Cloud Data Security and Governance Flashcards
6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Cloud Data Security and Governance flashcards as text
According to CCSK, what is the recommended approach for classifying data before moving it to the cloud?
Answer: Classify data by its sensitivity level and regulatory requirements before migration
Data should be classified by sensitivity and regulatory requirements before cloud migration to ensure appropriate controls are applied.
What is 'data remanence' and why is it a concern in cloud environments?
Answer: Data that persists on storage media after deletion, potentially exposing residual information
Data remanence refers to residual data left on storage after deletion, which is a concern in cloud because customers often cannot verify physical media sanitization.
Which encryption approach does CCSK recommend to maintain control of data even when stored in a cloud provider's infrastructure?
Answer: Customer-managed encryption keys (CMEK) where the customer holds the keys
Using customer-managed encryption keys ensures the customer retains control of data access even if the provider's environment is compromised.
What is 'data sovereignty' in the context of CCSK cloud security?
Answer: The legal principle that data is subject to the laws of the country where it is stored
Data sovereignty means stored data is governed by the laws and regulations of the jurisdiction where the data physically resides.
In CCSK, what is the primary function of a Data Loss Prevention (DLP) tool in cloud environments?
Answer: To detect and prevent unauthorized transfer or exposure of sensitive data
DLP tools identify sensitive data and enforce policies to prevent its unauthorized exfiltration or exposure in cloud environments.
What does CCSK recommend as a key control for data stored in object storage (e.g., S3 buckets)?
Answer: Enable versioning and enforce bucket policies restricting public access
Object storage should have public access blocked, versioning enabled, and bucket policies enforcing least-privilege access to prevent data exposure.