Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 676–750

934 questions total · 13pages · All types, answers revealed

Page 9

Page 10 of 13

Page 11
676
MCQmedium

Refer to the exhibit. An IAM policy is attached to a user. Which action is the user allowed to perform?

A.Change the bucket's policy.
B.Read an existing object from the bucket.
C.Upload a new object to the bucket.
D.Delete an object from the bucket.
AnswerB

The policy grants s3:GetObject on the bucket's objects, so the user can retrieve existing objects. It does not permit s3:PutObject or s3:DeleteObject, so writing or removing objects is denied. Reading an existing object is therefore the only allowed action.

Why this answer

The IAM policy grants the `s3:GetObject` action, which allows the user to read (download) an existing object from the specified S3 bucket. The policy explicitly allows this action for the bucket `my-bucket` and its objects, so the user can perform read operations on objects within that bucket.

Exam trap

ISC2 often tests the distinction between read and write permissions in S3 policies, where candidates mistakenly assume that `s3:GetObject` implies the ability to upload or modify objects, but each action (Get, Put, Delete) must be explicitly granted.

How to eliminate wrong answers

Option A is wrong because changing a bucket's policy requires the `s3:PutBucketPolicy` action, which is not included in the attached policy. Option C is wrong because uploading a new object requires the `s3:PutObject` action, which is not granted by the policy. Option D is wrong because deleting an object requires the `s3:DeleteObject` action, which is also absent from the policy.

677
Multi-Selectmedium

A cloud security engineer is hardening container runtime environments. Which TWO of the following are effective measures to prevent container escape?

Select 2 answers
A.Using the latest kernel version
B.Mounting the host filesystem as read-only
C.Running containers in privileged mode
D.Dropping all Linux capabilities except those required
E.Applying Seccomp profiles
AnswersD, E

Dropping unneeded Linux capabilities directly shrinks the kernel attack surface available inside a container, satisfying the stem's requirement to prevent escape. Without privileges such as CAP_SYS_ADMIN, a compromised process cannot mount filesystems, load modules or manipulate namespaces, so breakout techniques that depend on elevated capabilities fail.

Why this answer

Option D is correct because dropping all Linux capabilities except those strictly required follows the principle of least privilege and removes the powerful capabilities (such as CAP_SYS_ADMIN, CAP_NET_ADMIN, or CAP_SYS_PTRACE) that container-escape exploits typically abuse to break out of the namespace and interact with the host. Option E is correct because Seccomp profiles restrict the set of system calls a container process can invoke, blocking dangerous syscalls (e.g., ptrace, mount, unshare, keyctl) that are commonly leveraged in kernel-exploit-based escapes. Option A is not a preventive control for container escape: keeping the kernel patched reduces known vulnerabilities but does not by itself constrain a container's privileges or syscall surface.

Option B is not effective as stated because mounting the host filesystem read-only does not prevent escape — an attacker can still gain host access and then remount or exploit writable paths; the real mitigation is not exposing the host filesystem to the container at all. Option C is incorrect because privileged mode disables the very isolation mechanisms (capabilities, seccomp, AppArmor/SELinux, device cgroup) that prevent escape, making it the opposite of a hardening measure.

Exam trap

CCSP often tests whether candidates recognize that 'privileged mode' is a vulnerability, not a mitigation, and that generic practices like 'latest kernel' or 'read-only host mount' are distractors that sound secure but do not address container escape specifically.

678
MCQhard

A cloud-native payroll application stores employee bank details in a managed database. The security team wants to ensure that even if the database storage is compromised, the data cannot be read without explicit decryption. They also need to minimize changes to the application code. Which approach best meets these requirements?

A.Use database-native column encryption with keys stored in the database configuration.
B.Enable transparent data encryption (TDE) at the database storage layer using provider-managed keys.
C.Implement client-side field-level encryption using a customer-managed key (CMK) in a cloud KMS.
D.Rely on the cloud provider's default encryption at rest with provider-managed keys.
AnswerC

Client-side field-level encryption encrypts sensitive fields before they reach the database, so stored ciphertext is useless without the CMK. Using a customer-managed key in a cloud KMS keeps key control with the organization and enables explicit decryption. The application performs encryption and decryption, which is a code change but targeted to specific fields, meeting both requirements.

Why this answer

The team needs encryption where keys are controlled by the organization and decryption is explicit, not automatic. Client-side field-level encryption with a customer-managed key in a cloud KMS achieves this: ciphertext is stored in the database, and only holders of the CMK can decrypt. TDE, provider-managed keys, and database-native encryption with locally stored keys all leave decryption capability with the database or provider, failing the threat model.

Exam trap

The trap here is treating any encryption at rest as sufficient, when the decisive factor is who controls the keys and when decryption occurs.

679
Multi-Selecteasy

Which TWO cloud monitoring tools are used primarily for detecting anomalous behavior that may indicate a security incident? (Choose two.)

Select 2 answers
A.Infrastructure monitoring tool.
B.Intrusion detection system (IDS).
C.Cloud cost management tool.
D.Application performance monitoring (APM).
E.Security information and event management (SIEM) system.
AnswersB, E

An IDS monitors network or host traffic against signatures and behavioural baselines, generating alerts when activity deviates from normal patterns. That anomaly detection directly supports identifying potential security incidents, which is the monitoring purpose the question specifies.

Why this answer

An Intrusion Detection System (IDS) is specifically designed to monitor network traffic and system activities for signs of malicious activity or policy violations, making it a primary tool for detecting anomalous behavior indicative of a security incident. A Security Information and Event Management (SIEM) system aggregates and correlates logs from multiple sources, using rules and analytics to identify patterns of suspicious activity that may signal a security breach.

Exam trap

ISC2 often tests the distinction between monitoring for performance (infrastructure/APM tools) versus monitoring for security (IDS/SIEM), and candidates mistakenly choose infrastructure monitoring or APM because they think 'monitoring' broadly covers security, but these tools lack the specific anomaly detection and correlation capabilities required for incident detection.

680
MCQeasy

A cloud security professional is concerned about VM escape attacks. Which mitigation is most effective?

A.Encryption of VM disks
B.Regular patching of the hypervisor
C.Use of Type 2 hypervisors
D.Network segmentation between VMs
AnswerB

VM escape exploits target hypervisor vulnerabilities, so applying hypervisor patches closes the flaws an attacker would use to break out of a guest VM. This directly addresses the escape vector in a multi-tenant environment, where a single unpatched hypervisor flaw could expose every co-resident tenant.

Why this answer

VM escape attacks exploit vulnerabilities in the hypervisor to break out of a guest VM and access the host or other guests. Regularly patching the hypervisor closes known vulnerabilities (e.g., Xen, KVM, VMware ESXi CVEs) that attackers use to escape, making it the most direct and effective mitigation. Since the hypervisor is the isolation boundary, keeping it current is foundational to VM security.

Exam trap

CCSP often tests whether candidates confuse data-at-rest protections (disk encryption) or network controls (segmentation) with hypervisor-layer isolation — the trap is picking a control that addresses a different threat model than VM escape.

How to eliminate wrong answers

Option A is wrong because encrypting VM disks protects data at rest and does nothing to prevent a running VM from escaping to the host. Option C is wrong because Type 2 hypervisors (hosted, e.g., VirtualBox, VMware Workstation) run on top of a general-purpose OS and generally have a larger attack surface than Type 1 (bare-metal) hypervisors, so they are not a more effective mitigation. Option D is wrong because network segmentation between VMs limits lateral movement after a compromise but does not prevent the escape itself, which occurs at the hypervisor layer, not the network layer.

681
MCQhard

A cloud service provider (CSP) is designing a multi-tenant infrastructure and needs to ensure that a security incident in one tenant's environment does not compromise the confidentiality or integrity of other tenants. The CSP plans to use a combination of network segmentation, hypervisor isolation, and encryption. Which additional control is MOST critical to prevent side-channel attacks that could leak cryptographic keys or other sensitive data across tenants?

A.Ensure cryptographic operations use constant-time algorithms.
B.Implement virtual LANs (VLANs) and firewall rules between tenants.
C.Use hardware security modules (HSMs) for key management.
D.Enforce strict API rate limiting for each tenant.
AnswerA

Constant-time algorithms eliminate data-dependent timing variations, denying attackers the measurable execution differences that side-channel attacks exploit to infer cryptographic keys. Network segmentation, hypervisor isolation and encryption cannot address timing leakage across shared physical CPUs, so this control directly satisfies the stem's requirement to prevent cross-tenant key disclosure in the multi-tenant infrastructure.

Why this answer

Side-channel attacks, such as timing attacks, exploit variations in execution time to infer sensitive data like cryptographic keys. Constant-time algorithms ensure that cryptographic operations execute in a fixed duration regardless of input, eliminating timing variations that could be measured across shared physical hardware. This is critical in multi-tenant environments where tenants share CPU caches and memory buses, as it prevents an attacker from extracting key material through precise timing measurements.

Exam trap

ISC2 often tests the distinction between network-level isolation (VLANs, firewalls) and microarchitectural side-channel defenses, leading candidates to choose network controls when the question specifically targets side-channel attacks that bypass network segmentation.

How to eliminate wrong answers

Option B is wrong because VLANs and firewall rules provide network-layer isolation but do not address side-channel attacks that occur at the hardware or microarchitectural level, such as cache timing or branch prediction analysis. Option C is wrong because HSMs secure key storage and operations but do not prevent side-channel leakage from the CPU or memory during cryptographic processing; an attacker can still observe timing or power variations. Option D is wrong because API rate limiting controls request frequency to prevent abuse but has no effect on side-channel attacks that exploit shared processor resources like caches or execution pipelines.

682
MCQhard

A multinational bank is deploying a hybrid cloud with sensitive workloads on private infrastructure and analytics on a public cloud. The security team must ensure that data classified as confidential never leaves the private environment, while allowing the public cloud to process anonymized datasets. Which cloud deployment model characteristic is MOST relevant to enforcing this boundary?

A.The hybrid model automatically replicates all data to both environments for redundancy.
B.The private cloud eliminates the need for encryption at rest.
C.The hybrid model enables workload placement based on data classification and policy.
D.The public cloud provides stronger physical security than private data centers.
AnswerC

Hybrid cloud allows workloads and data to be placed according to sensitivity and regulatory policy. The bank can keep confidential data on private infrastructure while sending only anonymized datasets to the public cloud. This placement control is the defining characteristic that directly enforces the boundary between environments, making it the most relevant answer.

Why this answer

Hybrid cloud's primary security value in this scenario is the ability to place workloads and data according to classification and policy. The bank can enforce that confidential data stays private while anonymized datasets are processed publicly. Other options either misstate security properties or contradict the requirement, so workload placement based on data classification is the relevant characteristic.

Exam trap

The trap here is confusing hybrid cloud with automatic data replication, when hybrid actually enables policy-driven placement rather than copying everything everywhere.

683
MCQmedium

A cloud security architect is evaluating vulnerability management solutions for a hybrid cloud environment. The team needs to scan both on-premises servers and cloud workloads without installing agents on every system. Which approach is most suitable for cloud workloads?

A.Agent-based scanning using a cloud-native service
B.Network vulnerability scanning from a remote scanner
C.Container image scanning only
D.Agentless scanning via cloud APIs (CSPM)
AnswerD

Agentless scanning via cloud APIs queries the provider's control plane, so no software runs on each workload. This satisfies the stem's constraint of scanning cloud workloads without installing agents, unlike host-based tools that require per-system deployment.

Why this answer

Agentless scanning uses cloud APIs to assess vulnerabilities without requiring an agent on each instance. This is ideal for cloud workloads where agents may not be desired.

684
MCQeasy

An organization wants to detect potential crypto mining activity on their AWS EC2 instances. Which AWS service uses machine learning to identify such threats?

A.AWS WAF
B.Amazon GuardDuty
C.Amazon Inspector
D.AWS Shield
AnswerB

Amazon GuardDuty applies machine learning models to analyse VPC Flow Logs, DNS query logs, and CloudTrail management events for behavioural anomalies indicative of crypto mining, such as sustained outbound connections to known mining pools or unusual CPU utilisation patterns. This satisfies the constraint of detecting crypto mining on EC2 instances without requiring agent installation, as it relies on passive network and account-level telemetry.

Why this answer

Amazon GuardDuty is a threat detection service that uses machine learning, anomaly detection, and integrated threat intelligence to continuously monitor for malicious activity, including cryptocurrency mining (e.g., connections to known mining pools or unusual compute resource spikes). It analyzes AWS CloudTrail logs, VPC Flow Logs, and DNS logs to identify behavioral patterns indicative of crypto mining, such as sustained outbound traffic to mining pool IPs or unusual EC2 instance launches.

Exam trap

The trap here is that candidates often confuse Amazon Inspector (a vulnerability scanner) with GuardDuty (a threat detection service), mistakenly thinking Inspector's agent-based monitoring can detect runtime threats like crypto mining, when in fact Inspector only assesses configuration and software vulnerabilities.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting, not a service that uses machine learning to detect crypto mining activity on EC2 instances. Option C is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, not a machine learning-based threat detection service for behavioral anomalies like crypto mining. Option D is wrong because AWS Shield is a managed DDoS protection service that safeguards against distributed denial-of-service attacks, not a service that identifies crypto mining threats via machine learning.

685
MCQmedium

A security auditor is reviewing a cloud provider's controls to ensure that customer data is appropriately isolated. Which design principle is most directly related to this requirement?

A.Multitenancy isolation
B.Reversibility
C.Portability
D.Elasticity
AnswerA

Multitenancy isolation ensures one tenant's data, workloads, and processes cannot be accessed or affected by another sharing the same infrastructure. This design principle directly satisfies the auditor's requirement that customer data be appropriately segregated within the cloud provider's environment.

Why this answer

Multitenancy isolation is the design principle that ensures customer data and workloads are logically separated in a shared cloud environment. It directly addresses the auditor's requirement by preventing one tenant from accessing another's data through mechanisms like virtual networks, hypervisor separation, and encryption. This principle is fundamental to cloud security and compliance.

Exam trap

CCSP often tests the distinction between cloud characteristics and security principles; candidates may confuse isolation with portability or elasticity, which are about flexibility and scalability, not security separation.

How to eliminate wrong answers

Option B is wrong because reversibility refers to the ability to migrate data and applications back from the cloud to on-premises or another provider, not data isolation. Option C is wrong because portability is about the ease of moving applications and data between cloud environments, which is unrelated to isolation. Option D is wrong because elasticity is the ability to scale resources automatically based on demand, not a security isolation principle.

686
MCQhard

A company plans to deploy a multi-tier application across multiple cloud providers to avoid single points of failure. They need to ensure consistent security policies, including identity federation and network segmentation, across all environments. Which architecture consideration is MOST critical?

A.Using a single cloud provider for all tiers
B.Storing all data in a single provider's data center
C.Using different encryption standards for each provider
D.Implementing a unified security policy management tool
AnswerD

A unified policy management tool enforces identity federation and segmentation rules identically across providers, satisfying the stem's demand for consistent security policies. Without centralised control, each provider's native tooling diverges, creating gaps that undermine the multi-provider redundancy goal.

Why this answer

Implementing a unified security policy management tool is most critical for ensuring consistent security policies, including identity federation and network segmentation, across multiple cloud providers. Such a tool centralizes policy definition, translation, and enforcement, providing a single pane of glass for security management. This addresses the complexity of multi-cloud environments where native tools differ.

Other options either do not address multi-cloud (single provider) or introduce inconsistency (different encryption standards).

Exam trap

CCSP often tests the need for centralized policy management in multi-cloud, as candidates may focus on specific technologies like SSO or encryption but miss the overarching requirement for consistent enforcement across heterogeneous environments.

How to eliminate wrong answers

Option A is wrong because using a single cloud provider for all tiers contradicts the goal of avoiding single points of failure and does not address multi-cloud consistency; it also may not be feasible for all workloads. Option B is wrong because storing all data in a single provider's data center creates a single point of failure and does not support multi-cloud resilience. Option C is wrong because using different encryption standards for each provider leads to inconsistency and potential security gaps, rather than consistent policies.

687
MCQmedium

A company is adopting shift-left security. Which action best exemplifies this approach?

A.Running SAST scans during code development
B.Monitoring logs for suspicious activity
C.Performing security reviews after deployment
D.Conducting penetration testing annually
AnswerA

Running SAST during code development analyses source for vulnerabilities while developers write it, before commit or build. This exemplifies shift-left security by moving detection to the earliest lifecycle stage, satisfying the requirement to find flaws before they reach production.

Why this answer

Running SAST scans during code development is the best example of shift-left security because it moves security testing into the earliest phase of the SDLC, catching vulnerabilities before code is merged or deployed. Shift-left means integrating security practices earlier in development rather than after deployment. SAST during development directly embodies this principle.

Exam trap

CCSP often tests the confusion between shift-left (early development security) and shift-right (runtime monitoring and response), tricking candidates into selecting post-deployment activities as shift-left.

How to eliminate wrong answers

Option B is wrong because monitoring logs for suspicious activity is a detection and response activity that occurs after deployment, which is shift-right, not shift-left. Option C is wrong because security reviews after deployment are reactive and occur late in the lifecycle, contradicting shift-left. Option D is wrong because annual penetration testing is a periodic, post-deployment assessment, not an early-development practice.

688
MCQmedium

An organization uses cloud object storage for backup data and requires that once written, data cannot be modified or deleted for a specified retention period. Which feature should they enable?

A.Bucket versioning
B.Object lock with write-once-read-many (WORM) protection
C.Encryption at rest with customer-managed keys
D.Lifecycle management to expire objects old objects
AnswerB

Object lock enforces WORM semantics at the storage layer, preventing overwrite or deletion of an object version until its retention period expires, even by privileged users. This satisfies the immutability-for-a-specified-period constraint that ordinary versioning or lifecycle policies cannot guarantee.

Why this answer

Object lock with WORM protection is the correct feature because it enforces a retention policy that prevents any user, including the root account, from modifying or deleting objects until the retention period expires. This is specifically designed for compliance requirements such as SEC 17a-4(f) and ensures data immutability at the object level, which bucket versioning, encryption, or lifecycle rules cannot guarantee.

Exam trap

ISC2 often tests the misconception that bucket versioning alone provides data immutability, but versioning only protects against accidental overwrites by preserving old versions, not against intentional deletion or modification of the current version.

How to eliminate wrong answers

Option A is wrong because bucket versioning preserves multiple versions of an object but does not prevent deletion or overwrite of the current version; it only allows recovery of previous versions, not immutability. Option C is wrong because encryption at rest with customer-managed keys protects data confidentiality but does not enforce any write-once or retention constraints; data can still be modified or deleted by authorized users. Option D is wrong because lifecycle management automates the transition or expiration of objects based on age or rules, but it does not prevent deletion or modification during the retention period; in fact, it can delete objects prematurely if misconfigured.

689
Multi-Selecthard

A global enterprise is conducting a cloud risk assessment. Which THREE factors should be considered? (Select three.)

Select 3 answers
A.Color of the provider's logo
B.Inherent risk of data leaving the on-premises environment
C.Provider's stock price
D.Concentration risk from using a single cloud provider
E.Effectiveness of provider controls as evidenced by audit reports
AnswersB, D, E

Moving data to a provider transfers it outside the customer's direct control, introducing exposure from shared infrastructure, provider personnel and cross-border transfer. This inherent risk of data leaving the on-premises environment is a core factor in the cloud risk assessment the enterprise is conducting.

Why this answer

Option B is correct because moving data off-premises introduces inherent risk—loss of direct physical and logical control, jurisdictional exposure, and reliance on the provider's network and encryption—which is a core element of any cloud risk assessment. Option D is correct because concentration risk (vendor lock-in and dependence on a single provider) can create systemic exposure; if that provider suffers an outage, breach, or business failure, the enterprise's operations are broadly impacted, so it must be evaluated. Option E is correct because the effectiveness of the provider's controls must be verified through independent audit reports (e.g., SOC 2 Type II, ISO/IEC 27001 certifications, or CSA STAR), which provide evidence that security, availability, and confidentiality controls actually operate as claimed.

Option A is not relevant because a logo's color has no bearing on security, compliance, or operational risk. Option C is not relevant because stock price reflects market performance, not the provider's control effectiveness or the enterprise's risk exposure.

690
MCQeasy

A company is designing a multi-tier application in the cloud. The web tier must automatically scale based on CPU utilization, while the database tier should remain fixed to maintain data consistency. Which architectural pattern best meets these requirements?

A.Horizontal auto-scaling for the web tier and a fixed database tier
B.Manual scaling for both tiers
C.Vertical scaling of all tiers
D.Single-tier architecture with auto-scaling
AnswerA

Horizontal auto-scaling adds or removes web-tier instances behind a load balancer as CPU utilisation changes, absorbing variable demand. Keeping the database tier fixed avoids replication conflicts and preserves consistency, satisfying both constraints stated in the stem.

Why this answer

It separates the stateless web tier, which can safely scale horizontally using auto-scaling groups triggered by CPU utilization thresholds, from the stateful database tier, which must remain fixed to avoid consistency issues such as split-brain or replication lag. Horizontal scaling adds or removes identical web server instances without affecting session state, while a fixed database tier preserves ACID properties and prevents conflicts from concurrent writes across multiple database nodes.

Exam trap

ISC2 often tests the misconception that auto-scaling should apply uniformly to all tiers, but the trap here is that candidates forget the database tier requires stateful consistency and cannot scale horizontally without introducing eventual consistency or complex distributed transactions.

How to eliminate wrong answers

Option B is wrong because manual scaling for both tiers introduces operational overhead and cannot react dynamically to load changes, defeating the purpose of cloud elasticity. Option C is wrong because vertical scaling of all tiers (increasing instance size) has hard limits (maximum VM size) and does not address the need for the web tier to scale out; it also incorrectly scales the database tier, which should remain fixed. Option D is wrong because a single-tier architecture with auto-scaling collapses web and database functions into one layer, causing data consistency problems when multiple instances write to the same local storage and violating the multi-tier design requirement.

691
Multi-Selectmedium

A company uses a cloud key management service (KMS) with automatic key rotation enabled. Which TWO statements about key rotation are true?

Select 2 answers
A.The key ID changes after each rotation.
B.The old key is immediately destroyed after rotation.
C.New key material is generated, and the old key material is retained for decryption.
D.Applications using the key continue to work without modification.
E.All data encrypted with the old key must be re-encrypted.
AnswersC, D

Rotation generates new key material for future encryption while the previous version remains available for decryption, so existing ciphertext stays readable. This retained old material is why rotation does not require re-encrypting all stored data immediately.

Why this answer

Option C is correct because KMS rotation generates new cryptographic key material under the same logical key, while the previous key versions are retained so that data encrypted with them can still be decrypted. Option D is correct because applications reference the stable key identifier (key ID/ARN) rather than the underlying key material, so encryption and decryption continue to work transparently without code changes. Option A is wrong because the key ID remains the same; only the backing key material (key version) changes.

Option B is wrong because old key material is retained, not immediately destroyed, to preserve the ability to decrypt existing ciphertext. Option E is wrong because re-encryption is not required; old data remains decryptable via the retained old key versions.

Exam trap

ISC2 often tests the misconception that key rotation changes the key identifier or requires immediate re-encryption, when in fact the key ID remains stable and old key material is preserved for decryption.

692
MCQeasy

A security analyst reviews GCP Security Command Center findings and sees a high-severity alert for Event Threat Detection indicating that a service account key was used from an unexpected location. What is the best immediate action to contain the threat?

A.Disable the service account key
B.Create a new service account
C.Delete the service account
D.Rotate the key and monitor
AnswerA

Disabling the compromised service account key immediately invalidates the credential, halting any further authenticated API calls from the unexpected location. This directly satisfies the containment requirement, since the key itself is the abused authentication artefact and revocation stops the threat without deleting the account's audit history.

Why this answer

The correct immediate action is to disable the compromised service account key because Event Threat Detection has identified that the key is being used from an unexpected location, indicating potential unauthorized access. Disabling the key stops all further usage without deleting the service account or its other keys, preserving legitimate operations. This aligns with the principle of least privilege and incident response containment, as the key can later be rotated or deleted after investigation.

Exam trap

ISC2 CCSP exams often test the distinction between 'disable' and 'rotate' in key compromise scenarios, where candidates mistakenly choose rotation thinking it invalidates the old key, but rotation only creates a new key without disabling the old one unless explicitly done.

How to eliminate wrong answers

Option B is wrong because creating a new service account does not address the compromised key; the old key remains active and can still be used by the attacker. Option C is wrong because deleting the entire service account would disrupt all applications and resources relying on that account, which is an overly destructive action for a single compromised key. Option D is wrong because rotating the key (generating a new key) does not immediately disable the old compromised key; the old key remains valid until it is explicitly disabled or deleted, allowing continued unauthorized access during the rotation process.

693
MCQeasy

Which NIST essential characteristic of cloud computing allows the provider to dynamically assign and reassign resources to multiple tenants, often using a multi-tenant model?

A.Resource pooling
B.Rapid elasticity
C.Broad network access
D.Measured service
AnswerA

Resource pooling satisfies the multi-tenant constraint: the provider serves multiple consumers from a shared pool of configurable computing resources, with physical and virtual resources dynamically assigned and reassigned according to demand. Tenants remain isolated yet draw from common infrastructure, which is precisely the mechanism the stem describes.

Why this answer

Resource pooling is the NIST essential characteristic that allows the provider to dynamically assign and reassign physical and virtual resources to multiple tenants using a multi-tenant model. This pooling enables economies of scale and flexibility, as resources are shared and reassigned based on demand. The other characteristics do not specifically describe this dynamic assignment to tenants.

Exam trap

CCSP often tests the NIST definitions, and candidates may confuse resource pooling with rapid elasticity because both involve dynamic resource allocation; however, pooling specifically refers to serving multiple tenants from shared resources.

How to eliminate wrong answers

Option B is wrong because rapid elasticity refers to the ability to scale resources up and down quickly, not the pooling and reassignment to multiple tenants. Option C is wrong because broad network access means services are available over the network via standard mechanisms, not about resource assignment. Option D is wrong because measured service is about monitoring and metering resource usage for billing, not the dynamic assignment itself.

694
MCQeasy

Which tool is specifically designed to scan Infrastructure as Code (IaC) templates for cloud misconfigurations before deployment?

A.Checkov
B.OWASP ZAP
C.Snyk
D.GitGuardian
AnswerA

Checkov parses Terraform, CloudFormation and Kubernetes manifests statically, flagging insecure configurations such as public buckets or open security groups before deployment. This satisfies the pre-deployment constraint, since runtime and image scanners operate only after infrastructure already exists.

Why this answer

Checkov is an open-source static analysis tool built specifically to scan Infrastructure as Code templates — Terraform, CloudFormation, Kubernetes manifests, ARM templates, and others — for misconfigurations and policy violations before deployment. It encodes hundreds of built-in policies mapped to benchmarks like CIS and can run in CI/CD pipelines to shift security left. This makes it the purpose-built answer for pre-deployment IaC scanning.

Exam trap

The trap is tool-category confusion — candidates conflate 'cloud security tool' with 'IaC scanner' and pick Snyk (dependency scanning) or GitGuardian (secrets scanning) because they are well-known cloud-security names, missing that Checkov is the IaC-specific static analyzer.

How to eliminate wrong answers

Option B is wrong because OWASP ZAP is a dynamic application security testing (DAST) tool that probes running web applications for vulnerabilities like XSS and SQL injection — it does not parse IaC templates. Option C is wrong because Snyk is primarily a software composition analysis (SCA) and container/dependency vulnerability scanner; while it has some IaC capability, it is not specifically designed for IaC misconfiguration scanning the way Checkov is. Option D is wrong because GitGuardian is a secrets-detection tool that scans repositories for leaked credentials and API keys, not a misconfiguration scanner for IaC templates.

695
MCQhard

A multinational corporation uses multiple cloud service providers for its critical applications. The board is concerned about concentration risk. Which strategy would best address this risk?

A.Negotiating a longer contract with the primary cloud provider to ensure stability
B.Implementing a hybrid cloud model with on-premises infrastructure only
C.Adopting a multi-cloud strategy that distributes applications across multiple cloud providers
D.Requiring each business unit to use the same cloud provider for consistency
AnswerC

Distributing workloads across several providers directly reduces concentration risk by removing dependence on any single vendor's availability, pricing, or failure domain. Because the corporation already uses multiple cloud service providers, this approach satisfies the board's concern about over-reliance, ensuring no single provider outage or policy change can disrupt all critical applications simultaneously.

Why this answer

Concentration risk refers to over-reliance on a single provider. A multi-cloud strategy reduces this risk by distributing workloads across multiple providers, avoiding a single point of failure.

696
MCQmedium

An organization uses Azure Functions and needs to ensure that the function can securely access a database in a private VNet. What is the recommended approach?

A.Place the function in the same VNet as the database without any additional configuration
B.Use a VPN connection from the function to the database VNet
C.Enable VNet integration for the function app and configure the function to use the private IP of the database
D.Store database credentials in environment variables and use a public endpoint with IP whitelisting
AnswerC

VNet integration routes the function app's outbound traffic into the delegated subnet, letting it reach the database's private IP directly. This satisfies the stem's requirement for secure private access without exposing the database publicly. Combined with private endpoints or service endpoints, traffic stays on the Azure backbone, avoiding public internet exposure entirely.

Why this answer

VNet integration allows Azure Functions to access resources in a virtual network without exposing them to the internet, using a private IP.

697
Multi-Selectmedium

A cloud security team is building an incident response runbook for workloads on AWS. They need to ensure that when a compromised EC2 instance is detected, responders can preserve volatile evidence and prevent further malicious activity without destroying forensic artifacts. (Choose two.)

Select 2 answers
A.Reboot the instance to clear any malicious processes from memory.
B.Capture an EBS snapshot of the instance's volumes before making changes.
C.Isolate the instance using a security group that allows no inbound or outbound traffic.
D.Terminate the instance immediately to stop the attacker.
E.Detach the root volume and attach it to an analysis instance without snapshotting first.
AnswersB, C

An EBS snapshot captures the block-level state of the attached volumes, preserving disk-based artifacts such as logs, binaries, and configuration. Taking it before remediation ensures the evidence remains intact even if the instance is later terminated or modified, which is essential for forensic analysis and legal defensibility.

Why this answer

Effective cloud incident response follows the order of containment and preservation before remediation. Isolating the instance with a restrictive security group stops command-and-control and lateral movement while keeping the system alive, and capturing EBS snapshots first preserves disk artifacts. Together these steps contain the threat without destroying the evidence responders need.

Exam trap

The trap here is prioritizing immediate eradication, terminating or rebooting the instance, over containment and evidence preservation, which destroys volatile artifacts.

698
MCQeasy

A company uses Azure Sentinel as its SIEM. To ingest Azure Activity Logs and correlate with other data sources, which connector should be configured?

A.Office 365 connector
B.Azure Defender connector
C.Azure Activity connector
D.Windows Security Events connector
AnswerC

The Azure Activity connector streams subscription-level control-plane events, such as resource creation and role assignments, into the Microsoft Sentinel workspace. It satisfies the stem's requirement to ingest Azure Activity Logs and correlate them with other sources through analytics rules and workbooks.

Why this answer

The Azure Activity connector is specifically designed to ingest Azure Activity Logs, which contain subscription-level events such as resource creation, modification, and deletion. This connector enables Sentinel to correlate these operational logs with other data sources for comprehensive threat detection and incident response.

Exam trap

The trap is that candidates may confuse Azure Activity Logs (subscription-level operations) with Azure Defender alerts (security findings) or Office 365 logs (SaaS application logs). However, only the Azure Activity connector ingests subscription-level events needed for correlation with other data sources in Sentinel.

How to eliminate wrong answers

Option A is wrong because the Office 365 connector ingests logs from Microsoft 365 services (e.g., Exchange, SharePoint, Teams), not Azure subscription-level activity logs. Option B is wrong because the Azure Defender connector ingests security alerts from Azure Defender (formerly Azure Security Center), not raw Azure Activity Logs. Option D is wrong because the Windows Security Events connector ingests security event logs from Windows machines (e.g., Event ID 4625 for failed logons), not Azure platform logs.

699
MCQeasy

A financial services company is migrating its cardholder data environment to a public cloud IaaS platform. The security team must determine which controls remain the customer's responsibility under the shared responsibility model. Which of the following is the customer's responsibility in this IaaS deployment?

A.Maintaining the physical security controls of the data center housing the hosts
B.Managing the redundancy of the physical network switches that interconnect racks
C.Patching the guest operating system and its installed applications
D.Applying firmware and microcode updates to the underlying hypervisor hosts
AnswerC

In IaaS the provider secures the physical hosts, hypervisor, and network fabric, while the customer retains full control and responsibility for the guest operating system, middleware, and applications running on top of it. Patching the guest OS in the cardholder environment is therefore squarely a customer duty, and auditors will expect documented patch management evidence for those instances.

Why this answer

Under the shared responsibility model for IaaS, the provider owns security of the cloud, including facilities, hardware, and the hypervisor, while the customer owns security in the cloud. That includes the guest operating system, runtime, applications, and data. Because the question concerns a cardholder data environment, the customer must demonstrate patch management for the guest OS and applications as part of PCI DSS compliance obligations.

Exam trap

The trap here is assuming that because the provider manages the platform, it also patches the guest operating system, when in IaaS the customer always owns everything from the OS upward.

700
MCQeasy

A company is considering moving its customer relationship management (CRM) system to the cloud. The CRM is accessed through a web browser and the provider handles all maintenance, security, and infrastructure. Which cloud service model is being used?

A.IaaS
B.FaaS
C.SaaS
D.PaaS
AnswerC

SaaS delivers a complete, provider-managed application over the internet, so the vendor handles infrastructure, patching and security while users simply access the CRM through a browser. This satisfies the stem's constraint that the provider manages all maintenance, security and infrastructure, leaving the company only as a consumer of the finished service.

Why this answer

SaaS (Software as a Service) is the correct model because the provider delivers a complete, ready-to-use application (the CRM) over the web while managing all underlying infrastructure, platform, security patching, and maintenance. The customer only interacts with the application through a browser and does not manage servers, middleware, or runtime environments. This matches the classic SaaS definition where the consumer uses the provider's application running on cloud infrastructure.

Exam trap

The trap here is confusing SaaS with PaaS — candidates see 'web browser access' and 'provider handles maintenance' and pick PaaS, forgetting that PaaS still requires the customer to build and manage the application, whereas SaaS delivers the finished application.

How to eliminate wrong answers

Option A is wrong because IaaS provides raw compute, storage, and networking (e.g., AWS EC2) where the customer still manages the OS, middleware, and applications — the CRM provider would not be handling all maintenance. Option B is wrong because FaaS (Function as a Service) is an event-driven serverless compute model for running individual functions, not a full browser-accessed business application. Option D is wrong because PaaS provides a development and deployment platform (e.g., Heroku, App Engine) where the customer still builds and manages the application, whereas here the provider delivers the finished CRM application itself.

701
MCQhard

An organization is migrating a legacy application to the cloud and plans to use a cloud access security broker (CASB). Which of the following is the PRIMARY function of a CASB in securing cloud applications?

A.Performing vulnerability scans on cloud infrastructure
B.Encrypting data at rest in cloud storage
C.Protecting against distributed denial-of-service (DDoS) attacks
D.Enforcing security policies across cloud applications and controlling access
AnswerD

A CASB sits inline between users and cloud services, applying policy enforcement and access control as its core function. This directly addresses the migration scenario's need to govern sanctioned and unsanctioned cloud application usage, covering visibility, data loss prevention, threat protection and compliance enforcement.

Why this answer

The primary function of a CASB is to enforce security policies and control access across cloud applications, acting as an intermediary between users and cloud providers. It provides visibility into cloud usage, applies data loss prevention (DLP) rules, and enforces authentication and authorization policies, which directly addresses the need to secure a legacy application migrated to the cloud.

Exam trap

ISC2 often tests the distinction between a CASB's primary role (policy enforcement and access control) and secondary capabilities (like encryption or DLP), leading candidates to mistake a supporting feature for the core function.

How to eliminate wrong answers

Option A is wrong because vulnerability scanning of cloud infrastructure is typically performed by a cloud security posture management (CSPM) tool or a vulnerability scanner, not a CASB, which focuses on application-level policy enforcement and user access control. Option B is wrong because while a CASB can apply encryption for data in transit or at rest via tokenization or proxy-based encryption, its primary function is not encrypting data at rest; that is a feature of cloud storage services or dedicated encryption tools. Option C is wrong because protecting against DDoS attacks is handled by web application firewalls (WAFs) or DDoS mitigation services, not a CASB, which is designed for visibility, compliance, and access control for cloud applications.

702
MCQmedium

Refer to the exhibit. A cloud administrator sees this error log from AWS CloudTrail. The user [email protected] is a member of the 'Analysts' group. Which of the following is the most likely cause of the AccessDenied error?

A.The user is trying to access the bucket from a different AWS region.
B.The IAM policy attached to the user or group does not include s3:PutObject for that bucket.
C.The bucket policy explicitly denies access to the 'Analysts' group.
D.The bucket requires server-side encryption and the request did not include encryption headers.
AnswerB

The AccessDenied error arises because the identity-based IAM policy attached to the user or the Analysts group omits the s3:PutObject action for that bucket. Without an explicit Allow granting this action on the bucket ARN, IAM's default implicit deny blocks the request, satisfying the stem's authorisation constraint.

Why this answer

The AccessDenied error for an s3:PutObject operation indicates that the IAM policy attached to the user or group does not grant the necessary permissions. Since the user is a member of the 'Analysts' group, the most likely cause is that the group's IAM policy lacks an Allow effect for s3:PutObject on the target bucket. AWS IAM evaluates both identity-based and resource-based policies, and if no explicit Allow is present, the default implicit deny applies.

Exam trap

ISC2 often tests the distinction between an implicit deny (missing Allow) and an explicit deny (Deny statement), and candidates mistakenly assume a bucket policy or encryption requirement is the cause when the error is simply a missing permission in the IAM policy.

How to eliminate wrong answers

Option A is wrong because S3 bucket access is not region-specific; a bucket is a global resource and cross-region access is allowed by default unless explicitly restricted by a bucket policy or VPC endpoint. Option C is wrong because the error log does not indicate an explicit deny; an explicit deny would produce a different error message (e.g., 'AccessDenied' with a reason like 'explicit deny'), and the question states the user is a member of the 'Analysts' group without mentioning a bucket policy that denies them. Option D is wrong because if the bucket required server-side encryption and the request lacked encryption headers, the error would be 'AccessDenied' but with a specific message about encryption requirements (e.g., 'The bucket policy requires encryption headers'), not a generic AccessDenied for s3:PutObject.

703
Multi-Selecthard

A cloud security team is implementing a data discovery and classification solution for a multi-cloud environment. They need to identify and classify data stored in object storage buckets across AWS, Azure, and Google Cloud. The solution must automatically detect sensitive data such as personally identifiable information (PII) and protected health information (PHI). Which TWO capabilities are MOST critical for the solution to effectively classify data across these platforms? (Choose two.)

Select 2 answers
A.Integration with a SIEM to forward all classification events for real-time alerting.
B.The ability to automatically remediate misclassified data by moving it to a secure bucket.
C.The ability to enforce encryption at rest using provider-managed keys on all discovered buckets.
D.Prebuilt or customizable pattern recognition for PII and PHI, such as regular expressions and machine learning models.
E.Support for native API integration with each cloud provider's storage service to enumerate and sample objects.
AnswersD, E

Effective classification requires the ability to identify sensitive data patterns. Prebuilt or customizable detectors for PII and PHI enable the solution to recognize formats like Social Security numbers, credit card numbers, and medical record identifiers. Machine learning models can improve accuracy by learning from context. Without these, the solution cannot accurately classify data, especially across diverse data types and languages.

Why this answer

The two most critical capabilities for multi-cloud data discovery and classification are the ability to access data via native APIs and the ability to recognize sensitive data patterns. Native API integration enables the solution to enumerate and sample objects across different cloud storage services. Pattern recognition, including regular expressions and machine learning, allows accurate identification of PII and PHI.

Together, these enable effective classification. Other options are either post-classification actions or unrelated security controls.

Exam trap

The trap here is selecting operational or remediation features, such as SIEM integration or auto-remediation, as critical for classification, when the core requirements are data access and pattern detection.

704
Multi-Selecthard

Which THREE of the following are key components of an incident response plan specific to cloud environments? (Choose three.)

Select 3 answers
A.Establishing a process for preserving system snapshots and logs as evidence
B.Requiring involvement of the legal department for every incident
C.Defining procedures for contacting the cloud provider's support and security teams
D.Including a detailed data forensic analysis procedure for all incident types
E.Clarifying the shared responsibility model for incident handling
AnswersA, C, E

Snapshots and logs are volatile in cloud environments, so the plan must define collection, chain-of-custody and retention steps before instances are terminated or rotated. This meets the stem's cloud-specific requirement, where evidence often resides in provider-controlled storage.

Why this answer

Options A, C, and E are correct. A: Preserving system snapshots and logs is crucial for evidence collection and analysis in cloud incidents. C: Defining procedures for contacting the cloud provider’s support and security teams ensures timely assistance and coordination.

E: Clarifying the shared responsibility model for incident handling clarifies which party is responsible for each aspect of incident response. Option B is incorrect because not every incident requires legal department involvement; legal is typically consulted for specific scenarios such as data breaches or regulatory issues. Option D is incorrect because a detailed forensic analysis procedure for all incident types is impractical; procedures should be scalable and tailored to incident severity and type.

705
MCQeasy

A cloud administrator is designing a backup strategy for a critical database. Which of the following is the BEST approach to ensure data recoverability in case of a regional outage?

A.Regularly copy backups to a different geographic region.
B.Use tape backups stored in a physical safe in the same building.
C.Perform only daily backups without replication.
D.Store backups in a different availability zone within the same region.
AnswerA

Replicating backups to a separate geographic region ensures recoverability when an entire region fails, satisfying the regional outage constraint. Same-region copies would be lost with the region itself, so geographic separation is the mechanism that preserves data availability.

Why this answer

Replicating backups to a different geographic region ensures data recoverability even if the entire primary region experiences a catastrophic outage. This approach leverages cross-region replication, which provides independent fault domains and meets the recovery point objective (RPO) and recovery time objective (RTO) requirements for regional disaster scenarios. Cloud providers like AWS, Azure, and GCP offer services such as S3 Cross-Region Replication (CRR) or Azure Geo-Redundant Storage (GRS) to automate this process.

Exam trap

ISC2 often tests the distinction between 'availability zone' and 'region' redundancy, where candidates mistakenly believe that multiple AZs within a single region provide sufficient protection against a regional outage, but they do not—only cross-region replication ensures survivability from a full regional failure.

How to eliminate wrong answers

Option B is wrong because tape backups stored in a physical safe in the same building are vulnerable to the same regional disaster (e.g., earthquake, flood, power grid failure) and do not provide off-site protection; they also introduce latency and manual handling risks. Option C is wrong because performing only daily backups without replication creates a single point of failure; if the primary region fails, the backup data is lost or inaccessible, violating the principle of geographic redundancy. Option D is wrong because storing backups in a different availability zone within the same region does not protect against a regional outage, as the entire region can fail simultaneously (e.g., due to a widespread natural disaster or service provider failure).

706
Multi-Selectmedium

Which TWO measures are effective for securing container images in a cloud environment?

Select 2 answers
A.Store images in a public registry without scanning
B.Sign images to ensure integrity
C.Use latest tags without version pinning
D.Run containers with root privileges
E.Scan images for vulnerabilities before deployment
AnswersB, E

Signing container images with cryptographic hashes, verified against a trusted registry or key management system, ensures that the image has not been tampered with during transit or storage, directly satisfying the integrity constraint of the cloud environment. This mechanism prevents unauthorised modifications, such as injected malware, from being deployed in production, which is critical for maintaining a secure supply chain.

Why this answer

Option B is correct because cryptographically signing container images (e.g., with Docker Content Trust/Notary or Sigstore Cosign) lets the orchestrator verify image integrity and provenance, ensuring only trusted, untampered images are deployed. Option E is correct because scanning images for known CVEs in OS packages and application dependencies before deployment (using tools like Trivy, Clair, or Grype) catches vulnerabilities early and prevents shipping flawed images into production. Option A is wrong because a public registry without scanning exposes images to tampering and untracked vulnerabilities, undermining supply-chain security.

Option C is wrong because relying on mutable 'latest' tags without version pinning prevents reproducibility and integrity verification, making it easy to deploy unexpected or compromised images. Option D is wrong because running containers as root violates least privilege and dramatically increases the impact of a container escape or compromise.

Exam trap

ISC2 often tests the misconception that 'latest tags are safe because they always point to the most recent version,' but the trap is that 'latest' is a mutable tag that can silently introduce breaking changes or vulnerabilities, whereas version pinning (e.g., using a specific digest or semantic version) ensures deterministic and auditable deployments.

707
MCQhard

A financial institution uses a multi-cloud strategy with AWS and Azure. They must comply with PCI DSS. The security team found that a developer accidentally stored a file with credit card numbers in an S3 bucket that is publicly readable. Which immediate action should be taken to contain the breach?

A.Delete the file immediately.
B.Enable default encryption on the bucket.
C.Remove the public read permission on the bucket.
D.Revoke the developer's IAM credentials.
AnswerC

Removing the public read permission immediately stops anonymous internet access to the exposed credit card data, containing the breach. Revoking the bucket ACL or policy is the fastest containment step, satisfying PCI DSS obligations before any forensic or notification work begins.

Why this answer

Removing the public read permission on the S3 bucket immediately stops unauthorized access to the file containing credit card numbers, containing the breach in accordance with PCI DSS incident response requirements. This action does not destroy evidence (unlike deletion) and directly addresses the root cause—the bucket's misconfigured access control list (ACL) or bucket policy that allowed public read access. It is the fastest way to prevent further data exfiltration while preserving the file for forensic analysis.

Exam trap

ISC2 often tests the misconception that deleting the file or revoking credentials is the fastest containment step, but the trap here is that the root cause is the public permission, not the file's existence or the developer's identity—removing public access stops all anonymous access instantly, which is the correct containment action per incident response best practices.

How to eliminate wrong answers

Option A is wrong because deleting the file destroys potential forensic evidence needed for incident investigation and compliance reporting under PCI DSS Requirement 10 (track and monitor access to cardholder data), and the file may still be cached or accessible via bucket versioning or replication. Option B is wrong because enabling default encryption does not affect existing public read permissions; it only encrypts new objects at rest, leaving the already-exposed file still publicly readable. Option D is wrong because revoking the developer's IAM credentials does not remove the public read permission on the bucket; the file remains accessible to anyone on the internet, so the breach continues.

708
MCQhard

A security analyst is investigating a potential security incident in a Microsoft Azure environment. The analyst needs to review the history of role assignments and changes to Azure resources over the past 90 days. Which Azure service should the analyst use?

A.Azure Monitor Logs
B.Azure Security Center
C.Azure Activity Log
D.Azure AD Audit Logs
AnswerC

The Azure Activity Log provides a history of subscription-level events, including role assignments and resource changes. It retains data for 90 days by default, which aligns with the analyst's requirement. By reviewing the Activity Log, the analyst can see who made changes, what resources were affected, and when the changes occurred, which is essential for incident investigation.

Why this answer

The Azure Activity Log is the correct service because it records subscription-level events, including role assignments and resource modifications, and retains them for 90 days. This directly matches the analyst's need to review the history of changes over that period. Other services either focus on different scopes (like Azure AD) or require additional configuration for log retention.

Exam trap

The trap here is confusing Azure AD Audit Logs with Azure Activity Log, as both are audit logs but cover different scopes.

709
MCQhard

A financial services firm stores transaction logs in a cloud object storage bucket. Regulations require that deleted records be irrecoverable within 24 hours, even from provider-managed replicas and backups. The security team must select a deletion method that meets this requirement without relying on provider assurances. Which approach BEST satisfies the requirement?

A.Use cryptographic erasure by destroying the customer-managed key that encrypts the objects, rendering all copies undecipherable.
B.Enable bucket versioning and delete the current object versions, relying on the provider's lifecycle policy to purge noncurrent versions after 30 days.
C.Issue a delete request for each object and then open a support ticket asking the provider to confirm removal from all replicas and backups.
D.Move the objects to a colder storage class with a short retention period, then allow the provider to expire them automatically.
AnswerA

Cryptographic erasure destroys the key material, making every encrypted copy—including provider replicas and backups—unreadable without needing to locate each copy. Because the firm controls the customer-managed key, it does not rely on provider deletion guarantees. This meets the 24-hour irrecoverability requirement even when physical copies persist, and is a recognized cloud data destruction technique.

Why this answer

Cryptographic erasure is the only listed method that makes all copies—including provider-managed replicas and backups—unreadable by destroying the customer-controlled key. It avoids dependence on provider deletion timelines and assurances, so it can satisfy a strict 24-hour irrecoverability mandate. Versioning, delete requests, and storage-class changes leave recoverable copies or rely on provider processes.

Exam trap

The trap here is assuming that a delete request or lifecycle expiration removes every provider-held copy, when replicas and backups persist independently of the logical object.

710
MCQhard

A cloud architect is designing a multi-tenant environment. To ensure that a tenant's virtual machine cannot access another tenant's memory, which resource isolation technique should be enforced at the hypervisor level?

A.IOMMU for device isolation
B.Memory isolation via hardware-enforced page tables
C.CPU pinning
D.Network segmentation with VLANs
AnswerB

Hardware-enforced page tables give each tenant VM its own second-level address translation, so the hypervisor maps guest physical addresses to distinct machine frames. This satisfies the stem's requirement that one tenant's VM cannot read another tenant's memory, since no shared mapping exists.

Why this answer

Memory isolation via hardware-enforced page tables (using CPU features like Intel VT-x EPT or AMD-V NPT) ensures that each VM's memory is mapped in separate address spaces managed by the hypervisor, so a guest cannot address or read another guest's physical memory. This is the fundamental hypervisor-level mechanism that enforces memory isolation between tenants. It directly addresses the requirement that one tenant's VM cannot access another's memory.

Exam trap

CCSP often tests whether candidates confuse device isolation (IOMMU), CPU scheduling (pinning), or network isolation (VLANs) with memory isolation — the trap is picking a control that addresses a different resource than the one named in the question.

How to eliminate wrong answers

Option A is wrong because IOMMU isolates device DMA access (preventing devices from writing to arbitrary memory), which is important for device passthrough but does not isolate guest memory from other guests. Option C is wrong because CPU pinning binds vCPUs to physical cores for performance and predictability, not for memory isolation. Option D is wrong because network segmentation with VLANs isolates network traffic, not memory, and operates at Layer 2 rather than the hypervisor memory layer.

711
MCQmedium

A company is migrating a legacy monolithic application to a cloud-native microservices architecture. The security architect is concerned about securing inter-service communication. Which of the following should be implemented to ensure mutual authentication and encryption between services?

A.Deploy a service mesh with mutual TLS (mTLS) for all inter-service communication.
B.Use shared API keys embedded in each service's configuration.
C.Implement TLS termination at the load balancer with internal certificates.
D.Place all services in the same Virtual Private Cloud (VPC) and restrict ingress with security groups.
AnswerA

A service mesh sidecar proxy intercepts all inter-service traffic and enforces mutual TLS, giving each service a verifiable identity certificate plus encryption in transit. This satisfies the mutual authentication and encryption requirement across the microservices architecture without altering application code.

Why this answer

A service mesh with mutual TLS (mTLS) provides both encryption and mutual authentication for inter-service communication, ensuring that each service verifies the identity of the other before exchanging data. This is the recommended approach for cloud-native microservices because it offloads security concerns from application code and uses X.509 certificates to establish trust, aligning with zero-trust principles.

Exam trap

ISC2 often tests the misconception that network segmentation (VPC/security groups) alone is sufficient for securing inter-service communication, but the CCSP emphasizes that encryption and mutual authentication are required for data-in-transit security in a zero-trust model.

How to eliminate wrong answers

Option B is wrong because shared API keys embedded in configuration do not provide mutual authentication (only one-way authentication) and are vulnerable to leakage, rotation issues, and replay attacks. Option C is wrong because TLS termination at the load balancer means traffic between services is decrypted and re-encrypted, leaving internal traffic potentially unencrypted and without mutual authentication between services themselves. Option D is wrong because placing services in the same VPC with security groups restricts network access but does not provide encryption or mutual authentication for inter-service communication; it relies on network perimeter controls rather than cryptographic identity.

712
Multi-Selecteasy

Which TWO of the following are characteristics of security groups compared to network ACLs in a cloud VPC? (Select two.)

Select 2 answers
A.Operate at the subnet level
B.Stateful – return traffic is automatically allowed
C.Stateless – each packet is evaluated independently
D.Support both allow and deny rules
E.Only allow rules can be specified
AnswersB, E

Security groups track connection state, so response traffic for an established flow is permitted automatically without a matching inbound rule. Network ACLs are stateless and require explicit rules for both directions, which is the axis of difference.

Why this answer

Option B is correct because security groups are stateful: when an inbound or outbound connection is permitted, the return traffic for that established flow is automatically allowed without needing a separate rule, unlike network ACLs which are stateless. Option E is correct because security groups only support allow rules; there is no way to create an explicit deny rule in a security group, whereas network ACLs support both allow and deny rules. Options A, C, and D describe network ACLs rather than security groups: network ACLs operate at the subnet level (A), are stateless and evaluate each packet independently (C), and support both allow and deny rules (D), so they do not belong as characteristics of security groups.

Exam trap

The trap here is confusing the stateful nature of security groups with the stateless nature of network ACLs, and forgetting that security groups only support allow rules.

713
Multi-Selectmedium

A DevSecOps team is implementing security scanning in the CI/CD pipeline for a cloud application. Which THREE tools or practices should be included to shift security left?

Select 3 answers
A.Infrastructure-as-Code (IaC) security scanning
B.Static Application Security Testing (SAST)
C.Web Application Firewall (WAF) deployment
D.Runtime Application Self-Protection (RASP)
E.Dependency scanning (e.g., Snyk)
AnswersA, B, E

IaC scanning analyses templates such as Terraform and CloudFormation before deployment, detecting misconfigured storage buckets, permissive security groups, and missing encryption. This shifts security left by catching cloud configuration flaws at code review, before infrastructure is ever provisioned.

Why this answer

Infrastructure-as-Code (IaC) security scanning (A) is correct because it detects misconfigurations in templates such as Terraform, CloudFormation, or Kubernetes manifests before deployment, catching issues like open security groups or unencrypted storage early in the pipeline. Static Application Security Testing (SAST) (B) is correct because it analyzes source code without executing it to find vulnerabilities such as SQL injection or hardcoded secrets during the build phase, which is the essence of shifting security left. Dependency scanning (E), for example with Snyk, is correct because it identifies known CVEs in third-party libraries and open-source packages before they reach production, a critical early-stage control in DevSecOps.

Web Application Firewall (C) deployment is not included because a WAF is a runtime, perimeter defense that filters HTTP traffic in production rather than a shift-left pipeline practice. Runtime Application Self-Protection (D) is not included because RASP instruments the running application to detect and block attacks at execution time, which is a runtime control, not an early CI/CD scanning activity.

714
MCQmedium

A company identifies a high-risk vulnerability in a cloud application. The cost to remediate is significantly higher than the potential loss from exploitation. Which risk treatment strategy is most appropriate?

A.Acceptance
B.Avoidance
C.Transfer
D.Mitigation
AnswerA

Acceptance is appropriate when remediation cost outweighs potential loss, and the scenario states exactly that imbalance. Formally accepting the high-risk vulnerability, with documented justification and monitoring, satisfies the cost-benefit constraint rather than transferring, avoiding or mitigating it through disproportionate expenditure.

Why this answer

When the cost to remediate a vulnerability exceeds the potential loss from exploitation, the most appropriate risk treatment strategy is acceptance. This means the organization formally acknowledges the risk and chooses to tolerate it without implementing additional controls, often documented in a risk register. In cloud environments, this is common for low-impact, high-cost vulnerabilities where the business decides the residual risk is within its risk appetite.

Exam trap

ISC2 often tests the distinction between risk acceptance and risk mitigation, where candidates mistakenly choose mitigation because they assume all vulnerabilities must be fixed, ignoring the cost-benefit analysis that justifies acceptance.

How to eliminate wrong answers

Option B (Avoidance) is wrong because avoidance involves eliminating the risk entirely, such as discontinuing the vulnerable cloud service or feature, which would be disproportionate and unnecessary when the potential loss is lower than remediation cost. Option C (Transfer) is wrong because transfer shifts the risk to a third party, typically through cyber insurance or outsourcing, but does not reduce the cost of remediation and may not be feasible for a specific application vulnerability. Option D (Mitigation) is wrong because mitigation involves implementing controls to reduce the risk to an acceptable level, which contradicts the premise that remediation cost is higher than the potential loss; mitigation would still incur that high cost.

715
MCQmedium

A financial services company must comply with a regulation that requires encryption keys used for cloud services to be generated and stored on-premises in a Hardware Security Module (HSM). The cloud provider must not have any access to the keys. Which key management approach should the company adopt?

A.Cloud KMS with HSM-backed keys
B.Customer-Managed Encryption Keys (CMEK)
C.Bring Your Own Key (BYOK)
D.Hold Your Own Key (HYOK)
AnswerD

Hold Your Own Key keeps key generation and storage inside the customer's on-premises HSM, so the cloud provider never gains access to plaintext keys. This directly satisfies the regulation's mandate that keys remain on-premises and inaccessible to the provider, unlike cloud-hosted alternatives where the provider retains custodial control.

Why this answer

HYOK (Hold Your Own Key) is the only approach where the customer generates and stores the encryption keys entirely on-premises in their own HSM, and the cloud provider never has access to the plaintext keys. The cloud provider only receives encrypted data or wrapped keys, so it cannot decrypt the data. This satisfies the regulation's requirement that keys be generated and stored on-premises and that the provider have zero access.

In contrast, CMEK and BYOK still involve the cloud provider's key management infrastructure, which means the provider has some level of access or control.

Exam trap

CCSP often tests the distinction between key management models where the cloud provider still has access to keys (CMEK, BYOK) versus models where the customer retains exclusive control (HYOK), and candidates frequently confuse BYOK with HYOK, assuming that importing your own key means the provider has no access.

How to eliminate wrong answers

Option A is wrong because Cloud KMS with HSM-backed keys stores keys in the cloud provider's HSM, so the provider has access to the keys and they are not generated or stored on-premises. Option B is wrong because Customer-Managed Encryption Keys (CMEK) still reside in the cloud provider's KMS, meaning the provider has access to the key material and can potentially use it, violating the zero-access requirement. Option C is wrong because Bring Your Own Key (BYOK) allows you to import your own key material into the cloud provider's KMS, but once imported, the provider has access to the key and it is stored in the cloud, not exclusively on-premises.

716
MCQhard

A covered entity under HIPAA is moving electronic protected health information (ePHI) to a public cloud. What is the primary requirement before the cloud provider hosts ePHI?

A.The cloud provider must be located within the United States
B.The cloud provider must sign a Business Associate Agreement (BAA)
C.The cloud provider must be certified under ISO 27001
D.The covered entity must obtain written authorization from each patient
AnswerB

HIPAA requires a Business Associate Agreement before a cloud provider creates, receives, maintains or transmits ePHI on behalf of the covered entity. The BAA contractually binds the provider to safeguard ePHI and report breaches, satisfying the Privacy and Security Rules.

Why this answer

Under HIPAA, a cloud provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a Business Associate, and the covered entity must have a signed Business Associate Agreement (BAA) in place before ePHI is hosted. The BAA contractually obligates the provider to safeguard ePHI and comply with applicable HIPAA Privacy and Security Rule provisions.

Exam trap

CCSP often tests the misconception that geographic location or a generic security certification (ISO 27001) satisfies HIPAA — the legally required mechanism is the BAA, not location or certification.

How to eliminate wrong answers

Option A is wrong because HIPAA does not require the cloud provider to be physically located in the United States — it requires appropriate safeguards regardless of location, though cross-border data transfer may raise other legal issues. Option C is wrong because ISO 27001 certification is a voluntary security management standard and is not a HIPAA legal prerequisite, even though it can support compliance. Option D is wrong because obtaining patient authorization is required for uses/disclosures of PHI for purposes like marketing or research, not for engaging a business associate to host ePHI for treatment, payment, or operations.

717
MCQmedium

A cloud security team is implementing a Web Application Firewall (WAF) for a public-facing web application. The application uses a REST API with JSON payloads. Which of the following is the WAF's primary benefit?

A.Scanning for data loss prevention (DLP) violations
B.Preventing network-layer DDoS attacks
C.Encrypting data in transit between client and server
D.Inspecting HTTP traffic for malicious payloads
AnswerD

A WAF operates at the application layer, parsing HTTP requests and responses to detect and block malicious payloads such as SQL injection or cross-site scripting before they reach the REST API, directly satisfying the requirement to protect the public-facing JSON-based application.

Why this answer

A WAF operates at Layer 7 (application layer) and is specifically designed to inspect HTTP/HTTPS traffic for malicious payloads such as SQL injection, cross-site scripting (XSS), and JSON-based attacks. For a REST API using JSON, the WAF can parse and validate the JSON structure, blocking malformed or malicious payloads before they reach the application server. This is the primary benefit because it directly protects the application logic from web-based exploits.

Exam trap

ISC2 often tests the distinction between Layer 7 (application) and Layer 3/4 (network) security controls, so candidates mistakenly choose network-layer DDoS protection (Option B) because they confuse WAF with a general-purpose firewall.

How to eliminate wrong answers

Option A is wrong because DLP scanning is a function of data loss prevention tools, not a WAF; a WAF does not inspect data for policy violations like credit card numbers or PII. Option B is wrong because preventing network-layer DDoS attacks (e.g., SYN floods) is the role of a network firewall or DDoS mitigation appliance, not a WAF which focuses on application-layer attacks. Option C is wrong because encrypting data in transit is the job of TLS/SSL (e.g., HTTPS), not a WAF; a WAF inspects decrypted traffic after TLS termination or uses a reverse proxy model, but it does not perform encryption itself.

718
MCQhard

A multinational corporation uses a cloud-based data warehouse. The security team must enforce a policy that prevents any user from exporting query results containing more than 100 personally identifiable information (PII) records to an external IP address. Which cloud data security control is MOST appropriate?

A.Apply row-level security in the data warehouse to limit the number of PII records each user can query.
B.Enable database activity monitoring (DAM) on the data warehouse to log all queries and alert on large result sets.
C.Configure cloud storage bucket policies to deny access from external IP ranges.
D.Implement a cloud access security broker (CASB) with data loss prevention (DLP) policies that inspect outbound traffic for PII and block transfers exceeding the threshold.
AnswerD

A CASB with DLP can inspect data in transit, identify PII patterns, and enforce policies based on content and volume. It can block or alert on exports that exceed the defined threshold to external IPs, directly addressing the requirement. This is the most appropriate control because it operates at the data level and can be applied across cloud services.

Why this answer

A CASB with DLP is designed to inspect data in motion, recognize sensitive information like PII, and enforce policies based on content and volume. It can block or alert on transfers that exceed the defined threshold to external IP addresses, providing the inline enforcement needed to prevent data exfiltration. Other controls either lack content inspection or cannot block the transfer in real time.

Exam trap

The trap here is confusing access control with data loss prevention; bucket policies and row-level security govern access to data but do not inspect or limit the volume of data being exported.

719
MCQeasy

A company is migrating a legacy web application to the cloud. The application uses a relational database. The security team wants to ensure that database credentials are never hardcoded in the application and are automatically rotated. Which cloud-native approach should be used?

A.Store credentials in environment variables on the application server.
B.Encrypt the database connection string in a configuration file.
C.Use a database user with a long, complex password that is changed manually every 90 days.
D.Use a managed secrets management service that integrates with the database to rotate credentials.
AnswerD

A managed secrets service securely stores credentials and can automatically rotate them on a schedule. The application retrieves credentials at runtime via an API, eliminating hardcoding. This directly satisfies the requirements for secure storage and automatic rotation.

Why this answer

A managed secrets management service provides secure storage and automatic rotation of database credentials. The application retrieves credentials dynamically, so they are never hardcoded. This is the cloud-native best practice for secret management and meets both requirements.

Exam trap

The trap here is thinking that encrypting configuration files or using environment variables is sufficient, when they still expose secrets and lack automatic rotation.

720
MCQmedium

An organization uses GCP and wants to monitor for threats in real-time, including detecting malicious activity from compromised service accounts. Which GCP service should be used?

A.Cloud Audit Logs
B.Cloud Security Scanner
C.Container Threat Detection
D.Event Threat Detection
AnswerD

Event Threat Detection continuously analyses Cloud Audit Logs and VPC flow logs using threat intelligence to surface compromised service accounts, cryptomining and data exfiltration in near real-time. Security Command Center Premium surfaces these findings, satisfying the real-time monitoring requirement that Cloud Logging alone cannot provide.

Why this answer

Event Threat Detection is part of GCP Security Command Center and provides real-time threat detection for IAM anomalies, including compromised service accounts.

721
MCQhard

A multinational corporation uses a cloud-based data warehouse to analyze customer data across regions. The company must comply with GDPR, which restricts cross-border data transfers. The security architect needs to ensure that data subjects' personal data remains within the EU region and is not replicated to other regions. Which cloud data security control should be implemented?

A.Use of a cloud access security broker (CASB) to monitor data flows
B.Tokenization of all personal data before storing in the cloud data warehouse
C.Encryption of data at rest with customer-managed keys stored in the EU
D.Data residency policies enforced through cloud provider's region lock feature
AnswerD

Data residency policies enforced through the cloud provider's region lock feature allow the organization to restrict data storage and processing to a specific geographic region. This ensures that personal data remains within the EU, complying with GDPR's cross-border transfer restrictions. It is a direct control that prevents replication to other regions.

Why this answer

GDPR requires that personal data of EU subjects not be transferred to countries without adequate protection unless specific safeguards are in place. To ensure data remains within the EU, the organization should use the cloud provider's region lock or data residency feature, which restricts data storage and processing to a chosen region. This preventive control directly addresses the requirement.

Exam trap

The trap here is confusing encryption or tokenization with data residency; both protect data but do not prevent cross-border replication, which is the core GDPR concern.

722
MCQmedium

A security team wants to detect container image vulnerabilities before they are pushed to a registry. Which stage of the CI pipeline should container image scanning occur?

A.After build and before push to registry
B.During runtime in production
C.After deployment to production
D.After push to registry and before deployment
AnswerA

Scanning after the image build but before the registry push catches vulnerabilities while the artefact is still local, preventing flawed images from being published. This satisfies the stem's requirement to detect issues before images reach the registry.

Why this answer

Scanning container images after build but before push ensures vulnerabilities are caught early and not deployed.

723
MCQmedium

A cloud operations team is building a CI/CD pipeline that deploys container images to a managed Kubernetes cluster. Security policy requires that only images whose vulnerabilities have been scanned and approved can run. The team wants the cluster itself to refuse any pod that references an unapproved image, even if the pipeline is bypassed. Which mechanism should they implement?

A.Enable image vulnerability scanning in the container registry and configure the registry to block pulls of images that exceed the severity threshold.
B.Configure a Kubernetes admission controller with a policy engine, such as Open Policy Agent Gatekeeper, to reject pods referencing images that lack the approved scan attestation.
C.Enable Kubernetes audit logging and forward events to a SIEM so that alerts fire when pods with unapproved images are created.
D.Add a policy check stage to the CI/CD pipeline that fails the build when the scanned image contains vulnerabilities above the threshold.
AnswerB

An admission controller with a policy engine evaluates every pod creation request against policy before the object is persisted, so a pod referencing an image without the required scan attestation is rejected by the cluster regardless of how the manifest was submitted. This enforces the control at the platform layer rather than relying on the pipeline, which is exactly what the scenario requires.

Why this answer

The requirement is preventive enforcement at the cluster level, independent of the deployment channel. A Kubernetes admission controller backed by a policy engine intercepts pod creation and rejects any manifest that does not carry the approved scan attestation. Registry scanning, pipeline gates, and audit alerts each leave a path for an unapproved pod to run, so they cannot satisfy the policy as written.

Exam trap

The trap here is assuming that scanning images in the registry or pipeline is equivalent to blocking unapproved pods from running in the cluster.

724
MCQeasy

A cloud security analyst is reviewing access logs and notices that a pre-signed URL for an object was used after its expiration time. What should be the outcome of such an access attempt?

A.The request is redirected to a new URL automatically
B.The request is allowed because the URL was generated with valid credentials
C.The request is denied with an access denied error
D.The request is logged but still granted
AnswerC

A pre-signed URL carries a cryptographic signature embedding its expiry timestamp. Once that time passes, the storage service validates the signature and rejects the request, returning an access denied error rather than serving the object.

Why this answer

Pre-signed URLs embed an expiration timestamp (the X-Amz-Expires parameter, capped at 7 days for SigV4) that the storage service validates on every request. Once the current time exceeds that expiry, the signature is treated as invalid and the service returns HTTP 403 AccessDenied. The credentials used to generate the URL are irrelevant at access time — only the signed expiry governs validity.

Exam trap

The trap here is assuming that valid credentials or an active IAM identity can override an expired pre-signed URL — candidates conflate credential validity with signature validity and pick the 'allowed' option.

How to eliminate wrong answers

Option A is wrong because pre-signed URLs are static signed strings; the storage service has no mechanism to redirect an expired request to a freshly signed URL — that would defeat the security purpose of expiration. Option B is wrong because the validity of the generating credentials does not extend the URL's life; the embedded expiration is authoritative and is checked independently of whether the signer's keys are still active. Option D is wrong because logging an event does not imply granting access — an expired signature fails validation before any authorization decision, so the request is rejected, not merely audited.

725
MCQmedium

An organization is using GCP Security Command Center with Event Threat Detection. Which type of event is most likely to generate a finding for 'exfiltration'?

A.A service account creating a new VM
B.A user logging in from a new IP address
C.A firewall rule change allowing all inbound traffic
D.A large number of objects being downloaded from a Cloud Storage bucket
AnswerD

Event Threat Detection flags exfiltration when an unusually large volume of objects is downloaded from a Cloud Storage bucket, indicating bulk data theft. This behaviour matches the exfiltration detector's data-egress heuristics rather than IAM or network findings.

Why this answer

Event Threat Detection (ETD) in GCP Security Command Center monitors Cloud Storage access logs for anomalous data access patterns. A large number of object downloads from a single bucket within a short time window is a strong indicator of data exfiltration, as it matches the behavioral signature of bulk data extraction. ETD uses machine learning models trained on normal access baselines to flag such volume-based anomalies as 'exfiltration' findings.

Exam trap

A common trap in the ISC2 CCSP exam is confusing an anomalous sign-in event (Option B) with data exfiltration. Exfiltration requires a data transfer action, such as downloading many objects from a storage bucket, not just authentication from a new location.

How to eliminate wrong answers

Option A is wrong because creating a new VM is an infrastructure provisioning action, not a data movement event; ETD focuses on data access and network anomalies, not resource creation. Option B is wrong because a login from a new IP address typically triggers an 'anomalous login' or 'brute force' finding, not an exfiltration event; exfiltration requires data leaving the environment. Option C is wrong because a firewall rule change allowing all inbound traffic is a misconfiguration finding related to network security, not data exfiltration; ETD would flag this under 'open firewall' or 'ingress' rules, not data theft.

726
MCQmedium

A SOC analyst notices an alert for 'impossible travel' where a user logged in from New York and then from London within 15 minutes. The SIEM correlation rule likely compares which log fields?

A.User agent and browser type
B.Source IP address and timestamp
C.Destination IP and port
D.Volume of data transferred and timestamp
AnswerB

Impossible travel detection calculates the geographic distance between successive authentications and divides it by elapsed time. The SIEM rule therefore correlates source IP address, which resolves to location, against the timestamp of each login event to derive an impossible velocity.

Why this answer

Impossible travel detection correlates the geographic location derived from the source IP address with the login timestamp to compute whether the physical distance between two logins could be traveled in the elapsed time. If the implied speed exceeds a threshold (e.g., faster than commercial air travel), the SIEM flags the event as impossible travel.

Exam trap

CCSP often tests whether candidates understand that impossible travel is fundamentally a geolocation-plus-time correlation — distractors mention client attributes (user agent) or destination attributes (port) that don't establish physical location.

How to eliminate wrong answers

Option A is wrong because user agent and browser type describe the client software, not the user's physical location, so they cannot establish geographic impossibility. Option C is wrong because destination IP and port describe the target server being accessed, not the origin of the user's connection, so they don't reveal travel. Option D is wrong because data volume and timestamp measure exfiltration or usage patterns, not the geographic origin of logins, so they cannot detect impossible travel.

727
MCQeasy

A development team is migrating a legacy application to the cloud. Which security testing approach should be adopted early in the CI/CD pipeline to catch vulnerabilities as code is written?

A.Dynamic application security testing (DAST)
B.Penetration testing
C.Runtime application self-protection (RASP)
D.Static application security testing (SAST)
AnswerD

SAST analyses source code without executing it, detecting injection flaws, insecure patterns and hard-coded secrets as developers commit. This satisfies the stem's constraint of catching vulnerabilities early in the CI/CD pipeline, unlike DAST or penetration testing which require a running application.

Why this answer

Static application security testing (SAST) analyzes source code, bytecode, or binary code without executing the application, making it ideal for integration early in the CI/CD pipeline to catch vulnerabilities like SQL injection, buffer overflows, and XSS as code is written. This 'white-box' approach provides immediate feedback to developers, aligning with the shift-left security principle for cloud-native development.

Exam trap

ISC2 often tests the distinction between SAST (white-box, early pipeline) and DAST (black-box, post-deployment), and candidates mistakenly choose DAST because they think 'dynamic' implies early testing, but DAST requires a running application.

How to eliminate wrong answers

Option A is wrong because DAST tests the running application from the outside (black-box), which requires a deployed environment and cannot catch vulnerabilities at the code-writing stage. Option B is wrong because penetration testing is a manual or automated simulated attack on a live system, performed later in the SDLC, not during development. Option C is wrong because RASP is a runtime protection technology embedded in the application runtime environment that monitors and blocks attacks in production, not a testing tool for the CI/CD pipeline.

728
MCQeasy

Which security testing approach is most effective at identifying vulnerabilities early in the cloud software development lifecycle (SDLC) by analyzing source code without executing the application?

A.Interactive Application Security Testing (IAST)
B.Static Application Security Testing (SAST)
C.Runtime Application Self-Protection (RASP)
D.Dynamic Application Security Testing (DAST)
AnswerB

Static Application Security Testing examines source code without executing it, satisfying the stem's requirement to find flaws early in the cloud SDLC. By scanning for injection, insecure dependencies and coding errors at commit time, SAST shifts detection left, before deployment. Dynamic and runtime tools need a running application, so they cannot meet the "without executing" constraint.

Why this answer

Static Application Security Testing (SAST) is the correct approach because it analyzes source code, bytecode, or binary code without executing the application, making it ideal for identifying vulnerabilities early in the SDLC (shift-left). Unlike dynamic or runtime tools, SAST scans the codebase statically, catching issues like SQL injection, buffer overflows, and insecure cryptographic implementations before compilation or deployment.

Exam trap

ISC2 often tests the distinction between SAST and DAST by framing the question around 'early in the SDLC' and 'without executing the application'—candidates mistakenly choose DAST because it is a common security test, but DAST requires a running application and is performed later in the lifecycle.

How to eliminate wrong answers

Option A is wrong because Interactive Application Security Testing (IAST) requires the application to be running and instrumented, typically within a test environment, to analyze code paths during execution—it does not work on static source code. Option C is wrong because Runtime Application Self-Protection (RASP) is a runtime security control embedded in the application that monitors and blocks attacks during execution, not a testing tool for early SDLC vulnerability detection. Option D is wrong because Dynamic Application Security Testing (DAST) tests the running application from the outside (black-box) by sending HTTP requests and analyzing responses, which requires a deployed instance and cannot analyze source code statically.

729
MCQmedium

A retail company is designing a new cloud architecture for its e-commerce platform. The security team has been asked to define the cloud security architecture. According to the Cloud Security Alliance (CSA) Enterprise Architecture, which of the following is the PRIMARY purpose of the security architecture domain?

A.To ensure that the cloud provider meets all regulatory compliance requirements
B.To define the physical security controls for data centers hosting cloud services
C.To provide a framework for managing security risks and controls across the cloud ecosystem
D.To specify the encryption algorithms required for data at rest and in transit
AnswerC

The security architecture domain in the CSA Enterprise Architecture provides a structured approach to identify, assess, and mitigate security risks across all cloud service and deployment models. It ensures that security controls are integrated into the overall cloud architecture, aligning with business objectives and compliance requirements.

Why this answer

The security architecture domain in the CSA Enterprise Architecture is designed to provide a holistic framework for managing security risks across cloud environments. It integrates security controls and practices into the overall cloud architecture, ensuring that security is aligned with business goals and compliance obligations.

Exam trap

The trap here is confusing the security architecture domain with specific technical controls like encryption or physical security, rather than recognizing its overarching risk management purpose.

730
Multi-Selecthard

A cloud security team is designing a secure software development lifecycle (SDLC) for a new microservices application deployed to a public cloud. They want to ensure that security is embedded throughout development and operations. Which two practices should be implemented to achieve this? (Choose two.)

Select 2 answers
A.Conduct threat modeling during the design phase for each microservice.
B.Assign all security responsibilities exclusively to a centralized security team.
C.Automate security gates in the CI/CD pipeline that block builds on critical findings.
D.Disable detailed logging in production to reduce storage costs and improve performance.
E.Perform a full penetration test only after the application is deployed to production.
AnswersA, C

Threat modeling in the design phase identifies potential threats, attack surfaces, and required mitigations before code is written. For microservices, it clarifies trust boundaries between services, data flows, and authentication needs. This early analysis reduces costly rework and aligns security with architecture, making it a core practice for embedding security throughout the SDLC.

Why this answer

Embedding security throughout the SDLC requires proactive design-time analysis and automated enforcement in delivery. Threat modeling during design surfaces risks before code exists, while automated CI/CD security gates ensure every build meets policy and blocks critical findings. Together they shift security left and maintain it through deployment.

Production-only testing, centralized ownership, and reduced logging all weaken or delay security rather than integrating it continuously.

Exam trap

The trap here is equating a single late-stage activity or centralizing security ownership with embedding security throughout the lifecycle.

731
MCQmedium

A cloud application uses an API gateway to expose backend microservices. The security team wants to ensure that clients cannot bypass the gateway and call backend services directly. Which control should be implemented to enforce this?

A.Configure rate limiting on the API gateway to prevent clients from sending excessive requests.
B.Place the backend services in a private subnet and restrict inbound traffic to only the API gateway's security group or identity.
C.Enable mutual TLS on the API gateway so clients must present certificates to connect.
D.Enable access logging on the API gateway and forward logs to a central monitoring service.
AnswerB

By making backend services reachable only from the API gateway's network identity, direct client access is blocked. This enforces the gateway as the single entry point and ensures all requests pass through the gateway's authentication, throttling, and logging controls.

Why this answer

Enforcing that backend services accept traffic only from the API gateway requires network-level restriction, such as private subnets combined with security group or identity-based rules. Authentication, rate limiting, and logging at the gateway improve security but do not prevent a client from reaching a backend endpoint that remains exposed.

Exam trap

The trap here is assuming that strong gateway controls like mutual TLS or rate limiting also prevent direct backend access, when only network isolation of the backends enforces the gateway path.

732
MCQmedium

An IAM policy named S3ReadOnlyAccess has DefaultVersionId v3. What does this indicate?

A.The policy is newly created.
B.The policy is currently using version v3 as the default.
C.The policy has three custom versions.
D.The policy cannot be attached to any entity.
AnswerB

DefaultVersionId identifies which of the policy's stored versions is currently applied to attached principals. v3 being the default means that document governs permissions; earlier versions remain retrievable but inactive, so the effective policy is version three.

Why this answer

The DefaultVersionId of an IAM policy indicates which version is currently active and enforced when the policy is attached to an IAM user, group, or role. Since the policy is named S3ReadOnlyAccess and has DefaultVersionId v3, version v3 is the default and is being used for access control decisions. This is the standard behavior for IAM policies in AWS, where you can have multiple versions but only one is designated as the default.

Exam trap

ISC2 often tests the misconception that DefaultVersionId indicates the total number of versions or that a policy with a non-v1 default is somehow broken or unattachable, when in fact it simply shows which version is active.

How to eliminate wrong answers

Option A is wrong because a newly created policy would have DefaultVersionId v1, not v3, as the first version is always v1. Option C is wrong because DefaultVersionId v3 does not imply there are exactly three custom versions; there could be more versions (e.g., v1, v2, v3, v4) and only v3 is set as default, or some versions may be non-default. Option D is wrong because a policy with a default version can be attached to any entity; the DefaultVersionId simply indicates which version is active, and the policy remains attachable unless explicitly restricted.

733
Multi-Selecthard

A cloud security architect is designing a data retention and deletion strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a database service and object storage. Regulations require that customer data be permanently deleted upon request, including from backups and disaster recovery sites. Which TWO controls are MOST critical to ensure compliance? (Choose two.)

Select 2 answers
A.Maintain an immutable audit log of all deletion requests and actions taken.
B.Use a centralized key management system with automated key rotation every 30 days.
C.Ensure that the cloud provider's backup and disaster recovery processes include mechanisms to propagate deletions to all copies.
D.Implement cryptographic erase by destroying the encryption keys associated with the customer's data.
E.Enable versioning on object storage buckets to prevent accidental deletion.
AnswersC, D

Backups and DR sites often retain data separately, so deletions must be propagated to them. Without this, data could persist indefinitely. This control is critical to ensure that deletion requests are honored across all storage locations, including offsite replicas, meeting the regulatory requirement.

Why this answer

To ensure permanent deletion across backups and DR sites, cryptographic erase (destroying keys) and propagating deletions to all copies are critical. Key rotation and audit logs do not delete data, and versioning can retain data. These two controls together ensure that data is irrecoverable and removed from all storage locations.

Exam trap

The trap here is assuming that key rotation or audit logging can substitute for actual data deletion, when they only provide security or evidence, not removal.

734
MCQhard

A multinational corporation must comply with GDPR and local data residency laws. They are designing a cloud storage architecture that will store customer data in the EU region. However, to improve disaster recovery, they want to replicate data to a secondary region outside the EU. Which approach meets compliance requirements?

A.Use cross-region replication to a non-EU region but apply client-side encryption before upload
B.Use same-region replication within the EU and disable cross-region replication
C.Use cross-region replication to a US region and encrypt data with SSE-S3
D.Use cross-region replication to a non-EU region and rely on a Data Processing Agreement (DPA)
AnswerB

Keeping replication within the EU and disabling cross-region replication prevents customer data leaving the jurisdiction, satisfying GDPR and local data residency rules. Disaster recovery is still provided through same-region replication, so compliance is met without unlawful transfer.

Why this answer

GDPR and data residency laws restrict transferring EU personal data to non-EU regions without an adequate legal mechanism, and cross-region replication to a non-EU region constitutes such a transfer. Keeping replication within the EU (same-region or intra-EU) and disabling cross-region replication to non-EU locations satisfies residency while still providing redundancy. This is the only option that avoids an unlawful transfer entirely.

Exam trap

The trap is believing that encryption (client-side or SSE) or a DPA legally sanitizes a cross-border transfer — candidates pick encryption as a compliance shortcut when the regulation actually restricts the location of processing, not just its confidentiality.

How to eliminate wrong answers

Option A is wrong because client-side encryption does not change the fact that personal data is being stored and processed in a non-EU region — GDPR governs the transfer and processing location, not just the ciphertext's readability. Option C is wrong because SSE-S3 is provider-managed encryption at rest and provides no legal basis for transferring EU personal data to a US region; the data is still transferred and processed outside the EU. Option D is wrong because a DPA alone does not authorize unrestricted transfers to non-EU regions — you still need a valid transfer mechanism (SCCs, adequacy decision, BCRs) and the DPA does not override data residency statutes.

735
MCQhard

An organization is evaluating a cloud provider's SLA for a critical application. The provider offers a 99.95% uptime SLA with a 10% service credit for each 30-minute downtime period exceeding the threshold. The organization's business impact analysis requires a maximum downtime of 4.38 hours per year. Does the provider's SLA meet this requirement, and what is the annual allowed downtime based on the SLA?

A.No, because service credits only apply after 30 minutes of downtime, so actual uptime is lower.
B.Yes, because the 10% credit effectively increases the uptime commitment.
C.No, because 99.95% uptime allows 5 hours of downtime per year.
D.Yes, because the SLA guarantees 99.95% uptime, which equals 4.38 hours of downtime per year.
AnswerD

A 99.95% uptime commitment permits 0.05% annual unavailability, which equals 4.38 hours across a 8,760-hour year — precisely the maximum downtime the business impact analysis specifies. The service credit mechanism does not alter this allowance; it only compensates financially once any single 30-minute period exceeds the threshold.

Why this answer

99.95% uptime translates to 0.05% of a year. A standard 365-day year has 8,760 hours, so 8,760 × 0.0005 = 4.38 hours of allowed downtime per year. Since the business impact analysis requires a maximum of 4.38 hours, the SLA exactly meets the requirement.

The 10% service credit is a financial remedy, not an uptime guarantee, so it does not change the calculation.

Exam trap

The trap is confusing service credits with uptime guarantees — candidates assume a 10% credit improves availability, when credits are purely a financial remedy and the uptime percentage is unchanged.

How to eliminate wrong answers

Option A is wrong because the 30-minute credit threshold affects compensation, not the uptime percentage itself — the SLA still commits to 99.95% availability regardless of when credits kick in. Option B is wrong because service credits are refunds, not additional uptime; they do not increase the 99.95% commitment or reduce allowed downtime. Option C is wrong because 99.95% allows 4.38 hours, not 5 hours — 5 hours corresponds to roughly 99.943% uptime, so the math is incorrect.

736
Multi-Selectmedium

Which TWO of the following are recommended practices for securing container images in a cloud environment? (Select TWO)

Select 2 answers
A.Using the latest tag for all images
B.Scanning images for vulnerabilities in the CI pipeline
C.Running containers as root user
D.Storing images in a public registry for easier access
E.Signing container images with a cryptographic key
AnswersB, E

Scanning images in the CI pipeline detects known CVEs in base layers and dependencies before the image reaches the registry, satisfying the shift-left requirement. This catches vulnerable components at build time, when remediation is cheapest, rather than after deployment into the cloud environment.

Why this answer

Option B is correct because integrating image vulnerability scanning (e.g., with tools like Trivy, Clair, or Amazon ECR image scanning) directly into the CI pipeline catches known CVEs in base images and dependencies before they are pushed to a registry or deployed, shifting security left. Option E is correct because cryptographically signing images (e.g., with Docker Content Trust/Notary or Sigstore Cosign) lets orchestrators and admission controllers verify image provenance and integrity, preventing tampered or unauthorized images from running. Option A is wrong because the 'latest' tag is mutable and non-deterministic, so it undermines reproducibility and can silently pull a vulnerable or unexpected build.

Option C is wrong because running containers as root violates least privilege and increases the blast radius of a container escape. Option D is wrong because public registries expose images to unauthorized pulls and potential tampering; private, access-controlled registries are the recommended practice.

737
MCQmedium

A cloud customer's security team learns that a provider's subprocessor experienced a breach affecting the customer's data. The customer's contract requires the provider to notify the customer of subprocessor breaches. Under the GDPR, within what timeframe must the cloud provider, acting as a processor, notify the controller of a personal data breach?

A.Without undue delay after becoming aware of the breach
B.Within 30 calendar days of completing its internal forensic investigation
C.Within 72 hours of becoming aware of the breach
D.Within 24 hours of confirming that the breach involves personal data
AnswerA

Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. 'Without undue delay' is deliberately not a fixed number of hours; it means as soon as reasonably possible given the circumstances. The controller then decides whether to notify the supervisory authority within its own 72-hour window.

Why this answer

GDPR Article 33(2) requires a processor to inform the controller without undue delay after becoming aware of a personal data breach. The 72-hour clock applies to the controller's notification to the supervisory authority, not to the processor's notice to the controller. This sequencing lets the controller assess the breach and meet its own regulatory and contractual duties.

Exam trap

The trap here is applying the controller's 72-hour supervisory authority deadline to the processor's obligation to notify the controller, which is instead 'without undue delay.'

738
MCQmedium

An organization uses a cloud storage service to share files with external partners. They want to ensure that the files are automatically deleted after 30 days. Which data lifecycle control should be implemented?

A.Object lock
B.Lifecycle policy
C.Versioning
D.Access control list
AnswerB

A lifecycle policy applies object-age rules that automatically delete or transition stored objects once they reach the defined threshold, here 30 days. It enforces retention without manual intervention, unlike access controls or encryption, which govern who may read data rather than how long it persists.

Why this answer

A lifecycle policy is the correct data lifecycle control because it allows administrators to define rules that automatically expire and delete objects after a specified period, such as 30 days. This is a native feature of cloud storage services like Amazon S3, Azure Blob Storage, and Google Cloud Storage, enabling automated data retention and deletion without manual intervention.

Exam trap

ISC2 often tests the distinction between data protection controls (Object Lock, Versioning) and data lifecycle controls (Lifecycle Policy), leading candidates to confuse retention with deletion.

How to eliminate wrong answers

Option A is wrong because Object Lock is designed to prevent objects from being deleted or overwritten for a fixed retention period or indefinitely (legal hold), which is the opposite of automatic deletion. Option C is wrong because Versioning preserves multiple versions of an object, allowing recovery of deleted or overwritten versions, but does not automatically delete data after a time period. Option D is wrong because Access Control Lists (ACLs) manage permissions for who can read or write objects, not the lifecycle or scheduled deletion of data.

739
MCQhard

A financial institution is required to comply with the Sarbanes-Oxley Act (SOX) for its cloud-hosted financial applications. The cloud provider is responsible for the underlying infrastructure. Which of the following controls is most likely the responsibility of the financial institution as part of IT general controls (ITGC)?

A.Physical security of the data center housing the cloud servers
B.Logical access controls to the financial application, including user provisioning and segregation of duties
C.Network intrusion detection at the cloud perimeter
D.Patching of the hypervisor that hosts the virtual machines
AnswerB

Under the shared responsibility model, the financial institution owns application-layer ITGCs: provisioning users, enforcing least privilege and separating duties. Infrastructure controls sit with the provider, but logical access to the financial application remains the institution's SOX responsibility.

Why this answer

Under the shared responsibility model, the cloud provider secures the infrastructure (data centers, hypervisors, network fabric), while the customer is responsible for controls over their own data, applications, and access. Logical access controls — user provisioning, authentication, authorization, and segregation of duties — are IT general controls that the financial institution must implement and evidence for SOX compliance, since they directly affect the integrity of financial reporting systems.

Exam trap

CCSP often tests the shared responsibility boundary — candidates incorrectly assign infrastructure controls (physical security, hypervisor patching) to the customer, when those belong to the provider.

How to eliminate wrong answers

Option A is wrong because physical security of the data center is the cloud provider's responsibility under the shared responsibility model — the customer cannot control who enters a Google or AWS facility. Option C is wrong because network intrusion detection at the cloud perimeter is typically part of the provider's infrastructure security, though customers may add their own IDS for their workloads; it is not the primary ITGC the institution owns. Option D is wrong because hypervisor patching is the provider's responsibility — the hypervisor is part of the managed infrastructure layer, not the customer's application stack.

740
MCQeasy

Which of the following is a benefit of enabling log file validation for cloud audit logs?

A.It ensures the integrity of log files by allowing you to confirm that they have not been modified.
B.It automatically deletes old log files based on a retention policy.
C.It encrypts log files at rest.
D.It compresses log files to save storage space.
AnswerA

Log file validation uses cryptographic hashing to produce a digest for each audit log file, letting you verify that entries have not been altered or deleted after capture. This directly satisfies the stem's integrity requirement, supporting tamper-evident audit trails for compliance and forensic investigations.

Why this answer

Log file validation uses a hash-based digital signature (such as SHA-256) to create a digest file for each log file. This allows you to verify that the log files have not been tampered with, deleted, or modified after they were delivered, ensuring their integrity for forensic analysis and compliance.

Exam trap

The CCSP exam often tests the distinction between integrity (log file validation) and other security controls like encryption, compression, or lifecycle management, leading candidates to confuse validation with unrelated features.

How to eliminate wrong answers

Option B is wrong because CloudTrail log file validation does not manage retention or deletion; lifecycle policies are configured separately via S3 lifecycle rules or CloudTrail console settings. Option C is wrong because encryption at rest is provided by S3 server-side encryption (SSE-S3, SSE-KMS, or SSE-C), not by log file validation. Option D is wrong because compression is not a feature of log file validation; CloudTrail logs can be delivered in gzip format if configured, but validation does not compress them.

741
MCQmedium

A healthcare company is migrating a legacy three-tier application to AWS. The security team must ensure that the database tier is reachable only from the application tier, that the rule follows the application instances automatically as they scale, and that no rule permits a broader source. Which mechanism should the team use?

A.A network ACL on the database subnet that allows inbound traffic only from the application subnet CIDR range.
B.A security group on the database instances that allows inbound traffic from the VPC CIDR range on the database port.
C.AWS PrivateLink endpoint policies that restrict which application-tier principals may open connections to the database.
D.A security group on the database instances whose inbound rule references the security group ID of the application tier.
AnswerD

Referencing the application tier's security group as the source means any instance that carries that group is automatically allowed, so newly launched application instances are covered without rule changes. No CIDR is involved, so nothing in the VPC outside the application tier can connect, and the rule is stateful, so return traffic needs no extra configuration.

Why this answer

A security group rule that names the application tier's security group as its source gives an identity-based, stateful permission that tracks instances through scaling events and excludes every other resource in the VPC. CIDR-based subnet filters and VPC-wide rules are broader than needed, and PrivateLink does not address intra-VPC tier isolation.

Exam trap

The trap here is choosing a CIDR-based rule because it feels more precise, when only a security-group reference automatically follows elastic instances and excludes unrelated workloads in the same subnet.

742
MCQhard

During a security review of a serverless application, you notice that a Lambda function's execution role has permissions to delete all S3 buckets in the account. What is the most appropriate remediation to align with the principle of least privilege?

A.Create a custom IAM role that grants only the necessary actions on a specific S3 bucket
B.Store S3 bucket names in environment variables instead of hardcoding
C.Attach the AWS managed policy 'AmazonS3ReadOnlyAccess'
D.Remove the Lambda function's VPC integration
AnswerA

A custom IAM role scoped to only the necessary actions on a specific S3 bucket removes the wildcard delete permissions, directly enforcing least privilege for the Lambda execution role instead of leaving account-wide destructive access.

Why this answer

The correct remediation is to replace the overly permissive execution role with a custom IAM role scoped to only the specific S3 actions and the specific bucket the Lambda function actually needs. This directly enforces least privilege by eliminating the wildcard delete permissions across all buckets. AWS IAM evaluates the policy attached to the Lambda execution role on every API call, so narrowing the Resource ARN and Action list constrains the blast radius if the function is compromised.

Exam trap

CCSP often tests least privilege by offering plausible-sounding but non-authorization fixes (environment variables, VPC changes) — candidates must recognize that only IAM policy scoping actually reduces permissions.

How to eliminate wrong answers

Option B is wrong because storing bucket names in environment variables is a configuration-hygiene improvement, not an authorization control — the role would still permit deleting all buckets regardless of how names are supplied. Option C is wrong because AmazonS3ReadOnlyAccess grants read-only access, which would break any legitimate write or delete operations the function needs and is not a least-privilege fit for its actual function. Option D is wrong because removing VPC integration affects network reachability, not IAM permissions — the role would still retain the excessive S3 delete rights.

743
MCQeasy

A company is moving its customer database to a public cloud provider. The database contains personally identifiable information (PII) of European Union citizens. Which legal framework imposes requirements on the cloud customer regarding data protection and privacy in this scenario?

A.Sarbanes-Oxley Act (SOX)
B.General Data Protection Regulation (GDPR)
C.Health Insurance Portability and Accountability Act (HIPAA)
D.Payment Card Industry Data Security Standard (PCI DSS)
AnswerB

GDPR governs processing of EU citizens' personal data irrespective of where the controller or processor is established. Moving PII to a public cloud does not transfer accountability, so the cloud customer remains bound by GDPR's data protection and privacy obligations.

Why this answer

The General Data Protection Regulation (GDPR) is the correct legal framework because it specifically governs the processing of personally identifiable information (PII) of European Union citizens, regardless of where the data is stored or processed. As the cloud customer is moving a customer database containing EU PII to a public cloud provider, GDPR imposes strict requirements on the data controller (the customer) for data protection, consent, breach notification, and cross-border data transfer safeguards.

Exam trap

ISC2 often tests the misconception that any data privacy law applies globally, but the trap here is that candidates may choose HIPAA or PCI DSS because they are familiar with data protection, failing to recognize that GDPR is the only framework specifically designed for EU citizen PII regardless of industry.

How to eliminate wrong answers

Option A is wrong because the Sarbanes-Oxley Act (SOX) applies to financial reporting and internal controls for publicly traded companies in the U.S., not to general PII of EU citizens. Option C is wrong because the Health Insurance Portability and Accountability Act (HIPAA) applies only to protected health information (PHI) held by covered entities in the U.S., not to a general customer database containing EU PII. Option D is wrong because the Payment Card Industry Data Security Standard (PCI DSS) applies to cardholder data and payment card transactions, not to general PII or EU citizen data.

744
MCQmedium

A company's cloud infrastructure is subject to GDPR. The DPO requires that all customer personal data be encrypted at rest and in transit. The cloud provider offers SSE-S3 for object storage and enforces TLS 1.2 for API calls. Which additional control should the company implement to meet GDPR accountability requirements?

A.Implement client-side encryption with a key management service.
B.Enable detailed logging of all access to encrypted data.
C.Automatically delete backups older than 30 days.
D.Apply data masking to all personal data fields before storage.
AnswerB

Detailed access logging creates the audit trail GDPR accountability demands, evidencing who accessed personal data and when. SSE-S3 and TLS 1.2 already satisfy encryption at rest and in transit, so logging is the missing control.

Why this answer

While SSE-S3 and TLS 1.2 address encryption at rest and in transit, GDPR accountability requires the company to demonstrate compliance through audit trails. Enabling detailed logging of all access to encrypted data (Option B) provides the necessary records to prove who accessed personal data, when, and from where, fulfilling the 'demonstrate compliance' principle under Article 5(2) and Article 30 of the GDPR.

Exam trap

The trap here is that candidates confuse encryption controls (Options A and D) or data lifecycle policies (Option C) with accountability, which is a governance and audit requirement, not a technical data protection measure.

How to eliminate wrong answers

Option A is wrong because client-side encryption with a KMS is an additional encryption measure, but encryption is already satisfied by SSE-S3 and TLS 1.2; the gap is accountability, not encryption strength. Option C is wrong because automatically deleting backups older than 30 days is a data retention policy that may violate GDPR's storage limitation principle if not justified, and it does not address the accountability requirement for access logging. Option D is wrong because data masking before storage is a data minimization technique, but it does not create an audit trail; the DPO's requirement is specifically about accountability, not about reducing the sensitivity of stored data.

745
MCQmedium

A software vendor wants to offer its analytics product to several hospitals. Each hospital demands that its data reside on infrastructure dedicated to that hospital, that the hospital retain control over patching windows, and that the vendor's other customers never share the same physical hosts. The hospitals also want to share the cost of the common management tooling the vendor provides. Which cloud deployment model BEST matches these requirements?

A.Hybrid cloud
B.Community cloud
C.Private cloud
D.Public cloud
AnswerB

A community cloud is provisioned for exclusive use by a specific group of consumers that share common concerns such as compliance, security, or mission. The hospitals form exactly such a community, each getting dedicated infrastructure and control over its own patching while sharing the cost of the vendor's common management tooling. This matches the dedicated-tenancy and shared-cost requirements simultaneously.

Why this answer

The hospitals share a common set of concerns, including data residency, tenancy isolation, and patching control, and they want to pool the cost of the vendor's management tooling. That combination of exclusive use by a defined group plus shared economics is the defining characteristic of a community cloud. A public cloud conflicts with dedicated tenancy, a hybrid cloud addresses portability between models, and a private cloud serves one organization rather than a group sharing common requirements.

Exam trap

The trap here is reading dedicated infrastructure and choosing private cloud, overlooking that the consumers are multiple organizations sharing common concerns and costs.

746
Multi-Selecthard

Which THREE of the following are essential steps in a cloud data discovery process?

Select 3 answers
A.Map data flows between systems
B.Encrypt all discovered data
C.Classify data based on sensitivity
D.Identify where sensitive data resides
E.Create backup copies of data
AnswersA, C, D

Understanding data movement is critical.

Why this answer

Mapping data flows between systems is a foundational step in cloud data discovery. It enables organizations to understand how data moves across cloud services, APIs, and storage tiers, which is critical for identifying where sensitive data may be transmitted or stored. Without this mapping, discovery efforts may miss data in transit or in transient storage, leading to incomplete visibility.

Exam trap

ISC2 often tests the distinction between discovery steps and subsequent security controls, so the trap here is that candidates mistakenly treat encryption or backup as part of the discovery process when they are actually post-discovery remediation or protection actions.

747
MCQhard

A US-based cloud customer stores EU personal data in a provider's Singapore region and uses the provider's support team located in India. The customer relies on the EU-US Data Privacy Framework (DPF) for its own US transfers. Which action is required to legitimize the support team's access to that EU data?

A.Verify the provider's DPF certification covers the Indian support entity and the Singapore processing, or put an Article 46 transfer tool in place for the India access.
B.Obtain a derogation under Article 49 for occasional support access, since break-fix support is by definition non-repetitive.
C.Rely on the provider's Singapore data residency commitment because data stored in-region never leaves the jurisdiction.
D.Adopt binding corporate rules covering the customer's own corporate group, which automatically extends to provider personnel.
AnswerA

DPF certification is entity- and scope-specific: it only covers the certified US entity and the data categories and purposes listed. Remote access by a support team in India is itself a transfer to a third country, so the customer must confirm the certification's coverage or rely on an Article 46 mechanism such as SCCs for that access. Coverage cannot be assumed.

Why this answer

A transfer occurs whenever personal data is made accessible to an entity in a third country, including remote support access. DPF certification only covers the certified entity and the data categories it lists, so the customer must confirm the Indian support team is covered or execute a valid Article 46 mechanism such as SCCs. Storage location alone does not resolve the transfer question.

Exam trap

The trap here is treating data residency or a provider's DPF certification as covering all global support access, when remote access from a non-certified third country is itself a regulated transfer.

748
MCQhard

During a supply chain security review, a team discovers that container images are not being verified at admission time. Which Kubernetes-native tool should be implemented to ensure only signed images are deployed?

A.NetworkPolicy
B.PodSecurityPolicy
C.Admission controller (e.g., Kyverno) with image signature verification
D.ResourceQuota
AnswerC

Kyverno runs as a validating admission controller, so it evaluates image signatures against trusted keys before the pod is admitted, rejecting unsigned images. This is Kubernetes-native and enforces the supply chain requirement at admission time, unlike runtime scanners or registry-only checks.

Why this answer

An admission controller like OPA Gatekeeper or Kyverno can enforce policies that verify image signatures before allowing pod creation.

749
MCQhard

A financial services firm is designing a cloud environment that must comply with PCI DSS. The security architect proposes using a virtual private cloud (VPC) with subnets, security groups, and network ACLs. However, the compliance officer is concerned about the risk of data exposure due to misconfiguration. Which additional control would BEST address this concern?

A.Use a Web Application Firewall (WAF)
B.Implement a Security Information and Event Management (SIEM) system
C.Integrate Cloud Security Posture Management (CSPM)
D.Deploy Data Loss Prevention (DLP) tools
AnswerC

CSPM continuously monitors the VPC's subnets, security groups, and network ACLs for misconfigurations, detecting and remediating risky exposure before attackers exploit it. This directly addresses the compliance officer's misconfiguration concern, which static design controls alone cannot prevent.

Why this answer

CSPM tools continuously monitor cloud infrastructure configurations against compliance frameworks like PCI DSS, automatically detecting misconfigurations such as overly permissive security group rules or network ACLs that could expose cardholder data. This directly addresses the compliance officer's concern about data exposure due to misconfiguration by providing real-time visibility and remediation guidance, which is more proactive than the other options.

Exam trap

The trap here is that candidates often confuse CSPM with SIEM or DLP, thinking log analysis or data monitoring can catch configuration errors, but CSPM is the only tool specifically designed to audit and enforce cloud infrastructure configurations against compliance standards like PCI DSS.

How to eliminate wrong answers

Option A is wrong because a Web Application Firewall (WAF) protects against application-layer attacks (e.g., SQL injection, XSS) but does not detect or prevent misconfigurations in VPC subnets, security groups, or network ACLs. Option B is wrong because a Security Information and Event Management (SIEM) system aggregates and analyzes logs for threat detection and incident response, but it does not proactively scan cloud infrastructure for compliance misconfigurations or enforce security baselines. Option D is wrong because Data Loss Prevention (DLP) tools monitor and block sensitive data in transit or at rest, but they do not assess the underlying network or access control configurations that could lead to exposure.

750
MCQhard

A healthcare company uses a cloud-based patient management system. The cloud provider experiences a security incident that may have exposed protected health information (PHI). The provider notifies the company within 72 hours, as required by the service agreement. The company's internal breach response policy requires a legal review of the incident before notifying affected individuals. The legal review typically takes 48 hours. However, the company is required to notify patients within 60 days under HIPAA. With the 72-hour notification from the provider, the company has 60 days to notify patients. What is the most effective approach to meet the 60-day notification requirement while ensuring compliance with internal policy?

A.Notify patients immediately and then perform the legal review.
B.Wait for the legal review to complete before notifying patients.
C.Notify patients immediately based on the provider's notification.
D.Begin the legal review immediately and prepare patient notification in parallel.
AnswerD

Running the legal review concurrently with notification preparation uses the 72-hour provider notice and 60-day HIPAA window efficiently. Sequential review would consume 48 hours unnecessarily, yet parallel work still preserves the required legal approval before patients are contacted.

Why this answer

It allows the company to satisfy both the HIPAA 60-day notification requirement and its internal legal review policy by running the legal review and patient notification preparation concurrently. This parallel approach minimizes delay while ensuring that the notification content is legally vetted before release, which is critical for PHI incidents under HIPAA's Breach Notification Rule (45 CFR § 164.404).

Exam trap

ISC2 often tests the misconception that you must choose between compliance and internal policy, when in fact parallel processing of legal review and notification preparation is the correct approach to meet both requirements without violating the 60-day HIPAA deadline.

How to eliminate wrong answers

Option A is wrong because notifying patients immediately without legal review could expose the company to legal liability if the notification contains inaccurate or incomplete information, and it violates the internal policy requiring a legal review first. Option B is wrong because waiting for the legal review to complete before starting notification preparation could consume the entire 60-day window, risking non-compliance with HIPAA's 60-day deadline if the review takes longer than expected. Option C is wrong because notifying patients immediately based solely on the provider's notification bypasses the required legal review and may lead to premature disclosure of unverified PHI details, which could increase legal risk.

Page 9

Page 10 of 13

Page 11