Sample questions
Certified Cloud Security Professional CCSP practice questions
A cloud architect is designing a data loss prevention (DLP) solution for a SaaS application. The DLP must inspect data in transit between end users and the cloud as well as data at…
Under GDPR, what is the maximum time allowed for a data controller to notify the supervisory authority of a personal data breach?
A security team is investigating a potential data exfiltration incident where a large volume of data was downloaded from a cloud storage bucket. Which log source would provide the…
A company is moving its customer database to a public cloud provider. The database contains personally identifiable information (PII) of European Union citizens. Which legal framew…
A Kubernetes cluster is being hardened. Which THREE measures should be implemented to restrict container capabilities and reduce the risk of privilege escalation? (Select three.)
Cloud Platform and Infrastructure SecurityhardSee the answer and why each option is right or wrong →A security architect is designing network segmentation for a multi-tier application in the cloud. Which TWO configurations help enforce micro-segmentation? (Choose two.)
A medium-sized e-commerce company uses a cloud provider's container orchestration service (e.g., Amazon ECS or Google Kubernetes Engine). They have a security requirement to ensure…
A software company develops an API for third-party integrations. They want to ensure that only authorized partners can access the API. Which authentication mechanism is most approp…
A company uses a hybrid cloud model where sensitive data resides in a private cloud, while compute-intensive analytics run in a public cloud using anonymized data. What is the prim…
Cloud Concepts, Architecture, and DesignmediumSee the answer and why each option is right or wrong →A security engineer reviews the S3 bucket policy shown in the exhibit. Which security concern should be addressed immediately?
A cloud security analyst is investigating a potential data breach. They discover that an employee's credentials were used to access a cloud storage bucket containing sensitive file…
A company's cloud security policy mandates strict control over encryption keys used for data at rest. Which THREE practices are recommended for secure key management in the cloud?
Which TWO of the following are required elements of a valid Business Continuity Plan (BCP) in the cloud?
A cloud security engineer needs to ensure that a containerized application running in a Kubernetes cluster securely stores and rotates database credentials. Which is the most appro…
Which THREE of the following are key considerations when conducting a cloud risk assessment?
Which THREE of the following are essential steps in a cloud data discovery process?
A security team is deploying a Kubernetes cluster on a cloud platform and wants to harden the worker nodes against container breakout and privilege escalation. They are reviewing k…
Cloud Platform and Infrastructure SecurityhardSee the answer and why each option is right or wrong →A company uses a serverless architecture with AWS Lambda to process user-uploaded files. The Lambda function is triggered by an S3 bucket event. While reviewing security, the archi…
A cloud security engineer is reviewing the authentication mechanism for a web application. The application currently uses API keys transmitted in the URL query string. What is the…
A company uses a cloud provider's managed database service. The security team is concerned about the shared responsibility model for patching the operating system and database engi…
A company is implementing a cloud key management system (KMS) to control encryption keys for sensitive data. Which practice is essential to ensure the security of the keys?
A cloud security analyst is reviewing the network architecture of a VPC. The security team wants to block all traffic from a known malicious IP address at the subnet level. Which A…
Cloud Platform and Infrastructure SecuritymediumSee the answer and why each option is right or wrong →A cloud customer is subject to the Health Insurance Portability and Accountability Act (HIPAA). They are considering using a cloud provider that offers infrastructure as a service…
A security analyst reviews the bucket policy above. What is the primary security concern?