ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A cloud security architect must ensure that each tenant's data stored in a multi-tenant SaaS platform can be checked for unauthorized modification at any time without requiring the platform operator to decrypt the data. Which of the following approaches best satisfies this requirement while minimizing computational overhead?

  • Append an MD5 checksum with a static salt to every file and periodically recalculate the value for comparison.

  • Calculate a SHA-256 digest of each object at upload and store the hash in a separate, tamper-evident metadata repository for later comparison.

  • Encrypt the files with AES-256 in Galois/Counter Mode so the authentication tag can be used to confirm integrity when needed.

  • Apply reversible Base64 encoding to each file and verify integrity by decoding and comparing sizes.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot