โ† All CCSP Flashcard Decks

Cloud Data Security Flashcards

6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Data Security flashcards as text
  1. Which cloud storage type is best suited for unstructured data such as images, videos, and backups?

    Answer: Object storage

    Object storage is designed for unstructured data, storing items as objects with metadata and a unique identifier rather than in a hierarchical file system.

  2. What does a Data Loss Prevention (DLP) solution primarily do in a cloud environment?

    Answer: Monitors and controls the movement of sensitive data to prevent unauthorized exfiltration

    DLP solutions inspect and control data flows to detect and prevent the unauthorized transmission of sensitive information outside authorized boundaries.

  3. In the context of cloud data security, what is a data custodian responsible for?

    Answer: Implementing and managing the technical security controls that protect data

    The data custodian is responsible for the day-to-day management and technical protection of data as specified by the data owner.

  4. Which standard specifically provides guidance on personally identifiable information (PII) protection in public clouds?

    Answer: ISO/IEC 27018

    ISO/IEC 27018 is the code of practice specifically for protection of PII in public cloud computing environments.

  5. What is the key advantage of client-side encryption over server-side encryption in cloud storage?

    Answer: The cloud provider never has access to the plaintext data or encryption keys

    With client-side encryption, data is encrypted before it leaves the customer's environment, so the cloud provider can only ever see ciphertext.

  6. A company stores sensitive medical records in a cloud database. Which regulation primarily governs this data in the United States?

    Answer: HIPAA

    HIPAA (Health Insurance Portability and Accountability Act) governs the security and privacy of protected health information (PHI) in the US.