Courseiva

CCSP · topic practice

Cloud Data Security practice questions

Cloud Data Security covers how data is classified, protected, retained, and discovered across IaaS, PaaS, and SaaS. For CCSP you must reason about encryption at rest and in transit, key ownership models (BYOK, HYOK, CSEK), tokenization, masking, DLP, and data residency controls, then pick the control that actually satisfies a stated requirement.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Cloud Data Security

What the exam tests

What to know about Cloud Data Security

Be able to map a stated data protection requirement to the exact control: key custody model, scoped time-bound access, or region restriction. The single most important thing is identifying who owns and can revoke the encryption key, since that decides most answers.

Selecting customer-managed vs provider-managed keys, including Cloud KMS, Cloud HSM, and CSEK on GCP or SSE-KMS and SSE-C on AWS S3

Using pre-signed URLs or SAS tokens for time-limited, scoped access to a single object

Enforcing data residency with region-pinned buckets, VPC Service Controls, or organization policy constraints

Applying DLP API, Macie, or Sensitive Data Protection to discover, classify, and mask regulated data

Watch out for

Common Cloud Data Security exam traps

  • ▸Confusing encryption at rest with encryption in transit, or assuming default SSE gives the customer control over key lifecycle and revocation.
  • ▸Choosing a broad IAM role or bucket policy when the scenario demands access limited to one object and expiring automatically.
  • ▸Treating replication or multi-region storage as compliant with residency rules when copies leave the mandated jurisdiction.

Practice set

Cloud Data Security questions

20 questions · select your answer, then reveal the explanation

A healthcare organization is storing protected health information (PHI) in a cloud object storage service. They want to ensure that if a storage bucket is accidentally made public, the data remains unreadable. Which combination of controls best addresses this risk?

A cloud security engineer is configuring a Data Loss Prevention (DLP) API to scan a cloud storage bucket for personally identifiable information (PII). Which of the following is a de-identification technique that replaces sensitive values with a token that can be mapped back to the original data using a secure lookup table?

An organization wants to use cloud KMS to manage encryption keys. They require automatic key rotation every 90 days and the ability to define granular access policies for who can use the keys. Which key management model should they choose?

A company is using client-side encryption to encrypt data before uploading to cloud storage. They want to ensure that the cloud provider cannot access the encryption keys. However, they need to allow a cloud-based analytics service to process the data. Which approach should they take?

A data lifecycle policy requires that data be destroyed after a retention period. In a cloud object storage service, what is the most secure method to ensure that data is irretrievably destroyed?

An organization is deploying a cloud DLP solution to scan data at rest. They want to automatically classify and tag sensitive data, and then apply access controls based on the tags. Which cloud service capability is most directly used to enforce access decisions based on data classification tags?

A healthcare organization is migrating electronic health records to the cloud and must comply with data residency requirements that mandate all patient data remain within the European Union. The cloud provider offers multiple regions globally. Which of the following is the most appropriate action to ensure compliance?

A company is implementing a data loss prevention (DLP) strategy for cloud storage. They need to detect and mask credit card numbers in documents stored in a cloud storage bucket. The DLP service provides de-identification transforms including masking, tokenization, and pseudonymization. Which transform should the company use to irreversibly replace the credit card numbers with a placeholder while maintaining the original format for analytics?

A cloud security architect is designing access controls for a cloud storage bucket that contains sensitive customer data. The architect needs to implement a solution that provides granular, time-limited access to specific objects for external auditors. Which TWO methods should the architect consider? (Select TWO.)

A company is implementing a DLP strategy to protect PII in cloud storage. They need to discover sensitive data and then apply de-identification transforms. Which THREE de-identification transforms are appropriate for anonymizing PII while maintaining data utility for analytics? (Select THREE.)

A healthcare organization is migrating electronic health records (EHR) to the cloud and must comply with HIPAA. They want to use cloud-native encryption but retain the ability to immediately revoke access to all encrypted data. Which key management strategy best meets this requirement?

A company needs to encrypt data in transit between its on-premises data center and a cloud virtual private cloud (VPC). They require a dedicated, encrypted tunnel with consistent throughput. Which solution should be used?

A cloud architect is designing key management for a multi-tenant SaaS application. The architect must ensure that each customer's encryption keys are isolated and that the cloud provider cannot access the keys. Which TWO key management strategies meet these requirements? (Select TWO.)

A financial institution is migrating to the cloud and must comply with regulations requiring that sensitive data be stored only in specific geographic regions and that access to data is logged and monitored. Which THREE controls should be implemented? (Select THREE.)

A security analyst is reviewing a cloud storage bucket that contains archived customer records. The analyst wants to ensure that no object in the bucket can be modified or deleted for 7 years to meet regulatory retention requirements. Which TWO features should be enabled? (Select TWO.)

A cloud architect is designing a secure data sharing mechanism for a third-party partner. The partner needs temporary access to download a specific object from a private cloud storage bucket, but should not have broader access to the bucket. Which approach should be used?

An organization uses a cloud storage service with versioning enabled. They discover that a ransomware attack encrypted all current versions of their files. However, they can still recover the data. Which feature protects them?

An organization uses a cloud DLP API to scan data in Cloud Storage and BigQuery for sensitive information. They need to replace social security numbers (SSNs) with a non-reversible token that can be used for consistent mapping without exposing the original SSN. Which de-identification technique should they use?

A cloud security architect is designing a key management strategy for a multi-cloud environment. They want to ensure that encryption keys are generated and stored on-premises but can be used by cloud services for encryption operations. Which two key management models meet these requirements? (Choose two.)

An organization is designing a data residency strategy for compliance with data sovereignty laws. They must ensure that customer data remains within specific geographic boundaries. Which three measures should they implement? (Choose three.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Cloud Data Security sessions

Start a Cloud Data Security only practice session

Every question in these sessions is drawn from the Cloud Data Security domain — nothing else.

Related practice questions

Related CCSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CCSP exam test about Cloud Data Security?
Be able to map a stated data protection requirement to the exact control: key custody model, scoped time-bound access, or region restriction. The single most important thing is identifying who owns and can revoke the encryption key, since that decides most answers.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Cloud Data Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Cloud Data Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CCSP topics?
Use the topic links above to move to related areas, or go back to the CCSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CCSP exam covers. They are not copied from any real exam or dump site.