which cloud service feature should the administrator use?

A.Client-side encryption with a locally stored key.
B.Server-side encryption with customer-provided keys (SSE-C).
C.Server-side encryption with customer-managed keys in a cloud KMS.
D.Server-side encryption with provider-managed keys (SSE-S3 or equivalent).
AnswerC

Customer-managed keys in a cloud KMS allow the administrator to configure automatic rotation with a custom schedule, such as every 90 days. This meets the requirement for controlled rotation. The administrator retains control over the key lifecycle while benefiting from server-side encryption.

Why this answer

Customer-managed keys in a cloud KMS enable automatic rotation with a configurable schedule, satisfying the 90-day requirement. Provider-managed keys rotate automatically but without customer control over the interval. Client-side and customer-provided keys require manual rotation.

Thus, the KMS option is the correct choice.

Exam trap

The trap here is assuming that provider-managed keys allow custom rotation schedules, when in fact the rotation interval is controlled by the provider and not configurable.

45
Multi-Selecthard

A global enterprise is designing a cloud storage architecture with cross-region replication for disaster recovery. They must ensure that data replicated to a secondary region is encrypted with keys managed by the customer, and that those keys are stored in the secondary region's key management service (KMS). Which THREE capabilities must be enabled?

Select 3 answers
A.Default encryption with provider keys
B.Client-side encryption before upload
C.Permission for the replication service to use the secondary region's key
D.Cross-region replication
E.Customer-managed encryption keys in the secondary region
AnswersC, D, E

Replication must be granted explicit permission to encrypt with the customer-managed key held in the secondary region's KMS; without that authorisation, cross-region writes fail because the destination key cannot be used. This satisfies the stem's constraint that replicated data be encrypted under customer-managed keys stored in the secondary region.

Why this answer

Option D (Cross-region replication) is required because the scenario explicitly demands that data be replicated to a secondary region for disaster recovery, which is the core mechanism that copies objects across regions. Option E (Customer-managed encryption keys in the secondary region) is correct because the requirement states the replicated data must be encrypted with customer-managed keys that reside in the secondary region's KMS, satisfying the customer-controlled key mandate. Option C (Permission for the replication service to use the secondary region's key) is correct because the replication service must be authorized to encrypt the replicated objects with that secondary-region customer-managed key; without the appropriate KMS key policy/grant, replication would fail to apply the required encryption.

Option A (Default encryption with provider keys) does not belong because provider-managed keys do not meet the customer-managed key requirement. Option B (Client-side encryption before upload) does not belong because client-side encryption is performed before the data reaches the storage service and would not use the secondary region's KMS-managed customer keys as specified.

Exam trap

The trap is selecting default encryption or client-side encryption as sufficient; candidates must recognize that customer-managed keys in the secondary region require explicit permissions and cross-region replication configuration, not just any encryption method.

46
MCQmedium

A cloud security team is implementing data loss prevention (DLP) for sensitive data in a cloud data warehouse. They need to detect and classify Social Security numbers (SSNs) stored in tables. Which cloud service capability is most appropriate for this task?

A.Object storage bucket policies
B.Cloud DLP API
C.Key management service
D.Identity and access management (IAM)
AnswerB

Cloud DLP API inspects and classifies data at rest, using built-in infoType detectors to identify SSN patterns within warehouse tables, satisfying the requirement to detect and classify stored sensitive data. Unlike encryption or access controls, it performs content-level discovery, matching the stem's classification constraint directly.

Why this answer

Cloud DLP API is purpose-built to discover, classify, and de-identify sensitive data such as SSNs, credit card numbers, and PHI across storage and data warehouses using built-in and custom infoType detectors. It can scan BigQuery tables, Cloud Storage, and Datastore directly, making it the correct tool for detecting and classifying SSNs in a cloud data warehouse. The other options are access-control or key-management services that do not perform content inspection.

Exam trap

CCSP often tests whether candidates confuse access control with data classification — the trap is picking IAM or bucket policies because they sound like 'security controls,' when the question specifically asks about detecting and classifying sensitive content.

How to eliminate wrong answers

Option A is wrong because object storage bucket policies are IAM-style access controls that govern who can read/write objects — they do not inspect content or classify data types like SSNs. Option C is wrong because a key management service handles cryptographic key lifecycle (generation, rotation, destruction) and has no data-classification capability. Option D is wrong because IAM controls authentication and authorization (who can do what) and does not scan or classify data content.

47
MCQmedium

A cloud security team is implementing data loss prevention for a data lake that stores customer support logs. They need to redact credit card numbers from the logs before they are used for analytics. Which DLP de-identification technique should be applied?

A.Date shifting
B.Bucketing
C.Masking
D.Tokenization
AnswerC

Masking replaces detected credit card values with a placeholder character, such as a hash or asterisk, so the sensitive digits are irreversibly removed from the log records while the surrounding analytics fields remain intact and queryable.

Why this answer

Masking is the correct DLP de-identification technique because it replaces sensitive values like credit card numbers with obfuscated characters (e.g., ****-****-****-1234) while preserving the format and length of the original data. This allows the support logs to remain usable for analytics and pattern matching without exposing the actual PAN data. Masking is irreversible or partially reversible depending on configuration, making it ideal for redaction before analytics processing.

Exam trap

CCSP often tests the distinction between reversible pseudonymization (tokenization) and irreversible anonymization (masking) — candidates incorrectly choose tokenization because it sounds more 'secure,' but the question specifically asks for redaction of the number itself.

How to eliminate wrong answers

Option A is wrong because date shifting only alters date/timestamp values by a consistent offset to preserve temporal relationships for analytics, and does nothing to redact credit card numbers. Option B is wrong because bucketing groups values into ranges (e.g., age brackets) to generalize data, which would destroy the credit card number format and is not a redaction technique. Option D is wrong because tokenization replaces sensitive data with a surrogate token that maps back to the original value via a token vault — it preserves referential integrity but does not redact the number from view, and the token itself may still be considered sensitive.

48
MCQhard

A financial services company stores regulated data in a cloud object storage bucket and uses a cloud key management service (KMS) with customer-managed keys. An auditor asks how the company ensures that data remains protected if a malicious insider with KMS administrator rights attempts to export key material. Which KMS capability should the security team describe?

A.The KMS uses hardware security modules that are validated to FIPS 140-2 or FIPS 140-3 and are configured to prevent key material from being exported in plaintext.
B.The KMS automatically rotates customer-managed keys every 90 days, which limits the usefulness of any exported key material.
C.The KMS logs all key usage to an immutable audit trail, so any export attempt by an insider would be detected after the fact.
D.The KMS enforces multi-factor authentication for all administrative actions, which prevents an insider from exporting key material.
AnswerA

HSM-backed KMS implementations are designed so that key material never leaves the HSM in plaintext, even for administrators. FIPS validation provides assurance that the cryptographic module enforces this boundary. This directly answers the auditor's concern about an insider exporting keys, because administrative rights do not translate into the ability to extract raw key bytes.

Why this answer

HSM-backed KMS with FIPS validation is the correct capability because these modules are designed to keep key material inside the hardware boundary and prevent plaintext export, even by administrators. MFA, audit logging, and rotation are useful controls but do not stop an insider from extracting usable key material through legitimate administrative interfaces.

Exam trap

The trap here is confusing detective or access controls such as logging and MFA with the preventive guarantee that key material cannot be exported from a validated HSM.

49
Multi-Selecthard

A cloud security architect is designing a data retention and deletion strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a combination of object storage, block storage, and a managed database. Regulatory requirements mandate that data be irrecoverably deleted upon customer request. Which TWO of the following measures are MOST effective to ensure secure data disposal in the cloud? (Choose two.)

Select 2 answers
A.Rely on the cloud provider's media sanitization processes when storage is decommissioned.
B.Use a cloud provider's secure deletion API that performs a cryptographic erase on the storage volume.
C.Overwrite the data with zeros or random patterns multiple times.
D.Use cryptographic erasure by deleting the encryption keys associated with the data.
E.Implement a data retention policy that automatically deletes data after a set period.
AnswersB, D

Some cloud providers offer secure deletion APIs that perform cryptographic erasure on volumes or objects. This directly addresses the need for irrecoverable deletion and can be integrated into the application's deletion workflow. It is an effective measure for secure data disposal in the cloud.

Why this answer

Cryptographic erasure by deleting keys and using provider secure deletion APIs are both effective because they render data irrecoverable without relying on physical media destruction. Overwriting is unreliable in cloud environments, retention policies do not ensure immediate deletion, and provider media sanitization is not on-demand.

Exam trap

The trap here is assuming that traditional on-premises data destruction methods like overwriting are effective in the cloud, where storage abstraction prevents such guarantees.

50
Multi-Selecthard

A multinational corporation must comply with data residency requirements that mandate certain data must remain within the European Union. Additionally, the company needs to ensure high availability and disaster recovery for this data. Which TWO measures should be implemented? (Select TWO.)

Select 2 answers
A.Configure cross-region replication to another EU region
B.Implement IAM policies with conditions restricting data access to EU regions
C.Use cross-region replication to a region outside the EU
D.Select cloud regions located within the EU
E.Enable public access to the bucket for all users
AnswersA, D

Cross-region replication to a second EU region keeps data within the European Union while providing geographic redundancy, satisfying both the residency mandate and the disaster recovery requirement. Replicating to a non-EU region would breach residency, so the paired EU region is the decisive constraint.

Why this answer

Option D is correct because selecting cloud regions physically located within the EU is the foundational measure that ensures data is stored and processed inside EU territory, directly satisfying data residency mandates. Option A is correct because configuring cross-region replication to another EU region provides high availability and disaster recovery while keeping all replicated data within EU boundaries, so residency is not violated. Option B is not correct because IAM policies with region conditions control access authorization but do not by themselves guarantee that data is stored or replicated only within the EU.

Option C is not correct because replicating to a region outside the EU would violate the data residency requirement. Option E is not correct because enabling public access to the bucket weakens security and does nothing to meet residency or availability requirements.

Exam trap

The trap is confusing access control (IAM policies) with data residency; candidates may think restricting access to EU regions ensures residency, but residency is about where data is stored, not who can access it.

51
Multi-Selecthard

A healthcare organization stores electronic protected health information (ePHI) in a cloud environment. They need to implement data discovery and classification to meet HIPAA requirements. Which two techniques are most appropriate for identifying ePHI in unstructured data stored in cloud object storage? (Choose two.)

Select 2 answers
A.Regular expression pattern matching for known ePHI formats.
B.Full-disk encryption of the storage volumes.
C.Natural language processing (NLP) to detect medical terminology and context.
D.Metadata tagging based on file extensions and folder names.
E.Manual review of every file by a compliance officer.
AnswersA, C

Regular expressions can identify structured ePHI such as Social Security numbers, medical record numbers, and dates of birth in text files. This is a common technique in data discovery tools to flag potential ePHI. It is effective for known patterns but may produce false positives, so it is often combined with other methods.

Why this answer

Regular expression pattern matching and NLP are both content inspection techniques that can identify ePHI in unstructured data. Pattern matching catches formatted identifiers, while NLP detects medical context. Together they provide a robust discovery strategy.

Encryption, manual review, and metadata tagging do not effectively identify ePHI content at scale.

Exam trap

The trap here is assuming that metadata or file extensions are sufficient for data discovery, when in fact content inspection is required to reliably identify ePHI in unstructured data.

52
MCQmedium

A financial institution is implementing a data classification scheme for their cloud environment. They have data that, if exposed, could cause severe damage to the organization and is subject to strict regulatory requirements. Which classification level should be applied to this data?

A.Confidential
B.Restricted
C.Public
D.Internal
AnswerB

Restricted classification fits because the stem specifies severe organisational damage plus strict regulatory obligations, which demand the highest confidentiality controls, encryption, and least-privilege access. Unlike Confidential, Restricted typically enforces need-to-know access, formal authorisation, and audit logging, satisfying the financial regulator's requirements.

Why this answer

Restricted data is the highest classification level, typically used for data that, if compromised, could cause severe damage and is subject to strict regulations.

53
MCQeasy

A cloud security administrator is configuring access to a cloud object storage bucket that contains regulated data. The requirement is that only identities with an explicit business need can read objects, and that access decisions are evaluated centrally with fine-grained conditions such as department and time of day. Which capability BEST addresses this requirement?

A.A centralized policy engine that evaluates identity attributes and contextual conditions before granting object reads.
B.Bucket access control lists that grant read permission to specific user accounts.
C.Network ACLs that restrict access to the bucket from approved corporate IP ranges.
D.Pre-signed URLs generated by an administrator and distributed to approved users.
AnswerA

A centralized policy engine can evaluate identity attributes, resource tags, and contextual factors like time of day to make fine-grained authorization decisions. It provides consistent, auditable enforcement across the bucket and scales as identities and resources grow. This directly satisfies the need for explicit business-need-based, condition-aware access control.

Why this answer

A centralized policy engine evaluates identity attributes and contextual conditions, enabling fine-grained, least-privilege authorization for bucket reads. It provides consistent enforcement and auditing across the environment, which ACLs, pre-signed URLs, and network ACLs cannot deliver. Only the policy engine meets the requirement for condition-based, business-need-driven access decisions.

Exam trap

The trap here is treating network restrictions or pre-signed URLs as authorization controls, when they do not evaluate identity attributes or business need.

54
MCQeasy

When data is in transit between an on-premises data center and a cloud service, which of the following is the minimum encryption standard recommended by security best practices?

A.IPsec with 3DES
B.TLS 1.2
C.TLS 1.0
D.SSL 3.0
AnswerB

TLS 1.2 provides authenticated, encrypted transport with modern cipher suites, satisfying the minimum encryption standard for data in transit between on-premises systems and cloud services. Earlier versions such as TLS 1.0 and 1.1 are deprecated due to known vulnerabilities, so TLS 1.2 is the baseline best practice.

Why this answer

TLS 1.2 is the minimum encryption standard recommended by security best practices (NIST SP 800-52 Rev 2, PCI DSS) for data in transit between on-premises and cloud environments. It provides strong cipher suites (e.g., AES-GCM, SHA-256) and supports forward secrecy via ECDHE, which older protocols lack. CCSP candidates must recognize TLS 1.2 as the baseline acceptable protocol for protecting data in motion.

Exam trap

CCSP often tests the misconception that any encryption protocol is acceptable, when in fact deprecated protocols like SSL 3.0, TLS 1.0, and 3DES are explicitly disallowed by modern compliance frameworks.

How to eliminate wrong answers

Option A is wrong because IPsec with 3DES uses a deprecated 64-bit block cipher vulnerable to Sweet32 birthday attacks and is not the recommended minimum for cloud transit. Option C is wrong because TLS 1.0 lacks support for modern AEAD ciphers and is deprecated by RFC 8996 and PCI DSS. Option D is wrong because SSL 3.0 is obsolete, vulnerable to POODLE, and explicitly prohibited by RFC 7568.

55
MCQmedium

A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that any modification to a log file is detectable and that the original content cannot be repudiated. Which mechanism should they implement?

A.Use digital signatures with a private key to sign each log file.
B.Apply a cryptographic hash (e.g., SHA-256) to each log file and store the hash separately.
C.Enable object versioning and configure a lifecycle policy to retain all versions.
D.Enable server-side encryption with customer-provided keys (SSE-C).
AnswerA

Digital signatures provide integrity, authentication, and non-repudiation. If the private key is securely held by the log producer, any modification to the log file will invalidate the signature, and the signer cannot deny having signed it. This directly meets the requirements for tamper detection and non-repudiation.

Why this answer

Digital signatures use asymmetric cryptography to bind the signer's identity to the data. When a log file is signed, any alteration invalidates the signature, and the signer cannot deny signing. This satisfies both integrity and non-repudiation requirements.

Encryption alone provides confidentiality but not tamper evidence, while hashing without a signature lacks non-repudiation.

Exam trap

The trap here is assuming that encryption or hashing alone provides non-repudiation, when only a digital signature binds the signer's identity to the data.

56
MCQeasy

A cloud administrator is configuring a new object storage bucket that will hold internal project files. The organization's policy states that data must be encrypted at rest, but the team wants the cloud provider to handle all key management with no additional operational overhead. Which configuration meets this policy with the least administrative effort?

A.Use a third-party encryption gateway that proxies all uploads and encrypts objects before they reach the bucket.
B.Enable the bucket's default server-side encryption using provider-managed keys.
C.Store the files in a bucket without encryption but restrict access using bucket policies.
D.Encrypt each file on the client side before uploading it to the bucket.
AnswerB

Server-side encryption with provider-managed keys encrypts objects at rest automatically and the provider handles key creation, storage, and rotation. It requires no customer key infrastructure or application changes, so it meets the policy of encryption at rest with minimal operational overhead. This is the standard baseline for object storage and is usually enabled by default in modern cloud platforms.

Why this answer

Server-side encryption with provider-managed keys encrypts objects at rest automatically and delegates key lifecycle to the cloud provider. It requires no customer key handling, no application changes, and no extra infrastructure, so it satisfies the encryption-at-rest policy with the least administrative effort. Client-side encryption and third-party gateways add operational burden, while access policies alone do not encrypt data.

Exam trap

The trap here is conflating access control with encryption, when bucket policies restrict who can read data but leave the stored bytes unencrypted.

57
MCQeasy

A small business is migrating its customer database to a cloud-based database service. The security team wants to ensure that data is encrypted at rest using keys that the business controls, but they do not want to manage the underlying hardware security modules. Which cloud key management option should they choose?

A.Client-side encryption with keys stored on-premises.
B.Provider-managed keys with automatic rotation.
C.Bring your own key (BYOK) using a third-party key management service.
D.Customer-managed keys stored in a cloud KMS.
AnswerD

Customer-managed keys in a cloud KMS allow the business to control key lifecycle and permissions while the provider manages the HSM infrastructure. This meets the requirement for customer-controlled keys without the burden of managing hardware. It also integrates with cloud database services for encryption at rest.

Why this answer

Customer-managed keys in a cloud KMS provide the business with control over key lifecycle and access policies while the cloud provider handles the HSM infrastructure. This balances control with operational simplicity, making it ideal for organizations that want key control without managing hardware.

Exam trap

The trap here is confusing customer-managed keys with provider-managed keys; only customer-managed keys give the business control, but they still rely on the provider's HSM.

58
MCQeasy

A small business uses a cloud provider's default server-side encryption (SSE) to encrypt data at rest in their cloud storage. They are concerned about key management overhead. Which statement best describes the key management responsibility for SSE?

A.The customer and provider share key management responsibilities.
B.Keys are not used; encryption is transparent.
C.The customer generates and manages the keys.
D.The cloud provider manages the keys entirely.
AnswerD

With provider-managed SSE, the cloud provider generates, stores and rotates the data encryption keys entirely within its own key infrastructure; the customer never handles key material. This directly satisfies the small business's stated concern about key management overhead, since no customer-side key lifecycle tasks remain.

Why this answer

With default SSE (e.g., SSE-S3 in AWS), the cloud provider manages the encryption keys entirely. The customer is not involved in key generation, rotation, or storage. CMEK and CSEK require customer involvement.

BYOK involves importing customer keys.

59
Multi-Selecthard

A cloud security team is implementing data discovery and classification for a multi-cloud environment. They need to identify sensitive data such as personally identifiable information (PII) and protected health information (PHI) across structured and unstructured data stores. Which TWO approaches are MOST effective for accurate and scalable data discovery in this scenario? (Choose two.)

Select 2 answers
A.Use cloud-native data discovery services that integrate with the provider's storage and database services.
B.Deploy a third-party data discovery tool that supports multiple cloud providers and can scan both structured and unstructured data.
C.Use encryption to protect all data and assume that encrypted data does not need classification.
D.Implement network-based data loss prevention (DLP) appliances to inspect data in transit.
E.Rely on manual data tagging by data owners during data creation.
AnswersA, B

Cloud-native discovery services are designed to work with the provider's storage and database offerings, offering deep integration, automatic scaling, and reduced operational overhead. They can scan objects, files, and databases for sensitive data patterns and often include prebuilt classifiers for PII, PHI, and other data types. This makes them highly effective for multi-cloud environments when used per provider, though cross-cloud management may require additional tooling.

Why this answer

Cloud-native discovery services offer deep integration and scalability within each provider, while third-party multi-cloud tools provide a unified, cross-provider view and consistent classification. Together, they enable accurate and scalable discovery across structured and unstructured data in a multi-cloud environment. Manual tagging and network DLP are not sufficient for comprehensive data-at-rest discovery, and encryption does not remove the need for classification.

Exam trap

The trap here is assuming that encryption eliminates the need for data discovery and classification, or that manual tagging can scale in a multi-cloud environment.

60
MCQhard

A cloud architect is designing a data lifecycle policy for a SaaS application. According to the cloud data lifecycle, which phase immediately follows the 'Share' phase?

A.Store
B.Archive
C.Use
D.Destroy
AnswerB

In the cloud data lifecycle, Archive directly follows Share, since data no longer actively used moves into long-term retention. This satisfies the stem's requirement for the phase immediately after Share, distinguishing it from Create, Store, Use, and Destroy.

Why this answer

In the CSA cloud data lifecycle (Create, Store, Use, Share, Archive, Destroy), the Archive phase immediately follows Share. Archiving moves data that is no longer actively used but must be retained for compliance or business reasons into long-term, lower-cost storage.

Exam trap

CCSP often tests memorization of the exact CSA data lifecycle sequence — the trap is confusing the order of Use, Share, and Archive, since intuitively one might think Use comes after Share or that Store follows Share, when the canonical order is Create → Store → Use → Share → Archive → Destroy.

How to eliminate wrong answers

Option A is wrong because Store occurs earlier in the lifecycle (after Create), before Use and Share — it is not the phase after Share. Option C is wrong because Use precedes Share in the CSA lifecycle model; data is used by applications/users before it is shared with others. Option D is wrong because Destroy is the final phase, occurring after Archive, not immediately after Share.

61
MCQmedium

A company wants to use a cloud KMS to encrypt data but requires that the encryption key never leaves their on-premises hardware security module (HSM) due to compliance. Which key management model should they adopt?

A.Customer-Managed Encryption Key (CMEK)
B.Customer-Supplied Encryption Key (CSEK)
C.Hold Your Own Key (HYOK)
D.Bring Your Own Key (BYOK)
AnswerC

Hold Your Own Key keeps cryptographic material inside the customer's on-premises HSM, so encryption and decryption occur locally and only ciphertext reaches the cloud KMS. This satisfies the compliance constraint that the key never leaves the HSM, unlike cloud-hosted models where key material resides in the provider's infrastructure.

Why this answer

HYOK (Hold Your Own Key) is the only model where the encryption key material is generated, stored, and used exclusively within the customer's on-premises HSM and never exported to the cloud provider. The cloud KMS is used only to wrap or reference the key, satisfying compliance mandates that keys must remain under customer physical control. CMEK, CSEK, and BYOK all involve the key material being imported into or generated within the cloud provider's infrastructure at some point.

Exam trap

CCSP often tests the distinction between BYOK (import your key into the cloud KMS) and HYOK (key never leaves your premises), so candidates who assume 'bring your own key' means the key stays on-premises pick BYOK incorrectly.

How to eliminate wrong answers

Option A is wrong because CMEK keys are generated and stored inside the cloud provider's KMS, so the key material resides in the provider's HSM, not the customer's on-premises HSM. Option B is wrong because CSEK keys are supplied by the customer at request time but are still transmitted to and used by the cloud service, meaning the key leaves customer control. Option D is wrong because BYOK typically means the customer generates the key on-premises but then imports it into the cloud KMS, after which the key material resides in the provider's HSM.

62
Multi-Selectmedium

A cloud security team is implementing data loss prevention (DLP) for a SaaS application that stores sensitive documents. They need to detect and prevent unauthorized sharing of documents containing personally identifiable information (PII). Which two cloud data security controls should be implemented? (Choose two.)

Select 2 answers
A.Data classification and labeling of documents based on content
B.Encryption of documents at rest with customer-managed keys
C.Regular security awareness training for employees
D.Multi-factor authentication (MFA) for all users accessing the SaaS application
E.Cloud access security broker (CASB) with DLP policies
AnswersA, E

Data classification and labeling automatically identify and tag documents containing PII. This enables DLP policies to be applied based on labels, ensuring that sensitive documents are subject to stricter sharing controls. It is a foundational control for effective DLP, as it helps the system understand which data requires protection.

Why this answer

To detect and prevent unauthorized sharing of PII in a SaaS application, the team needs both a CASB with DLP policies and data classification and labeling. The CASB provides the enforcement mechanism to inspect and control data flows, while classification and labeling identify which documents contain PII so that DLP policies can be applied effectively. Together, they form a comprehensive DLP solution.

Exam trap

The trap here is assuming that encryption or MFA alone can prevent data loss; they protect data but do not detect or stop sharing by authorized users.

63
MCQeasy

Which of the following is the most granular method to grant time-limited access to a specific object in a cloud storage bucket without requiring the requester to have cloud provider credentials?

A.Bucket ACLs
B.Bucket policies with conditions
C.Identity-based policies
D.Signed URLs
AnswerD

Signed URLs embed a cryptographic signature and expiry directly in the URL, granting time-limited access to one specific object. The requester needs no cloud provider credentials, satisfying the granularity and credential-free constraints in the stem.

Why this answer

Signed URLs (also called presigned URLs) are generated by the object owner using their own credentials and embed a cryptographic signature plus an expiration timestamp directly in the URL. Anyone holding the URL can retrieve that single object until the expiry time, without needing any cloud provider identity or credentials. This makes them the most granular, time-limited access mechanism for a specific object.

Exam trap

CCSP often tests the distinction between identity-based access (requires credentials) and resource-based, time-limited access (signed URLs), so candidates who reflexively pick 'bucket policy' or 'IAM role' miss the credential-free, per-object granularity requirement.

How to eliminate wrong answers

Option A is wrong because bucket ACLs grant permissions at the bucket or object level to predefined grantees (users, groups, or authenticated users) and do not natively provide time-limited, credential-free access. Option B is wrong because bucket policies with conditions apply to principals defined in IAM or the account, still requiring the requester to authenticate with cloud credentials. Option C is wrong because identity-based policies are attached to IAM principals and require the requester to have a cloud identity and credentials — the opposite of the requirement.

64
MCQmedium

A company uses a cloud KMS to manage encryption keys for its cloud storage buckets. The security team wants to ensure that keys are rotated automatically every 90 days and that access to keys is restricted based on user roles. Which key management feature should they configure?

A.Key versioning and deletion policies
B.Key rotation policy and access control key policies
C.Key import and export policies
D.Key expiration and renewal policies
AnswerB

Configuring a rotation policy enforces automatic key replacement every 90 days, satisfying the stem's rotation constraint without manual intervention. Access control key policies bind permissions to user roles, restricting key usage to authorised principals. Together they deliver both required capabilities within the cloud KMS, whereas alternative options address only one requirement or none.

Why this answer

A cloud KMS rotation policy lets the security team schedule automatic key rotation (e.g., every 90 days) without manual intervention, while key policies (IAM/resource policies attached to the key) enforce role-based access control over who can use, manage, or view the key. Together these two features directly satisfy both stated requirements: automatic 90-day rotation and role-restricted key access.

Exam trap

CCSP often tests the confusion between key rotation (limiting cryptographic exposure over time) and key versioning/deletion (retention and destruction) — candidates pick versioning because it sounds related to lifecycle, but only a rotation policy satisfies an automatic 90-day schedule.

How to eliminate wrong answers

Option A is wrong because key versioning only retains prior key versions for decryption/recovery and deletion policies only govern scheduled destruction of keys — neither automates rotation nor restricts access by role. Option C is wrong because import/export policies govern bringing externally generated key material into or out of the KMS (BYOK/HYOK scenarios) and have nothing to do with rotation schedules or role-based access. Option D is wrong because 'expiration and renewal' is not a standard KMS feature set — keys do not auto-renew like certificates; rotation, not expiration, is the mechanism for limiting key lifetime.

65
MCQhard

A cloud security team is implementing a data classification scheme for objects stored in a cloud environment. They need to ensure that classification labels persist with the data, travel with it when copied or moved between services, and can be used to enforce access and DLP policies automatically. Which approach BEST achieves these outcomes?

A.Store classification labels in a separate spreadsheet maintained by the data governance team and update it after each data movement.
B.Use file naming conventions that include the classification level in the object name and enforce policies based on name patterns.
C.Embed classification metadata as tags or object metadata that are preserved through supported copy and move operations and referenced by policy engines.
D.Apply classification only at the storage bucket level and rely on bucket policies to enforce access.
AnswerC

Embedding classification as tags or object metadata keeps labels attached to the data, and supported copy and move operations preserve them when configured correctly. Policy engines and DLP services can reference these labels to enforce access and handling rules automatically. This satisfies persistence, portability, and automated enforcement in a scalable way.

Why this answer

Embedding classification as tags or object metadata keeps labels attached to the data and allows them to be carried through supported copy and move operations. Policy engines and DLP services can then enforce access and handling rules automatically based on those labels. Spreadsheets, bucket-level classification, and naming conventions lack persistence, portability, and reliable automated enforcement.

Exam trap

The trap here is assuming that bucket-level classification or naming conventions provide object-level, portable labels, when only embedded metadata or tags travel with the data and drive automated enforcement.

66
MCQhard

An organization is required to use client-side encryption for all data uploaded to a cloud storage service to ensure that the cloud provider has no access to plaintext. However, they also need to allow the cloud provider to perform server-side operations like indexing and search on the encrypted data. Which technology can address this conflict?

A.Format-preserving encryption
B.Searchable encryption
C.Tokenization
D.Homomorphic encryption
AnswerB

Searchable encryption lets the provider index and query ciphertext without decrypting it, preserving client-side key custody. It resolves the conflict by enabling server-side search operations over encrypted objects while the provider never gains plaintext access, satisfying both the no-plaintext constraint and the indexing requirement.

Why this answer

Searchable encryption allows data to remain encrypted at rest while still supporting server-side operations such as keyword search and indexing over the ciphertext. It enables the cloud provider to perform searches without decrypting the data, satisfying both the client-side encryption requirement and the need for server-side search functionality. This directly resolves the conflict described.

Exam trap

CCSP often tests the distinction between encryption technologies that enable computation versus those that enable search — candidates may confuse homomorphic encryption (computation) with searchable encryption (search/indexing).

How to eliminate wrong answers

Option A is wrong because format-preserving encryption maintains the format of plaintext (e.g., credit card numbers) but does not inherently enable searchable operations on encrypted data. Option C is wrong because tokenization replaces sensitive data with non-sensitive tokens, but the tokens are typically stored and mapped by a tokenization system, and search is limited to exact token matches, not general indexing. Option D is wrong because homomorphic encryption allows computation on ciphertext but is computationally expensive and not designed for efficient indexing and search at scale.

67
MCQhard

A company uses a cloud KMS service with an HSM backing for key storage. The security policy requires that keys be rotated automatically every 90 days and that old keys be retained for at least one year to decrypt archived data. Which key management feature should be configured to meet these requirements?

A.Key hierarchy with root key separation
B.Key versioning with rotation schedule
C.Key policy with conditions for automatic rotation
D.Key import with manual rotation
AnswerB

Key versioning retains prior key versions alongside the current one, so scheduled rotation every 90 days generates new versions while old versions persist to decrypt archived data. This satisfies both the 90-day automatic rotation and one-year retention constraints simultaneously.

Why this answer

Key versioning with a rotation schedule allows the KMS to automatically rotate keys every 90 days while retaining old key versions for decryption of archived data. Each rotation creates a new key version, and old versions remain available for decryption but are not used for new encryption. This meets both the rotation and retention requirements without manual intervention.

Exam trap

CCSP often tests the difference between key rotation, key versioning, and key policies, and candidates may choose key policies or key hierarchy thinking they enable automatic rotation, when in fact versioning with a rotation schedule is the specific feature.

How to eliminate wrong answers

Option A (Key hierarchy with root key separation) is wrong because it describes the structure of keys (root, data encryption keys) but does not provide automatic rotation or retention of old versions. Option C (Key policy with conditions for automatic rotation) is wrong because key policies define access permissions, not rotation schedules; while policies can enforce rotation, they do not themselves rotate keys or retain versions. Option D (Key import with manual rotation) is wrong because it requires manual rotation and does not automatically retain old versions for decryption; it also does not meet the 90-day automatic rotation requirement.

68
MCQmedium

A financial services company uses a cloud DLP API to scan data stored in Cloud Storage and BigQuery. They need to reduce the risk of exposing credit card numbers in reports by replacing the first 12 digits with asterisks while preserving the last four. Which de-identification technique should they apply?

A.Pseudonymization
B.Bucketing
C.Tokenization
D.Masking
AnswerD

Masking replaces characters with a substitute such as asterisks, so the first 12 digits become masked while the last four remain readable for reporting. Tokenisation would substitute the whole value, and bucketing or date shifting cannot preserve the trailing digits.

Why this answer

Masking replaces sensitive data with a redacted or partially obscured version while preserving the format and often the last few characters for referential purposes. Replacing the first 12 digits of a credit card number with asterisks while keeping the last four is the textbook definition of masking — it preserves usability (e.g., for customer service verification) while removing the sensitive payload. Cloud DLP APIs such as Google Cloud DLP provide a masking transformation (e.g., 'maskingCharacter' with 'numberToMask') that performs exactly this operation.

Exam trap

The trap is conflating masking with tokenization or pseudonymization — candidates see 'replace digits' and think 'tokenize,' but tokenization replaces the whole value with a token, whereas masking partially obscures while preserving format.

How to eliminate wrong answers

Option A is wrong because pseudonymization replaces identifiers with consistent surrogate values (e.g., a hash or token) that allow re-identification via a mapping table — it does not obscure digits with asterisks. Option B is wrong because bucketing groups values into ranges (e.g., age 30-39) to generalize data, which is useless for credit card numbers where the last four must remain visible. Option C is wrong because tokenization substitutes the entire value with a non-sensitive token stored in a secure vault; the original digits are not partially preserved, and the format is not maintained for display.

69
Multi-Selectmedium

A cloud architect is designing a data classification strategy for a multi-cloud environment. The strategy must automatically tag resources with classification labels and enforce access controls based on those labels. Which THREE components are essential for this automated classification and enforcement?

Select 3 answers
A.IAM policies that reference classification tags
B.Tagging resources with classification labels
C.Pre-signed URLs for temporary access
D.Automated DLP scanning to identify sensitive data
E.HSM-backed key generation
AnswersA, B, D

IAM policies that reference classification tags enforce access decisions dynamically, so permissions follow the label rather than static resource names. Without tag-based policy evaluation, automated classification produces metadata that never gates access, breaking the enforcement half of the requirement.

Why this answer

Option B is essential because the strategy requires resources to actually carry classification labels (e.g., via cloud-native tagging such as AWS tags, Azure tags, or GCP labels), which serve as the metadata foundation that any automated enforcement mechanism must reference. Option D is essential because automated DLP scanning (e.g., Amazon Macie, Azure Information Protection, or Google Cloud DLP) is what discovers and identifies sensitive data so that classification labels can be applied automatically rather than manually, directly enabling the 'automatically tag' requirement. Option A is essential because IAM policies that reference classification tags (e.g., AWS IAM policy conditions using aws:ResourceTag or azureResourceTags) are the mechanism that translates labels into actual access-control decisions, satisfying the 'enforce access controls based on those labels' requirement.

Option C is not correct because pre-signed URLs only grant temporary access to a specific object and do not perform classification or tag-based policy enforcement. Option E is not correct because HSM-backed key generation addresses cryptographic key protection and management, not data classification or label-based access control.

70
MCQeasy

A cloud engineer is configuring a storage bucket that will hold publicly accessible marketing images. The security policy requires that data at rest be encrypted, but the images are not sensitive and the team wants to minimize operational overhead. Which cloud storage encryption option is most appropriate?

A.Customer-managed keys stored in a hardware security module that the team rotates manually each quarter.
B.No encryption at rest, because the images are publicly accessible and therefore not confidential.
C.Client-side encryption where the application encrypts each image before uploading and manages its own key store.
D.Provider-managed encryption keys with automatic rotation, using the cloud provider's default encryption at rest.
AnswerD

Provider-managed keys provide encryption at rest with no key management burden on the team, which matches the low-sensitivity, low-overhead requirement. The provider handles key storage, rotation, and access control, so the marketing images remain encrypted without additional configuration. This satisfies the policy while avoiding unnecessary complexity for non-sensitive public content.

Why this answer

Provider-managed encryption keys are the best fit because they satisfy the encryption-at-rest policy while imposing no key management burden on the team. The images are public and non-sensitive, so stronger controls such as customer-managed keys or client-side encryption add cost and complexity without proportional benefit. The policy requirement is met with minimal operational effort.

Exam trap

The trap here is equating stronger key control with better security in every case, when the scenario's low sensitivity and low-overhead requirement make provider-managed keys the appropriate choice.

71
MCQeasy

A financial services company stores customer transaction data in a cloud object storage bucket. The company requires that all data be encrypted at rest using keys that it generates and manages on-premises, with the cloud provider having no access to the keys. Which encryption approach should the company use?

A.Server-side encryption with AES-256
B.Client-side encryption with customer-owned keys
C.Server-side encryption with bring your own key (BYOK) to cloud KMS
D.Server-side encryption with customer-managed keys (CMK) in cloud KMS
AnswerB

Encrypting data before it leaves the organisation means the provider stores only ciphertext, and keys generated and retained on-premises are never exposed to the cloud service. This satisfies the requirement that the provider has no access to keys, unlike provider-managed or customer-managed keys held in the cloud.

Why this answer

Client-side encryption with customer-owned keys means the company encrypts data before uploading it to cloud storage, and the keys never leave the company's on-premises environment. The cloud provider stores only ciphertext and has no access to the plaintext or the keys, satisfying the requirement that the provider cannot access the keys.

Exam trap

CCSP often tests the distinction between BYOK/CMK (provider still holds key material in its KMS) and true client-side encryption (customer retains sole key custody) — candidates who equate 'customer-managed' with 'provider cannot access' pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because server-side encryption with AES-256 is managed by the cloud provider, which holds the keys and can decrypt data — violating the no-provider-access requirement. Option C is wrong because BYOK to cloud KMS still imports the key material into the provider's KMS, where the provider's infrastructure handles it and could theoretically access it. Option D is wrong because customer-managed keys (CMK) in cloud KMS are stored and managed within the provider's KMS, so the provider has access to the key material and can decrypt data.

72
Multi-Selectmedium

A company stores sensitive data in cloud object storage and wants to protect against ransomware attacks that could encrypt or delete objects. Which TWO measures should they implement? (Choose two.)

Select 2 answers
A.Use cross-region replication
B.Implement immutable storage (e.g., Object Lock)
C.Configure signed URLs for access
D.Enable object versioning
E.Set short object lifetimes using lifecycle policies
AnswersB, D

Object Lock enforces WORM protection at the object level, preventing overwrite or deletion for a defined retention period — even by compromised credentials or malicious insiders. This directly satisfies the ransomware constraint, since encrypted or deleted objects cannot be altered until retention expires, enabling clean recovery.

Why this answer

Option B (immutable storage such as Object Lock) is correct because it enforces WORM (write once, read many) protection, preventing objects from being modified or deleted for a defined retention period even by compromised or malicious accounts, which directly blocks ransomware encryption or deletion. Option D (object versioning) is correct because it preserves prior versions of each object, so if ransomware overwrites or encrypts the current version, the previous clean versions remain recoverable. Option A (cross-region replication) only copies data to another region and would replicate corrupted or encrypted objects too, so it does not protect against ransomware.

Option C (signed URLs) merely grants time-limited access to specific objects and does not prevent an attacker with valid credentials from encrypting or deleting data. Option E (short object lifetimes via lifecycle policies) actually deletes objects sooner, which increases data loss risk rather than protecting against ransomware.

Exam trap

Candidates often mistakenly choose cross-region replication or lifecycle policies as ransomware defenses, not realizing that replication alone does not prevent deletion/encryption, and lifecycle policies could actually delete data. The correct approach combines immutable storage to prevent modification and versioning to allow recovery of prior states.

73
Multi-Selecthard

A cloud security architect is designing a data retention and destruction strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a mix of block storage, object storage, and a managed database. Regulatory requirements mandate that data be irrecoverably destroyed upon customer offboarding, and that the destruction be verifiable. Which TWO of the following practices BEST support these requirements? (Choose two.)

Select 2 answers
A.Maintain an immutable audit log of all data destruction actions, including key deletions and storage reclamation.
B.Implement a secure overwrite process that writes random data to all blocks occupied by the customer's data.
C.Use cryptographic erasure by deleting the customer-specific encryption keys from the cloud KMS.
D.Rely on the cloud provider's shared responsibility model to ensure physical media destruction at end-of-life.
E.Use data anonymization techniques to remove personally identifiable information before deletion.
AnswersA, C

An immutable audit log provides verifiable evidence that destruction actions occurred. It can record key deletion events, storage deletion operations, and timestamps. This supports the requirement for verifiable destruction by creating a tamper-evident record that can be presented to auditors, complementing the actual destruction method.

Why this answer

Cryptographic erasure by deleting customer-specific keys ensures data is irrecoverable, and an immutable audit log provides verifiable evidence of the destruction. Together, they meet the regulatory requirements for irrecoverable and verifiable destruction in a multi-tenant cloud environment where physical media destruction is not customer-controlled.

Exam trap

The trap here is assuming that overwriting data or relying on provider media destruction is sufficient, but in cloud multi-tenant environments, cryptographic erasure with verifiable logs is the only reliable and auditable method.

74
MCQhard

An organization must implement encryption for data in transit between its on-premises data center and a cloud provider. The data is sensitive and the organization requires a dedicated, encrypted tunnel. Which solution should be used?

A.Client-side encryption before upload
B.TLS 1.2 for API communication
C.VPN connection
D.Cloud KMS for key exchange
AnswerC

A VPN connection builds an encrypted tunnel over the public internet between the on-premises data centre and the cloud provider, satisfying the requirement for encryption in transit. Site-to-site IPsec VPNs provide the dedicated, encrypted tunnel specified, unlike TLS alone, which secures individual application sessions rather than the whole network path.

Why this answer

A VPN connection provides a dedicated, encrypted tunnel between the on-premises data center and the cloud provider, ensuring data in transit is protected. It uses protocols like IPsec or SSL/TLS to encrypt all traffic, meeting the requirement for a dedicated encrypted tunnel for sensitive data.

Exam trap

The trap is confusing data-in-transit encryption methods (TLS, client-side encryption) with a dedicated tunnel solution (VPN), causing candidates to pick a less comprehensive option that doesn't meet the 'dedicated tunnel' requirement.

How to eliminate wrong answers

Option A is wrong because client-side encryption before upload protects data at rest and in transit to the storage service, but does not create a dedicated tunnel; it also requires application changes and does not encrypt all traffic. Option B is wrong because TLS 1.2 for API communication only secures specific API calls, not all data in transit, and does not provide a dedicated tunnel. Option D is wrong because Cloud KMS is for key management, not for establishing encrypted tunnels; it manages encryption keys but does not encrypt data in transit itself.

75
MCQmedium

A financial services company stores customer transaction data in a cloud object storage service. The security team wants to ensure that if a malicious insider gains access to the storage bucket, they cannot read the data. Which encryption approach provides the highest level of protection against the cloud provider and insiders?

A.Client-side encryption using a customer-managed key
B.Server-side encryption with AES-256 (SSE-S3)
C.Server-side encryption with customer-provided keys (SSE-C)
D.Transport Layer Security (TLS) for data in transit
AnswerA

Encrypting before upload means ciphertext reaches the bucket, so the provider and any insider only ever see unreadable data. Because the customer-managed key never leaves the organisation's control, decryption is impossible without it, satisfying the requirement that bucket access alone cannot expose transaction data.

Why this answer

Client-side encryption with a customer-managed key ensures data is encrypted before it leaves the customer's environment, so the cloud provider never possesses the plaintext or the key. This provides the highest protection against both the cloud provider and malicious insiders because even with bucket access, the ciphertext is useless without the customer-held key. This is the strongest option for isolating data from provider and insider threats.

Exam trap

The trap is equating 'encryption at rest' with 'protection from the provider' — candidates forget that server-side encryption options leave key control with the provider, which does not satisfy the insider-threat requirement.

How to eliminate wrong answers

Option B is wrong because SSE-S3 uses keys fully managed by the cloud provider, meaning the provider (and anyone who compromises provider-side controls) can decrypt the data. Option C is wrong because SSE-C, while using customer-provided keys, still requires sending the key to the provider for each request, so the provider transiently handles the key and could theoretically access plaintext. Option D is wrong because TLS only protects data in transit and does nothing to protect data at rest from insider or provider access.

Page 1 of 2 · 120 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Ccsp Data Security questions.