Best Control for Protecting Cloud-Stored Customer Personal Information
Which of the following is the BEST control to protect customer personal information that is stored in the cloud?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests prioritization of technical data protection controls over privacy modifications or provider-managed infrastructure, where candidates often mistakenly select anonymization or physical security measures.
Strong encryption is widely recognized as the most effective safeguard for customer personal information stored in cloud environments, with candidates and experts agreeing it maintains confidentiality even during unauthorized access.
Option B (Appropriate data anonymization) is frequently chosen because it aligns with privacy regulations, but it permanently alters data usability and fails to actively protect original records from breach exposure like encryption does.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Strong encryption methods render customer personal information unreadable to unauthorized entities, protecting both data at rest and in transit within cloud infrastructure. As highlighted in top-voted discussions, encryption ensures that stolen data remains unintelligible without the corresponding decryption keys, directly satisfying confidentiality requirements. This approach aligns with CISM principles that prioritize implementing robust, organization-controlled technical safeguards in shared third-party environments.Why the Other Options Are Wrong
Data anonymization modifies the original dataset, making it unsuitable for business processes that require retaining and processing actual PII. Physical access controls are primarily managed by the cloud service provider under the shared responsibility model, leaving customers without direct enforcement capabilities. Timely deletion reduces long-term exposure but offers zero protection for actively stored records against immediate compromise or ransomware threats.Community Comment Notes
Exam candidates consistently validate encryption as the definitive safeguard, emphasizing its dual role in securing data across cloud storage layers. One highly rated comment clarifies that encryption guarantees data unintelligibility to attackers without the proper keys, reinforcing why it outperforms alternative privacy-focused techniques in certification exams. Multiple users note that while anonymization addresses compliance, it does not replace active cryptographic defense mechanisms for live datasets.Official Reference
Exam Strategy
Always evaluate cloud security questions through the lens of the shared responsibility model; prioritize logical controls you can directly implement over those managed by the provider. When balancing privacy versus security measures, remember that confidentiality controls like encryption take precedence when defending against unauthorized access rather than altering data utility.
Frequently Asked Questions
Why isn't data anonymization the best control here?
Anonymization permanently alters data, making it unusable for business processes that require original PII. Encryption preserves data utility while actively defending against breaches.
Does the cloud provider handle physical access controls?
Under the shared responsibility model, providers manage physical security, but organizations remain accountable for logical controls like encryption to protect their stored data.
Related Analysis
Practice All CISM Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISM Practice Test →