Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Cloud Security Professional

Domain 2Objective 3

Design and Apply Data Security Technologies and Strategies CCSP Practice Questions (Page 4)

Part of the Cloud Data Security domain, which accounts for 20% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~14–24 in this domain), expect 2–3 from this objective — we provide 36 practice questions to prepare you well beyond it. (estimate)

36questions here
8free pages
12concepts
20%of the exam

Questions 16–20

  1. 16application · medium

    A company's DLP solution flags a large number of false positives because it detects the word 'confidential' in routine internal documents. The security team wants to reduce false positives while still detecting genuinely sensitive data such as social security numbers and bank account numbers. Which configuration change should the team make?

    Select an answer first
  2. 17application · medium

    A company needs to encrypt data in a cloud object storage service. The security team is evaluating whether to use a cloud-provider-managed key or a customer-managed key. The company has a compliance requirement to control and rotate the encryption keys independently of the cloud provider. Which option should the company choose?

    Select an answer first
  3. 18application · medium

    A law firm sends settlement agreements to clients through a cloud-based document portal. A client later disputes the terms, claiming the firm altered the document after it was signed. The firm needs to prove that the document was not modified and that it originated from the firm. Which combination of technologies should the firm use?

    Select an answer first
  4. 19application · medium

    A marketing analytics company collects customer behavior data and wants to share it with a third-party research firm for aggregate trend analysis. The data includes email addresses, postal codes, and purchase histories. The company must ensure that individual customers cannot be re-identified from the shared dataset. Which approach should the company take?

    Select an answer first
  5. 20foundation · easy

    A cloud architect is selecting an encryption algorithm to protect data at rest in a cloud object storage service. The requirement is for a widely supported, symmetric algorithm that provides strong security with a 256-bit key. Which algorithm best meets this requirement?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.