ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A healthcare provider stores electronic health records on encrypted block storage volumes in an IaaS environment. Regulatory policy requires that no residual data be recoverable once a volume is deleted and the underlying physical drives are re-provisioned to other tenants. Which data sanitization method should the cloud customer contractually require the provider to perform to meet this requirement with the least operational overhead?
File-level deletion of the records using standard operating system commands within the virtual machine
Disabling the storage device's TRIM command before deleting the files
Cryptographic erasure by destroying the volume's encryption key in the provider's key management system
A single-pass zero overwrite of the logical volume initiated from the guest operating system
Cryptographic erasure (also called crypto-shredding) renders data unreadable by permanently destroying the only copy of the encryption key that protects the stored information. Because the ciphertext on the drives cannot be decrypted without the key, the data is considered sanitized even if the physical media are later reused. Guest-level file deletion or a single-pass overwrite from within the VM do not affect data remnants that reside outside the virtual machine's view, and disabling TRIM does nothing to remove existing data. Therefore, requiring the provider to perform cryptographic erasure best satisfies the regulatory mandate while imposing minimal operational impact.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is cryptographic erasure?
Open an interactive chat with Bash
Why is cryptographic erasure better than file-level deletion or single-pass overwrite?
Open an interactive chat with Bash
What does TRIM do, and why is disabling it ineffective for data sanitization?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .