ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization is migrating customer records from several on-premises databases and shared file repositories into both AWS S3 and Azure Blob Storage. You are asked to design an automated cloud-native solution that will continuously discover and classify U.S. Social Security numbers and other personally identifiable information (PII) stored in CSV tables, PDF contracts, and image scans uploaded by users. Which approach best meets the requirement while keeping the number of missed detections (false negatives) to a minimum?

  • Scan all objects with a static library of regular expressions for U.S. Social Security numbers and other PII formats.

  • Deploy ML-based content inspection services in each cloud and add Exact Data Match lookups against a hashed reference dataset of known PII values.

  • Require storage administrators to tag every bucket and object with metadata that specifies whether it contains PII and run discovery jobs against the tags only.

  • Analyze VPC flow logs to flag any outbound traffic that matches known PII patterns, assuming data at rest will then be located.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot