Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityEasy

A cloud security engineer needs to ensure that data stored in a cloud object storage bucket is protected against accidental deletion or modification for a specific retention period, even by administrators. Which feature should be enabled?

  1. AServer-Side Encryption
  2. BAccess Control Lists (ACLs)
  3. CVersioning
  4. DObject Lock
Show answer & explanation

Correct answer: D. Object Lock

Object Lock provides an immutable, write-once-read-many (WORM) model for objects, preventing them from being deleted or overwritten for a fixed amount of time or indefinitely.

Why the other options are wrong

  • A. Server-side encryption protects data confidentiality but does not prevent deletion or modification.
  • B. ACLs control access permissions but do not prevent deletion or modification by authorized users.
  • C. Versioning keeps multiple versions of an object but does not prevent the deletion of all versions or the bucket itself.

Cloud Object Lock

A feature in cloud object storage that prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely, ensuring data immutability.

  • Provides Write-Once-Read-Many (WORM) capability.
  • Protects against accidental or malicious deletion/modification.
  • Can be configured with retention periods or legal holds.

Memory trick: LOCK your precious data in the cloud, so it stays exactly as you made it, safe from any slip-ups or bad actors.

More Cloud Platform and Infrastructure Security questions