ISC2 Certified Cloud Security Professional (CCSP) Practice Question
An e-commerce company is refactoring its order-processing application to run on containers in a public IaaS provider. Corporate policy requires adherence to the cloud secure data lifecycle and the ability to recover the workload if an entire region fails. Which design approach best meets both requirements while minimizing vendor lock-in?
Encrypt data at rest with customer-managed keys and implement cross-region asynchronous replication plus point-in-time restore for all datasets.
Use provider-managed server-side encryption and rely only on multiple availability zones inside the primary region for redundancy.
Deploy network firewalls and a web application firewall but store all application data unencrypted in object storage within the same region.
Run the service in an active-active configuration across two availability zones and disable snapshot backups to reduce storage costs.
Encrypting data at rest with customer-managed keys enforces ownership and control through every phase of the secure data lifecycle. Combining that encryption with cross-region asynchronous replication of databases, object storage, and backups - together with point-in-time restore - provides a tested recovery path should the primary region become unavailable. The other options leave either the encryption responsibility with the provider (limiting control), keep all copies in a single region, store data in clear text, or eliminate backups entirely; none of these satisfy both the lifecycle security requirement and regional disaster recovery objective.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the cloud secure data lifecycle?
Open an interactive chat with Bash
What is cross-region asynchronous replication and why is it important?
Open an interactive chat with Bash
What are customer-managed keys and why are they important?
Open an interactive chat with Bash
What is the cloud secure data lifecycle?
Open an interactive chat with Bash
What is cross-region asynchronous replication?
Open an interactive chat with Bash
Why use customer-managed keys instead of provider-managed keys?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .