CCSP Cloud Data Security: 300 practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

CCSP Cloud Data Security: 300 practice questions

CCSP 300 questions 12 shown free

12 of the 300 Cloud Data Security questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for CCSP? Take the free 5-min readiness check →

1. Apply information-rights protection to the downloaded: Which control is most appropriate?

Medium
A university research consortium permits investigators to download protected study files for offline analysis. An investigator’s authorization is later withdrawn, but downloaded files remain usable without contacting the consortium. The consortium needs a control addressing rights after download, while recognizing that screenshots and exported plaintext cannot necessarily be undone. Which control is most appropriate?
  1. Delete the investigator’s consortium account so the original repository can no longer authorize access.
    Deprovisioning can stop new repository access, but it cannot reliably revoke downloaded content without rights-aware enforcement.
  2. Block outbound network traffic from investigator workstations to restrict further file use.
    Network restrictions may limit connectivity but do not themselves enforce rights on files already downloaded for offline use.
  3. Apply information-rights protection to the downloaded files. ✓
    Information-rights protection can bind permissions to protected content and, through supported clients, enforce identity, license, or key checks after download.
  4. Encrypt the storage bucket that contains the consortium’s original research files.
    Bucket encryption protects the source storage location but does not govern copies already downloaded to investigator systems.
The trap
Confuses network control with content-level rights enforcement. Applies at-rest protection to the wrong copy. Assumes source-account removal controls existing copies.

Information-rights controls can enforce permissions on downloaded content through supported clients.

2. Preserve the hash and record acquisition plus each custody: Which evidence characteristic most directly suppor

Medium
An energy company’s incident team must verify whether a privileged user modified a production object. The provider supplies an event record containing actor identity, object identifier, action, timestamp with timezone, acquisition method, and hash. Which evidence characteristic most directly supports verifying event integrity and chain of custody?
  1. Document the provider facility, replicated region, and storage tier where the record was retained.
    Location and storage details provide context but do not establish the record’s cryptographic integrity or custody history.
  2. Rotate the administrator’s credentials and retain the event record in replicated storage after collection.
    Credential rotation may reduce further risk and replication may improve availability, but neither action establishes evidence integrity or chain of custody.
  3. Record the event timestamp and timezone.
    Time information helps correlate events, but it does not by itself verify integrity or document how evidence was handled.
  4. Preserve the hash and record acquisition plus each custody transfer. ✓
    A cryptographic hash supports consistency verification, while acquisition details and custody transfers document how the evidence was collected and handled.
The trap
Treats temporal context as provenance. Confuses hosting context with forensic provenance. Combines incident remediation and availability with evidence handling.

Hashes plus documented acquisition and custody transfers support evidence integrity verification.

3. Enforce server-side authorization for each requested: Which action is most appropriate?

Medium
A cloud migration team discovers that an application authorizes storage access using only a tenant identifier. A same-tenant user can modify another customer’s object by changing its object identifier in an API request. The team must remediate the failed authorization test. Which action is most appropriate?
  1. Encrypt all objects with customer-managed keys.
    Encryption can protect confidentiality but does not decide whether a caller may modify a particular object.
  2. Require users to connect through the corporate network.
    Network restrictions do not prevent an authorized same-tenant user from bypassing object-level checks.
  3. Enforce server-side authorization for each requested object and action. ✓
    The application must verify the requester’s authority for the specific object and operation on the server.
  4. Move the objects from object storage to block volumes.
    Changing storage technology does not make the application validate object ownership or permitted actions.
The trap
Network location cannot replace object authorization. Storage type does not establish authorization. Encryption does not fix object-level authorization.

Use server-side checks for the specific object and requested action.

4. Validate schema: Select TWO controls that correctly represent those categories.

Easy
An online retailer is defining controls for customer data across its lifecycle. The design must include one creation-time control and one use-time control. Select TWO controls that correctly represent those categories.

Select two. More than one option is correct — every correct one is ticked below.

  1. Remove the original filename after upload completion and record the renamed object.
    Changing or recording metadata after upload does not validate data at creation or control how it is used later.
  2. Validate schema, classification, and purpose as data enters the service. ✓
    These checks operate when data is created or ingested, establishing acceptable structure and handling context.
  3. Replicate every object to another region before allowing downstream processing.
    Replication supports resilience or availability, but it does not validate data at creation or govern how authorized users access it.
  4. Rotate the encryption key after the retention period ends, regardless of whether the data remains needed.
    Key rotation may support cryptographic management, but it is neither the required creation-time validation nor the required use-time access control.
  5. Enforce authorization and masking whenever an application accesses the data. ✓
    Authorization and masking govern who may use data and what representation is presented during use.
The trap
Confuses a resilience measure with creation-time or use-time control. Confuses metadata handling with lifecycle control. Treats delayed key management as a creation or use control.

Creation controls validate incoming data; use controls govern access and presentation.

5. Legal counsel decides whether to suspend deletion: Who is accountable for deciding whether scheduled deletion

Medium
An insurance business receives a litigation notice covering a customer-data repository. Its retention schedule would delete several records next week, but the legal department has not yet defined which records fall within the notice. The privacy officer manages retention policy, while legal counsel owns litigation decisions. Who is accountable for deciding whether scheduled deletion must be suspended?
  1. The cloud provider decides because it performs deletion.
    The provider may execute authorized instructions but does not determine the customer’s litigation obligations.
  2. Legal counsel decides whether to suspend deletion. ✓
    Counsel determines the legal hold’s scope and whether it conflicts with scheduled deletion.
  3. The privacy officer decides because retention policy governs all records.
    The privacy officer manages routine retention policy, but that role does not define the scope of the litigation hold.
  4. The storage administrator decides based on capacity and system timing.
    Capacity and scheduling information cannot determine which records must be preserved under the legal notice.
The trap
Technical execution is not legal decision ownership. Routine retention policy does not resolve litigation scope. Operational constraints do not establish legal authority.

Legal counsel determines the hold’s scope and whether deletion must pause.

6. Customer inventories and classifies tables and exports: An exhibit records: “Customer scans tables monthly; pr

Hard
A managed database provider hosts customer tables and automated snapshots. The contract says the customer classifies content, while the provider operates service-controlled copies. An exhibit records: “Customer scans tables monthly; provider supplies snapshot inventory quarterly; exports are not inventoried.” What action best resolves the responsibility boundary?
  1. Customer inventories and classifies tables and exports; provider evidences service-controlled copies. ✓
    This assigns content classification to the customer while requiring provider evidence for snapshots and other controlled copies.
  2. Treat provider snapshot inventory as sufficient evidence that all customer exports are discovered.
    Snapshot inventory does not establish discovery of customer-created exports outside the provider-managed snapshot process.
  3. Require the provider to classify every customer column and determine its business sensitivity.
    The customer owns classification decisions; the provider can supply inventory and operational evidence for service-controlled copies.
  4. Ask the provider to scan only database filenames because extensions identify sensitive structured data.
    Structured classification depends on content, context, and ownership rather than names or extensions alone.
The trap
Uses metadata alone to classify structured information. Assumes one inventory covers separately created copies. Confuses provider operation with customer ownership of classification.

The customer classifies data; the provider must evidence discovery of copies within its operational boundary.

7. The data owner sets classification and access requirements: Who should resolve the classification conflict and

Medium
A logistics operator stores shipment addresses, driver identity records, and route telemetry. Operations wants broad access for dispatch efficiency, while security requires tighter handling for identity records. The organization names a data owner for each dataset and custodians for platform administration. Who should resolve the classification conflict and set access requirements?
  1. The custodian sets classification after configuring database permissions.
    Custodians implement handling controls but normally do not decide the data’s business classification.
  2. The dispatch supervisor decides because operational access determines practical business value.
    Operational knowledge informs the decision, but authority remains with the designated data owner.
  3. The data owner sets classification and access requirements. ✓
    The data owner decides classification and access requirements, balancing operational use against security obligations.
  4. The cloud provider decides because it controls the hosted storage platform.
    Infrastructure control does not transfer the customer’s governance authority over its information.
The trap
Confuses hosting control with data ownership. Treats operational proximity as formal ownership. Confuses implementation responsibility with governance authority.

The designated data owner resolves classification and access requirements; custodians implement the resulting controls.

8. Reject the exception: What is the appropriate decision?

Easy
A media platform policy requires separate data-encryption keys and key-encryption keys, restricted key administration, and auditable rotation. A team requests an exception to use one provider-managed key for all media because it simplifies operations. No outage, legal requirement, or authorized compensating control justifies the exception. What is the appropriate decision?
  1. Approve it after restricting the provider key to encryption operations.
    Restricting usage does not satisfy the required separate keys and restricted key administration boundaries.
  2. Reject the exception; retain separate keys and audited rotation. ✓
    The proposed design removes explicitly required separation and rotation controls without an authorized basis for exception.
  3. Use hashing instead and document the operational exception.
    Hashing cannot provide recoverable confidentiality for media and does not satisfy the stated encryption requirements.
  4. Approve it with symmetric encryption and quarterly access reviews.
    Additional reviews do not replace the policy’s required separation of data-encryption and key-encryption keys.
The trap
A review schedule is not equivalent to key separation. A narrower privilege does not create separate key roles. Hashing is not a replacement for media encryption.

Reject the unjustified exception and preserve the required key boundaries.

9. Differential privacy bounds designed privacy loss: Which statement identifies the residual limitation?

Medium
A digital payments company uses differential privacy before releasing analytics from a training dataset. An assessor asks whether the published model proves that a particular customer record was absent from training. Which statement identifies the residual limitation?
  1. Removing names prevents proof of training membership.
    Removing direct identifiers does not establish that a record was absent or prevent linkage through other information.
  2. Differential privacy bounds designed privacy loss; it does not prove nonmembership. ✓
    Differential privacy provides a formal bounded guarantee under its design and privacy budget, not certainty that a particular record was excluded.
  3. Differential privacy guarantees that sensitive attributes cannot be inferred.
    It does not provide universal zero leakage or perfect prevention of every inference under all conditions.
  4. Encrypting the model proves the record was never processed during training.
    Encryption protects data or computation in some designs but does not establish dataset membership or exclusion.
The trap
Identifier removal is not proof of anonymity or nonmembership. Confidentiality protection is not provenance evidence. A bounded guarantee is not absolute noninference.

Differential privacy bounds privacy loss but cannot prove an individual record was excluded.

10. Offline revocation cannot guarantee removal of already: What conclusion is supported?

Easy
A public agency’s information-rights record states: “Downloaded documents may be opened offline for 14 days. Revocation is checked when the client reconnects. Recipients may print.” Management asks whether revoking a user immediately guarantees that previously downloaded plaintext is no longer usable. What conclusion is supported?
  1. The 14-day license guarantees confidentiality after a recipient prints the document.
    License expiry may constrain supported clients but cannot undo screenshots, prints, or already exported plaintext.
  2. Revocation immediately deletes every downloaded copy from recipient devices.
    Offline clients cannot receive immediate policy changes, and rights management cannot retrieve existing plaintext or prints.
  3. Offline revocation cannot guarantee removal of already downloaded plaintext or printed copies. ✓
    Rights enforcement depends on client behavior and reconnection, while exported plaintext and prints may remain outside enforcement.
  4. Storage encryption ensures revoked recipients cannot read plaintext they already downloaded.
    Storage encryption does not automatically control authorized users possessing decrypted downloaded content.
The trap
Treats license expiry as universal content control. Assumes remote deletion of offline and exported content. Confuses storage protection with post-download rights enforcement.

Offline checks and exported copies limit what information-rights revocation can guarantee.

11. Configure and validate tenant-scoped event fields before: Before the next investigation, which action most dir

Easy
A telecommunications operator has contractual authority to obtain provider audit events during incidents. Its incident procedure already defines retention, permissions, and a designated evidence custodian, but current events lack tenant identifiers. Before the next investigation, which action most directly addresses the remaining prerequisite?
  1. Collect a provider snapshot because snapshots automatically contain complete audit history.
    A snapshot has defined scope and does not automatically include application, network, or historical audit records.
  2. Hash the existing events to create missing tenant attribution.
    Hashing detects subsequent changes but cannot reconstruct identifiers absent from the original event data.
  3. Obtain other tenants’ events to compare likely event patterns.
    Collection must remain authorized and tenant-scoped; unrelated tenant data creates privacy and evidentiary problems.
  4. Configure and validate tenant-scoped event fields before relying on the logs. ✓
    Tenant identifiers are necessary to associate events with the correct customer scope during collection and analysis.
The trap
Assumes point-in-time artifacts contain all history. Confuses integrity evidence with missing context. Expands collection beyond authorized scope.

Tenant identifiers must exist and be validated before audit events can reliably support tenant-specific investigations.

12. The lifecycle process lacks verified sanitization coverage: What control gap is demonstrated?

Hard
A regional hospital group decommissions block volumes after migrations. Administrators delete files and detach volumes, but provider records show snapshots, replicas, and backups remain under retention. The group’s requirement is to make patient data recovery infeasible before media reuse or disposal. What control gap is demonstrated?
  1. The lifecycle process lacks verified sanitization coverage for retained copies. ✓
    Deleting files and detaching volumes do not address provider-held snapshots, replicas, and backups requiring suitable verified sanitization.
  2. The group needs more replication because replicas provide stronger historical recovery.
    Replication improves availability but can preserve deleted or corrupted data and does not sanitize retained copies.
  3. The group should overwrite only the detached volume because provider copies mirror deletion.
    Provider snapshots, replicas, and backups may have separate lifecycle behavior and require explicit coverage and evidence.
  4. The group needs filesystem encryption because block volumes cannot support encryption.
    Block storage can use encryption, but encryption alone does not prove destruction of retained copies or keys.
The trap
Makes an incorrect storage-type assumption. Assumes deletion propagates to every copy. Confuses resilience with secure disposal.

File deletion and detachment leave retained provider copies outside the demonstrated sanitization process.

288 more Cloud Data Security questions

The remaining 288 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your CCSP readiness — free

Other CCSP domains

Part of the Certsqill CCSP question bank · Cloud Data Security · Every answer, right and wrong, comes with its own explanation.