CCSP Cloud Application Security Practice Question
Which TWO are effective strategies for securing cloud application data at rest?
⚠ Common exam trap
ISC2 often tests the distinction between access control (RBAC) and encryption, where candidates mistakenly think that restricting access is sufficient to secure data at rest, ignoring that encryption is required to protect against physical theft or unauthorized storage-level access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
File-level encryption
File-level encryption (C) is correct because it encrypts individual files or folders on disk, ensuring that data at rest remains unreadable even if the underlying storage or host is compromised. Transparent data encryption (D) is correct because it encrypts database files and backups at rest at the storage engine level, protecting data without requiring application changes. Both directly address the confidentiality of stored data, which is the core goal of securing data at rest. Role-based access control (A) governs who may access resources but does not itself encrypt stored data. Database activity monitoring (B) detects and alerts on suspicious database activity but is a detective control, not a data-at-rest protection. Network segmentation (E) limits lateral movement and exposure but does not protect data at rest on storage media.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Role-based access control
Why it's wrong here
Role-based access control governs who may invoke operations on data, not the cryptographic protection of stored objects; it does not render data unreadable if storage media or snapshots are exposed. It is tempting because it is a fundamental access control, and would be correct where the requirement is limiting which identities can read or modify a data store.
- ✗
Database activity monitoring
Why it's wrong here
Database activity monitoring observes and alerts on queries against a database; it detects suspicious access but leaves the underlying stored data in plaintext, so it does not secure data at rest. It is tempting because it is a genuine database security control, and would be correct where the requirement is auditing or detecting anomalous access patterns.
- ✓
File-level encryption
Why this is correct
File-level encryption protects data at rest per file or object, so each item carries its own cryptographic boundary independent of the storage volume. This satisfies the stem's at-rest requirement by securing data even when underlying storage, snapshots or backups are exposed, unlike volume-level controls.
- ✓
Transparent data encryption
Why this is correct
Transparent data encryption encrypts the database files and logs at rest beneath the DBMS, with keys managed separately and no application changes required. This satisfies the stem's at-rest requirement by protecting stored data and backups against media theft or unauthorised file access.
- ✗
Network segmentation
Why it's wrong here
Network segmentation limits lateral movement between workloads, but stored data remains readable once an attacker reaches the storage volume or snapshot. It is tempting because it is a valid defence-in-depth control, and would be correct where the requirement is containing blast radius or isolating tiers rather than protecting data at rest.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.