nerdexam
Isaca

CRISC · Question #42

Which of the following practices would be MOST effective in protecting personality identifiable information (Ptl) from unauthorized access m a cloud environment?

The correct answer is B. Utilize encryption with logical access controls. To effectively protect Personally Identifiable Information (PII) from unauthorized access in a cloud environment, a combination of encryption and logical access controls is most effective.

Submitted by anna_se· Apr 18, 2026Information Technology and Security

Question

Which of the following practices would be MOST effective in protecting personality identifiable information (Ptl) from unauthorized access m a cloud environment?

Options

  • AApply data classification policy
  • BUtilize encryption with logical access controls
  • CRequire logical separation of company data
  • DObtain the right to audit

How the community answered

(56 responses)
  • A
    5% (3)
  • B
    68% (38)
  • C
    9% (5)
  • D
    18% (10)

Why each option

To effectively protect Personally Identifiable Information (PII) from unauthorized access in a cloud environment, a combination of encryption and logical access controls is most effective.

AApply data classification policy

Applying a data classification policy is an important foundational step for managing data but does not directly implement technical protection against unauthorized access.

BUtilize encryption with logical access controlsCorrect

Encryption protects PII by rendering it unreadable to unauthorized parties, even if the data is exfiltrated, while logical access controls ensure only authorized users can access the encrypted data. Combining both provides a robust defense-in-depth approach against unauthorized access, safeguarding PII both at rest and in transit.

CRequire logical separation of company data

Requiring logical separation of company data isolates different datasets but doesn't inherently protect PII within a segregated area from unauthorized access if other controls are weak.

DObtain the right to audit

Obtaining the right to audit provides oversight and accountability but is a contractual or governance control, not a direct technical measure to prevent unauthorized access.

Concept tested: Cloud PII protection security controls

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/encryption-overview

Topics

#PII Protection#Cloud Security#Encryption#Access Controls

Community Discussion

No community discussion yet for this question.

Full CRISC Practice