ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your company uses a SaaS collaboration platform to share sensitive design documents with external suppliers. The security team mandates that users must be prevented from printing or copying the files, their access must be revocable even after the files are downloaded, and suppliers should still be able to work offline for up to seven days. Which control best meets all of these requirements?
Enable server-side encryption with customer-managed keys for the storage bucket that contains the shared documents.
Turn on object versioning and MFA delete for the storage bucket to preserve prior versions and prevent unauthorized deletions.
Require TLS 1.2 for all sessions to the SaaS application to encrypt data in transit.
Implement a cloud-based Information Rights Management solution that embeds usage policies in each document and validates licenses when the file is opened.
Information Rights Management (IRM) embeds an encrypted wrapper and usage policy directly into each file. Every time a user opens the document, the application contacts a license (rights) server to verify current permissions; if the user account is disabled, the license request is denied and the local copy becomes unreadable, effectively revoking access. IRM policies can also include specific usage restrictions such as blocking print or copy operations and permitting a limited offline access window (for example, seven days) before the user must re-authenticate. TLS protects data only in transit, not after download. Server-side encryption with customer-managed keys safeguards data at rest but offers no post-download control. Object versioning with MFA delete aids recovery and tamper resistance but does not enforce usage restrictions or revocation on distributed copies.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Information Rights Management (IRM) in cloud security?
Open an interactive chat with Bash
How does IRM differ from server-side encryption?
Open an interactive chat with Bash
Why is TLS 1.2 insufficient for controlling file usage in this scenario?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .