Cloud Data Security Flashcards
6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Data Security flashcards as text
Which data security technique ensures that data remains protected even if the storage medium is stolen?
Answer: Encryption at rest
Encryption at rest protects data stored on physical media by rendering it unreadable without the correct decryption key.
What is the primary purpose of data classification in a cloud environment?
Answer: To assign appropriate security controls based on sensitivity
Data classification categorizes data by sensitivity so that the appropriate security controls can be applied to each category.
In cloud data security, what does IRM (Information Rights Management) primarily protect?
Answer: Documents and files after they leave the organization
IRM enforces usage policies on documents and files so that access controls follow the content even outside the organization's perimeter.
Which technique replaces sensitive data with a non-sensitive substitute that retains the format but has no exploitable value?
Answer: Tokenization
Tokenization substitutes sensitive data values with random tokens that are meaningless to an attacker but can be reverse-mapped via a secure vault.
What is data sovereignty in the context of cloud storage?
Answer: The principle that data is subject to the laws of the country in which it is stored
Data sovereignty means that stored data is governed by the legal jurisdiction of the country where the physical storage resides.
Which CCSP domain specifically addresses the security of data stored, processed, and transmitted in the cloud?
Answer: Cloud Data Security
Cloud Data Security is Domain 2 of the CCSP CBK and focuses on data lifecycle management, storage, retention, and protection.