Free ISC2 Certified Cloud Security Professional (CCSP) practice — 6 questions on Cloud Data Security, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Cloud Data Security
A cloud customer stores highly sensitive tenant data on a multi-tenant object storage platform. At the end of the data's retention period, the customer must guarantee the data is permanently unrecoverable, but has no ability to physically access or destroy the underlying storage media (SSD arrays are shared across tenants and the CSP will not allow physical destruction requests). Which method BEST satisfies this secure-deletion requirement?
Crypto-shredding (cryptographic erasure) is the standard cloud-native secure deletion method: if data was encrypted with a unique key, destroying all copies of that key makes the remaining ciphertext computationally infeasible to recover, without needing physical access to shared media.
Question 2 of 6 · Cloud Data Security
A payment processing company must remove primary account numbers (PANs) from PCI DSS scope across its legacy batch-processing systems. The legacy systems require the field to retain the exact same length and numeric format as a real card number, and the actual PAN must never be reconstructable by systems outside a dedicated vault. Which data protection technique BEST meets these requirements?
Tokenization replaces the PAN with a surrogate value of identical format/length, with the mapping held only in a separate, tightly controlled token vault. Downstream systems that only ever handle the token are removed from PCI DSS scope, while legacy systems keep working unmodified.
Question 3 of 6 · Cloud Data Security
A financial regulator mandates that a specific class of encryption keys must NEVER be transmitted to, stored by, or become accessible in plaintext form to the cloud service provider, even temporarily. The organization still wants to leverage the CSP's compute services to process the encrypted data. Which key management model satisfies this requirement?
HYOK ensures key material physically never leaves the customer's own HSM. The CSP sends cryptographic operation requests to the external HSM (e.g., via KMIP or a proxy) and only ever receives the result, never the plaintext key itself — satisfying strict 'never accessible to the CSP' mandates.
Question 4 of 6 · Cloud Data Security
An enterprise distributes sensitive financial reports to external partners via email attachments and cloud file shares. Leadership requires that even after a file is downloaded and copied to a partner's personal USB drive or personal laptop, the document's access restrictions and expiration policy must still be enforced. Which capability must be configured to meet this requirement?
Information Rights Management (IRM) with persistent protection embeds encryption and the usage-rights policy directly into the file. Enforcement happens at open-time via the IRM client, independent of where the file is later copied or stored, satisfying the 'protection follows the data' requirement.
Question 5 of 6 · Cloud Data Security
Under GDPR-aligned data protection requirements, which de-identification technique results in output that is STILL classified as personal data because a separately maintained mapping allows the original identity to be recovered?
Pseudonymization specifically replaces identifiers with substitute values while retaining a separate mapping/key that allows re-identification. Because re-identification is possible, regulators (including GDPR) continue to treat pseudonymized data as personal data subject to full data protection obligations.
Question 6 of 6 · Cloud Data Security
An organization must present cloud infrastructure logs as evidence in a legal proceeding following a suspected breach in a shared IaaS environment. Opposing counsel is expected to challenge the integrity of the evidence. Which action BEST preserves a defensible chain of custody for these logs?
A defensible chain of custody requires demonstrable, verifiable integrity: hashing logs at the moment of collection proves they haven't been altered afterward, WORM storage prevents subsequent tampering, and a signed custody log documents every handler and transfer — meeting evidentiary standards for admissibility.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.