ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is migrating customer records from several on-premises databases and shared file repositories into both AWS S3 and Azure Blob Storage. You are asked to design an automated cloud-native solution that will continuously discover and classify U.S. Social Security numbers and other personally identifiable information (PII) stored in CSV tables, PDF contracts, and image scans uploaded by users. Which approach best meets the requirement while keeping the number of missed detections (false negatives) to a minimum?
Scan all objects with a static library of regular expressions for U.S. Social Security numbers and other PII formats.
Deploy ML-based content inspection services in each cloud and add Exact Data Match lookups against a hashed reference dataset of known PII values.
Require storage administrators to tag every bucket and object with metadata that specifies whether it contains PII and run discovery jobs against the tags only.
Analyze VPC flow logs to flag any outbound traffic that matches known PII patterns, assuming data at rest will then be located.
Combining machine-learning (ML) content inspection with Exact Data Match (EDM)-style lookups provides two complementary detection methods. Supervised ML classifiers (such as those used by Amazon Macie or Microsoft Purview) can recognize patterns in a wide variety of structured, semi-structured, and unstructured objects, including text in PDFs and optical character recognition of images. EDM adds deterministic matching against a hashed reference set of real customer data, dramatically reducing false negatives that pure pattern matching could miss. Relying only on regular expressions, user-applied metadata, or network flow logs does not provide the same coverage or accuracy across different file types and clouds.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Exact Data Match (EDM) and how does it work?
Open an interactive chat with Bash
Why are machine-learning (ML) content inspection tools used for PII discovery?
Open an interactive chat with Bash
What are the limitations of using only regular expressions for PII detection?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .