ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization stores sensitive customer data in a public cloud provider's object storage. The objects are encrypted with keys you control using a client-side KMS. The contract stipulates that all customer data must be permanently destroyed within 24 hours of service termination, yet you have no access to the provider's physical media. Which data-deletion method best satisfies both the timing and assurance requirements?

  • Issue a TRIM command to force secure erase of each SSD block holding the data.

  • Immediately revoke and securely destroy the encryption keys used for the objects (cryptographic erasure).

  • Request the provider to degauss all drives that may contain your objects and supply a destruction certificate.

  • Instruct the provider to run a DoD 5220.22-M three-pass overwrite on the storage disks.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot