ISC2 · Free Practice Questions · Last reviewed May 2026
36real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
17% of exam · 6 sample questions below
A company requires that its cloud service provider offers a dedicated environment with no shared infrastructure. Which cloud deployment model should the company choose?
Public cloud
Hybrid cloud
Community cloud
Private cloud
A private cloud provides infrastructure dedicated solely to one organisation, with no shared compute, storage or network resources. Public, hybrid and community models all involve some shared infrastructure, so only the private deployment model satisfies the no-sharing constraint.
Which cloud service model provides the consumer with the ability to deploy and run custom applications using the provider's programming languages, libraries, and tools, but does not allow management of the underlying infrastructure?
PaaS
PaaS supplies runtimes, libraries and tools so the consumer deploys custom code without managing servers, operating systems or middleware. That matches the stem exactly: provider-supplied programming languages and tools, with no control over underlying infrastructure.
SaaS
IaaS
CaaS
A security auditor is reviewing a cloud provider's controls to ensure that customer data is appropriately isolated. Which design principle is most directly related to this requirement?
Multitenancy isolation
Multitenancy isolation ensures one tenant's data, workloads, and processes cannot be accessed or affected by another sharing the same infrastructure. This design principle directly satisfies the auditor's requirement that customer data be appropriately segregated within the cloud provider's environment.
Reversibility
Portability
Elasticity
A company is adopting a hybrid cloud model to run sensitive workloads on-premises and less critical applications in the public cloud. Which security consideration is most critical for this environment?
Using a single cloud provider for both environments
Ensuring high-speed network connectivity
Maintaining consistent security policies across both environments
Hybrid splits workloads across two trust domains, so a single control framework must span both. Consistent policies satisfy the stem's need to govern sensitive on-premises systems and public cloud workloads under one security posture, preventing gaps where data crosses the boundary.
Implementing data encryption at rest only
Which cloud characteristic allows a consumer to automatically provision computing resources, such as server time and storage, as needed without requiring human interaction with the service provider?
On-demand self-service
On-demand self-service lets the consumer unilaterally provision capabilities such as server time and storage automatically, with no human interaction required from the provider. That directly matches the stem's requirement for self-provisioning without service provider involvement.
Rapid elasticity
Broad network access
Resource pooling
A cloud customer is evaluating a provider's service level agreement (SLA) that guarantees 99.99% availability. What is the maximum allowable downtime per year (in minutes) before the SLA is violated?
8.76 hours
52.56 minutes
A 99.99% availability guarantee permits 0.01% annual downtime. Applied to 525,600 minutes per year, that equals 52.56 minutes, the exact threshold the SLA specifies. Any outage exceeding this figure breaches the agreement, making it the maximum allowable downtime the stem requests.
5.26 minutes
87.6 hours
Want more Cloud Concepts, Architecture, and Design practice?
Practice this domain20% of exam · 6 sample questions below
A financial services company is migrating sensitive customer data to the cloud. They require that encryption keys be generated and stored on-premises in their own hardware security module (HSM), with the cloud provider never having access to the plaintext keys. Which key management model should they implement?
Customer-managed encryption keys (CMEK)
Bring your own key (BYOK)
Cloud provider default encryption (SSE-S3)
Hold your own key (HYOK)
HYOK generates and retains keys in the customer's on-premises HSM, so plaintext keys never reach the provider; the cloud only ever handles ciphertext or wrapped keys. This satisfies the requirement that the provider cannot access plaintext keys.
A multinational corporation must comply with GDPR and local data residency laws. They are designing a cloud storage architecture that will store customer data in the EU region. However, to improve disaster recovery, they want to replicate data to a secondary region outside the EU. Which approach meets compliance requirements?
Use cross-region replication to a non-EU region but apply client-side encryption before upload
Use same-region replication within the EU and disable cross-region replication
Keeping replication within the EU and disabling cross-region replication prevents customer data leaving the jurisdiction, satisfying GDPR and local data residency rules. Disaster recovery is still provided through same-region replication, so compliance is met without unlawful transfer.
Use cross-region replication to a US region and encrypt data with SSE-S3
Use cross-region replication to a non-EU region and rely on a Data Processing Agreement (DPA)
Which of the following is the most granular method to grant time-limited access to a specific object in a cloud storage bucket without requiring the requester to have cloud provider credentials?
Bucket ACLs
Bucket policies with conditions
Identity-based policies
Signed URLs
Signed URLs embed a cryptographic signature and expiry directly in the URL, granting time-limited access to one specific object. The requester needs no cloud provider credentials, satisfying the granularity and credential-free constraints in the stem.
A data classification scheme for a cloud environment defines labels such as Public, Internal, Confidential, and Restricted. Which label should be applied to data that, if disclosed, would cause severe damage to the organization and is subject to regulatory fines?
Restricted
Restricted fits because the stem demands the highest sensitivity tier for severe damage plus regulatory penalties. Unlike Confidential, which covers unauthorised disclosure causing damage, Restricted is reserved for data whose compromise triggers legal sanctions, so it satisfies the classification scheme's top-level handling, encryption and access-control requirements.
Public
Confidential
Internal
A cloud storage bucket is configured with versioning enabled. A ransomware attack encrypts all objects in the bucket. How can the organization recover the original data?
Use the cloud provider's backup service to restore the bucket
Replicate data from the cross-region replica
Use the cloud provider's ransomware recovery service
Restore from previous versions of the objects
Versioning retains prior copies of each object, so overwritten or encrypted current versions can be replaced by restoring an earlier, unencrypted version. This recovers the original data without paying a ransom or relying on provider intervention.
When data is in transit between an on-premises data center and a cloud service, which of the following is the minimum encryption standard recommended by security best practices?
IPsec with 3DES
TLS 1.2
TLS 1.2 provides authenticated, encrypted transport with modern cipher suites, satisfying the minimum encryption standard for data in transit between on-premises systems and cloud services. Earlier versions such as TLS 1.0 and 1.1 are deprecated due to known vulnerabilities, so TLS 1.2 is the baseline best practice.
TLS 1.0
SSL 3.0
Want more Cloud Data Security practice?
Practice this domain17% of exam · 6 sample questions below
A cloud security architect is designing a multi-tenant environment on a hypervisor. Which hypervisor type provides the most robust isolation between tenant virtual machines by running directly on the hardware without a host operating system?
Type 2 hosted hypervisor (e.g., VirtualBox)
Paravirtualized hypervisor (e.g., Xen)
Container runtime (e.g., Docker)
Type 1 bare-metal hypervisor (e.g., VMware ESXi)
A Type 1 hypervisor runs directly on bare metal, so each tenant VM's isolation boundary is enforced by the hypervisor kernel itself rather than a general-purpose host OS. That removes the host operating system's larger attack surface, satisfying the requirement for the most robust isolation between tenants.
A security analyst discovers that a container running in a Kubernetes cluster has been compromised. The attacker escalated privileges and accessed the host's kernel. Which of the following misconfigurations most likely allowed this container escape?
The container was run with the --privileged flag
The --privileged flag disables the default seccomp, AppArmor and capability restrictions, granting the container nearly all Linux capabilities plus access to host devices. That lets an attacker mount the host filesystem or load kernel modules, escaping to the host kernel.
The container was run with a default Seccomp profile
The container was run with a read-only root filesystem
The container was run with an AppArmor profile in enforce mode
A DevOps team is building a container image for a cloud-native application. To minimize the attack surface and reduce the number of vulnerabilities, which type of base image should they use?
A full distribution image like Ubuntu
An Alpine-based image
A distroless image
A distroless image contains only the application and its runtime dependencies, omitting package managers, shells and other OS utilities. This directly minimises the attack surface and vulnerability count, satisfying the stem's requirement to reduce exploitable components in the container image.
The 'latest' tag of any official image
A security engineer is implementing container image security. They want to ensure that only signed images from a trusted registry can be deployed in the Kubernetes cluster. Which tool should they use to enforce this at the admission controller level?
Clair
Trivy
Cosign
Cosign signs container images and stores signatures in the registry, letting an admission controller verify provenance before pods are admitted. This enforces the trusted-registry constraint at admission time, rejecting any unsigned or tampered image before it reaches the cluster.
Snyk Container
A cloud security analyst is reviewing the network architecture of a VPC. The security team wants to block all traffic from a known malicious IP address at the subnet level. Which AWS network security component should they use?
Network ACL (NACL)
Network ACLs are stateless, subnet-level filters that evaluate allow and deny rules against source and destination IP addresses. A deny rule for the malicious IP therefore blocks its traffic before it reaches any instance in the subnet, matching the subnet-level blocking constraint.
Transit gateway
Security group
VPC peering connection
A company has multiple VPCs in different cloud accounts that need to communicate with each other. They also need to enforce centralized security policies and simplify network management. Which cloud networking service should they use to create a hub-and-spoke topology?
Virtual network peering
Cloud transit gateway
A cloud transit gateway acts as a regional hub, peering each VPC through a single attachment rather than building a full mesh of pairwise connections. This satisfies the centralised policy enforcement and simplified management constraints, since security rules and routing are configured once at the hub across all accounts.
Private link service
Virtual network endpoint
Want more Cloud Platform and Infrastructure Security practice?
Practice this domain17% of exam · 6 sample questions below
A company is migrating a legacy application to the cloud. The application uses hardcoded database credentials. Which secure development practice should be implemented to address this?
Use code signing for all deployments
Implement input validation on all user inputs
Enable encryption at rest for the database
Use a secrets management service
A secrets management service stores database credentials outside the codebase and injects them at runtime, removing hardcoded values from the application. This satisfies the secure development requirement by centralising rotation, access control and auditing of those credentials.
A security architect is designing a CI/CD pipeline for a cloud-native application. The team wants to automatically scan container images for vulnerabilities before deployment. Which of the following is the most effective approach?
Manually review images before each deployment
Integrate a container image scanner into the pipeline
Embedding a container image scanner as a pipeline stage inspects each built image for known CVEs before deployment, failing the build on policy violations. This shifts detection left, blocking vulnerable images from reaching the cluster rather than scanning after release.
Perform vulnerability scanning at runtime using a host-based agent
Scan the network for open ports on the container hosts
A SaaS provider uses a customer-managed encryption key (CMEK) model for data-at-rest. The provider's application runs in a multi-tenant cloud environment. Which attack surface is MOST directly mitigated by this approach?
Misconfigured storage buckets exposing data
Insider threats from cloud provider employees
CMEK prevents provider access to customer data without the key.
SQL injection vulnerabilities in the application
Side-channel attacks on shared physical hardware
An organization is developing a mobile app that communicates with a cloud API. To ensure secure authentication, which of the following should be used?
Session cookies for state management
Basic authentication with username and password
OAuth 2.0 with OpenID Connect
OAuth 2.0 supplies delegated authorisation tokens, while OpenID Connect adds an identity layer with a signed ID token, letting the app verify the end user. This satisfies the secure authentication requirement that plain OAuth 2.0 alone cannot provide.
API keys sent in HTTP headers
A cloud security team is implementing a Web Application Firewall (WAF) for a public-facing web application. The application uses a REST API with JSON payloads. Which of the following is the WAF's primary benefit?
Scanning for data loss prevention (DLP) violations
Preventing network-layer DDoS attacks
Encrypting data in transit between client and server
Inspecting HTTP traffic for malicious payloads
A WAF operates at the application layer, parsing HTTP requests and responses to detect and block malicious payloads such as SQL injection or cross-site scripting before they reach the REST API, directly satisfying the requirement to protect the public-facing JSON-based application.
A company deploys microservices in Kubernetes. Each service communicates via gRPC with mutual TLS. A security assessment reveals that some services use self-signed certificates. What is the primary risk?
Inability to revoke certificates
Exposure of private keys in the container image
Increased latency due to certificate validation
Man-in-the-middle (MITM) attacks between services
Self-signed certificates lack a trusted certificate authority, so services cannot reliably verify each other's identity during the mutual TLS handshake. An attacker positioned between pods could present their own self-signed certificate and impersonate a legitimate service, intercepting gRPC traffic. This directly enables man-in-the-middle attacks, satisfying the scenario's mutual authentication requirement.
Want more Cloud Application Security practice?
Practice this domain16% of exam · 6 sample questions below
A security engineer needs to ensure that all API calls made to cloud resources are logged for auditing. Which cloud auditing feature should be enabled to capture management and data events?
Cloud monitoring and logging service
Configuration management service
Threat detection service
Cloud audit logging service
A cloud audit logging service records API activity, capturing both management events (control-plane operations) and data events (object-level reads and writes) with caller identity, timestamp and source IP. Enabling it satisfies the requirement to log all API calls for auditing.
A security analyst is investigating a potential breach and needs to verify the integrity of audit logs stored in cloud storage. Which feature should the analyst rely on to confirm that logs have not been tampered with?
Server-side encryption of logs
Log file integrity validation
Log file integrity validation produces cryptographic hashes that let the analyst confirm stored audit logs have not been altered or deleted. It directly satisfies the tamper-detection requirement, unlike versioning or retention locks, which prevent deletion but do not prove integrity.
Anomaly detection on logs
Immutable storage for logs
An organization uses a cloud-based SIEM solution. Which cloud service provides native integration to stream audit logs into the SIEM?
Security monitoring service
Centralized logging service
A centralised logging service natively collects and forwards audit trails from cloud resources, providing the direct streaming integration the SIEM consumes. It removes the need for custom agents or polling, satisfying the native-integration constraint in the stem.
Policy management service
Recommendation service
A SOC analyst notices an alert for 'impossible travel' where a user logged in from New York and then from London within 15 minutes. The SIEM correlation rule likely compares which log fields?
User agent and browser type
Source IP address and timestamp
Impossible travel detection calculates the geographic distance between successive authentications and divides it by elapsed time. The SIEM rule therefore correlates source IP address, which resolves to location, against the timestamp of each login event to derive an impossible velocity.
Destination IP and port
Volume of data transferred and timestamp
A security team needs to implement automated remediation for non-compliant resources in a cloud environment. They want to automatically fix public object storage bucket policies. Which combination of services should be used?
Audit logging service and serverless compute function
Threat detection service and workflow orchestration service
Security hub and vulnerability management service
Configuration management service and serverless compute function
A configuration management service continuously evaluates resource configuration against policy and detects non-compliant public bucket policies, then invokes a serverless function to remediate them automatically. This pairing satisfies the requirement for automated, event-driven correction without manual intervention.
A cloud security architect is evaluating vulnerability management solutions for a hybrid cloud environment. The team needs to scan both on-premises servers and cloud workloads without installing agents on every system. Which approach is most suitable for cloud workloads?
Agent-based scanning using a cloud-native service
Network vulnerability scanning from a remote scanner
Container image scanning only
Agentless scanning via cloud APIs (CSPM)
Agentless scanning via cloud APIs queries the provider's control plane, so no software runs on each workload. This satisfies the stem's constraint of scanning cloud workloads without installing agents, unlike host-based tools that require per-system deployment.
Want more Cloud Security Operations practice?
Practice this domain13% of exam · 6 sample questions below
A covered entity under HIPAA is planning to migrate electronic protected health information (ePHI) to a public cloud environment. Which of the following is a mandatory requirement before using the cloud service?
Encrypt all ePHI with keys managed solely by the covered entity
Conduct a physical on-site audit of the cloud provider's data centers
Obtain a signed Business Associate Agreement from the cloud provider
HIPAA requires a Business Associate Agreement before any covered entity shares ePHI with a cloud provider, since the provider qualifies as a business associate. The signed BAA contractually binds the provider to safeguard ePHI and satisfies the mandatory prerequisite for cloud migration.
Ensure the cloud provider is certified under the Privacy Shield framework
A cloud customer receives a litigation hold notice requiring preservation of data stored in an object storage service. Which service feature should the customer use to ensure data cannot be modified or deleted until the hold is released?
Apply a retention policy using Object Lock
Object Lock enforces write-once-read-many (WORM) protection at the object level, preventing modification or deletion for a defined retention period. This directly satisfies the litigation hold's requirement that data remain immutable until the hold is formally released, independent of user permissions.
Set a lifecycle policy to transition to archival storage
Enable versioning on the bucket
Configure server-side encryption
A company is negotiating a cloud service agreement and wants to ensure it can verify the provider's security controls independently. Which contractual clause is essential for this purpose?
Data deletion clause
Right to audit clause
A right to audit clause contractually grants the customer the ability to independently verify the provider's security controls, through assessments or evidence review. Without it, assurance rests solely on provider assertions, so it directly satisfies the requirement for independent verification.
Service Level Agreement (SLA) on uptime
Data portability clause
A cloud provider's data center is located in Country A, but the customer's data is subject to litigation in Country B. The court in Country B orders the cloud provider to produce data. The cloud provider refuses, citing Country A's laws that prohibit disclosure. This situation best illustrates which challenge in eDiscovery?
Data portability
Jurisdiction issues
Two sovereign legal regimes impose conflicting obligations: Country B compels production while Country A prohibits disclosure. This clash of laws governing the same data is a jurisdiction issue, exactly the eDiscovery challenge the stem describes when the provider refuses the court order.
Data preservation
Forensic soundness
When assessing cloud risk, an organization identifies that if a single cloud provider fails, the organization cannot operate. This risk is known as:
Third-party risk
Inherent risk
Concentration risk
Concentration risk arises when dependency on a single provider creates correlated failure exposure, so one outage halts all operations. Unlike operational or compliance risk, it specifically measures over-reliance on one entity, matching the stem's single-provider failure scenario.
Residual risk
A company using a SaaS application for HR management receives a data subject access request (DSAR) under GDPR from an employee. The cloud provider is the data processor. The company as data controller must respond within what timeframe?
One month
Under GDPR Article 12(3), the controller must respond to a data subject access request without undue delay and in any event within one month of receipt, extendable by two further months for complex requests. The processor's role does not alter this controller deadline.
90 days
45 days
72 hours
Want more Legal, Risk, and Compliance practice?
Practice this domainThe CCSP exam has 150 questions and must be completed in 240 minutes. The passing score is 700/1000.
Scenario questions on cloud security architecture, governance, risk management, infrastructure security, application security, and operations.
The exam covers 6 domains: Cloud Concepts, Architecture, and Design, Cloud Data Security, Cloud Platform and Infrastructure Security, Cloud Application Security, Cloud Security Operations, Legal, Risk, and Compliance. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISC2 CCSP exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.