ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A financial services company must retain compliance audit logs for seven years in write-once-read-many (WORM) form. After the first 30 days, the logs are rarely accessed and the firm wants to minimize storage cost without sacrificing durability. Which cloud-native design best satisfies these requirements?
Export the logs to a managed NFS file share replicated across regions using active-active sync.
Store the logs in object storage with an immutable (object-lock) policy and a lifecycle rule that moves objects to the provider's archival tier after 30 days.
Place the logs on encrypted, multi-zone replicated block volumes configured for continuous incremental backups.
Write the logs to high-performance ephemeral SSD attached to each compute instance and take daily snapshots to another region.
Most public-cloud object storage platforms (for example, AWS S3, Azure Blob, GCP Cloud Storage) support an "object lock" or "immutable blob" feature that enforces WORM retention. When combined with a lifecycle policy that automatically transitions data to a cold or archival tier after 30 days, the data remains immutable for the required period, enjoys very high durability (often eleven nines), and costs are reduced because long-term data sits on lower-priced archival media.
Ephemeral instance storage is deleted on VM stop or failure, so it cannot satisfy any retention requirement. Block volumes-even if encrypted and replicated-do not offer native WORM controls and are usually more expensive for infrequently accessed data. Managed file shares provide POSIX/NFS semantics but likewise lack integrated WORM enforcement and low-cost archival tiers. Therefore, immutable object storage with lifecycle transition is the only option that meets all constraints.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are WORM retention policies in cloud storage?
Open an interactive chat with Bash
What is a lifecycle rule in cloud storage?
Open an interactive chat with Bash
How does durability differ across storage tiers in cloud platforms?
Open an interactive chat with Bash
What is object storage and how does it support WORM compliance?
Open an interactive chat with Bash
What is a lifecycle policy in cloud storage, and how does transitioning data to archival tiers reduce costs?
Open an interactive chat with Bash
Why do block volumes and managed file shares fail to meet WORM compliance or cost-efficiency for long-term retention?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .