CCSK Cloud Data Security and Governance 1 — Questions and Answers
Question 1: According to CCSK, what is the recommended approach for classifying data before moving it to the cloud?
- Classify data based on cost to store
- Classify data by its sensitivity level and regulatory requirements before migration (Correct answer)
- Classify data by file size and format only
- Classify data after migration is complete
Correct answer: Classify data by its sensitivity level and regulatory requirements before migration
Data should be classified by sensitivity and regulatory requirements before cloud migration to ensure appropriate controls are applied.
Question 2: What is 'data remanence' and why is it a concern in cloud environments?
- Data that persists on storage media after deletion, potentially exposing residual information (Correct answer)
- Data that is replicated across multiple cloud regions
- Data that remains encrypted during processing
- Data that is retained for compliance archiving
Correct answer: Data that persists on storage media after deletion, potentially exposing residual information
Data remanence refers to residual data left on storage after deletion, which is a concern in cloud because customers often cannot verify physical media sanitization.
Question 3: Which encryption approach does CCSK recommend to maintain control of data even when stored in a cloud provider's infrastructure?
- Provider-managed encryption with default keys
- Customer-managed encryption keys (CMEK) where the customer holds the keys (Correct answer)
- No encryption for publicly accessible data
- Encryption only during transmission
Correct answer: Customer-managed encryption keys (CMEK) where the customer holds the keys
Using customer-managed encryption keys ensures the customer retains control of data access even if the provider's environment is compromised.
Question 4: What is 'data sovereignty' in the context of CCSK cloud security?
- A cloud provider's right to use customer data for analytics
- The legal principle that data is subject to the laws of the country where it is stored (Correct answer)
- A customer's right to delete their data at any time
- The ability to encrypt data across international borders
Correct answer: The legal principle that data is subject to the laws of the country where it is stored
Data sovereignty means stored data is governed by the laws and regulations of the jurisdiction where the data physically resides.
Question 5: In CCSK, what is the primary function of a Data Loss Prevention (DLP) tool in cloud environments?
- To back up data to multiple cloud regions
- To detect and prevent unauthorized transfer or exposure of sensitive data (Correct answer)
- To encrypt all data stored in the cloud
- To monitor cloud provider uptime and availability
Correct answer: To detect and prevent unauthorized transfer or exposure of sensitive data
DLP tools identify sensitive data and enforce policies to prevent its unauthorized exfiltration or exposure in cloud environments.
Question 6: What does CCSK recommend as a key control for data stored in object storage (e.g., S3 buckets)?
- Leave buckets public by default for performance
- Enable versioning and enforce bucket policies restricting public access (Correct answer)
- Store all objects without encryption for faster retrieval
- Grant all IAM users read/write access by default
Correct answer: Enable versioning and enforce bucket policies restricting public access
Object storage should have public access blocked, versioning enabled, and bucket policies enforcing least-privilege access to prevent data exposure.
According to CCSK, what is the recommended approach for classifying data before moving it to the cloud?