Cloud Data Security and Governance Flashcards
6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Data Security and Governance flashcards as text
What is 'egress filtering' and why is it important for cloud data security?
Answer: Monitoring and restricting outbound data flows to prevent unauthorized data exfiltration
Egress filtering monitors and controls outbound network traffic to prevent sensitive data from leaving the environment without authorization.
According to CCSK, what is a key challenge of applying traditional DRM (Digital Rights Management) in cloud environments?
Answer: DRM requires persistent connectivity to rights servers which can conflict with cloud availability patterns
Traditional DRM requires connection to rights servers to validate access, which can create availability and latency issues in distributed cloud environments.
What is the concept of 'data residency' and how does it differ from data sovereignty?
Answer: Data residency specifies where data is physically stored; data sovereignty refers to which laws govern it
Data residency defines the physical location where data is stored, while data sovereignty addresses which legal framework governs that data.
In CCSK, what is 'volume storage encryption' primarily used to protect against?
Answer: Unauthorized access to data if physical storage media is removed or accessed outside the system
Volume storage encryption protects data at rest so that raw access to the storage media yields no readable data without the encryption key.
What does CCSK say about the use of 'data masking' in non-production cloud environments?
Answer: Sensitive production data should be masked or anonymized before use in test or development environments
Non-production environments typically have weaker security controls, so sensitive data should be masked or synthesized to reduce exposure risk.
Which CCSK principle states that data should only be retained for as long as necessary for its intended purpose?
Answer: Data minimization and retention policies
Data minimization and retention policies require organizations to delete data when it is no longer needed, reducing risk and storage exposure.