Courseiva
Cloud Application Security →mediumMultiple Select

CCSP Cloud Application Security Practice Question

Which TWO are effective strategies for securing cloud application data at rest?

⚠ Common exam trap

ISC2 often tests the distinction between access control (RBAC) and encryption, where candidates mistakenly think that restricting access is sufficient to secure data at rest, ignoring that encryption is required to protect against physical theft or unauthorized storage-level access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

File-level encryption

File-level encryption (C) is correct because it encrypts individual files or folders on disk, ensuring that data at rest remains unreadable even if the underlying storage or host is compromised. Transparent data encryption (D) is correct because it encrypts database files and backups at rest at the storage engine level, protecting data without requiring application changes. Both directly address the confidentiality of stored data, which is the core goal of securing data at rest. Role-based access control (A) governs who may access resources but does not itself encrypt stored data. Database activity monitoring (B) detects and alerts on suspicious database activity but is a detective control, not a data-at-rest protection. Network segmentation (E) limits lateral movement and exposure but does not protect data at rest on storage media.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Role-based access control

    Why it's wrong here

    Role-based access control governs who may invoke operations on data, not the cryptographic protection of stored objects; it does not render data unreadable if storage media or snapshots are exposed. It is tempting because it is a fundamental access control, and would be correct where the requirement is limiting which identities can read or modify a data store.

  • ✗

    Database activity monitoring

    Why it's wrong here

    Database activity monitoring observes and alerts on queries against a database; it detects suspicious access but leaves the underlying stored data in plaintext, so it does not secure data at rest. It is tempting because it is a genuine database security control, and would be correct where the requirement is auditing or detecting anomalous access patterns.

  • ✓

    File-level encryption

    Why this is correct

    File-level encryption protects data at rest per file or object, so each item carries its own cryptographic boundary independent of the storage volume. This satisfies the stem's at-rest requirement by securing data even when underlying storage, snapshots or backups are exposed, unlike volume-level controls.

  • ✓

    Transparent data encryption

    Why this is correct

    Transparent data encryption encrypts the database files and logs at rest beneath the DBMS, with keys managed separately and no application changes required. This satisfies the stem's at-rest requirement by protecting stored data and backups against media theft or unauthorised file access.

  • ✗

    Network segmentation

    Why it's wrong here

    Network segmentation limits lateral movement between workloads, but stored data remains readable once an attacker reaches the storage volume or snapshot. It is tempting because it is a valid defence-in-depth control, and would be correct where the requirement is containing blast radius or isolating tiers rather than protecting data at rest.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.