Courseiva
hardMultiple SelectObjective-mapped

CCSP Practice Question: Which THREE of the following are key components…

Which THREE of the following are key components of a cloud data governance framework?

⚠ Common exam trap

ISC2 often tests the distinction between governance components (policies, roles, processes) and technical security controls (encryption, masking), leading candidates to mistakenly select data masking or encryption as governance framework elements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data retention policies

Data retention policies are a key component of a cloud data governance framework because they define the lifecycle of data, specifying how long data must be kept and when it should be securely deleted. This ensures compliance with legal, regulatory, and business requirements, such as GDPR or HIPAA, and prevents unnecessary storage costs and security risks from outdated data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data retention policies

    Why this is correct

    Policies define how long data is kept and when to delete.

  • Data access controls

    Why this is correct

    Access controls enforce who can access data.

  • Data masking

    Why it's wrong here

    Masking is a technique to protect sensitive data, not a governance component.

  • Data classification

    Why this is correct

    Classifying data based on sensitivity is fundamental to governance.

  • Data encryption at rest

    Why it's wrong here

    Encryption is a security control, not a governance component.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.