ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization stores daily customer invoices and application log files in the same public-cloud object bucket. Corporate policy requires invoices to remain immutable and accessible for seven years, after which they must be permanently deleted without any administrator action. Log files, on the other hand, may be retained only 30 days to control storage costs. Which solution best meets both retention requirements while minimizing ongoing operational effort?
Enable cross-region replication on the bucket so older objects are overwritten during the replication cycle, satisfying the deletion requirement automatically.
Set the bucket to read-only for all users; when seven years have passed, remove the bucket manually to delete the invoices and logs.
Create two object-lifecycle rules: one that transitions invoice objects to an immutable archival tier and schedules their deletion after seven years, and another that deletes log objects 30 days after creation.
Tag invoice objects as "DoNotDelete" and instruct administrators to run a quarterly script that purges data older than the required retention period.
Object-level lifecycle management lets you create granular rules that automatically apply to objects bearing specific tags or prefixes. One rule can lock invoice objects in a write-once archival tier and schedule their deletion exactly seven years after creation. A second rule can remove log objects 30 days after they are written. Because the policy is enforced by the storage platform itself, no manual scripting, permission changes, or replication workarounds are required. Relying on administrators to run periodic purge scripts risks human error and violates the requirement for automatic enforcement. Geo-replication and read-only ACLs do not satisfy automatic deletion, nor do they guarantee immutability for the mandated period.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is object-lifecycle management in cloud storage?
Open an interactive chat with Bash
What is an immutable archival tier in cloud storage?
Open an interactive chat with Bash
Why is manual intervention risky for compliance with data retention policies?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .