exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 91 discussion

Actual exam question from ISC's CCSP
Question #: 91
Topic #: 1
[All CCSP Questions]

What is the first stage of the cloud data lifecycle where security controls can be implemented?

  • A. Use
  • B. Store
  • C. Share
  • D. Create
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
brandV
Highly Voted 3 years, 3 months ago
Selected Answer: D
While security controls are implemented in the create phase in the form of SSL/TLS, this only protects data in transit and not data at rest. The store phase is the first phase in which security controls are implemented to protect data at rest.
upvoted 9 times
...
[Removed]
Highly Voted 3 years, 3 months ago
Create. as per CBK, Data classification is foundational security control. page 44, cbk 3rd edition.
upvoted 7 times
...
krauzo
Most Recent 2 months ago
Selected Answer: D
create - when data is created it can be properly classified
upvoted 1 times
...
Vee_Wang
4 months ago
Selected Answer: B
create stage, you can define the classification . While security control is implemented in store stage.
upvoted 1 times
...
CBO2025
5 months, 1 week ago
Selected Answer: B
When your create data, you're just typing or modifying however, when you submit it, you'll trigger the store phase, hence the secuirt starts at the store phase
upvoted 1 times
...
Kneebee
1 year ago
B is the correct choice - the CCSP official study indicates this is the first stage where security controls can be implemented to protect data at rest.
upvoted 2 times
...
FranklinG
1 year, 1 month ago
This is a tricky question to try and trip you up. It says "the first stage" making it sound like the first phase in the data life cycle world, which would be "Create." However, "Store" is the right answer, because in the "Create" phase the data owner is defined, then data is categorized, classified, labeled, tagged and marked. And if created remotely, data should be encrypted, and connections secured (VPN) and secure key management practices should be practiced. Now, in the "Store" phase which occurs almost concurrently with the "Create" phase is where it's immediately important to employ: The use of backup methods on top of security controls to prevent data loss. Additional encryption for data at rest. DLP and IRM technologies are used to ensure that data security is enforced during the Use and Share phases of the cloud data lifecycle.
upvoted 2 times
...
JBvino
1 year, 5 months ago
While security controls are implemented in the create phase in the form of SSL/TLS, this only protects data in transit and not data at rest. The store phase is the first phase in which security controls are implemented to protect data at rest.
upvoted 2 times
kollmekay
1 year, 1 month ago
But the question doesnt mention data in transit
upvoted 1 times
...
...
MartijnBdV
1 year, 8 months ago
Selected Answer: D
security controls can be initially implemented at the create phase as well, specifically in the form of technologies such as SSL/TLS with data that is inputted or imported.
upvoted 2 times
...
escaprix
1 year, 10 months ago
Selected Answer: B
Store no hay duda
upvoted 2 times
...
Purespace
2 years ago
Selected Answer: D
Create - as has been said throughout the comments, data classification and labeling is most certainly a "security control" as defined in NIST SP 800-53, ISO 27001, HITRUST, etc. (look up "information handling" in the control sets).
upvoted 1 times
...
secisfun
2 years, 4 months ago
Selected Answer: D
Create
upvoted 1 times
...
kepalon
3 years ago
In Create is the 1st phase where labels can be assign; In Store is the 1st phase where controls can be implemented.
upvoted 5 times
...
xaccan
3 years, 11 months ago
Store The Store phase often happens in tandem with (or immediately after) the Create phase. During this phase, the created or modified data is saved to some sort of digital repository within the application or system. Storage can be in the form of saved files on a filesystem, rows and columns saved to a database, or objects saved in a cloud storage system. During the Store phase, the classification level assigned during creation is used to assign and implement appropriate security controls. Controls like encryption (at rest), Access Control Lists (ACLs), logging, and monitoring are important during this phase. In addition, this phase is when you should consider how to appropriately back up your data to maintain redundancy and availability
upvoted 4 times
...
phanil1
3 years, 11 months ago
In Create, you can only define the controls like classification, you cannot apply until you store them. store is correct answer.
upvoted 5 times
...
asldavid
4 years, 1 month ago
Should be "D". Data classification is done during the create phase.
upvoted 4 times
...
Rangakarthik
4 years, 3 months ago
Yes I do agree here
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago