ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A financial-services firm is moving customer analytics workloads to a multi-region public cloud. Because customer records contain personal data protected by GDPR, the security team must ensure that no dataset is ever created or copied outside of EU cloud regions. Which control provides the most effective and automatic enforcement of this requirement during the provisioning process?
Require administrators to manually tag every resource with the appropriate country code after deployment.
Enable object-lock or write-once-read-many (WORM) protection on all cloud storage buckets.
Apply IaC guardrail policies that block resource creation in regions outside the approved EU allow list.
Run periodic vulnerability scans that score resources with non-EU IP addresses.
Infrastructure-as-code (IaC) guardrails-such as service control policies, Azure Policy, or Terraform Sentinel rules-can validate deployment parameters before resources are created. By allowing only approved EU regions in the policy, any attempt to provision storage or databases elsewhere is rejected, preventing data from ever residing outside the EU. Object lock controls immutability, not geography; vulnerability scans occur after deployment and do not stop data placement; and manual tagging relies on human effort and is therefore error-prone and not truly automatic.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Infrastructure-as-Code (IaC)?
Open an interactive chat with Bash
What are IaC guardrails, and why are they important?
Open an interactive chat with Bash
How does GDPR impact data placement in the cloud?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .