ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your security team must archive cloud audit logs to meet a regulation that mandates seven years of write-once-read-many (WORM) retention while also minimizing cost after the first 90 days. The company already stores logs in an S3-compatible object-storage service that supports both lifecycle policies and an "object lock" feature. Which archival configuration BEST satisfies the regulatory immutability requirement and the long-term cost objective?
Enable object lock in compliance mode on the log bucket and add a lifecycle policy that transitions objects to the provider's cold archive tier after 90 days.
Place the logs on a managed file-share service, turn on file versioning, and keep weekly snapshots for seven years.
Keep the logs in object storage without object lock but restrict write access to a service account protected by multifactor authentication.
Store the logs on encrypted block storage volumes and replicate them asynchronously to a second region for seven years.
Enabling object lock in compliance (WORM) mode prevents anyone-including administrators-from modifying or deleting the objects until the legal-hold period expires, meeting the immutability requirement. Adding a lifecycle rule that automatically moves the objects from the primary storage class to the provider's lowest-cost cold archive tier after 90 days drastically reduces ongoing storage costs while still retaining the data for the full seven-year period. The other options fail to guarantee immutability (block storage replication and access controls can still allow alteration), rely on snapshots rather than WORM enforcement, or omit lifecycle transitions that enable cost optimization.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is WORM retention in the context of cloud storage?
Open an interactive chat with Bash
How do cold archive tiers reduce storage costs?
Open an interactive chat with Bash
What are lifecycle policies in cloud storage?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .