Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 1–75

934 questions total · 13pages · All types, answers revealed

Page 1 of 13

Page 2
1
MCQmedium

A company is subject to PCI DSS and plans to use a cloud provider to process credit card transactions. The cloud provider has been assessed by a Qualified Security Assessor (QSA). According to PCI DSS, what must the company obtain from the provider to demonstrate compliance?

A.The provider's PCI DSS Attestation of Compliance (AOC) and Responsibility Matrix
B.A signed Business Associate Agreement
C.An ISO 27001 certificate
D.A SOC 2 Type II report
AnswerA

The PCI DSS Attestation of Compliance evidences the provider's assessed compliance status, while the Responsibility Matrix defines which requirements the provider covers versus the customer. Together they satisfy the obligation to demonstrate compliance for card processing.

Why this answer

Under PCI DSS, when a customer uses a cloud provider to process cardholder data, the provider must be assessed by a QSA and issue an Attestation of Compliance (AOC) along with a Responsibility Matrix (also called a Shared Responsibility Matrix or PCI DSS Responsibility Matrix). The AOC documents the provider's validated compliance status, and the Responsibility Matrix defines which PCI DSS requirements are met by the provider versus the customer. Together they let the customer demonstrate its own compliance to its acquirer or QSA.

Exam trap

CCSP often tests the confusion between compliance frameworks — candidates see 'cloud provider' and 'compliance' and reach for SOC 2 or ISO 27001, but PCI DSS specifically requires a QSA-issued AOC and Responsibility Matrix from the service provider.

How to eliminate wrong answers

Option B is wrong because a Business Associate Agreement is a HIPAA construct governing protected health information, not a PCI DSS artifact — it has no bearing on cardholder data compliance. Option C is wrong because an ISO 27001 certificate attests to an information security management system, not to PCI DSS controls; it is useful evidence but does not satisfy PCI DSS's specific requirement for a QSA-assessed AOC. Option D is wrong because a SOC 2 Type II report covers the Trust Services Criteria (security, availability, etc.) and, while often used as supporting evidence, is not the PCI DSS-specific attestation the standard requires from a service provider.

2
MCQmedium

A security analyst is using a cloud security posture management (CSPM) tool that reports a finding of "storage bucket publicly accessible." However, upon manual inspection, the bucket's ACL and bucket policy both restrict access to authorized users only. What is the most likely cause of the false positive?

A.The bucket is in a different region
B.The bucket policy has a syntax error
C.The bucket contains objects with public ACLs
D.The CSPM tool is misconfigured
AnswerC

CSPM evaluates effective public access, not just bucket-level ACLs and policies. If individual objects carry public-read ACLs, the bucket is effectively exposed even though its own policy restricts access, so the tool flags it. The object-level ACLs are the actual cause.

Why this answer

A CSPM tool may flag a bucket as publicly accessible if any object within the bucket has a public ACL, even if the bucket-level ACL and policy are private. The tool evaluates the effective permissions of the bucket and its contents, and a single public object can trigger the finding. Manual inspection of only bucket-level settings would miss this.

Exam trap

CCSP often tests the shared responsibility model and the difference between bucket-level and object-level permissions; candidates may assume the CSPM tool is wrong without considering object ACLs.

How to eliminate wrong answers

Option A is wrong because the region of the bucket does not affect its public accessibility; CSPM tools evaluate buckets regardless of region. Option B is wrong because a syntax error in the bucket policy would likely cause the policy to be ignored or rejected, not make the bucket public; it would not cause a false positive for public access. Option D is wrong because while CSPM misconfiguration is possible, the scenario describes a specific discrepancy that is explained by object-level ACLs; assuming tool misconfiguration without evidence is less likely.

3
MCQhard

A company has multiple VPCs in different cloud accounts that need to communicate with each other. They also need to enforce centralized security policies and simplify network management. Which cloud networking service should they use to create a hub-and-spoke topology?

A.Virtual network peering
B.Cloud transit gateway
C.Private link service
D.Virtual network endpoint
AnswerB

A cloud transit gateway acts as a regional hub, peering each VPC through a single attachment rather than building a full mesh of pairwise connections. This satisfies the centralised policy enforcement and simplified management constraints, since security rules and routing are configured once at the hub across all accounts.

Why this answer

A cloud transit gateway allows you to connect multiple VPCs and on-premises networks through a central hub, simplifying management and enabling centralized security policies. Virtual network peering is point-to-point and does not scale well for many VPCs.

4
MCQhard

A cloud customer is preparing for litigation and needs to place a legal hold on specific data stored in an object storage service. The cloud provider offers features such as object lock and retention policies. What is the primary challenge the customer must address to ensure the legal hold is effective across all copies of the data?

A.Ensuring that the legal hold is time-limited and automatically expires after 90 days.
B.Ensuring that the legal hold is applied to all copies of the data, including replicas and backups, and that the hold prevents modification as well as deletion.
C.Verifying that the cloud provider has a backup of the data in a different geographic region.
D.Obtaining a court order that specifically authorizes the cloud provider to preserve the data.
AnswerB

Object lock and retention policies apply per object or bucket, so the challenge is propagating the hold to every replica and backup copy and enforcing immutability against both modification and deletion, ensuring no copy escapes the hold.

Why this answer

In cloud environments, data may be replicated across multiple regions or stored in backups. A legal hold must prevent deletion or alteration of all copies, including replicas and backups. Failure to apply hold to all copies can result in spoliation.

5
MCQmedium

A cloud security engineer is concerned about VM escape attacks in a multi-tenant environment. Which of the following is the most effective mitigation strategy?

A.Regularly patching and updating the hypervisor
B.Using host-based intrusion detection on each VM
C.Implementing network segmentation between VMs
D.Enforcing strong passwords on guest OS accounts
AnswerA

VM escape exploits abuse hypervisor vulnerabilities, so regularly patching and updating the hypervisor removes the flaws an attacker needs to break out of a guest. This directly mitigates the escape vector in a multi-tenant environment where one flaw could expose co-resident tenants.

Why this answer

VM escape attacks exploit hypervisor vulnerabilities. The primary defense is to keep the hypervisor patched and hardened, as other controls like IDS/IPS or guest OS hardening do not directly prevent escape.

6
MCQmedium

An organization is moving a legacy application to the cloud and wants to minimize changes to the application code. They require full control over the operating system and middleware. Which cloud service model is most appropriate?

A.PaaS
B.SaaS
C.IaaS
D.FaaS
AnswerC

IaaS supplies virtualised compute, storage, and networking while leaving the guest operating system and middleware under customer control. This satisfies the requirement for full OS and middleware control with minimal code changes, unlike PaaS, which abstracts the platform layer.

Why this answer

IaaS provides the customer with virtualized compute, storage, and networking while giving them full control over the operating system, middleware, and runtime — exactly what a legacy application needing minimal code changes requires. The customer manages the guest OS and above, while the provider handles the physical infrastructure and hypervisor. This makes IaaS the most appropriate model for lift-and-shift migrations with OS-level control requirements.

Exam trap

CCSP often tests the control-versus-management tradeoff across service models; the trap is choosing PaaS because it 'sounds modern,' ignoring the requirement for full OS and middleware control.

How to eliminate wrong answers

Option A is wrong because PaaS abstracts the OS and middleware, so the customer cannot control the operating system and would likely need to modify the application to fit platform constraints. Option B is wrong because SaaS delivers a fully managed application, offering no control over OS or middleware and typically requiring significant application changes or replacement. Option D is wrong because FaaS (serverless functions) abstracts everything below the function code, imposes execution time limits, and is unsuitable for a legacy application requiring persistent OS-level control.

7
MCQhard

A cloud customer's provider announces that a sub-processor in a new jurisdiction will begin handling EU personal data next month. The customer's DPA gives it a right to object but states that continued use of the service constitutes acceptance. Which action best preserves the customer's legal position under GDPR Article 28(2)?

A.Accept the change and rely on the provider's downstream SCCs with the new sub-processor as sufficient protection for the customer.
B.Perform a new data protection impact assessment covering the sub-processor and treat a favorable outcome as consent to the change.
C.Exercise the objection right in writing before the change takes effect and document the outcome, escalating to termination if the provider cannot accommodate it.
D.Notify the supervisory authority of the sub-processor change and request a formal opinion before responding to the provider.
AnswerC

Article 28(2) requires the controller to have the opportunity to object to sub-processor changes, and Article 28(4) makes the processor liable for sub-processors. A timely written objection preserves the contractual right, creates evidence of the objection, and forces a documented resolution. Silent acceptance by continued use would waive the objection and lock in the new sub-processor.

Why this answer

Article 28(2) gives the controller the right to object to new sub-processors, and Article 28(4) holds the processor liable for sub-processor performance. Exercising the objection in writing before the change takes effect preserves the remedy and creates an auditable record. Remaining silent while continuing to use the service typically constitutes acceptance and extinguishes the objection right.

Exam trap

The trap here is believing that a DPIA, a regulator notification, or downstream SCCs can substitute for formally exercising the contractual right to object before the acceptance-by-continued-use deadline.

8
Multi-Selecthard

A cloud architect is evaluating a public cloud provider for a regulated workload. The provider offers a shared responsibility model. Which TWO of the following are typically the cloud customer's responsibilities under that model? (Choose two.)

Select 2 answers
A.Configuring identity and access management policies
B.Maintaining the physical network fabric between availability zones
C.Classifying and protecting data stored in the cloud
D.Patching the hypervisor
E.Managing physical access to the data center
AnswersA, C

Identity and access management policies are configured by the customer to control who can access their resources and data. The provider secures the underlying identity platform, but the customer defines users, roles, permissions, and federation. This is a core customer responsibility in public cloud, especially for regulated workloads where least privilege must be enforced.

Why this answer

Under the shared responsibility model, the customer is responsible for security in the cloud, which includes configuring identity and access management policies and classifying and protecting data. Physical access, hypervisor patching, and physical network fabric are provider responsibilities. Regulated workloads require the customer to focus on data protection and access control while relying on the provider for infrastructure security.

Exam trap

The trap here is assuming the provider secures everything, when the customer still owns identity configuration and data protection even in a public cloud.

9
MCQmedium

A multinational corporation is migrating its customer data to a cloud provider that operates data centers in multiple jurisdictions. To comply with the General Data Protection Regulation (GDPR), the company must ensure that customer data remains within the European Economic Area (EEA) unless adequate safeguards are in place. The cloud provider offers data residency options but does not guarantee that data will never be accessed from outside the EEA. What is the BEST course of action for the company?

A.Enter into a Data Processing Agreement (DPA) that includes Standard Contractual Clauses (SCCs) with the provider.
B.Accept the provider's data residency feature as sufficient compliance.
C.Pseudonymize all customer data before uploading to the cloud.
D.Encrypt all data and store the keys on-premises.
AnswerA

Standard Contractual Clauses are European Commission-approved transfer mechanisms that impose GDPR-equivalent safeguards on the importer, satisfying the stem's requirement for adequate safeguards where residency alone cannot prevent extraterritorial access. A DPA alone merely documents processing terms; the SCCs appended to it provide the binding legal basis for lawful EEA-to-third-country transfers.

Why this answer

A Data Processing Agreement (DPA) with Standard Contractual Clauses (SCCs) is the correct mechanism under GDPR to lawfully transfer personal data outside the EEA when the cloud provider cannot guarantee that data will never be accessed from outside the EEA. SCCs are a set of contractual terms approved by the European Commission that impose obligations on both the data exporter and importer to ensure adequate data protection, even if the provider's data residency feature is not absolute. This approach directly addresses the GDPR requirement for adequate safeguards when data may be accessed from third countries.

Exam trap

ISC2 often tests the misconception that technical controls like encryption or pseudonymization alone can substitute for a legal transfer mechanism under GDPR, when in fact the regulation requires a recognized adequacy decision or appropriate safeguards (such as SCCs) regardless of the technical protections applied.

How to eliminate wrong answers

Option B is wrong because relying solely on the provider's data residency feature does not address the risk of data being accessed from outside the EEA, which would violate GDPR's transfer restrictions without an appropriate safeguard mechanism. Option C is wrong because pseudonymization alone does not constitute an adequate safeguard under GDPR for international data transfers; it reduces identifiability but does not prevent the data from being subject to foreign legal access or processing outside the EEA. Option D is wrong because while encryption with on-premises key storage can reduce exposure, it does not eliminate the legal requirement for a valid transfer mechanism under GDPR (such as SCCs or Binding Corporate Rules) when the cloud provider operates globally and data may be accessed from outside the EEA.

10
MCQeasy

A cloud customer is preparing for an audit of its provider and wants to rely on the provider's existing independent attestation rather than conduct its own on-site review. Which document should the customer request to evaluate the provider's controls over security, availability, and confidentiality?

A.An ISO/IEC 27001 certificate listing the provider's statement of applicability for its corporate IT systems.
B.A completed CSA CAIQ self-assessment submitted by the provider's security team.
C.A SOC 2 Type II report covering the trust services criteria relevant to the customer's use of the service.
D.A SOC 1 Type II report covering controls relevant to the customer's internal control over financial reporting.
AnswerC

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of controls against the trust services criteria over a period of time. It lets the customer evaluate security, availability, and confidentiality without an on-site visit. The customer must still verify the report's period, scope, and complementary user entity controls.

Why this answer

A SOC 2 Type II report is the standard independent attestation for security, availability, and confidentiality controls over a period of time, allowing a customer to evaluate a provider without an on-site review. The customer should confirm the report's scope covers the in-use service, the audit period is recent, and any listed complementary user entity controls are implemented on its side.

Exam trap

The trap here is confusing SOC 1, which addresses financial reporting controls, or unverified self-assessments such as the CAIQ, with the independent trust services attestation a cloud security audit requires.

11
Multi-Selecthard

A cloud architect is designing a multi-cloud strategy to avoid vendor lock-in. Which three design considerations should be included? (Choose three.)

Select 3 answers
A.Implement abstraction layers such as containers or cloud-agnostic APIs
B.Design applications with portability in mind using microservices
C.Choose cloud-agnostic data formats and storage interfaces
D.Standardize on one cloud provider for core services
E.Use provider-specific APIs for optimal performance
AnswersA, B, C

Abstraction layers decouple workloads from provider-specific services, letting containers and cloud-agnostic APIs run unchanged across AWS, Azure and Google Cloud. This directly satisfies the stem's vendor lock-in constraint by enabling portability, so migration between providers avoids the costly re-engineering that proprietary APIs and managed services would otherwise force.

Why this answer

Option A is correct because abstraction layers such as containers (e.g., Docker images orchestrated by Kubernetes) and cloud-agnostic APIs (e.g., S3-compatible object storage, OpenTofu/Terraform) decouple workloads from any single provider's proprietary interfaces, making migration between clouds feasible. Option B is correct because designing applications as loosely coupled microservices, ideally packaged in portable containers and communicating over standard protocols like HTTP/REST or gRPC, allows individual services to be redeployed on another provider without rewriting the whole application. Option C is correct because using cloud-agnostic data formats and storage interfaces (e.g., Parquet, JSON, SQL, or S3-compatible APIs) prevents data from being trapped in a proprietary store and keeps it readable and movable across providers.

Option D is incorrect because standardizing on a single cloud provider for core services increases vendor lock-in rather than avoiding it. Option E is incorrect because provider-specific APIs, while sometimes offering better performance or deeper feature integration, tightly couple the application to that vendor and undermine portability.

Exam trap

ISC2 often tests the misconception that standardizing on a single provider's core services is part of a multi-cloud strategy, when in fact it increases lock-in, and that provider-specific APIs are acceptable for portability, when they directly undermine the abstraction goal.

12
Multi-Selectmedium

A cloud security architect is designing a data retention and deletion strategy for a SaaS application hosted in a public cloud. The organization must ensure that data is securely deleted when no longer needed, and that deletion is verifiable. Which two practices should be implemented? (Choose two.)

Select 2 answers
A.Use cryptographic erasure by destroying the encryption keys associated with the data.
B.Rely on the cloud provider's standard data deletion process as specified in their SLA.
C.Implement a data retention policy that automatically deletes data after a set period and logs the deletion events.
D.Overwrite data with zeros before deletion to ensure it cannot be recovered.
E.Store all data in a single cloud region to simplify deletion.
AnswersA, C

Cryptographic erasure renders data unrecoverable by destroying the keys used to encrypt it. This is effective in cloud environments where physical media destruction is not possible. It provides a verifiable method of deletion because once keys are destroyed, the ciphertext cannot be decrypted, meeting the requirement for secure and verifiable deletion.

Why this answer

Cryptographic erasure destroys keys to make data unrecoverable, and automated retention policies with logging provide verifiable deletion. Together, they ensure data is securely deleted and that deletion can be audited. These practices are well-suited to cloud environments where physical media control is absent.

Exam trap

The trap here is assuming that overwriting data with zeros is a valid secure deletion method in the cloud, when cloud storage abstraction makes it ineffective and unverifiable.

13
MCQmedium

An organization wants to deploy a cloud environment where multiple separate agencies with common compliance requirements share the infrastructure, but each agency retains some control over their own resources. Which deployment model best fits this scenario?

A.Hybrid cloud
B.Public cloud
C.Private cloud
D.Community cloud
AnswerD

A community cloud is provisioned for exclusive use by a specific community of organisations sharing common compliance concerns, yet each participating agency can retain control over its own resources. This matches the stem's requirement for shared infrastructure among agencies with common compliance needs.

Why this answer

A community cloud is a deployment model where infrastructure is shared by several organizations with common concerns (e.g., compliance, security, jurisdiction). In this scenario, multiple agencies with common compliance requirements share the infrastructure while each retains control over their own resources, which aligns exactly with the community cloud model. This model balances cost-efficiency with the specific needs of a defined community.

Exam trap

The trap is confusing community cloud with public or hybrid cloud; candidates often focus on 'shared infrastructure' and pick public cloud, ignoring the 'common compliance requirements' and 'multiple agencies' that define a community cloud.

How to eliminate wrong answers

Option A is wrong because a hybrid cloud combines private and public clouds, typically for workload portability, not for sharing among multiple agencies with common compliance needs. Option B is wrong because a public cloud is owned by a single provider and shared by the general public, not tailored to a specific community's compliance requirements. Option C is wrong because a private cloud is dedicated to a single organization, which would not allow multiple agencies to share infrastructure while retaining control.

14
MCQeasy

Which cloud service model provides the customer with the ability to deploy and run custom applications using the provider's infrastructure, where the customer manages the applications and data, but does not manage the underlying operating system or hardware?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Function as a Service (FaaS)
D.Infrastructure as a Service (IaaS)
AnswerA

PaaS supplies the managed runtime, middleware and operating system, so the customer deploys code and manages only applications and data. This satisfies the stem's constraint that the underlying OS and hardware remain the provider's responsibility, unlike IaaS where the guest OS is customer-managed.

Why this answer

Platform as a Service (PaaS) provides the customer with the ability to deploy and run custom applications using the provider's infrastructure, where the customer manages the applications and data, but does not manage the underlying operating system or hardware. This matches the description exactly.

Exam trap

CCSP often tests the differences between IaaS, PaaS, and SaaS, and candidates may confuse PaaS with IaaS or FaaS, especially when the question emphasizes managing applications but not the OS.

How to eliminate wrong answers

Option B is wrong because Software as a Service (SaaS) provides fully functional applications managed by the provider, and the customer does not manage the application or data in the same way; they just use the software. Option C is wrong because Function as a Service (FaaS) is a subset of serverless computing where the customer deploys functions, but it is not the broad service model described; FaaS abstracts even more, and the customer only manages the function code. Option D is wrong because Infrastructure as a Service (IaaS) provides virtualized computing resources, but the customer manages the operating system and middleware, which contradicts the requirement of not managing the OS.

15
MCQhard

A company uses a private artifact registry for internal packages. An attacker publishes a malicious package with the same name as an internal package to a public registry. Which attack is being described?

A.Dependency confusion attack
B.Supply chain poisoning
C.Typosquatting
D.Man-in-the-middle attack
AnswerA

Dependency confusion exploits a resolver's preference for public registries over private ones. When a package name exists in both, the build tool fetches the attacker's higher-versioned public copy, executing malicious code. This matches the stem's scenario: identical internal and public package names, enabling supply-chain compromise.

Why this answer

This is a dependency confusion attack, where an attacker uploads a malicious package to a public registry (e.g., npm, PyPI, Maven Central) using the same name as a private package used internally by the target organization. When a build system or developer's package manager is configured to check public registries first (or as a fallback), it may download the attacker's malicious version instead of the legitimate internal package, leading to code execution or data exfiltration.

Exam trap

The ISC2 CCSP exam often tests the distinction between 'dependency confusion' and 'supply chain poisoning', but dependency confusion is a specific subtype where the attacker exploits name collision between public and private registries.

How to eliminate wrong answers

Option B (Supply chain poisoning) is wrong because supply chain poisoning is a broader category that includes any compromise of the software supply chain (e.g., injecting malicious code into a legitimate package, compromising build servers), not specifically the act of publishing a package with the same name as an internal one to a public registry. Option C (Typosquatting) is wrong because typosquatting relies on a user mistyping a package name (e.g., 'requsts' instead of 'requests'), not on the exact same name as an internal package. Option D (Man-in-the-middle attack) is wrong because a MITM attack intercepts network traffic between the client and registry (e.g., via ARP spoofing or rogue TLS proxy), not by publishing a package to a public registry.

16
MCQeasy

A healthcare organization is migrating to AWS and must protect electronic protected health information (ePHI) stored in S3. They use AWS KMS with a custom key policy that restricts key usage to specific IAM roles. The compliance team discovers that some S3 objects are encrypted with AWS managed keys (SSE-S3) instead of the required SSE-KMS using the custom key. The security architect needs to ensure all future uploads use the customer-managed KMS key. After implementing a bucket policy that denies s3:PutObject if the required encryption is not present, the development team reports that their existing automation scripts fail with access denied errors. The scripts use the AWS SDK and do not explicitly set encryption headers. The security architect must find a solution that enforces encryption with the custom key while minimizing disruption. Which course of action BEST resolves the issue?

A.Modify the bucket policy to use a Deny effect with a condition on the s3:x-amz-server-side-encryption-aws-kms-key-id header being null, and also enable S3 default encryption with the custom KMS key so that objects uploaded without explicit headers are automatically encrypted with the correct key.
B.Implement AWS Config rules to detect non-compliant objects and automatically re-encrypt them with the correct key, while keeping the bucket policy unchanged.
C.Remove the bucket policy and rely solely on S3 default encryption with the custom KMS key, because default encryption applies to all objects.
D.Create a new S3 bucket with the required policy and migrate all data using AWS DataSync, then delete the old bucket.
AnswerA

Correct: Default encryption catches objects without headers, and the bucket policy denies explicit mismatches, enforcing both backward compatibility and compliance.

Why this answer

It combines a bucket policy that denies s3:PutObject when the s3:x-amz-server-side-encryption-aws-kms-key-id header is null (ensuring the custom KMS key ID is explicitly provided) with S3 default encryption configured to use the same custom KMS key. This dual approach ensures that even if the SDK scripts do not set encryption headers, the default encryption will automatically apply the required KMS key, making the policy condition pass and avoiding access denied errors. The Deny condition on the null header forces explicit encryption headers when they are set, while default encryption handles the case where no headers are provided, thus enforcing compliance without breaking existing automation.

Exam trap

ISC2 often tests the misconception that S3 default encryption alone is sufficient to enforce encryption compliance, but the trap here is that default encryption does not prevent explicit overrides, so a bucket policy with a Deny condition is still needed to block non-compliant uploads.

How to eliminate wrong answers

Option B is wrong because AWS Config rules are reactive and can only detect and remediate non-compliant objects after they are uploaded; they do not prevent the initial upload failure caused by the bucket policy, so the access denied errors would still occur. Option C is wrong because relying solely on S3 default encryption without a bucket policy does not enforce that all uploads use the custom KMS key; a user or script could still override the default encryption by explicitly specifying SSE-S3 or another key, leading to non-compliant objects. Option D is wrong because migrating to a new bucket with AWS DataSync is unnecessarily disruptive, does not address the root cause of the automation scripts not setting encryption headers, and would still require a similar policy and default encryption setup on the new bucket.

17
Multi-Selecthard

When evaluating a cloud service provider's SLA, which TWO metrics are MOST relevant for assessing availability and reliability?

Select 2 answers
A.Uptime percentage (e.g., 99.99%)
B.Support ticket response time
C.Maximum throughput per instance
D.Average latency for API calls
E.Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
AnswersA, E

Uptime percentage quantifies the proportion of agreed service time the provider's service remains operational, directly measuring availability. It is the primary SLA metric for assessing whether the provider meets its committed reliability target over the contract period.

Why this answer

Option A (Uptime percentage, e.g., 99.99%) is correct because uptime is the primary SLA metric that quantifies availability, directly expressing the percentage of time the service is operational and typically tied to service credits when the committed threshold is missed. Option E (Recovery Time Objective (RTO) and Recovery Point Objective (RPO)) is correct because these metrics define reliability in terms of how quickly service is restored after an outage (RTO) and how much data loss is tolerable (RPO), which are core to assessing a provider's resilience and disaster recovery commitments. Option B (Support ticket response time) relates to support quality and incident handling, not directly to availability or reliability guarantees.

Option C (Maximum throughput per instance) is a performance/capacity metric rather than an availability or reliability measure. Option D (Average latency for API calls) is a performance metric that affects responsiveness but does not by itself indicate availability or reliability.

Exam trap

CCSP often tests the distinction between availability and reliability metrics; candidates may confuse performance metrics (latency, throughput) with availability/reliability, or overlook RTO/RPO as key reliability indicators.

18
Multi-Selectmedium

A company's cloud security policy mandates strict control over encryption keys used for data at rest. Which THREE practices are recommended for secure key management in the cloud?

Select 3 answers
A.Rotate encryption keys on a regular schedule.
B.Use a single master key for all encryption operations.
C.Store keys in the same cloud region as the data to reduce latency.
D.Store keys in a separate account from the data storage.
E.Use a hardware security module (HSM) to generate and protect keys.
AnswersA, D, E

Limits the amount of data exposed if a key is compromised.

Why this answer

Regular key rotation limits the window of exposure if a key is compromised and aligns with cryptographic best practices (e.g., NIST SP 800-57). In cloud environments, automated rotation policies (e.g., AWS KMS automatic yearly rotation or manual rotation for customer-managed keys) ensure that even if an attacker obtains an old key, it cannot decrypt current data.

Exam trap

ISC2 often tests the misconception that storing keys in the same region as data is acceptable for performance, but the CCSP emphasizes that security controls (like geographic separation) override minor latency concerns in key management.

19
Multi-Selectmedium

A company is deploying a multi-tier application on AWS. They need to protect the application layer from common web attacks and also restrict traffic between tiers. Which TWO network security controls should they use?

Select 2 answers
A.PrivateLink for database access
B.AWS WAF integrated with Application Load Balancer
C.Security groups between application tiers
D.VPC peering with all VPCs
E.Network ACLs for each subnet
AnswersB, C

AWS WAF attached to an Application Load Balancer inspects HTTP/HTTPS requests at layer 7, blocking SQL injection, cross-site scripting and similar OWASP threats. This satisfies the requirement to protect the application layer from common web attacks.

Why this answer

Option B (AWS WAF integrated with Application Load Balancer) is correct because AWS WAF inspects HTTP/HTTPS requests at Layer 7 and can block common web exploits such as SQL injection and cross-site scripting using managed rule groups attached to an ALB, directly satisfying the requirement to protect the application layer. Option C (Security groups between application tiers) is correct because security groups are stateful, instance-level virtual firewalls whose inbound rules can reference other security groups, allowing precise tier-to-tier traffic restriction (for example, permitting only the app tier's SG to reach the database tier on port 3306). Option A is not appropriate here because PrivateLink provides private connectivity to services and endpoints, not application-layer attack filtering or inter-tier traffic control.

Option D is wrong because VPC peering only connects networks for routing and does not filter or restrict traffic between application tiers. Option E is less suitable because network ACLs are stateless, subnet-level filters that cannot reference security groups or enforce granular per-tier application rules as cleanly as security groups.

20
Multi-Selectmedium

A company subject to SOX is using a cloud ERP system. Which THREE of the following IT general controls are essential for SOX compliance?

Select 3 answers
A.Audit logging of user activities and system changes
B.Physical security of the cloud provider's data centers
C.Access controls to ensure segregation of duties
D.Change management procedures for the ERP system
E.Multi-factor authentication for all cloud provider administrators
AnswersA, C, D

Audit logging captures user activity and system changes in the cloud ERP, creating the tamper-evident trail auditors need to evidence financial reporting integrity. This satisfies SOX's requirement for reliable, reviewable records supporting assertions about transactions and controls over financial systems.

Why this answer

Option A is correct because SOX ITGC requires audit logging of user activities and system changes to provide an evidentiary trail for financial reporting controls, enabling detection of unauthorized or anomalous activity and supporting audit testing. Option C is correct because access controls that enforce segregation of duties prevent any single user from initiating, approving, and recording financial transactions, which is a core SOX requirement to reduce fraud risk over financial data in the ERP. Option D is correct because change management procedures ensure that modifications to the ERP system are authorized, tested, approved, and documented, protecting the integrity and availability of financially relevant applications and data.

Option B is not correct because physical security of the cloud provider's data centers is the provider's responsibility under the shared responsibility model and is typically addressed through SOC 1/SOC 2 reports rather than being an essential control the customer must implement for SOX. Option E is not correct because, while MFA for cloud provider administrators is a good practice, SOX ITGC focuses on the customer's controls over its own users and privileged access to the ERP, not on the cloud provider's internal administrative accounts.

Exam trap

CCSP often tests the shared responsibility boundary — candidates incorrectly select provider-side controls (physical security, CSP admin MFA) as customer SOX controls.

21
MCQhard

A security engineer is reviewing a cloud application that uses OAuth 2.0 to delegate access to a third-party API. The application is a single-page application (SPA) running in the browser. The engineer wants to prevent authorization code interception and ensure that the client cannot impersonate another client. Which OAuth 2.0 enhancement should be implemented?

A.Proof Key for Code Exchange (PKCE)
B.OpenID Connect (OIDC) with the implicit flow
C.Client credentials grant with a client secret
D.Resource owner password credentials grant
AnswerA

PKCE mitigates authorization code interception attacks by requiring the client to send a code verifier that matches a previously sent code challenge. This binds the authorization code to the client that initiated the request, preventing an attacker who intercepts the code from exchanging it. For SPAs, which cannot securely store client secrets, PKCE is the recommended enhancement.

Why this answer

PKCE is specifically designed to secure the authorization code flow for public clients like SPAs that cannot hold a client secret. It prevents code interception by binding the code to a dynamically generated verifier. The implicit flow, client credentials, and resource owner password credentials either expose tokens or require secrets that SPAs cannot protect, and none address code interception.

Exam trap

The trap here is assuming that OIDC or the implicit flow solves SPA security, when PKCE is the required enhancement for the authorization code flow in public clients.

22
MCQmedium

An API endpoint returns user profile data including fields like 'credit_card_number' even when the client application does not need it. Which OWASP API security risk does this represent?

A.Injection
B.Broken Object Level Authorization
C.Mass Assignment
D.Excessive Data Exposure
AnswerD

Excessive Data Exposure occurs when an API returns full object properties and relies on the client to filter fields, so sensitive attributes like credit_card_number reach clients that never needed them. This matches the stem exactly, unlike Broken Object Property Level Authorisation.

Why this answer

The API returns sensitive data (credit_card_number) that the client application does not need, violating the principle of least data exposure. This is a classic Excessive Data Exposure risk (OWASP API Security Top 10 #3), where the server trusts the client to filter the response rather than limiting the fields returned based on the client's actual authorization or need.

Exam trap

ISC2 often tests the distinction between Excessive Data Exposure and Mass Assignment, where candidates mistakenly choose Mass Assignment because both involve 'extra data,' but Mass Assignment specifically applies to write operations (e.g., PUT/POST) where an attacker modifies fields they shouldn't, not to read responses.

How to eliminate wrong answers

Option A is wrong because Injection (e.g., SQL, NoSQL, OS command) involves untrusted data being sent to an interpreter as part of a command or query, not the passive return of unnecessary fields in a response. Option B is wrong because Broken Object Level Authorization (BOLA) deals with an attacker accessing objects (e.g., user profiles) they should not have permission to view, not the server returning extra fields within an authorized response. Option C is wrong because Mass Assignment (also known as Autobinding) occurs when user-supplied input is bound to internal object properties without proper filtering, typically in create/update operations, not in a read-only response that simply includes extra fields.

23
MCQmedium

A DevOps team is implementing a CI/CD pipeline for a cloud application. They want to automatically scan source code for security vulnerabilities before building the application. Which type of scanning should they integrate?

A.Interactive Application Security Testing (IAST)
B.Dynamic Application Security Testing (DAST)
C.Static Application Security Testing (SAST)
D.Runtime Application Self-Protection (RASP)
AnswerC

Static Application Security Testing analyses source code without executing it, satisfying the requirement to scan before the build stage. It inspects code artefacts directly for vulnerabilities such as injection flaws, giving the DevOps team early feedback in the CI/CD pipeline prior to compilation or deployment.

Why this answer

Static Application Security Testing (SAST) analyzes source code, bytecode, or binaries without executing the application, making it ideal for scanning code in a CI/CD pipeline before the build stage. It detects vulnerabilities such as SQL injection, XSS, and hardcoded secrets by inspecting code patterns and data flows. Integrating SAST early shifts security left, catching flaws before they reach runtime.

Exam trap

CCSP often tests the SAST/DAST/IAST/RASP distinction — candidates pick DAST because it sounds like 'scanning,' but only SAST analyzes source code without executing the application.

How to eliminate wrong answers

Option A is wrong because IAST instruments a running application during testing (often QA), so it requires execution and is not a pre-build source scan. Option B is wrong because DAST tests a running application from the outside by sending requests, which requires a deployed build and cannot scan source code. Option D is wrong because RASP runs inside the application at runtime to block attacks, providing protection rather than pre-build source analysis.

24
MCQhard

A multinational corporation must comply with GDPR and store EU customer data only within the European Union. Which cloud storage security measure directly addresses this requirement?

A.Pre-signed URLs
B.Data residency configuration
C.Bucket policies with IAM conditions
D.Cross-region replication
AnswerB

Data residency configuration pins storage and processing to specific geographic regions, so EU customer data remains physically within the European Union. This directly satisfies the GDPR locality constraint, unlike encryption, access controls or tokenisation, which protect confidentiality but do not restrict where data is stored.

Why this answer

Data residency configuration lets an organization pin where cloud data is stored and processed — for example, restricting an S3 bucket, Azure region, or GCP location to EU regions so EU customer data never leaves the European Union. This directly satisfies GDPR's data-location requirement by enforcing geographic placement at the storage/service level. It is the control that maps one-to-one to the 'store EU data only in the EU' mandate.

Exam trap

CCSP often tests the confusion between access control (bucket policies, IAM, pre-signed URLs) and data placement (residency) — candidates pick a strong-sounding access control when the question is specifically about where data is stored.

How to eliminate wrong answers

Option A is wrong because pre-signed URLs only grant temporary, time-limited access to a specific object; they say nothing about where the object is stored and cannot enforce geographic boundaries. Option C is wrong because bucket policies with IAM conditions control who can access data and under what conditions (IP, MFA, time), not where the data physically resides — a permissive policy still allows storage in any region. Option D is wrong because cross-region replication deliberately copies data to other regions, which would violate the EU-only residency requirement rather than satisfy it.

25
MCQmedium

A company uses a cloud provider's key management service. They want to rotate keys automatically every 90 days. What is the correct way to achieve this?

A.Enable automatic key rotation in the KMS settings.
B.Manually update the key alias each quarter.
C.Create a new key and update all applications to use it.
D.Use a third-party HSM.
AnswerA

Enabling automatic key rotation in the KMS settings lets the service generate new key material on a defined schedule, such as every 90 days, without manual intervention. This satisfies the rotation requirement natively, whereas manual rotation would not meet the automated 90-day cadence.

Why this answer

Cloud KMS services (e.g., AWS KMS, Azure Key Vault, GCP Cloud KMS) offer a built-in automatic key rotation feature that can be configured to rotate the key material every 90 days without any manual intervention. Enabling this setting ensures that new cryptographic material is generated for the key, while the old key material remains available for decrypting data encrypted with it, maintaining seamless security compliance.

Exam trap

ISC2 often tests the misconception that updating a key alias or creating a new key manually is equivalent to automatic rotation, when in fact automatic rotation is a specific KMS feature that preserves key continuity and requires no application changes.

How to eliminate wrong answers

Option B is wrong because updating a key alias does not change the underlying key material; it only reassigns a friendly name to the same key, so it does not achieve rotation. Option C is wrong because creating a new key and updating all applications to use it is a manual, error-prone process that defeats the purpose of automated rotation and can cause decryption failures if old data is not re-encrypted. Option D is wrong because a third-party HSM (Hardware Security Module) is used for generating and storing keys outside the cloud KMS, but it does not provide automatic key rotation; rotation would still need to be implemented separately.

26
MCQmedium

A company is required to encrypt all data in transit between its on-premises data center and its cloud environment. They have a hybrid cloud setup and need a secure tunnel for all traffic. Which solution should they implement?

A.Client-side encryption
B.Pre-signed URLs
C.VPN connection
D.TLS 1.2+ for all API calls
AnswerC

A VPN connection builds an encrypted IPsec tunnel between the on-premises gateway and the cloud endpoint, encapsulating all traffic crossing the public internet. This directly satisfies the requirement to encrypt data in transit across the hybrid link, unlike object-storage encryption or key-management services, which protect data at rest rather than the network path.

Why this answer

A VPN connection creates an encrypted IPsec tunnel between the on-premises data center and the cloud environment, securing all traffic in transit across the public internet for a hybrid setup. This satisfies the requirement for a secure tunnel for all traffic, not just API calls. Client-side encryption, pre-signed URLs, and TLS for API calls address different scopes and do not provide a site-to-site encrypted tunnel.

Exam trap

The trap is choosing TLS for API calls because it sounds like 'encryption in transit' — but the question asks for a secure tunnel for ALL traffic in a hybrid setup, which requires a site-to-site VPN, not application-layer TLS.

How to eliminate wrong answers

Option A is wrong because client-side encryption protects data before it is sent to the cloud but does not create a secure network tunnel for all traffic between sites. Option B is wrong because pre-signed URLs are time-limited access links to specific objects in object storage, not a transport encryption mechanism for hybrid connectivity. Option D is wrong because TLS 1.2+ secures individual API calls (application-layer encryption) but does not encrypt all traffic between the data center and cloud, nor does it provide a persistent tunnel for non-HTTP protocols.

27
MCQhard

A cloud security engineer is configuring network security for a multi-tier application in AWS. The web servers must be accessible from the internet on port 443, the application servers should only receive traffic from the web servers, and the database servers should only accept traffic from the application servers on port 3306. Which combination of security controls should be used?

A.Security groups with source referencing the web server security group for app tier, and app server security group for DB tier
B.NACLs on each subnet with rules referencing source IP ranges
C.A single NACL applied to all subnets with layer 7 filtering
D.Route tables with deny rules to restrict inter-subnet traffic
AnswerA

Security groups support source referencing, so the app tier's inbound rule names the web server security group and the database tier's names the app server security group. This enforces the tiered traffic flow on port 3306 without hard-coded CIDRs, satisfying the stem's constraints.

Why this answer

In AWS, security groups are stateful virtual firewalls that can reference other security groups as sources. For the web tier, allow inbound 443 from 0.0.0.0/0. For the app tier, allow inbound from the web server security group.

For the DB tier, allow inbound on 3306 from the app server security group. This creates a least-privilege, layered defense without hardcoding IP addresses.

Exam trap

CCSP often tests the difference between security groups (stateful, instance-level, allow rules only) and NACLs (stateless, subnet-level, allow/deny rules), and candidates may incorrectly choose NACLs for dynamic, least-privilege control.

How to eliminate wrong answers

Option B is wrong because NACLs are stateless and operate at the subnet level; referencing source IP ranges is less dynamic and does not automatically adapt to autoscaling web servers, increasing management overhead and risk of misconfiguration. Option C is wrong because a single NACL with layer 7 filtering is not possible—NACLs operate at layers 3 and 4 and cannot inspect application-layer data. Option D is wrong because route tables control routing, not security; they do not have deny rules for inter-subnet traffic in the way described, and security is not their purpose.

28
MCQhard

A cloud security engineer is reviewing incident response procedures for a hybrid cloud environment. During a security incident, the team needs to collect forensic evidence from a compromised virtual machine while preserving its state. Which of the following actions should be taken first?

A.Take a snapshot of the virtual machine's disk
B.Notify the cloud provider
C.Disconnect the virtual machine from the network
D.Install a forensic agent on the virtual machine
AnswerC

Disconnecting the VM from the network isolates it, preventing further attacker activity, data exfiltration or remote tampering while leaving memory and disk state intact for capture. This preserves volatile evidence before any snapshot or acquisition step alters the system.

Why this answer

Disconnecting the VM from the network is the first step to prevent further compromise, stop data exfiltration, and preserve the current state of the VM's memory and disk for forensic analysis. This isolates the VM without altering its running state, allowing later snapshot or memory capture. Notifying the provider or installing agents could tip off attackers or modify the system, and taking a snapshot first might capture a compromised state but doesn't stop ongoing malicious activity.

Exam trap

CCSP often tests the misconception that evidence collection (e.g., snapshot) should come before containment, but containment is always the first priority to stop the spread and preserve volatile data.

How to eliminate wrong answers

Option A is wrong because taking a snapshot first does not prevent ongoing attacker activity or data leakage; isolation should precede evidence collection. Option B is wrong because notifying the cloud provider is not the first action; it may be required later but does not immediately contain the incident. Option D is wrong because installing a forensic agent modifies the VM and could alert the attacker, and it is not a containment step.

29
Multi-Selectmedium

Which THREE of the following are effective measures to prevent unauthorized access to cloud storage buckets? (Select THREE)

Select 3 answers
A.Enabling bucket versioning
B.Enabling 'Block all public access' settings
C.Enabling server-side encryption
D.Requiring identity and access management (IAM) authentication for all access
E.Setting bucket access control lists (ACLs) to 'private'
AnswersB, D, E

Blocking all public access overrides bucket policies and ACLs that would otherwise expose objects, preventing anonymous or unintended internet reads. This directly satisfies the requirement by closing the most common unauthorised access path to cloud storage.

Why this answer

Option B is correct because enabling 'Block all public access' settings on a cloud storage bucket prevents any anonymous or public read/write access, which is a primary vector for unauthorized access. Option D is correct because requiring IAM authentication for all access ensures every request is evaluated against identity-based policies, so only authenticated and authorized principals can reach the bucket. Option E is correct because setting bucket ACLs to 'private' removes grants to AllUsers and AuthenticatedUsers, restricting access to the bucket owner and explicitly authorized accounts.

Option A does not belong because bucket versioning only preserves object versions for recovery and does not control who can access the bucket. Option C does not belong because server-side encryption protects data at rest from disclosure but does not prevent unauthorized users from accessing the bucket if permissions are misconfigured.

Exam trap

CCSP often tests the difference between access control measures and data protection measures — candidates select encryption or versioning because they sound security-related, missing that the question asks specifically about preventing unauthorized access.

30
MCQmedium

A cloud security team is implementing VPC peering between two VPCs in the same region. Which statement about VPC peering is correct?

A.VPC peering requires VPN gateways to establish connectivity
B.VPC peering enables private IP connectivity across VPCs without internet
C.VPC peering automatically encrypts all traffic between VPCs
D.VPC peering supports transitive routing through intermediate VPCs
AnswerB

VPC peering establishes a direct routing relationship between two VPCs using their private IPv4 or IPv6 addresses, so instances communicate over the cloud provider's internal backbone. Traffic never traverses the public internet, satisfying the private connectivity requirement without gateways or VPNs.

Why this answer

VPC peering creates a direct, private network route between two VPCs using their private IPv4 or IPv6 CIDR blocks, so instances communicate as if on the same network without traversing the public internet, VPN, or a NAT device. Traffic stays on the cloud provider's backbone, which is why it is considered private connectivity. This is the defining characteristic of VPC peering and the reason it is used for cross-VPC application tiers, shared services, and multi-account architectures.

Exam trap

The trap here is conflating 'private connectivity' with 'encrypted connectivity' — candidates assume private automatically means encrypted, but VPC peering provides routing isolation, not cryptographic protection.

How to eliminate wrong answers

Option A is wrong because VPC peering does not require VPN gateways — it is a native routing relationship between VPCs, not an IPsec tunnel; VPN gateways are used for site-to-site or client VPN connectivity. Option C is wrong because VPC peering does not automatically encrypt traffic; it provides private routing, and encryption must be added separately (e.g., TLS at the application layer) if required. Option D is wrong because VPC peering is explicitly non-transitive — if VPC A peers with B and B peers with C, A cannot reach C through B; a direct peering or a transit gateway is needed.

31
Multi-Selecteasy

A cloud architect is designing a data classification scheme for a financial services firm. The data includes public marketing materials, internal emails, customer account numbers, and credit card information. Which two data categories should be classified as 'restricted' under PCI DSS and other regulations?

Select 2 answers
A.Public marketing materials
B.Credit card information
C.Internal emails
D.Customer account numbers
AnswersB, D

PCI DSS mandates the strictest protection for cardholder data, including the primary account number. Credit card information therefore belongs in the restricted category, alongside customer account numbers, because its exposure triggers regulatory breach notification and heavy penalties.

Why this answer

Credit card information (B) is correctly classified as restricted because PCI DSS explicitly governs cardholder data, including the Primary Account Number (PAN) and sensitive authentication data, requiring strong encryption, masking, and strict access controls. Customer account numbers (D) also belong in the restricted category because they are regulated non-public personal information (NPI) under financial privacy laws such as GLBA, and their exposure can enable identity theft or account takeover. Public marketing materials (A) are intended for open distribution and carry no confidentiality requirement, so they are not restricted.

Internal emails (C) may contain sensitive content, but as a general category they are typically classified as internal or confidential rather than restricted, since not every internal email includes regulated data.

Exam trap

ISC2 often tests the misconception that all internal communications (like emails) are automatically 'restricted' under PCI DSS, when in fact only data containing specific regulated elements (e.g., PANs, SAD) qualifies for that classification.

32
MCQeasy

An analyst receives the above error when trying to download a file from a cloud storage bucket. The bucket policy and user permissions appear correct. What is the most likely cause?

A.The object is encrypted with server-side encryption using a provider-managed key, which requires additional grants
B.The bucket is configured to block all public access
C.The bucket policy denies all GetObject actions
D.The user lacks permission to decrypt the object using the customer-managed encryption key
AnswerD

Bucket policies and identity permissions govern access to the object, but decryption of a customer-managed key requires separate key permissions. Without decrypt rights on the KMS key, the download fails even though the storage-level permissions appear correct.

Why this answer

When a cloud storage object is encrypted with a customer-managed encryption key (CMEK), the GetObject API call requires the user to have both GetObject permission on the bucket policy and Decrypt permission on the specific encryption key. Even if the bucket policy and user IAM permissions appear correct for storage actions, the absence of the decrypt permission on the key will cause an access denied error. This is a common misconfiguration because the error message does not explicitly mention the key, leading analysts to overlook the key permission.

Exam trap

ISC2 often tests the misconception that bucket policies and IAM permissions alone control access to encrypted objects, ignoring the separate key permission layer required for objects encrypted with customer-managed keys.

How to eliminate wrong answers

Option A is wrong because SSE-S3 (AES-256) uses server-side encryption with Amazon S3-managed keys, which do not require any additional grants or KMS permissions; the error would not occur due to missing grants. Option B is wrong because if the bucket were configured to block all public access, the error would typically be a 403 Access Denied, but the scenario states the bucket policy and user permissions appear correct, implying the bucket is not blocking all access. Option C is wrong because if the bucket policy denied all s3:GetObject actions, the user would consistently fail to download any object, but the analyst would likely see a different error or the policy would be obviously incorrect; the question states the policy 'appears correct,' so a blanket deny is not the most likely cause.

33
MCQmedium

A healthcare company stores medical images in a cloud object storage bucket. The images are accessed by radiologists via a web application. The security team wants to ensure that data is encrypted in transit and that the encryption keys are not accessible to the cloud provider. Which solution should they implement?

A.Enable server-side encryption with customer-provided keys (SSE-C) and enforce HTTPS for all access.
B.Configure the bucket to use HTTPS with TLS 1.2 and enable server-side encryption with provider-managed keys.
C.Implement client-side encryption with keys stored in an on-premises HSM and enforce HTTPS for all access.
D.Use client-side encryption with keys stored in the cloud provider's KMS and enforce HTTPS for all access.
AnswerC

Client-side encryption with keys in an on-premises HSM ensures the cloud provider never has access to the keys, satisfying the key control requirement. Enforcing HTTPS encrypts data in transit. Together, these meet both requirements: data is encrypted in transit and the provider cannot access the encryption keys.

Why this answer

Client-side encryption with keys held in an on-premises HSM ensures the cloud provider never possesses the key material, so the provider cannot access the plaintext. Enforcing HTTPS encrypts data in transit, meeting both the transit encryption and key control requirements. This combination provides the necessary security for sensitive medical images.

Exam trap

The trap here is assuming that server-side encryption with customer-provided keys (SSE-C) keeps keys inaccessible to the provider, when in fact the keys are used within the provider's environment and could be exposed.

34
Multi-Selectmedium

Which TWO are effective strategies for securing cloud application data at rest?

Select 2 answers
A.Role-based access control
B.Database activity monitoring
C.File-level encryption
D.Transparent data encryption
E.Network segmentation
AnswersC, D

File-level encryption protects data at rest per file or object, so each item carries its own cryptographic boundary independent of the storage volume. This satisfies the stem's at-rest requirement by securing data even when underlying storage, snapshots or backups are exposed, unlike volume-level controls.

Why this answer

File-level encryption (C) is correct because it encrypts individual files or folders on disk, ensuring that data at rest remains unreadable even if the underlying storage or host is compromised. Transparent data encryption (D) is correct because it encrypts database files and backups at rest at the storage engine level, protecting data without requiring application changes. Both directly address the confidentiality of stored data, which is the core goal of securing data at rest.

Role-based access control (A) governs who may access resources but does not itself encrypt stored data. Database activity monitoring (B) detects and alerts on suspicious database activity but is a detective control, not a data-at-rest protection. Network segmentation (E) limits lateral movement and exposure but does not protect data at rest on storage media.

Exam trap

ISC2 often tests the distinction between access control (RBAC) and encryption, where candidates mistakenly think that restricting access is sufficient to secure data at rest, ignoring that encryption is required to protect against physical theft or unauthorized storage-level access.

35
MCQeasy

A company is migrating its customer database to a cloud object storage service. The database contains personally identifiable information (PII). The security team requires that all data be encrypted at rest and that the company retains exclusive control over the encryption keys. Which solution BEST meets these requirements?

A.Use server-side encryption with cloud provider-managed keys (SSE-S3).
B.Use SSL/TLS encryption for data in transit only.
C.Use client-side encryption with customer-managed keys stored on-premises.
D.Use server-side encryption with customer-provided keys (SSE-C).
AnswerC

Client-side encryption encrypts data before it reaches the object store, and keys held on-premises mean the provider never possesses them. This satisfies both stem requirements: encryption at rest and exclusive customer control over the encryption keys.

Why this answer

Client-side encryption with customer-managed keys stored on-premises ensures that the encryption keys never leave the company's control, and the data is encrypted before it is uploaded to the cloud object storage service. This satisfies both the requirement for encryption at rest and exclusive key control, as the cloud provider never has access to the plaintext keys or the ability to decrypt the data.

Exam trap

The trap here is that candidates often confuse SSE-C with client-side encryption, assuming that providing your own key to the server (SSE-C) gives you exclusive control, but in SSE-C the cloud provider still handles the encryption/decryption process and may retain the key in memory, whereas client-side encryption ensures the provider never sees the key at all.

How to eliminate wrong answers

Option A is wrong because server-side encryption with cloud provider-managed keys (SSE-S3) means the cloud provider generates, manages, and stores the encryption keys, giving the provider potential access to the keys and violating the requirement for exclusive customer control. Option B is wrong because SSL/TLS encryption only protects data in transit between the client and the cloud service; it does not provide encryption at rest for the stored database, so it fails the core requirement. Option D is wrong because server-side encryption with customer-provided keys (SSE-C) still involves the cloud provider performing the encryption and decryption operations using keys supplied by the customer, meaning the provider has temporary access to the keys in memory during operations, which does not meet the requirement for exclusive customer control over the keys.

36
MCQeasy

A cloud engineer is configuring logging for an AWS Lambda function that processes sensitive data. The security team requires that all invocations are logged, including the request and response payloads, and that logs are retained for 90 days. Which action should the engineer take?

A.Enable AWS X-Ray tracing for the Lambda function and configure a 90-day retention for X-Ray traces.
B.Use AWS Config to record Lambda function configurations and set a 90-day retention for configuration history.
C.Configure the Lambda function to log to Amazon CloudWatch Logs and set the log group retention to 90 days.
D.Enable AWS CloudTrail logging for the Lambda function and configure a CloudWatch Logs retention policy of 90 days.
AnswerC

Lambda automatically logs to CloudWatch Logs if the function's execution role has permissions. By adding logging statements in the function code, the engineer can log request and response payloads. Setting the CloudWatch Logs retention policy to 90 days meets the retention requirement. This is the standard way to capture detailed invocation logs, including payloads, for Lambda functions.

Why this answer

To log all invocations with request and response payloads, the Lambda function must write logs to CloudWatch Logs. This is done by including logging statements in the function code. CloudWatch Logs allows setting a retention policy of 90 days.

CloudTrail, X-Ray, and AWS Config do not capture full payloads, so they are not suitable.

Exam trap

The trap here is assuming that CloudTrail or X-Ray can capture full request and response payloads for Lambda invocations.

37
Multi-Selecthard

A cloud architect is designing a federated identity solution so that employees of a partner company can access a shared SaaS application without creating separate local accounts. The architect must select mechanisms that enable secure cross-domain authentication and attribute exchange. (Choose two.)

Select 2 answers
A.OpenID Connect (OIDC)
B.Data Loss Prevention (DLP) endpoint agent
C.Internet Protocol Security (IPsec) transport mode
D.Dynamic Host Configuration Protocol (DHCP) snooping
E.Security Assertion Markup Language (SAML) 2.0
AnswersA, E

OIDC builds on OAuth 2.0 to provide federated authentication and delivers identity attributes through the ID token and UserInfo endpoint. It enables partner users to authenticate through their home identity provider and access the SaaS application without local accounts, satisfying the cross-domain authentication and attribute exchange requirement.

Why this answer

Federated identity requires protocols that carry authentication assertions and user attributes across security domains. SAML 2.0 and OpenID Connect both do this, allowing partner employees to authenticate with their home identity provider and access the shared SaaS application without local accounts. IPsec, DLP endpoint agents, and DHCP snooping operate at network or data layers and cannot federate identities.

Exam trap

The trap here is selecting a transport security mechanism such as IPsec, which protects packets but never authenticates users across domains.

38
MCQmedium

A global e-commerce company must store customer payment data in a specific geographic region to comply with local data residency laws. Which cloud configuration ensures that data never leaves the required region?

A.Use a global load balancer to route traffic
B.Enable cross-region replication to a secondary region for disaster recovery
C.Store data in a private cloud on-premises
D.Select a specific cloud region for the storage and disable cross-region replication
AnswerD

Selecting a specific cloud region pins data at rest to that geography, and disabling cross-region replication prevents automatic copying to paired or secondary regions. This directly satisfies the data residency constraint, since no replication mechanism can move payment data outside the required jurisdiction.

Why this answer

Data residency is achieved by selecting a cloud region (e.g., 'EU-West-1') and configuring storage buckets or databases with region-specific policies. Additionally, bucket policies can explicitly deny access from outside the region, and replication features should be disabled or configured to stay within the region.

39
MCQeasy

Which phase of the cloud data lifecycle involves making data available for processing by applications and users?

A.Archive
B.Store
C.Use
D.Create
AnswerC

The Use phase covers data being made available to applications and users for processing, following Create, Store and before Share, Archive and Destroy. It is the lifecycle stage where authorised consumers actively access and work with the data.

Why this answer

The Use phase of the cloud data lifecycle is when data is made available to applications and users for processing, analysis, and consumption. It follows Create and Store, and precedes Share, Archive, and Destroy. During Use, controls like access management, encryption in use, and monitoring are applied to protect data while it is actively being processed.

Exam trap

The trap is confusing Store with Use — candidates often pick 'Store' because data must be stored before it can be used, but the question specifically asks about making data available for processing, which is the Use phase.

How to eliminate wrong answers

Option A is wrong because Archive is the phase where data is moved to long-term, low-cost storage for retention and is not actively processed. Option B is wrong because Store is the phase where data is persisted in the storage medium, not the phase where it is made available for processing. Option D is wrong because Create is the phase where new data is generated or acquired, before it is stored or used.

40
MCQhard

A cloud-native application uses a microservices architecture deployed on Kubernetes. The security team wants to ensure that only authorized services can communicate with each other, and that communication is encrypted. Which Kubernetes feature should be used to meet these requirements?

A.Role-Based Access Control (RBAC) to restrict which services can access the Kubernetes API.
B.Kubernetes Secrets to store service credentials and TLS certificates.
C.Pod Security Policies to enforce security contexts and prevent privileged containers.
D.Network Policies with a service mesh like Istio for mutual TLS.
AnswerD

Network Policies control pod-to-pod communication at Layer 3/4, but they do not encrypt traffic. A service mesh like Istio provides mutual TLS (mTLS) for service-to-service encryption and can enforce authorization policies. Together, they ensure only authorized services communicate and that traffic is encrypted, meeting both requirements.

Why this answer

Network Policies provide segmentation by allowing or denying traffic between pods based on labels and namespaces. However, they do not encrypt traffic. A service mesh like Istio adds mutual TLS (mTLS) to encrypt all service-to-service communication and can enforce fine-grained authorization policies.

Using both together ensures that only authorized services communicate and that the traffic is encrypted.

Exam trap

The trap here is assuming that Network Policies alone provide encryption, or that RBAC or Secrets can secure service communication, when they address different layers.

41
Multi-Selecthard

Which TWO of the following are effective methods to protect against server-side request forgery (SSRF) in a cloud application? (Choose two.)

Select 2 answers
A.Use SSL inspection to check for malicious payloads
B.Whitelist allowed outbound destinations
C.Block all outbound network traffic from the application
D.Disable unused URL schemes such as file:// and dict://
E.Sanitize all user input for URL parameters
AnswersB, D

Whitelisting prevents requests to internal or malicious hosts.

Why this answer

Whitelisting allowed outbound destinations is a primary defense against SSRF. By explicitly permitting only trusted external hosts (e.g., specific API endpoints or internal services), the application cannot be tricked into making requests to arbitrary internal or external targets, even if an attacker controls the URL parameter.

Exam trap

ISC2 often tests the misconception that input sanitization alone is sufficient for SSRF protection, when in reality the attack exploits the server's trust in the destination, not the input format, making whitelisting and scheme restrictions the effective controls.

42
MCQhard

A company uses a cloud key management service with customer-managed keys to encrypt data in a cloud storage bucket. The security team wants to ensure that if a key is compromised, they can revoke the cloud service's ability to decrypt the data immediately. What should they do?

A.Rotate the key to a new version.
B.Delete the key permanently from the cloud key management service.
C.Regenerate the key material by importing a new key.
D.Disable the key in the cloud key management service or revoke the key's access permissions for the cloud service.
AnswerD

Disabling the customer-managed key or revoking the cloud service's grant removes its ability to unwrap the data encryption key, immediately halting decryption. This satisfies the requirement for instant revocation of the service's decryption capability if the key is compromised.

Why this answer

Disabling the customer-managed key or revoking the cloud service's permissions to use it immediately prevents the service from performing cryptographic operations with that key, effectively cutting off decryption. This is a reversible, fast action that preserves the key material for potential recovery. It directly addresses the requirement to revoke the cloud service's ability to decrypt data immediately.

Exam trap

CCSP often tests the difference between key rotation, deletion, and disabling — candidates pick rotation or deletion thinking they revoke access, but only disabling or revoking permissions immediately stops decryption without destroying the key.

How to eliminate wrong answers

Option A is wrong because rotating the key creates a new key version but does not revoke access to existing data encrypted under the old version; the service can still decrypt old ciphertext with the previous version. Option B is wrong because deleting the key permanently is destructive and irreversible after the waiting period, and it does not provide immediate revocation without risking data loss; deletion also has a mandatory waiting period in most KMS services. Option C is wrong because regenerating key material by importing a new key creates a new key or version and does not immediately revoke the cloud service's access to the existing key used for the data.

43
MCQmedium

A security engineer needs to automate the remediation of any S3 bucket that is publicly accessible. The solution should work within a single AWS account and not require manual intervention. Which combination of services is MOST appropriate?

A.AWS Config rule + AWS Lambda auto-remediation
B.Amazon GuardDuty + AWS Step Functions
C.AWS CloudTrail + Amazon SNS
D.AWS Trusted Advisor + AWS Systems Manager
AnswerA

AWS Config continuously evaluates bucket policies and ACLs against a rule flagging public access, then triggers Lambda for automatic remediation. This satisfies the no-manual-intervention constraint within one account, because Config detects drift and Lambda removes the public grant without human approval.

Why this answer

AWS Config can continuously evaluate S3 bucket settings against a custom or managed rule (e.g., s3-bucket-public-read-prohibited). When the rule detects a noncompliant bucket, it triggers an AWS Lambda function via auto-remediation, which can modify the bucket's ACL or policy to remove public access. This combination provides fully automated, event-driven remediation without manual steps.

Exam trap

In the CCSP exam context, candidates often confuse detection services (GuardDuty, CloudTrail) with configuration enforcement services (AWS Config), leading them to select a solution that only detects but does not remediate public S3 buckets.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity (e.g., unusual API calls), not a configuration compliance tool; it cannot directly enforce S3 bucket policies. Option C is wrong because AWS CloudTrail records API activity but does not evaluate or remediate configurations, and Amazon SNS only sends notifications, not automated fixes. Option D is wrong because AWS Trusted Advisor provides best-practice checks and recommendations, but it does not offer native auto-remediation; AWS Systems Manager can automate actions but requires custom runbooks and is not designed for real-time S3 bucket compliance enforcement.

44
MCQmedium

A DevOps team is deploying an application that will store encryption keys in a cloud KMS. The security policy requires that keys be stored in a hardware security module (HSM) and that key material never leaves the HSM boundary. Which key management option should they choose?

A.Customer-managed encryption keys (CMEK) with software-backed storage
B.Cloud KMS with HSM-backed key storage
C.Hold your own key (HYOK) with on-premises HSM
D.Bring your own key (BYOK) with key import to cloud KMS
AnswerB

HSM-backed key storage generates and retains key material inside a validated hardware module, so cryptographic operations occur within the HSM boundary and keys are never exported. This directly satisfies the policy that key material must never leave the HSM.

Why this answer

Cloud KMS with HSM-backed key storage ensures that key material is generated and stored inside a FIPS 140-2 Level 3 validated HSM, and cryptographic operations occur within the HSM boundary. This satisfies the requirement that keys be stored in an HSM and that key material never leaves the HSM.

Exam trap

CCSP often tests the distinction between BYOK (importing key material) and HSM-backed keys (where the key is generated and stored in an HSM) — candidates may assume BYOK automatically means HSM, but it does not.

How to eliminate wrong answers

Option A is wrong because software-backed CMEK stores key material in software, not an HSM, violating the HSM requirement. Option C is wrong because HYOK with an on-premises HSM keeps keys outside the cloud, but the question asks for a cloud KMS option where keys are stored in an HSM — HYOK also introduces latency and operational complexity, and the key material is not in the cloud KMS. Option D is wrong because BYOK with key import allows you to bring your own key material into cloud KMS, but the imported key material may be stored in software-backed KMS unless you specifically choose HSM-backed keys; BYOK alone does not guarantee HSM storage.

45
MCQhard

Refer to the exhibit. A security engineer discovers that the S3 bucket policy allows public read access from the entire corporate network (10.0.0.0/16). However, the company wants to restrict access only to the security team's subnet (10.0.1.0/24). What modification should be made to the policy?

A.Add a Deny statement for the 10.0.0.0/16 range.
B.Add a Deny statement for IP addresses outside 10.0.1.0/24.
C.Remove the Condition element to allow access from any IP.
D.Change the Condition value to "aws:SourceIp": "10.0.1.0/24".
AnswerD

The aws:SourceIp condition currently permits the whole 10.0.0.0/16 range, so narrowing that value to 10.0.1.0/24 restricts bucket access to the security team's subnet. This satisfies the stem's requirement to limit public read access to that subnet only.

Why this answer

Modifying the Condition value to "aws:SourceIp": "10.0.1.0/24" directly restricts the S3 bucket policy to allow read access only from the security team's subnet. The original policy uses the aws:SourceIp condition key with the broader 10.0.0.0/16 range, so narrowing it to 10.0.1.0/24 precisely enforces the required access control. This approach leverages AWS IAM policy evaluation logic where an explicit Allow with a condition must be satisfied for access to be granted.

Exam trap

ISC2 often tests the misconception that adding a Deny statement for the broader range (Option A) is the correct way to narrow access, but candidates fail to realize that Deny would block the intended subnet as well, whereas modifying the Condition value is the proper method to restrict an existing Allow.

How to eliminate wrong answers

Option A is wrong because adding a Deny statement for the 10.0.0.0/16 range would block all traffic from the corporate network, including the security team's subnet (10.0.1.0/24), which is the opposite of the desired outcome. Option B is wrong because adding a Deny for IP addresses outside 10.0.1.0/24 is overly broad and would deny access from any IP not in that subnet, but the original policy already has an Allow for 10.0.0.0/16; a Deny for all other IPs would not fix the over-permissive Allow and could cause unintended conflicts in policy evaluation (Deny always overrides Allow). Option C is wrong because removing the Condition element would allow access from any IP address, which completely violates the security requirement to restrict access to the security team's subnet.

46
MCQmedium

A cloud security team is reviewing data retention for a software-as-a-service application hosted in a public cloud. Legal counsel requires that customer data be deleted permanently when a subscription ends, and that deletion be demonstrable to auditors. The cloud provider's storage system uses log-structured storage and maintains replicas across multiple availability zones. Which action best supports demonstrable, permanent deletion?

A.Delete the objects through the provider's API and rely on the provider's standard garbage collection.
B.Use cryptographic erasure by destroying the customer-specific encryption key, and retain the key-destruction audit record.
C.Ask the cloud provider to issue a media-sanitization certificate for the underlying disks.
D.Overwrite the objects with random data before deleting them from the bucket.
AnswerB

Cryptographic erasure renders data unrecoverable by destroying the key that protects it, even if encrypted remnants persist on media or replicas. Because the key destruction event can be logged and attested, it produces demonstrable evidence for auditors. This method is well suited to multi-tenant, replicated cloud storage where physical media cannot be individually sanitized.

Why this answer

Cryptographic erasure destroys the key that protects a customer's data, making the ciphertext permanently unrecoverable even if remnants persist on replicated or log-structured media. The key-destruction event can be logged and attested, giving auditors the evidence legal counsel requires. API deletion, overwriting, and tenant-level media sanitization cannot guarantee or demonstrate that every copy is gone in shared cloud storage.

Exam trap

The trap here is assuming that deleting an object or overwriting it removes every replica, when shared, log-structured cloud storage may retain inaccessible blocks that only key destruction can neutralize.

47
MCQmedium

A security team is setting up a DLP solution to scan cloud storage for credit card numbers. They want to automatically mask the detected credit card numbers so that only the last four digits are visible. Which DLP de-identification transform should they use?

A.Pseudonymization
B.Bucketing
C.Tokenization
D.Masking
AnswerD

Masking replaces characters within the detected credit card number, exposing only the final four digits while obscuring the rest. This directly satisfies the requirement that only the last four digits remain visible, unlike tokenization, which substitutes the entire value with an unrelated surrogate.

Why this answer

Masking replaces sensitive values with a redacted or partially obscured version — for credit card numbers, showing only the last four digits (e.g., **** **** **** 1234) while hiding the rest. It is a de-identification transform that preserves format and usability for display/analytics without exposing the full PAN. This matches the requirement exactly: detect and automatically mask so only the last four digits remain visible.

Exam trap

CCSP often tests the distinction between reversible de-identification (tokenization, pseudonymization) and irreversible display-oriented transforms (masking) — candidates pick tokenization because it sounds more secure when the question specifically asks for partial visibility.

How to eliminate wrong answers

Option A is wrong because pseudonymization replaces identifiers with consistent artificial values (e.g., a stable token or hash) that can be re-linked to the original via a separate mapping — it does not produce a 'last four digits visible' display. Option B is wrong because bucketing groups values into ranges or categories (e.g., age bands, income brackets) to generalize data, which is not applicable to showing partial card digits. Option C is wrong because tokenization substitutes the PAN with a surrogate token stored in a vault; the token is not the last four digits and requires the vault to detokenize, so it does not meet the 'only last four visible' requirement.

48
MCQmedium

A cloud application experiences intermittent failures during peak load. Logs show database connection timeouts. Which architecture change would best address this issue?

A.Implement connection pooling
B.Enable auto-scaling on the application tier
C.Use read replicas
D.Increase database instance size
AnswerA

Connection pooling reuses established database connections instead of opening a new one per request, so the application stops exhausting the database's connection limit during peak load. This directly removes the connection-timeout constraint recorded in the logs, letting concurrent requests queue briefly rather than fail outright.

Why this answer

Connection pooling reuses a set of established database connections, avoiding the overhead of repeatedly opening and closing connections during high concurrency. This directly resolves intermittent timeouts caused by connection exhaustion or slow connection establishment under peak load, without requiring additional infrastructure.

Exam trap

ISC2 often tests the misconception that scaling the application tier or database size alone solves connection management issues, when the real bottleneck is connection establishment overhead and pool limits.

How to eliminate wrong answers

Option B is wrong because auto-scaling the application tier adds more compute instances, which increases the number of concurrent database connection requests and can worsen connection exhaustion, not fix it. Option C is wrong because read replicas only offload read queries, not the connection management overhead or write-related timeouts. Option D is wrong because increasing database instance size provides more memory/CPU but does not address the fundamental issue of connection churn or exhaustion; the database may still hit its max_connections limit.

49
MCQhard

An organization uses a multi-cloud strategy and wants to perform a risk assessment that accounts for the shared responsibility model. Which approach is most appropriate?

A.Use ISO 27001 controls as the sole basis for assessment
B.Apply the NIST Cybersecurity Framework across all cloud providers
C.Use cloud-specific risk assessment frameworks like CSA STAR
D.Adopt COBIT for risk management alignment
AnswerC

CSA STAR provides cloud-specific controls mapped to the shared responsibility model, so each party's obligations across IaaS, PaaS and SaaS are assessed. Generic frameworks such as ISO 27001 or NIST do not delineate provider versus customer duties per service model.

Why this answer

CSA STAR (Security, Trust, Assurance, and Risk) is purpose-built for cloud environments and directly incorporates the shared responsibility model, providing a cloud-specific control framework (Cloud Controls Matrix) that maps to ISO 27001, NIST, and other standards. Because the organization operates multi-cloud, CSA STAR's provider-neutral, cloud-native controls allow consistent assessment across AWS, Azure, and GCP while explicitly delineating customer vs. provider responsibilities. This makes it the most appropriate basis for a shared-responsibility-aware risk assessment.

Exam trap

CCSP often tests the misconception that any widely recognized framework (ISO 27001, NIST CSF, COBIT) is equally valid for cloud risk assessment, when the exam expects candidates to recognize that only cloud-specific frameworks like CSA STAR explicitly encode the shared responsibility model.

How to eliminate wrong answers

Option A is wrong because ISO 27001 is a general-purpose ISMS standard that does not natively express the cloud shared responsibility model or cloud-specific controls, so using it alone would leave provider/customer boundary risks unaddressed. Option B is wrong because the NIST CSF is a voluntary, high-level framework of outcomes (Identify, Protect, Detect, Respond, Recover) that is not cloud-specific and does not define shared-responsibility control ownership. Option D is wrong because COBIT is an IT governance and management framework focused on aligning IT with business objectives, not a cloud risk assessment framework, and it does not address shared responsibility controls.

50
Multi-Selecthard

Which TWO of the following are primary responsibilities of a cloud service customer under the shared responsibility model regarding compliance with regulations such as GDPR?

Select 2 answers
A.Conducting annual penetration tests on the provider's infrastructure
B.Ensuring the cloud provider's physical security controls are adequate
C.Implementing data encryption for sensitive data at rest
D.Verifying the provider's compliance certifications are current
E.Configuring access controls for their own user accounts
AnswersC, E

Under the shared responsibility model, the customer owns its data and must apply encryption to sensitive data at rest, since the provider cannot classify or protect content it does not own. This satisfies the stem's GDPR compliance requirement for customer-side safeguards.

Why this answer

Under the shared responsibility model, the cloud customer is responsible for securing their own data and access, so option C (implementing data encryption for sensitive data at rest) is correct because protecting the confidentiality of regulated data such as GDPR personal data is a customer obligation, typically achieved via provider-managed or customer-managed keys (e.g., AES-256, KMS/HSM). Option E (configuring access controls for their own user accounts) is also correct because identity and access management — defining users, roles, permissions, MFA, and least privilege — is a customer responsibility for their tenant, and GDPR requires appropriate technical measures to restrict access to personal data. Option A is not a customer responsibility because penetration testing of the provider's underlying infrastructure is performed by the provider (customers may only run permitted tests against their own workloads under the provider's policy).

Option B is not a customer responsibility because physical security controls of data centers are owned by the cloud provider. Option D is not a primary customer compliance responsibility in the shared model; while customers may review a provider's certifications, the provider is responsible for obtaining and maintaining them.

51
MCQhard

A multinational corporation uses a cloud DLP service to scan data stored in cloud storage and a cloud data warehouse for personally identifiable information (PII). The DLP scan identifies credit card numbers in a dataset. According to the cloud data lifecycle, at which stage should the DLP scan ideally be performed to minimize exposure?

A.Store
B.Use
C.Create
D.Share
AnswerC

Scanning at the Create stage catches credit card numbers before the dataset is stored, classified or shared, so exposure is minimised at the point of entry. Later lifecycle stages (Store, Use, Share) would already have written PII to cloud storage and the warehouse, widening the breach surface.

Why this answer

The Create stage is where data is first generated, acquired, or entered into the cloud environment, making it the earliest point at which PII can be identified and classified. Performing DLP scanning at Create prevents sensitive data from ever being persisted, processed, or shared in unprotected form, which minimizes the exposure window across the entire cloud data lifecycle. Scanning at later stages (Store, Use, Share) means the data has already been written to storage or consumed by applications, increasing the risk and cost of remediation.

Exam trap

CCSP often tests the misconception that scanning data at rest (Store) is 'early enough' for DLP, when the lifecycle model expects controls at the earliest possible stage—Create—to truly minimize exposure.

How to eliminate wrong answers

Option A (Store) is wrong because scanning at Store only catches data after it has already been persisted to cloud storage or a warehouse, meaning the PII has already been written to disk and potentially replicated or backed up. Option B (Use) is wrong because the Use stage involves processing and analytics, so by that point the data has already been stored and may have been accessed by multiple services or users. Option D (Share) is wrong because Share is the latest possible stage, where data has already been transmitted to external or internal consumers, making any DLP finding a post-exposure incident rather than a preventive control.

52
MCQhard

A multinational corporation runs its critical applications on a cloud platform. The security team has implemented a Security Information and Event Management (SIEM) solution that collects logs from various cloud services, including virtual machines, storage, and databases. The SIEM is configured to generate alerts based on predefined rules. Recently, the team noticed an increase in false positive alerts, causing alert fatigue among the analysts. Additionally, there is a lack of context in the alerts, making it difficult to triage and prioritize incidents. The team wants to improve the efficiency of the SOC without increasing headcount. Which of the following is the BEST course of action to address these issues?

A.Deploy a user and entity behavior analytics (UEBA) tool to baseline normal behavior and generate alerts based on anomalies.
B.Assign more analysts to manually review and tune the alert rules.
C.Implement automated response playbooks for the most common alerts to reduce analyst workload.
D.Increase the threshold levels for all alert rules to reduce the number of alerts generated.
E.Create additional correlation rules to capture more specific attack patterns.
AnswerA

UEBA baselines normal user and entity activity, then alerts on statistical deviations rather than static rule thresholds, cutting the false positives causing alert fatigue. It also enriches alerts with behavioural context, enabling analysts to triage and prioritise without added headcount.

Why this answer

UEBA uses machine learning to establish baselines of normal user and entity behavior, then generates alerts only when deviations occur. This directly reduces false positives by filtering out benign anomalies and enriches alerts with behavioral context, enabling analysts to triage and prioritize incidents more efficiently without increasing headcount.

Exam trap

ISC2 often tests the distinction between reducing alert volume (e.g., tuning thresholds) and improving alert quality (e.g., adding context via UEBA), trapping candidates who choose threshold increases or additional rules without recognizing that false positives stem from static, context-free detection logic.

How to eliminate wrong answers

Option B is wrong because manually reviewing and tuning alert rules is labor-intensive, does not scale, and fails to address the root cause of false positives—static rules cannot adapt to evolving normal behavior. Option C is wrong because automated response playbooks reduce analyst workload for confirmed incidents but do not reduce false positive alerts or add context; they may even automate responses to false positives, worsening the problem. Option D is wrong because increasing threshold levels indiscriminately reduces all alerts, including true positives, and does not add context; it is a blunt approach that risks missing real attacks.

Option E is wrong because creating additional correlation rules increases the number of alerts and complexity, likely exacerbating false positives and alert fatigue without providing behavioral context.

53
MCQhard

A security analyst is investigating a potential breach and needs to verify the integrity of audit logs stored in cloud storage. Which feature should the analyst rely on to confirm that logs have not been tampered with?

A.Server-side encryption of logs
B.Log file integrity validation
C.Anomaly detection on logs
D.Immutable storage for logs
AnswerB

Log file integrity validation produces cryptographic hashes that let the analyst confirm stored audit logs have not been altered or deleted. It directly satisfies the tamper-detection requirement, unlike versioning or retention locks, which prevent deletion but do not prove integrity.

Why this answer

Log file integrity validation is the cloud-native feature (e.g., AWS CloudTrail log file integrity validation) that uses cryptographic hashing and digital signatures to prove that log files have not been altered or deleted after delivery. It produces a digest file for each log delivery containing SHA-256 hashes and a signature, allowing the analyst to verify tamper-evidence. This directly answers the requirement to 'confirm logs have not been tampered with.'

Exam trap

CCSP often tests the difference between encryption (confidentiality), immutability (prevention of change), and integrity validation (detection of change) — candidates pick encryption or immutability when the question specifically asks to 'verify' or 'confirm' integrity.

How to eliminate wrong answers

Option A is wrong because server-side encryption protects logs at rest from unauthorized reading but does not provide any mechanism to detect whether the log contents were modified after being written. Option C is wrong because anomaly detection identifies suspicious activity patterns in log data but cannot cryptographically prove the logs themselves are unaltered. Option D is wrong because immutable storage (e.g., S3 Object Lock) prevents future modification or deletion but does not provide a verification mechanism to confirm integrity of logs that were written before the lock or to detect tampering that occurred prior to immutability being applied.

54
MCQhard

A cloud provider offers a service with an SLA of 99.999% availability. What is the maximum allowable downtime per year in minutes? (Assume 365 days)

A.8.76 minutes
B.5.26 minutes
C.0.526 minutes
D.52.6 minutes
AnswerB

A 99.999% availability SLA permits 0.001% annual downtime. With 365 days, that equals 525,600 minutes per year, so the allowable outage is 525,600 × 0.00001 = 5.256 minutes, rounded to 5.26 minutes. This satisfies the stem's five-nines constraint precisely.

Why this answer

An SLA of 99.999% availability (often called 'five nines') allows for a maximum of 5.26 minutes of downtime per year. This is calculated by taking the total minutes in a year (365 days × 24 hours × 60 minutes = 525,600 minutes) and multiplying by the allowed unavailability (100% - 99.999% = 0.001%, or 0.00001 as a decimal). 525,600 × 0.00001 = 5.256 minutes, which rounds to 5.26 minutes.

Exam trap

CCSP often tests the ability to calculate downtime from availability percentages; the trap is misplacing the decimal point or using the wrong number of minutes in a year (e.g., 525,600 vs 525,960 for leap year). Candidates may also confuse 99.999% with 99.99%.

How to eliminate wrong answers

Option A is wrong because 8.76 minutes corresponds to 99.998% availability (or 99.999% if calculated with 365.25 days? Actually 8.76 minutes is for 99.9983%? Let's check: 525,600 × 0.0000167 = 8.76, which is 99.99833% availability, not five nines). Option C is wrong because 0.526 minutes is one-tenth of the correct value, corresponding to 99.9999% availability (six nines). Option D is wrong because 52.6 minutes is ten times the correct value, corresponding to 99.99% availability (four nines).

55
Multi-Selectmedium

Which TWO of the following are best practices for implementing baseline configuration management in a cloud environment? (Choose two.)

Select 2 answers
A.Allow administrators to manually adjust configurations as needed to maintain flexibility
B.Disable configuration drift detection to reduce alert fatigue
C.Automate the deployment of baseline configurations using orchestration tools
D.Grant all users read/write access to configuration repositories for efficiency
E.Store and manage configuration templates in a version-controlled repository
AnswersC, E

Ensures consistent and repeatable deployments.

Why this answer

Automating the deployment of baseline configurations using orchestration tools (e.g., AWS CloudFormation, Terraform, or Ansible) ensures consistency, reduces human error, and enforces security controls across cloud resources. This aligns with the principle of immutable infrastructure, where configurations are deployed programmatically rather than manually adjusted.

Exam trap

ISC2 often tests the misconception that manual flexibility or disabling detection features are acceptable trade-offs for operational convenience, when in fact they directly violate cloud security operations best practices.

56
MCQeasy

A cloud security engineer is deploying a web application on Google Cloud Platform (GCP) and needs to protect it from common web exploits like SQL injection and cross-site scripting. The engineer wants a managed service that can be configured with security policies. Which GCP service should be used?

A.Google Cloud Armor
B.Google Cloud Load Balancing
C.Google Cloud VPN
D.Google Cloud Identity-Aware Proxy (IAP)
AnswerA

Google Cloud Armor is a managed web application firewall (WAF) that provides protection against common web vulnerabilities such as SQL injection and cross-site scripting. It integrates with HTTP(S) load balancing and allows you to define security policies with rules to filter traffic. This matches the requirement for a managed service to protect the web application.

Why this answer

Google Cloud Armor is the correct service because it is a managed WAF that can be configured with security policies to protect against web exploits. It integrates with load balancing to filter malicious traffic. The other services provide identity control, network connectivity, or load distribution, but none offer WAF functionality.

Exam trap

The trap here is assuming that Cloud Load Balancing includes WAF capabilities, but it requires Cloud Armor for that purpose.

57
MCQmedium

A cloud customer's legal team must decide which party bears responsibility for generating audit evidence that demonstrates regulatory compliance. The customer uses IaaS from a provider. According to the CSA Cloud Controls Matrix and shared responsibility principles, how should audit evidence obligations be divided?

A.The cloud provider is solely responsible for producing all audit evidence because it operates the physical infrastructure and hypervisor.
B.A third-party auditor engaged by the customer must independently verify every control across both the provider and customer environments, regardless of who operates them.
C.The customer must obtain evidence for controls it operates, while the provider supplies evidence for controls it operates, with each party relying on the other's attestations where appropriate.
D.The provider is responsible only for evidence related to its own internal corporate compliance, not for any controls that support customer workloads.
AnswerC

Under the shared responsibility model, each party is accountable for the controls it implements. In IaaS, the provider evidences physical, network, and hypervisor controls, often through SOC 2 or ISO/IEC 27001 reports; the customer evidences guest OS, application, and data controls. This division is the basis for CSA CCM and contractual audit rights, ensuring complete coverage without duplicating effort.

Why this answer

In a shared responsibility model, audit evidence must map to who operates each control. For IaaS, the provider evidences the physical, network, and hypervisor layers, while the customer evidences the guest OS, applications, and data. Contractual audit rights and provider attestations like SOC 2 reports bridge the gap, allowing each party to rely on the other's evidence for controls outside its own scope.

Exam trap

The trap here is assuming that the cloud provider is responsible for all audit evidence because it owns the infrastructure, when in fact the customer must evidence the controls it operates.

58
MCQmedium

A developer accidentally commits cloud access keys to a public GitHub repository. Which tool would be most effective in detecting this secret exposure?

A.Terraform
B.GitGuardian
C.npm audit
D.tfsec
AnswerB

GitGuardian continuously scans repositories and commit history for exposed credentials, using pattern matching and entropy analysis to detect cloud access keys even after commits are pushed. It alerts immediately and supports remediation, directly addressing the accidental public exposure of keys described in the scenario.

Why this answer

GitGuardian is a dedicated secrets detection platform that scans repositories (including public GitHub repos) for exposed credentials, API keys, and tokens using pattern matching and entropy analysis. It integrates with GitHub via webhooks or CI/CD to alert on commits containing secrets. This directly addresses the scenario of accidentally committed cloud access keys.

Exam trap

The trap is confusing infrastructure-as-code scanners (tfsec, Checkov) or dependency scanners (npm audit) with secret detection tools — only dedicated secret scanners catch hardcoded credentials.

How to eliminate wrong answers

Option A is wrong because Terraform is an infrastructure-as-code tool for provisioning cloud resources — it does not scan for secrets in repositories. Option C is wrong because npm audit checks Node.js dependencies for known vulnerabilities (CVEs) in packages, not for hardcoded secrets in source code. Option D is wrong because tfsec is a static analysis tool for Terraform configurations, identifying misconfigurations like open security groups — it does not detect secrets committed to Git.

59
Multi-Selecthard

A cloud security team is building an incident response runbook for compromised compute instances in a public cloud. They need to preserve volatile evidence and maintain chain of custody while minimizing service disruption. Which TWO actions should be included in the runbook? (Choose two.)

Select 2 answers
A.Disable all logging on the instance to prevent the attacker from tampering with logs, then re-enable after remediation.
B.Capture a memory dump of the running instance before shutting it down, storing the dump in a write-once location with a documented hash.
C.Immediately terminate the instance to prevent further malicious activity and rely on the cloud provider's internal logs for evidence.
D.Create a snapshot of the instance's volumes and copy it to a restricted forensic account, recording the snapshot ID and creation time.
E.Reboot the instance into safe mode to clear malicious processes, then continue using it for production traffic.
AnswersB, D

Volatile evidence such as memory contents is lost on shutdown or reboot, so capturing a memory dump first preserves critical artifacts like running processes and network connections. Storing it in a write-once location and recording a cryptographic hash establishes integrity and chain of custody, which are essential for forensic validity and later legal or disciplinary use.

Why this answer

Preserving volatile memory before any shutdown and snapshotting persistent volumes into an isolated forensic account together capture the full evidence set while maintaining integrity. Both actions record identifiers and hashes for chain of custody, and they allow the original instance to be contained or rebuilt without losing forensic artifacts, which is the core of a defensible cloud incident response runbook.

Exam trap

The trap here is believing that terminating or rebooting a compromised instance is the safest first step, when doing so destroys volatile evidence and breaks chain of custody before memory and disk artifacts can be captured.

60
MCQeasy

Which AWS service uses machine learning to detect threats such as crypto mining activity on EC2 instances and compromised IAM credentials?

A.AWS Shield
B.AWS WAF
C.AWS Inspector
D.Amazon GuardDuty
AnswerD

Amazon GuardDuty continuously analyses CloudTrail, VPC Flow Logs and DNS logs with managed machine learning and threat intelligence to surface findings including cryptocurrency mining on EC2 instances and compromised IAM credentials. It satisfies the stem's requirement for an AWS-native, ML-driven threat detection service without deploying agents.

Why this answer

Amazon GuardDuty is a threat detection service that uses machine learning and anomaly detection to identify malicious activity.

61
MCQeasy

An organization uses a cloud security monitoring service for threat detection. A finding indicates that a virtual machine instance is communicating with a known cryptocurrency mining pool. What type of threat does this represent?

A.Reconnaissance port scanning
B.Ransomware activity
C.Compromised credentials exfiltration
D.Crypto mining on a virtual machine
AnswerD

Communication with a known cryptocurrency mining pool indicates the instance's compute resources have been hijacked to mine cryptocurrency, typically via malware or a compromised workload. This unauthorised resource consumption is classified as crypto mining on a virtual machine.

Why this answer

A cloud security monitoring service detects threats by analyzing network traffic logs, DNS logs, and API call logs. A finding of communication with a known cryptocurrency mining pool indicates that the virtual machine instance is likely compromised and running crypto mining software, which consumes excessive compute resources and represents a malicious activity type known as crypto mining.

Exam trap

The trap here is that candidates confuse crypto mining with ransomware or credential theft, but the key differentiator is the specific network communication pattern to a mining pool, not data encryption or API abuse.

How to eliminate wrong answers

Option A is wrong because reconnaissance port scanning involves probing for open ports or services, not communication with a known mining pool, which is a specific outbound connection to a malicious IP/domain. Option B is wrong because ransomware activity typically involves encrypting data and demanding payment, not the sustained CPU usage and network traffic to mining pools characteristic of crypto mining. Option C is wrong because compromised IAM credentials exfiltration would manifest as unauthorized API calls or access to sensitive resources, not direct outbound connections to mining infrastructure.

62
MCQmedium

Refer to the exhibit. A security auditor is reviewing the security group configuration for a web server. Which change would improve the security posture without breaking the application functionality?

A.Remove Rule 2 because HTTPS should be restricted to a specific IP range.
B.Remove Rule 1 because SSH should not be open to the internet.
C.Remove Rule 4 because outbound traffic should be restricted.
D.Remove Rule 3 because RDP should be allowed from anywhere.
AnswerB

Rule 1 permits SSH from 0.0.0.0/0, exposing remote administration to internet-wide brute-force and exploit attempts. Removing it eliminates that exposure while leaving the HTTP and HTTPS rules that serve the application intact, so functionality is preserved and the attack surface shrinks.

Why this answer

SSH (port 22) should never be open to the internet (0.0.0.0/0) on a web server. Removing Rule 1 eliminates this unnecessary exposure while the web server's HTTP/HTTPS rules remain intact, preserving application functionality. This aligns with the principle of least privilege and reduces the attack surface.

Exam trap

ISC2 often tests the misconception that all common ports (like HTTPS or outbound traffic) must be restricted to improve security, when in fact the critical mistake is leaving management protocols (SSH, RDP) open to the internet.

How to eliminate wrong answers

Option A is wrong because HTTPS (port 443) is typically required to be open to the internet for a public web server to serve encrypted traffic; restricting it to a specific IP range would break functionality for external users. Option C is wrong because outbound traffic (Rule 4) is necessary for the web server to fetch updates, resolve DNS, or communicate with backend services; removing it would likely break application functionality. Option D is wrong because RDP (port 3389) should never be allowed from anywhere (0.0.0.0/0) due to its high risk of brute-force attacks; the statement suggests allowing it, which worsens security posture.

63
MCQmedium

A cloud security architect is designing the network segmentation for a three-tier web application hosted in a single Amazon VPC. The database tier must accept connections only from the application tier, and the application tier must accept connections only from the web tier. The architect wants the enforcement to be stateful, evaluated per elastic network interface, and independent of subnet CIDR ranges so that instances can be replaced without rewriting rules. Which control should the architect use to enforce this segmentation?

A.A VPC peering connection between the three tier subnets with route table entries restricting traffic
B.AWS PrivateLink endpoints published by each tier and consumed by the tier above it
C.Security groups attached to each tier's instances, referencing other security groups as sources
D.Network ACLs on each subnet, with rules that allow only the CIDR range of the adjacent tier's subnet
AnswerC

Security groups are stateful, attach to elastic network interfaces, and support referencing another security group as a source. This lets the database tier accept traffic only from the application tier's group, and the application tier only from the web tier's group, without hardcoding subnet CIDR ranges. Replacement instances that join the same group inherit the rules automatically, which matches the architect's requirements exactly.

Why this answer

Security groups provide stateful, interface-level filtering and allow other security groups to be referenced as sources, which decouples the rules from subnet addressing. That combination satisfies the stateful, per-interface, CIDR-independent requirement and survives instance replacement. Subnet-level ACLs, route tables, and PrivateLink endpoints do not deliver group-based, stateful enforcement within a single VPC.

Exam trap

The trap here is assuming that network ACLs provide the same stateful, group-referenced filtering as security groups, when ACLs are stateless and CIDR-based.

64
MCQeasy

A cloud security architect is designing a key management strategy for a multi-cloud environment. Which of the following is a BEST practice for key management?

A.Use the same key for all data to simplify rotation
B.Store keys in each cloud provider's native KMS separately
C.Embed keys in application code for simplicity
D.Use a centralized key management system that integrates with all clouds
AnswerD

A centralised key management system provides consistent policy, lifecycle, and auditing across all cloud providers, avoiding fragmented per-cloud key stores. This satisfies the multi-cloud constraint by unifying key governance while integrating with each provider's native encryption services.

Why this answer

A centralized key management system (KMS) that integrates with all cloud providers enables consistent key lifecycle management, reduces the risk of key sprawl, and ensures uniform access control policies across a multi-cloud environment. This approach aligns with the principle of separation of duties and allows for centralized auditing and rotation without vendor lock-in.

Exam trap

ISC2 often tests the misconception that using each cloud provider's native KMS separately is a best practice for multi-cloud, but the trap is that this ignores the need for centralized control, auditability, and cross-cloud interoperability, which are critical for enterprise security.

How to eliminate wrong answers

Option A is wrong because using the same key for all data violates the cryptographic isolation principle; if that single key is compromised, all data is exposed, and rotation becomes a massive operational burden. Option B is wrong because storing keys separately in each cloud provider's native KMS creates fragmented key management, increases complexity for cross-cloud data sharing, and makes consistent policy enforcement nearly impossible. Option C is wrong because embedding keys in application code is a severe security violation; keys can be extracted from code repositories, logs, or decompiled binaries, directly contradicting the NIST SP 800-57 recommendation to never store keys in plaintext or in code.

65
Multi-Selectmedium

A cloud customer must comply with GDPR's right to erasure (right to be forgotten). Which TWO of the following are technical challenges the customer faces when the data is stored in a cloud object storage service with versioning and cross-region replication?

Select 2 answers
A.Ensuring data is accessible only via a specific IP range
B.Removing previous versions of objects
C.Encrypting the data at rest with customer-managed keys
D.Exporting data in a machine-readable format
E.Deleting data from all replicated copies across regions
AnswersB, E

Versioning retains every prior iteration of an object, so erasure requires enumerating and deleting each version individually rather than the current object alone. This satisfies the stem's versioning constraint, since residual versions still contain the personal data subject to the erasure request.

Why this answer

Option B is correct because object storage versioning retains every prior version of an object, so a GDPR erasure request cannot be satisfied by simply deleting the current object; the customer must also enumerate and permanently remove all noncurrent versions (e.g., via S3 versioning delete markers plus explicit version deletion or lifecycle expiration). Option E is correct because cross-region replication creates additional copies in other regions, and the right to erasure requires those replicas to be deleted as well, which is technically challenging due to replication lag, delete-marker propagation behavior, and the need to verify deletion in every target region. Option A is not a right-to-erasure challenge but an access-control/network-restriction concern, typically handled with bucket policies, VPC endpoints, or IP conditions.

Option C concerns encryption key management and confidentiality, not the deletion of data. Option D relates to data portability under GDPR Article 20, not the right to erasure under Article 17.

Exam trap

CCSP often tests GDPR data subject rights — candidates confuse the right to erasure (Article 17) with the right to data portability (Article 20) or pick encryption controls that address confidentiality rather than deletion.

66
MCQeasy

Which CSA STAR tier involves a third-party assessment against ISO 27001?

A.Tier 4 – Peer review
B.Tier 1 – Self-assessment
C.Tier 3 – Continuous monitoring
D.Tier 2 – Third-party assessment
AnswerD

Tier 2 requires an independent third-party assessment against a recognised standard, specifically ISO/IEC 27001, plus the CSA Cloud Controls Matrix. Tier 1 is self-assessment only, so it cannot satisfy the third-party assessment constraint stated in the stem.

Why this answer

The CSA STAR (Security, Trust, Assurance, and Risk) program has three tiers: Tier 1 (Self-Assessment), Tier 2 (Third-Party Assessment), and Tier 3 (Continuous Monitoring). Tier 2 specifically requires a third-party assessment against the ISO/IEC 27001 standard, where an accredited certification body audits the cloud service provider's Information Security Management System (ISMS) for compliance. This tier provides a higher level of assurance than self-assessment, as it involves independent validation of security controls.

Exam trap

ISC2 often tests the misconception that Tier 2 is the 'self-assessment' tier, confusing it with Tier 1, or that there is a Tier 4 for peer review, which does not exist in the CSA STAR framework.

How to eliminate wrong answers

Option A is wrong because Tier 4 does not exist in the CSA STAR program; the tiers are limited to 1, 2, and 3, and 'Peer review' is not a defined tier. Option B is wrong because Tier 1 is the Self-Assessment tier, which involves the cloud provider completing a Consensus Assessments Initiative Questionnaire (CAIQ) without any third-party involvement or ISO 27001 audit. Option C is wrong because Tier 3 is Continuous Monitoring, which focuses on ongoing security telemetry and automated reporting (e.g., via the CSA STAR Watch program), not a one-time third-party assessment against ISO 27001.

67
MCQmedium

A cloud architect is designing a system for a media streaming company that experiences unpredictable spikes in viewer demand during live events. The company wants to minimize infrastructure costs during periods of low demand while maintaining the ability to handle sudden increases in traffic. The architect proposes using a cloud deployment model that provides rapid elasticity and measured service. Which cloud deployment model BEST meets these requirements?

A.Private cloud
B.Hybrid cloud
C.Public cloud
D.Community cloud
AnswerC

A public cloud provides on-demand self-service, rapid elasticity, and measured service, allowing the streaming company to scale resources up during spikes and down during low demand, paying only for what is used. This aligns with the requirements of minimizing costs during low demand while handling sudden increases in traffic.

Why this answer

The public cloud model is designed to provide on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. These characteristics allow the media streaming company to automatically scale resources during live events and reduce costs when demand is low. Private, community, and hybrid models do not offer the same combination of rapid elasticity and cost efficiency for unpredictable workloads.

Exam trap

The trap here is assuming that a hybrid cloud is always the best choice for handling variable demand because it combines private and public resources, but the scenario does not require a private component, making public cloud the simpler and more cost-effective solution.

68
MCQmedium

Which container image security practice is most effective at reducing the attack surface by removing unnecessary components and lowering the number of CVEs?

A.Using the :latest tag for base images
B.Adding security agents inside the image
C.Using distroless base images
D.Scanning images only at build time
AnswerC

Distroless images contain only the application and its runtime dependencies, omitting package managers, shells and OS utilities. Removing these unnecessary components shrinks the attack surface and reduces the CVE count, directly satisfying the stem's constraint.

Why this answer

Distroless images contain only the application and its runtime dependencies, minimizing the attack surface.

69
MCQhard

A cloud application uses a microservices architecture deployed on Kubernetes. The security team wants to enforce that only signed container images from a trusted registry can be deployed to the cluster. Which Kubernetes feature should be used to achieve this?

A.Pod security policies
B.Role-based access control (RBAC)
C.Admission controllers with image signature verification
D.Network policies
AnswerC

Admission controllers intercept requests to the Kubernetes API server before objects are persisted. By integrating an admission controller that verifies image signatures, such as the Open Policy Agent (OPA) Gatekeeper with a signature verification policy or the Sigstore policy controller, you can enforce that only images signed by trusted keys are admitted. This directly meets the requirement to allow only signed images from a trusted registry.

Why this answer

To enforce that only signed container images from a trusted registry are deployed, an admission controller with image signature verification is required. This controller validates the signature of the image before allowing the pod to be created. Tools like OPA Gatekeeper or Sigstore's policy controller can be configured to check signatures against trusted public keys.

This ensures supply chain security and prevents unauthorized or tampered images from running in the cluster.

Exam trap

The trap here is confusing access control (RBAC) or network segmentation (Network policies) with image integrity enforcement, which requires an admission controller that can verify cryptographic signatures.

70
MCQhard

A security operations centre uses AWS CloudTrail and wants to detect when an IAM access key belonging to a privileged role is used from an unrecognized IP address outside business hours. The team already has CloudTrail management events delivered to Amazon CloudWatch Logs. Which approach best detects this behaviour with the LEAST operational overhead?

A.Write a CloudWatch Logs Insights query and schedule it hourly to email matching events to the security team
B.Create a CloudWatch Logs metric filter that matches the access key event and an alarm that triggers when the source IP is outside an allowlist
C.Configure an AWS Config custom rule that evaluates IAM access key metadata against approved CIDR ranges
D.Enable Amazon GuardDuty and rely on its IAM finding types for anomalous access key usage
AnswerD

GuardDuty continuously analyzes CloudTrail management events, VPC Flow Logs, and DNS logs with machine learning and threat intelligence, producing findings such as anomalous IAM access key usage from unusual geolocations or IP addresses. It requires no custom rule authoring, delivers findings automatically, and integrates with EventBridge for response, making it the lowest-overhead option.

Why this answer

Detecting anomalous use of privileged access keys from unfamiliar IPs outside normal hours is a behavioural threat-detection problem. Amazon GuardDuty ingests CloudTrail management events continuously and applies anomaly detection and threat intelligence to surface findings like anomalous access key usage, requiring no custom filters or scheduled queries, which minimizes operational overhead for the SOC.

Exam trap

The trap here is reaching for custom CloudWatch metric filters or Logs Insights queries to detect suspicious access key use, when a managed threat-detection service already performs this behavioural analysis with no rule maintenance.

71
MCQhard

During a security incident in GCP, a forensic analyst needs to determine the exact timeline of events leading to a credential compromise. Which log source provides the most detailed information about IAM policy changes and authentication events?

A.VPC Flow Logs
B.Cloud Audit Logs
C.Cloud DNS logs
D.Cloud Monitoring metrics
AnswerB

Cloud Audit Logs capture Admin Activity entries recording IAM policy changes and authentication events, with timestamps and actor identities. This gives the forensic analyst the precise chronology of the credential compromise, which other log sources such as VPC Flow Logs or firewall logs cannot provide.

Why this answer

GCP Cloud Audit Logs record all admin activities and data access, including IAM changes and authentication, making them the best source for timeline reconstruction.

72
MCQhard

Refer to the exhibit. A cloud security analyst reviews the bucket policy for example-bucket. Based on the policy, which of the following is true?

A.Requests from IP 192.0.2.10 over HTTPS are allowed.
B.Access is denied because the Principal is set to "*", which is insecure.
C.Requests from IP 192.0.2.10 over HTTP are allowed because the deny statement only applies when SecureTransport is false.
D.Any IP address can perform GetObject requests if they use HTTPS.
AnswerA

The allow statement permits GetObject from that IP range, and the deny does not apply because HTTPS is used.

Why this answer

The bucket policy includes an explicit Allow statement granting s3:GetObject to all principals (Principal: "*") from the IP address 192.0.2.10, and the condition "Bool": {"aws:SecureTransport": "true"} ensures that only HTTPS requests are allowed. Since the request originates from the specified IP and uses HTTPS, it satisfies both the Allow condition and is not blocked by the Deny statement, which only denies requests when SecureTransport is false (i.e., HTTP). Thus, the request is permitted.

Exam trap

ISC2 often tests the nuance that an explicit Deny overrides an Allow, but here the Deny only applies to HTTP (SecureTransport false), so HTTPS requests from the allowed IP are still permitted, leading candidates to mistakenly think the Deny blocks all requests.

How to eliminate wrong answers

Option B is wrong because setting Principal to "*" is not inherently insecure; AWS S3 bucket policies commonly use "*" to grant public access, and security is enforced through conditions like IP restrictions and SecureTransport requirements. Option C is wrong because the Deny statement applies when SecureTransport is false, but the Allow statement explicitly requires SecureTransport to be true; therefore, a request from IP 192.0.2.10 over HTTP would be denied by the Deny statement (since SecureTransport is false) and also would not satisfy the Allow condition. Option D is wrong because the Allow statement is restricted to the specific IP address 192.0.2.10; any other IP address attempting GetObject over HTTPS would not match the Allow condition and would be implicitly denied (or explicitly denied if another Deny statement exists).

73
MCQhard

A cloud security engineer is responsible for securing a serverless application built on AWS Lambda. The application processes sensitive customer data and writes results to an Amazon S3 bucket. The engineer must ensure that the Lambda function has only the permissions it needs to write to that specific bucket, and that the credentials are not hardcoded. Which approach should the engineer take?

A.Use an IAM user with an inline policy for S3 access and configure the Lambda function to use those credentials via the AWS SDK.
B.Embed the access keys in the Lambda function's environment variables.
C.Create an IAM role with a policy granting s3:PutObject to the specific bucket and attach it to the Lambda function.
D.Store IAM user access keys in AWS Secrets Manager and retrieve them in the Lambda function code.
AnswerC

This approach follows the principle of least privilege by granting only the necessary permission to the specific bucket. The IAM role is assumed by the Lambda function at runtime, and AWS automatically rotates the temporary credentials. This eliminates hardcoded credentials and ensures secure access. It is the recommended best practice for Lambda functions.

Why this answer

The best practice for granting permissions to AWS Lambda is to use an IAM role with a narrowly scoped policy. The role provides temporary credentials that are automatically rotated, and the policy grants only the required s3:PutObject permission to the specific bucket. This adheres to least privilege and eliminates the need for hardcoded or stored long-term credentials.

Other options involve long-term credentials or insecure storage, which are not recommended.

Exam trap

The trap here is thinking that storing keys in Secrets Manager is secure enough, but it still uses long-term credentials instead of temporary role-based access.

74
MCQmedium

A cloud security architect is designing a multi-tenant SaaS platform hosted on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application instance in one tenant's environment cannot decrypt another tenant's data. The architect wants to use AWS Key Management Service (KMS) to manage encryption keys. Which approach BEST meets this requirement?

A.Use AWS KMS with a single customer managed key, but enable automatic key rotation every 90 days and require all tenants to use the same key alias for encryption and decryption.
B.Use a single AWS KMS customer managed key with a key policy that grants decrypt permissions to all tenant application roles, and rely on application-level tenant ID checks before decryption.
C.Create a separate AWS KMS customer managed key per tenant, with a key policy that grants decrypt permission only to that tenant's application role, and store the tenant's data encrypted under its own key.
D.Store all tenant data in a single Amazon S3 bucket encrypted with SSE-S3, and use S3 bucket policies to restrict each tenant's application role to its own prefix.
AnswerC

Per-tenant KMS keys with scoped key policies enforce cryptographic isolation at the key-management layer. Even if an application instance is compromised, its IAM role only has decrypt permission on its own tenant's key, so it cannot decrypt other tenants' ciphertext. This directly satisfies the requirement.

Why this answer

Cryptographic isolation in a multi-tenant cloud environment requires that each tenant's data be protected by a distinct key whose usage is governed by least-privilege policies. Per-tenant AWS KMS customer managed keys with narrowly scoped key policies ensure that a compromised application instance can only decrypt its own tenant's data. Shared keys, even with rotation or application-level checks, do not prevent cross-tenant decryption if credentials are compromised.

Exam trap

The trap here is assuming that application-level tenant ID checks or a shared KMS key with rotation provide sufficient isolation, when true cryptographic isolation requires distinct keys with scoped permissions per tenant.

75
MCQmedium

A security engineer needs to scan all container images stored in Amazon Elastic Container Registry (ECR) for vulnerabilities. The scan must be automated whenever a new image is pushed. Which solution meets this requirement?

A.Use Amazon Macie for image scanning.
B.Configure AWS Security Hub to scan images.
C.Use AWS Lambda to invoke Clair on each push.
D.Enable Amazon Inspector continuous scanning for ECR repositories.
AnswerD

Amazon Inspector's continuous scanning integrates natively with Amazon ECR, automatically re-evaluating repositories when new images are pushed, which satisfies the automation constraint without custom orchestration. Unlike basic ECR scan-on-push, Inspector provides ongoing vulnerability assessment across the repository, detecting newly disclosed CVEs in existing images as well as fresh pushes.

Why this answer

Amazon Inspector continuous scanning for Amazon ECR automatically scans container images for software vulnerabilities whenever a new image is pushed to the repository. This feature is natively integrated with ECR, requires no additional infrastructure, and provides findings directly in the Inspector console and via AWS Security Hub. Option D is correct because it is the only AWS-native, automated, and fully managed solution that meets the requirement.

Exam trap

Many candidates mistakenly think that any security service (like Macie or Security Hub) can perform vulnerability scanning, when in fact only Inspector has the native capability to scan ECR images continuously and automatically.

How to eliminate wrong answers

Option A is wrong because Amazon Macie is designed for discovering and protecting sensitive data (e.g., PII, credentials) in S3 buckets, not for scanning container images for vulnerabilities. Option B is wrong because AWS Security Hub is a centralized security findings aggregator and does not perform image scanning itself; it can consume findings from Inspector but cannot initiate scans. Option C is wrong because while AWS Lambda can invoke Clair (an open-source vulnerability scanner), this approach requires custom code, management of the Clair infrastructure, and is not a native AWS managed service; it also does not automatically trigger on every push without additional event wiring (e.g., S3 events or ECR push notifications), making it less reliable and more complex than the native solution.

Page 1 of 13

Page 2