CCSP Cloud Data Security: 300 practice questions
12 of the 300 Cloud Data Security questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CCSP? Take the free 5-min readiness check →
1. Apply information-rights protection to the downloaded: Which control is most appropriate?
- Delete the investigator’s consortium account so the original repository can no longer authorize access.Deprovisioning can stop new repository access, but it cannot reliably revoke downloaded content without rights-aware enforcement.
- Block outbound network traffic from investigator workstations to restrict further file use.Network restrictions may limit connectivity but do not themselves enforce rights on files already downloaded for offline use.
- Apply information-rights protection to the downloaded files. ✓Information-rights protection can bind permissions to protected content and, through supported clients, enforce identity, license, or key checks after download.
- Encrypt the storage bucket that contains the consortium’s original research files.Bucket encryption protects the source storage location but does not govern copies already downloaded to investigator systems.
Information-rights controls can enforce permissions on downloaded content through supported clients.
2. Preserve the hash and record acquisition plus each custody: Which evidence characteristic most directly suppor
- Document the provider facility, replicated region, and storage tier where the record was retained.Location and storage details provide context but do not establish the record’s cryptographic integrity or custody history.
- Rotate the administrator’s credentials and retain the event record in replicated storage after collection.Credential rotation may reduce further risk and replication may improve availability, but neither action establishes evidence integrity or chain of custody.
- Record the event timestamp and timezone.Time information helps correlate events, but it does not by itself verify integrity or document how evidence was handled.
- Preserve the hash and record acquisition plus each custody transfer. ✓A cryptographic hash supports consistency verification, while acquisition details and custody transfers document how the evidence was collected and handled.
Hashes plus documented acquisition and custody transfers support evidence integrity verification.
3. Enforce server-side authorization for each requested: Which action is most appropriate?
- Encrypt all objects with customer-managed keys.Encryption can protect confidentiality but does not decide whether a caller may modify a particular object.
- Require users to connect through the corporate network.Network restrictions do not prevent an authorized same-tenant user from bypassing object-level checks.
- Enforce server-side authorization for each requested object and action. ✓The application must verify the requester’s authority for the specific object and operation on the server.
- Move the objects from object storage to block volumes.Changing storage technology does not make the application validate object ownership or permitted actions.
Use server-side checks for the specific object and requested action.
4. Validate schema: Select TWO controls that correctly represent those categories.
Select two. More than one option is correct — every correct one is ticked below.
- Remove the original filename after upload completion and record the renamed object.Changing or recording metadata after upload does not validate data at creation or control how it is used later.
- Validate schema, classification, and purpose as data enters the service. ✓These checks operate when data is created or ingested, establishing acceptable structure and handling context.
- Replicate every object to another region before allowing downstream processing.Replication supports resilience or availability, but it does not validate data at creation or govern how authorized users access it.
- Rotate the encryption key after the retention period ends, regardless of whether the data remains needed.Key rotation may support cryptographic management, but it is neither the required creation-time validation nor the required use-time access control.
- Enforce authorization and masking whenever an application accesses the data. ✓Authorization and masking govern who may use data and what representation is presented during use.
Creation controls validate incoming data; use controls govern access and presentation.
5. Legal counsel decides whether to suspend deletion: Who is accountable for deciding whether scheduled deletion
- The cloud provider decides because it performs deletion.The provider may execute authorized instructions but does not determine the customer’s litigation obligations.
- Legal counsel decides whether to suspend deletion. ✓Counsel determines the legal hold’s scope and whether it conflicts with scheduled deletion.
- The privacy officer decides because retention policy governs all records.The privacy officer manages routine retention policy, but that role does not define the scope of the litigation hold.
- The storage administrator decides based on capacity and system timing.Capacity and scheduling information cannot determine which records must be preserved under the legal notice.
Legal counsel determines the hold’s scope and whether deletion must pause.
6. Customer inventories and classifies tables and exports: An exhibit records: “Customer scans tables monthly; pr
- Customer inventories and classifies tables and exports; provider evidences service-controlled copies. ✓This assigns content classification to the customer while requiring provider evidence for snapshots and other controlled copies.
- Treat provider snapshot inventory as sufficient evidence that all customer exports are discovered.Snapshot inventory does not establish discovery of customer-created exports outside the provider-managed snapshot process.
- Require the provider to classify every customer column and determine its business sensitivity.The customer owns classification decisions; the provider can supply inventory and operational evidence for service-controlled copies.
- Ask the provider to scan only database filenames because extensions identify sensitive structured data.Structured classification depends on content, context, and ownership rather than names or extensions alone.
The customer classifies data; the provider must evidence discovery of copies within its operational boundary.
7. The data owner sets classification and access requirements: Who should resolve the classification conflict and
- The custodian sets classification after configuring database permissions.Custodians implement handling controls but normally do not decide the data’s business classification.
- The dispatch supervisor decides because operational access determines practical business value.Operational knowledge informs the decision, but authority remains with the designated data owner.
- The data owner sets classification and access requirements. ✓The data owner decides classification and access requirements, balancing operational use against security obligations.
- The cloud provider decides because it controls the hosted storage platform.Infrastructure control does not transfer the customer’s governance authority over its information.
The designated data owner resolves classification and access requirements; custodians implement the resulting controls.
8. Reject the exception: What is the appropriate decision?
- Approve it after restricting the provider key to encryption operations.Restricting usage does not satisfy the required separate keys and restricted key administration boundaries.
- Reject the exception; retain separate keys and audited rotation. ✓The proposed design removes explicitly required separation and rotation controls without an authorized basis for exception.
- Use hashing instead and document the operational exception.Hashing cannot provide recoverable confidentiality for media and does not satisfy the stated encryption requirements.
- Approve it with symmetric encryption and quarterly access reviews.Additional reviews do not replace the policy’s required separation of data-encryption and key-encryption keys.
Reject the unjustified exception and preserve the required key boundaries.
9. Differential privacy bounds designed privacy loss: Which statement identifies the residual limitation?
- Removing names prevents proof of training membership.Removing direct identifiers does not establish that a record was absent or prevent linkage through other information.
- Differential privacy bounds designed privacy loss; it does not prove nonmembership. ✓Differential privacy provides a formal bounded guarantee under its design and privacy budget, not certainty that a particular record was excluded.
- Differential privacy guarantees that sensitive attributes cannot be inferred.It does not provide universal zero leakage or perfect prevention of every inference under all conditions.
- Encrypting the model proves the record was never processed during training.Encryption protects data or computation in some designs but does not establish dataset membership or exclusion.
Differential privacy bounds privacy loss but cannot prove an individual record was excluded.
10. Offline revocation cannot guarantee removal of already: What conclusion is supported?
- The 14-day license guarantees confidentiality after a recipient prints the document.License expiry may constrain supported clients but cannot undo screenshots, prints, or already exported plaintext.
- Revocation immediately deletes every downloaded copy from recipient devices.Offline clients cannot receive immediate policy changes, and rights management cannot retrieve existing plaintext or prints.
- Offline revocation cannot guarantee removal of already downloaded plaintext or printed copies. ✓Rights enforcement depends on client behavior and reconnection, while exported plaintext and prints may remain outside enforcement.
- Storage encryption ensures revoked recipients cannot read plaintext they already downloaded.Storage encryption does not automatically control authorized users possessing decrypted downloaded content.
Offline checks and exported copies limit what information-rights revocation can guarantee.
11. Configure and validate tenant-scoped event fields before: Before the next investigation, which action most dir
- Collect a provider snapshot because snapshots automatically contain complete audit history.A snapshot has defined scope and does not automatically include application, network, or historical audit records.
- Hash the existing events to create missing tenant attribution.Hashing detects subsequent changes but cannot reconstruct identifiers absent from the original event data.
- Obtain other tenants’ events to compare likely event patterns.Collection must remain authorized and tenant-scoped; unrelated tenant data creates privacy and evidentiary problems.
- Configure and validate tenant-scoped event fields before relying on the logs. ✓Tenant identifiers are necessary to associate events with the correct customer scope during collection and analysis.
Tenant identifiers must exist and be validated before audit events can reliably support tenant-specific investigations.
12. The lifecycle process lacks verified sanitization coverage: What control gap is demonstrated?
- The lifecycle process lacks verified sanitization coverage for retained copies. ✓Deleting files and detaching volumes do not address provider-held snapshots, replicas, and backups requiring suitable verified sanitization.
- The group needs more replication because replicas provide stronger historical recovery.Replication improves availability but can preserve deleted or corrupted data and does not sanitize retained copies.
- The group should overwrite only the detached volume because provider copies mirror deletion.Provider snapshots, replicas, and backups may have separate lifecycle behavior and require explicit coverage and evidence.
- The group needs filesystem encryption because block volumes cannot support encryption.Block storage can use encryption, but encryption alone does not prove destruction of retained copies or keys.
File deletion and detachment leave retained provider copies outside the demonstrated sanitization process.
288 more Cloud Data Security questions
The remaining 288 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CCSP readiness — freeOther CCSP domains
- Cloud Concepts, Architecture and Design — 255 questions →
- Cloud Platform and Infrastructure Security — 255 questions →
- Cloud Security Operations — 255 questions →
- Cloud Application Security — 240 questions →
- Legal, Risk and Compliance — 195 questions →
- All 1500 CCSP questions →
- CCSP certification: requirements, cost and exam format →