Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 751–825

934 questions total · 13pages · All types, answers revealed

Page 10

Page 11 of 13

Page 12
751
MCQhard

A multinational corporation uses a cloud-based data lake to store aggregated analytics data. The security team needs to ensure that data subjects can exercise their right to erasure under GDPR, even when data is replicated across multiple cloud regions and stored in immutable backups. Which strategy best addresses this requirement?

A.Store all personal data in a single cloud region to simplify deletion and avoid cross-region replication issues.
B.Use crypto-shredding by encrypting each data subject's records with a unique key and destroying that key upon erasure request.
C.Anonymize the data by removing direct identifiers, then consider the erasure request fulfilled.
D.Implement a centralized deletion workflow that removes the data from all primary storage and waits for backup retention periods to expire.
AnswerB

Crypto-shredding makes data unrecoverable by destroying the unique encryption key, even if ciphertext remains in backups or replicas. This effectively satisfies the right to erasure because the data cannot be decrypted. It works across regions and immutable backups without needing to physically delete every copy.

Why this answer

Crypto-shredding is the most effective way to satisfy erasure requests when data is replicated and backed up immutably. By destroying the unique key for a data subject, the ciphertext becomes useless, achieving erasure without needing to locate and delete every copy. This approach is scalable and works across regions.

Exam trap

The trap here is assuming that deleting data from primary storage fulfills erasure, ignoring immutable backups and cross-region replicas.

752
MCQhard

A multinational corporation uses a cloud-based data warehouse. The security team must ensure that data remains encrypted at rest and that encryption keys are automatically rotated every 90 days without manual intervention. The keys must be stored in a hardware security module (HSM) and be auditable. Which solution meets these requirements?

A.Use a cloud KMS with automatic key rotation enabled and HSM-backed keys.
B.Implement application-level encryption with keys stored in a local hardware security module (HSM) and rotate them manually every 90 days.
C.Store encryption keys in a third-party secrets manager and rotate them using a scheduled script.
D.Use provider-managed encryption keys and rely on the provider's default rotation schedule.
AnswerA

A cloud KMS with automatic rotation and HSM-backed keys provides automated key rotation at defined intervals, stores keys in HSMs, and generates audit logs. This directly meets the requirements for automatic 90-day rotation, HSM storage, and auditability without manual effort.

Why this answer

A cloud KMS with automatic rotation and HSM-backed keys provides automated, policy-driven key rotation at specified intervals, ensures keys are stored in hardware security modules, and generates audit logs. This satisfies all requirements: encryption at rest, automatic 90-day rotation, HSM storage, and auditability.

Exam trap

The trap here is assuming that any key management service with rotation capabilities will automatically meet HSM and audit requirements, when in fact not all KMS offerings are HSM-backed or provide the necessary audit detail.

753
MCQmedium

A company is implementing a SIEM solution and needs to ingest security logs from multiple AWS accounts into a centralized security account. Which AWS service can best aggregate findings from all accounts?

A.Amazon GuardDuty
B.Amazon CloudWatch Logs
C.AWS Security Hub
D.AWS Config
AnswerC

AWS Security Hub aggregates findings across accounts through its multi-account administration, letting a delegated security account receive and consolidate findings from every member account. This directly satisfies the requirement to centralise findings from multiple AWS accounts into one security account, unlike services scoped to a single account.

Why this answer

AWS Security Hub is purpose-built to aggregate and normalize findings from multiple AWS accounts and services (GuardDuty, Inspector, Macie, Config, Firewall Manager, and third-party tools) into a single pane of glass. Using AWS Organizations integration, a delegated administrator account can centrally view and manage findings across all member accounts, which is exactly the SIEM-ingestion pattern described.

Exam trap

CCSP often tests the confusion between detection services (GuardDuty) and aggregation services (Security Hub) — candidates pick GuardDuty because it 'finds threats' but miss that the question asks about aggregating findings from many accounts.

How to eliminate wrong answers

Option A is wrong because GuardDuty is a threat-detection service that generates its own findings — it does not aggregate findings from other accounts or services into a central view. Option B is wrong because CloudWatch Logs stores and queries log data but does not normalize or aggregate security findings across accounts; it is a logging substrate, not a findings aggregator. Option D is wrong because AWS Config tracks resource configuration changes and compliance, producing configuration items and conformance packs, not a unified cross-account security findings dashboard.

754
MCQeasy

A cloud customer is concerned about the risk of unauthorized access to data due to the shared infrastructure of a public cloud. What type of risk does this represent?

A.Control risk
B.Detection risk
C.Inherent risk
D.Residual risk
AnswerC

Inherent risk is the risk that exists before any controls are applied, arising here from the public cloud's shared infrastructure exposing data to unauthorised access. It reflects the exposure intrinsic to the chosen architecture, not residual or control risk.

Why this answer

Inherent risk is the level of risk that exists before any controls are applied, arising from the nature of the activity or environment itself. The shared infrastructure of a public cloud introduces exposure to unauthorized access due to multi-tenancy, and this exposure exists inherently before the customer implements mitigating controls — making it an inherent risk.

Exam trap

CCSP often tests the distinction between inherent, residual, control, and detection risk — candidates must recognize that the question describes exposure before mitigation, which is inherent risk, not residual risk.

How to eliminate wrong answers

Option A is wrong because control risk refers to the risk that controls fail to prevent or detect a problem, not the baseline exposure from the environment. Option B is wrong because detection risk is the risk that monitoring or audit procedures fail to detect a material issue, which is a subset of control effectiveness, not the baseline exposure. Option D is wrong because residual risk is what remains after controls are applied — the question describes the risk before mitigation, not after.

755
MCQmedium

A company is migrating to the cloud and must comply with the Health Insurance Portability and Accountability Act (HIPAA). They plan to store electronic protected health information (ePHI) in a cloud database. Which of the following is a mandatory requirement for the cloud service agreement?

A.The CSP must store data in a specific geographic location.
B.The CSP must perform quarterly penetration tests.
C.The CSP must encrypt all data at rest using AES-256.
D.The CSP must sign a Business Associate Agreement (BAA).
AnswerD

HIPAA requires a Business Associate Agreement whenever a covered entity engages a third party handling ePHI. The CSP storing ePHI is a business associate, so a signed BAA is mandatory in the cloud service agreement, contractually binding the provider to safeguard the data.

Why this answer

Under HIPAA, a covered entity or business associate must have a written Business Associate Agreement (BAA) with any cloud service provider (CSP) that creates, receives, maintains, or transmits electronic protected health information (ePHI) on their behalf. The BAA is a mandatory contractual requirement that establishes the CSP's permitted uses and disclosures of ePHI, as well as its obligations to safeguard the data. Without a signed BAA, the CSP cannot lawfully handle ePHI, making this the only option that is a direct regulatory mandate under HIPAA.

Exam trap

ISC2 often tests the distinction between mandatory (required) and addressable (optional but must be documented if not implemented) specifications under HIPAA, leading candidates to incorrectly select encryption or testing frequency as mandatory requirements.

How to eliminate wrong answers

Option A is wrong because HIPAA does not mandate a specific geographic storage location; data residency requirements may arise from other regulations or organizational policy, but they are not a HIPAA requirement. Option B is wrong because HIPAA does not prescribe a specific frequency for penetration tests; the Security Rule requires periodic assessments of security measures, but quarterly testing is not a mandatory requirement. Option C is wrong because while encryption of ePHI at rest is an addressable implementation specification under the HIPAA Security Rule, AES-256 is not explicitly mandated; the rule allows for equivalent alternatives that meet the standard of protecting data.

756
MCQmedium

A financial services firm stores sensitive customer data in an object storage bucket. The security team wants to prevent the cloud provider's administrators from accessing the plaintext data, even though the provider manages the underlying infrastructure. The firm also needs to retain full control over the encryption keys and the ability to revoke access immediately. Which approach best meets these requirements?

A.Implement client-side encryption where the firm generates and stores keys in its own on-premises HSM.
B.Use provider-managed encryption with customer-managed keys stored in the provider's KMS.
C.Use a cloud access security broker (CASB) to encrypt data before it reaches the bucket.
D.Enable server-side encryption with provider-managed keys and enforce TLS for all data transfers.
AnswerA

Client-side encryption with keys held in an on-premises HSM ensures the cloud provider never has access to the plaintext or the keys. The firm retains exclusive control and can revoke access by simply not providing the key. This directly satisfies the requirement to prevent provider administrators from accessing plaintext data.

Why this answer

Client-side encryption with keys stored in an on-premises HSM ensures that the cloud provider never possesses the keys or the plaintext. This gives the firm exclusive control and the ability to revoke access instantly by withholding the key. Other methods leave key management with the provider or do not fully prevent provider access.

Exam trap

The trap here is assuming that using a cloud KMS with customer-managed keys prevents provider access, when in fact the provider still controls the infrastructure and may have privileged access to keys.

757
MCQeasy

A cloud security team is reviewing container security practices. Which of the following is the most effective way to minimize the attack surface of a container image?

A.Using the latest version of a base image
B.Using a minimal base image such as distroless
C.Using the :latest tag to ensure freshness
D.Scanning the image for CVEs after deployment
AnswerB

Distroless images omit package managers, shells and other OS utilities, leaving only the application and its runtime dependencies. Fewer installed components mean fewer exploitable binaries and a smaller vulnerability surface, directly satisfying the requirement to minimise the image's attack surface.

Why this answer

Using a minimal base image such as distroless is the most effective way to reduce a container image's attack surface because it strips the package manager, shell, and unnecessary OS utilities, leaving only the application and its runtime dependencies. Fewer installed packages means fewer libraries that can contain exploitable CVEs, and the absence of a shell makes post-exploitation pivoting much harder. Distroless images, maintained by Google, include only the runtime (e.g., a JRE or Python interpreter) and the app itself.

Exam trap

CCSP often tests the difference between preventive minimization (distroless, multi-stage builds) and detective scanning — candidates pick 'scan after deployment' because it sounds thorough, but it does not reduce attack surface.

How to eliminate wrong answers

Option A is wrong because using the latest version of a base image does not minimize attack surface — a full OS base image still ships hundreds of packages, and 'latest' can introduce unexpected changes. Option C is wrong because the :latest tag is mutable and non-deterministic, breaking reproducibility and potentially pulling in new vulnerabilities; it also does not reduce the number of components. Option D is wrong because scanning for CVEs after deployment is a detective control, not a preventive reduction of attack surface — the vulnerable components are already running.

758
MCQhard

A company uses a serverless architecture with AWS Lambda to process user-uploaded files. The Lambda function is triggered by an S3 bucket event. While reviewing security, the architect wants to ensure that the Lambda function cannot be invoked by unauthorized S3 buckets or accounts. What is the most secure configuration?

A.Use a condition in the policy that checks the source IP address.
B.Place the Lambda function inside a VPC with a VPC endpoint for S3.
C.Configure the Lambda function's resource-based policy to grant permission only to the specific S3 bucket ARN and its owner account.
D.Attach a resource-based policy that allows any S3 bucket to invoke the function.
AnswerC

A resource-based policy naming the exact S3 bucket ARN and owner account restricts invocation to that single source, satisfying the requirement that unauthorised buckets or accounts cannot trigger the function. Broader service principals would permit other buckets.

Why this answer

The most secure way to restrict Lambda invocation to a specific S3 bucket is to use a resource-based policy that explicitly grants the `lambda:InvokeFunction` permission only to the trusted bucket's ARN and the owning AWS account. This ensures that even if another S3 bucket or account attempts to trigger the function, the invocation is denied by the Lambda permission model, which evaluates both the resource-based policy and the caller's identity.

Exam trap

The trap here is that candidates often confuse network-level controls (like VPC placement or IP filtering) with identity-based access controls, failing to realize that S3 event notifications invoke Lambda through AWS's internal service-to-service channel, which bypasses network restrictions and requires explicit resource-based policy conditions.

How to eliminate wrong answers

Option A is wrong because checking the source IP address is ineffective for S3 event notifications, as S3 invokes Lambda via AWS internal services, not from a fixed public IP; the source IP can vary and is not a reliable control for cross-account or cross-bucket invocation. Option B is wrong because placing the Lambda function inside a VPC with a VPC endpoint for S3 controls network traffic but does not restrict which S3 buckets or accounts can invoke the function; invocation permissions are governed by IAM and resource-based policies, not network placement. Option D is wrong because allowing any S3 bucket to invoke the function violates the principle of least privilege and would permit unauthorized buckets or accounts to trigger the Lambda, leading to potential data exfiltration or abuse.

759
Multi-Selecteasy

A company is implementing a hybrid cloud architecture. Which two components are essential for establishing a secure connection between on-premises and cloud environments? (Choose two.)

Select 2 answers
A.Direct connect or dedicated interconnect
B.Identity and access management (IAM)
C.Cloud access security broker (CASB)
D.Web application firewall (WAF)
E.Virtual private network (VPN) gateway
AnswersA, E

A dedicated interconnect bypasses the public internet, giving private, predictable bandwidth between on-premises and cloud. For a hybrid architecture demanding a secure connection, this satisfies the isolation and throughput constraint that shared internet paths cannot guarantee.

Why this answer

Option A (Direct connect or dedicated interconnect) is correct because a dedicated private circuit such as AWS Direct Connect or Azure ExpressRoute bypasses the public internet, providing a consistent, low-latency, and secure private link between the on-premises data center and the cloud provider's network. Option E (VPN gateway) is correct because it establishes an encrypted IPsec/IKE tunnel over the public internet between the on-premises VPN device and the cloud VPN gateway, which is the standard mechanism for secure hybrid connectivity. Together these are the two essential transport components for a secure on-premises-to-cloud connection.

Option B (IAM) is not a connectivity component; it governs authentication and authorization of identities and does not establish the network link. Option C (CASB) is a policy enforcement and visibility layer for cloud service usage, not a site-to-site transport mechanism. Option D (WAF) protects web applications from HTTP-layer attacks and does not provide the hybrid network connection.

Exam trap

The trap here is that candidates often confuse security controls (IAM, CASB, WAF) with network connectivity components, mistakenly thinking that any security tool is essential for hybrid cloud connectivity, when in fact only dedicated circuits and VPN gateways provide the actual secure link between environments.

760
Multi-Selecthard

Which THREE are key considerations when designing a secure software development lifecycle (SSDLC) for cloud applications?

Select 3 answers
A.Static code analysis during development
B.Threat modeling at design phase
C.Security testing in production
D.Using a single cloud provider
E.Secure coding standards
AnswersA, B, E

Static code analysis scans source during development, catching injection flaws and insecure patterns before deployment. It satisfies the SSDLC requirement to embed security checks early in the build phase rather than relying on production controls.

Why this answer

Static code analysis during development (A) is correct because SAST tools scan source code for vulnerabilities such as injection flaws and insecure API usage before deployment, shifting security left in the SSDLC. Threat modeling at the design phase (B) is correct because it identifies trust boundaries, data flows, and potential attack vectors (e.g., STRIDE) early, when architectural changes are cheapest to make. Secure coding standards (E) are correct because they give developers concrete, enforceable rules (e.g., OWASP ASVS, input validation, output encoding) that reduce the introduction of common vulnerabilities in cloud-native code.

Security testing in production (C) is not a core SSDLC design consideration; while runtime monitoring and DAST may occur post-deployment, production testing is an operational activity rather than a lifecycle design principle. Using a single cloud provider (D) is irrelevant to SSDLC security design and may even increase lock-in and single-point-of-failure risk, so it is not a key consideration.

Exam trap

ISC2 often tests the distinction between activities that are part of the secure development lifecycle (design, code, test) versus operational security tasks (production testing), and candidates mistakenly select 'Security testing in production' because they confuse it with runtime security monitoring or penetration testing.

761
Multi-Selecthard

A cloud security team is designing a detective control strategy for a multi-account AWS organization. The team wants to continuously evaluate resource configurations against CIS AWS Foundations Benchmark controls across all accounts and receive alerts when a resource drifts from the desired state. The team also wants to automatically remediate noncompliant resources where possible. Which TWO AWS services should be combined to meet these requirements? (Choose two.)

Select 2 answers
A.AWS Trusted Advisor
B.AWS Config with conformance packs
C.AWS Systems Manager Automation runbooks
D.AWS Security Hub with CIS AWS Foundations Benchmark standard
E.Amazon GuardDuty
AnswersB, C

AWS Config continuously records resource configurations and evaluates them against rules. Conformance packs bundle AWS Config rules mapped to standards such as the CIS AWS Foundations Benchmark and can be deployed across an organization using a delegated administrator account. This provides the continuous compliance evaluation and drift detection the team requires across all accounts.

Why this answer

Continuous configuration evaluation against CIS controls across an organization is delivered by AWS Config conformance packs, which package standards-mapped rules and support multi-account deployment through a delegated administrator. Automatic remediation of noncompliant resources is delivered by AWS Config remediation actions that invoke AWS Systems Manager Automation runbooks. Security Hub and Trusted Advisor provide visibility or advice but do not perform the configuration recording and automated remediation this design requires.

Exam trap

The trap here is assuming AWS Security Hub alone enforces CIS compliance and remediates drift, when it aggregates findings and depends on AWS Config for evaluation and on Systems Manager Automation for remediation.

762
MCQmedium

A cloud security architect is designing a workload that must store encryption keys in a hardware security module (HSM) that is validated to FIPS 140-2 Level 3. The workload runs on a major public cloud provider. The architect wants to minimize operational overhead while ensuring the keys never leave the HSM boundary. Which cloud service model should the architect select?

A.A cloud provider's managed Hardware Security Module (HSM) service offering dedicated, tamper-resistant HSM appliances.
B.A software-based key management service that uses a shared, multi-tenant key store with encryption at rest.
C.A cloud provider's virtual private cloud (VPC) with a customer-managed encryption key stored in the provider's object storage.
D.An on-premises HSM connected to the cloud via a VPN tunnel, with keys replicated to the cloud provider's key vault.
AnswerA

A managed HSM service provides dedicated FIPS 140-2 Level 3 validated hardware, and the provider handles patching, scaling, and high availability. Keys are generated and stored inside the HSM boundary and cannot be exported in plaintext. This matches the requirement for minimal operational overhead while keeping keys within validated hardware, which is exactly what the architect needs.

Why this answer

The requirement is for a FIPS 140-2 Level 3 validated HSM with minimal operational overhead and keys that never leave the HSM. A managed HSM service provides dedicated, validated hardware while the provider handles maintenance and availability, satisfying both security and operational needs. Alternatives either lack hardware validation, export keys outside the boundary, or add unnecessary management burden.

Exam trap

The trap here is assuming that any encryption key store with encryption at rest meets the HSM requirement, when FIPS 140-2 Level 3 specifically demands tamper-resistant hardware.

763
MCQhard

A cloud security team is implementing a data loss prevention (DLP) solution for a cloud storage environment. They need to detect and prevent the exfiltration of sensitive data, including personally identifiable information (PII) and intellectual property, in real time. The solution must also provide granular reporting on policy violations. Which approach is most effective?

A.Use a cloud-native DLP service that integrates with the cloud storage API and inspects data at rest and in transit.
B.Rely on the cloud provider's built-in encryption and access controls to prevent data exfiltration.
C.Deploy endpoint DLP agents on all user devices to monitor data transfers.
D.Implement a network-based DLP appliance at the perimeter to inspect all traffic leaving the cloud.
AnswerA

A cloud-native DLP service integrated with the storage API can inspect data in real time as it is accessed or moved, and can enforce policies to block exfiltration. It provides granular reporting and is designed for the cloud environment. This meets the requirements for real-time detection and prevention of sensitive data loss.

Why this answer

A cloud-native DLP service integrated with the storage API can inspect data in real time, enforce policies to block exfiltration, and provide granular reporting. It is designed for cloud environments and can monitor both data at rest and in transit within the cloud, making it the most effective solution for detecting and preventing sensitive data loss.

Exam trap

The trap here is assuming that perimeter or endpoint DLP tools are sufficient for cloud storage, when they often miss internal cloud data flows and API-based access.

764
MCQmedium

A company has enabled object versioning on its cloud storage bucket to protect against accidental deletion. A ransomware attack encrypts all objects and creates new versions. To recover the data, the company needs to restore the previous unencrypted versions. What is the most efficient recovery method?

A.Delete the current versions or use the previous versions directly
B.Use the object lifecycle policy to delete current versions
C.Request the cloud provider to restore from their backups
D.Restore from a backup stored in a different region
AnswerA

Because versioning preserved the pre-ransomware copies, the unencrypted objects still exist as prior versions. Deleting the current encrypted versions or promoting the previous versions restores data directly, avoiding full backup restoration and satisfying the efficient recovery requirement.

Why this answer

With object versioning enabled, the previous unencrypted versions of the objects still exist in the bucket as noncurrent versions, so the most efficient recovery is to delete the current (encrypted) versions or simply access the previous versions directly. This avoids any external restore process and leverages the versioning feature exactly as designed. The recovery is fast, in-place, and requires no provider intervention or cross-region transfer.

Exam trap

CCSP often tests whether candidates understand that versioning preserves prior objects in place — many pick backup or provider restore options, missing that the previous versions are directly accessible.

How to eliminate wrong answers

Option B is wrong because a lifecycle policy is used to automate deletion or transition of versions over time — it is not a recovery mechanism and would not restore data. Option C is wrong because the cloud provider does not maintain customer-accessible backups of object versions; the provider's responsibility ends at durability of the storage layer, and requesting a restore is not a supported recovery path. Option D is wrong because restoring from a cross-region backup is slower, costlier, and unnecessary when versioning already preserves the prior objects in the same bucket.

765
MCQmedium

A healthcare company runs a containerized patient portal on a managed Kubernetes service. The security team needs to ensure that container images cannot be deployed if they contain known critical vulnerabilities. The build pipeline already produces an SBOM. Which control should be enforced at the admission layer to meet this requirement?

A.Configure network policies to limit pod-to-pod traffic and enable mutual TLS between all services in the cluster.
B.Enable a runtime security agent that alerts when a container executes a known malicious binary, and route alerts to the SOC for manual triage.
C.Configure the cluster's admission controller to reject pods whose images are not signed by the organization's trusted cosign key, and run a vulnerability scan as part of the CI pipeline before signing.
D.Restrict the cluster's image registry to an internal private registry and require developers to push images only to that registry.
AnswerC

Admission control that enforces signature verification ensures only images approved by the CI pipeline (which includes vulnerability scanning) are admitted. Because the SBOM is already produced, integrating scanning into the pipeline and signing only clean images gives a verifiable, cryptographically enforced gate at deploy time, satisfying the requirement without relying on runtime detection.

Why this answer

Preventing deployment of vulnerable images requires a preventive control at admission that verifies images were scanned and approved. Signing images after a CI vulnerability scan and enforcing signature verification in the admission controller creates a cryptographic gate. Detection, private registries, and network controls do not evaluate image contents before scheduling, so they cannot block vulnerable workloads.

Exam trap

The trap here is assuming that scanning images in CI alone is sufficient, when the scan result must be enforced at admission through signature or policy verification to actually prevent deployment.

766
MCQhard

A cloud provider offers a virtual private cloud (VPC) with a subnet that hosts a database. A security architect must ensure that only instances in a specific application security group can connect to the database on port 3306, and that no other traffic from the internet or other subnets can reach it. The architect is configuring security groups and network ACLs. Which combination of rules BEST achieves this?

A.Configure the database security group to allow inbound TCP 3306 from 0.0.0.0/0, and configure the network ACL to deny all traffic except from the application subnet CIDR.
B.Configure the database security group to allow inbound TCP 3306 from the application subnet CIDR, and configure the network ACL to allow inbound TCP 3306 from the application security group ID.
C.Configure the database security group to allow inbound TCP 3306 from the application security group ID, and leave the network ACL at its default allow-all state.
D.Configure the database security group to allow inbound TCP 3306 from the application security group ID, and configure the subnet's network ACL to allow inbound TCP 3306 from the application subnet CIDR only.
AnswerC

Security groups are stateful and support referencing other security groups as sources, so allowing inbound TCP 3306 from the application security group ID ensures only instances with that security group can connect. The default NACL allows all traffic, so it does not interfere. This combination precisely meets the requirement without over-permitting.

Why this answer

Security groups are stateful and can reference other security groups as sources, which is the most precise way to allow only instances with a specific application security group to reach the database. Network ACLs are stateless and subnet-level; they cannot reference security group IDs and should generally be left at default allow unless additional subnet-level controls are needed. Allowing the application security group ID on the database security group meets the requirement exactly.

Exam trap

The trap here is assuming network ACLs can reference security group IDs or that subnet CIDR is equivalent to security group membership, when only security groups support security group references and stateful evaluation.

767
Multi-Selectmedium

Which THREE of the following are key components of a data protection impact assessment (DPIA) under GDPR?

Select 3 answers
A.List of all data subjects' names
B.Copy of the encryption algorithm
C.Measures to address risks
D.Description of processing operations
E.Assessment of necessity and proportionality
AnswersC, D, E

Correct. The DPIA must describe measures to mitigate identified risks.

Why this answer

Article 35 of the GDPR explicitly requires a DPIA to include 'measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data.' This is a core component that demonstrates how the controller will mitigate identified privacy risks to an acceptable level.

Exam trap

ISC2 often tests the misconception that a DPIA is a technical audit checklist requiring detailed cryptographic or personal data inventories, when in fact it is a risk management document focused on necessity, proportionality, and risk mitigation measures.

768
MCQeasy

A cloud security administrator is configuring encryption for a new cloud storage bucket that will hold archived logs. The logs are not highly sensitive but must be encrypted at rest to meet a compliance requirement. The administrator wants to minimize operational overhead and does not need to manage keys. Which encryption option is MOST appropriate?

A.Server-side encryption with customer-managed keys stored in a cloud KMS.
B.Server-side encryption with customer-provided keys (SSE-C) supplied with each API request.
C.Client-side encryption with keys stored on-premises in a hardware security module (HSM).
D.Server-side encryption with provider-managed keys (SSE-S3 or equivalent).
AnswerD

Server-side encryption with provider-managed keys automatically encrypts data at rest and handles key management, rotation, and storage. It requires no customer action and imposes minimal operational overhead. Since the logs are not highly sensitive and the requirement is simply encryption at rest, this option meets the compliance need without additional complexity. It is the default and most cost-effective approach for such scenarios.

Why this answer

For non-sensitive data with a simple encryption-at-rest requirement and a desire to minimize operational overhead, provider-managed server-side encryption is the most appropriate. It is automatic, requires no key management, and meets compliance. Customer-managed or client-side options add unnecessary complexity and cost without providing additional value for this use case.

Exam trap

The trap here is over-engineering the solution by assuming that any encryption requirement necessitates customer-managed or client-side keys, when provider-managed keys are sufficient for low-sensitivity data.

769
Multi-Selectmedium

Which THREE of the following are common challenges in securing serverless applications?

Select 3 answers
A.Lack of control over the underlying kernel and OS
B.Insecure handling of event source inputs
C.Vulnerabilities in third-party libraries and dependencies
D.Increased attack surface due to many small functions
E.Difficulty in applying stateful firewall rules
AnswersB, C, D

Event source inputs reach functions as untrusted payloads from queues, buckets, HTTP triggers or databases. Without validation and sanitisation, injection and malformed-data attacks succeed, making insecure handling of event source inputs a genuine serverless security challenge.

Why this answer

Option B is correct because serverless functions are triggered by diverse event sources (API Gateway, S3, SNS, SQS, etc.), and failing to validate or sanitize these inputs exposes functions to injection and event-injection attacks. Option C is correct because serverless deployments rely heavily on third-party packages and runtime dependencies, so vulnerable or outdated libraries become a primary risk since providers do not patch application code. Option D is correct because decomposing an application into many small functions multiplies entry points and triggers, enlarging the attack surface that must be individually secured and monitored.

Option A is not a distinguishing serverless challenge since the provider manages the kernel and OS, removing that control burden from the customer. Option E is not applicable because serverless architectures are inherently stateless and typically rely on security groups, IAM, and WAF rather than stateful firewall rules.

Exam trap

ISC2 often tests the misconception that serverless eliminates all infrastructure security concerns, leading candidates to overlook the critical need for input validation and dependency management, while incorrectly assuming that network controls like firewalls are still applicable.

770
MCQeasy

A cloud security administrator is responsible for managing access to a cloud management console. The organization wants to enforce multi-factor authentication (MFA) for all human users and ensure that programmatic access uses short-lived credentials instead of long-term access keys. Which approach BEST aligns with these requirements?

A.Use an identity provider with SAML 2.0 federation for console access with MFA enforced, and use IAM roles with temporary credentials for programmatic access via AWS STS.
B.Create a single shared IAM user for all administrators with MFA enabled and distribute the access keys securely to the team.
C.Create IAM users with long-term access keys and attach an IAM policy that requires MFA for console access only.
D.Store IAM user access keys in AWS Secrets Manager and rotate them every 90 days, while enabling MFA for the root account only.
AnswerA

SAML 2.0 federation with an identity provider enforces MFA at the identity provider and issues temporary console sessions. For programmatic access, assuming IAM roles via AWS STS provides short-lived credentials that expire automatically. This combination meets both requirements without long-term keys.

Why this answer

Enforcing MFA for human users is best achieved through federation with an identity provider that applies MFA, such as SAML 2.0, which issues temporary console sessions. For programmatic access, assuming IAM roles via AWS STS provides temporary credentials that rotate automatically, eliminating long-term access keys. Together these practices enforce MFA and short-lived credentials, aligning with cloud security best practices.

Exam trap

The trap here is thinking that rotating long-term access keys or enabling MFA only for the root account satisfies the requirement, when true compliance requires federation with MFA and temporary credentials for programmatic access.

771
Multi-Selecteasy

Which TWO of the following are valid methods for securing data at rest in a cloud storage service?

Select 2 answers
A.Disabling encryption to reduce latency.
B.Implementing client-side encryption before uploading data.
C.Using server-side encryption with customer-managed keys.
D.Setting the storage bucket to public read access.
E.Enabling access logging for the storage bucket.
AnswersB, C

Client-side encryption ensures data is encrypted before transmission.

Why this answer

Client-side encryption ensures data is encrypted before it leaves the client environment, so the cloud provider never has access to the plaintext. This is a valid method for securing data at rest in cloud storage, as the encrypted objects are stored in the service and can only be decrypted by the client holding the keys.

Exam trap

ISC2 often tests the distinction between encryption methods (client-side vs. server-side) and security controls (e.g., logging vs. encryption), so the trap here is that candidates may confuse access logging or public access settings with data-at-rest protection mechanisms.

772
MCQhard

During a cloud audit, the auditor finds that the CSP's data deletion process does not meet contractual requirements. The customer's data may still be recoverable after termination. What is the best next step for the customer?

A.Initiate a remediation plan with defined timelines
B.Immediately terminate the contract with the CSP
C.Report the CSP to the regulatory authority
D.Ignore the finding because it is a minor issue
AnswerA

A remediation plan with defined timelines formally addresses the contractual gap, compelling the CSP to correct deletion practices and providing verifiable milestones. It satisfies the stem's need for the best next step, since immediate termination or litigation would be disproportionate before giving the provider opportunity to remedy.

Why this answer

When a cloud audit reveals that the CSP's data deletion process does not meet contractual requirements, the customer should initiate a remediation plan with defined timelines to address the issue. This ensures the CSP corrects the deficiency and data is properly deleted. Option B (immediately terminating the contract) may be too drastic and could disrupt operations without solving the immediate data recovery risk.

Option C (reporting to regulatory authority) might be appropriate if no remediation occurs, but it is not the first step. Option D (ignoring) is unacceptable as it leaves data at risk.

773
MCQhard

An Azure application uses a key vault key for client-side encryption of data. The application also communicates with a cloud service over HTTPS. After deploying, the handshake failure occurs. Which of the following is the most likely cause?

A.The application is using the wrong key version
B.The key vault key is not accessible due to network restrictions
C.The client and server do not have a common TLS version or cipher suite
D.The key vault key is not enabled for encryption
AnswerC

A TLS handshake failure arises from mismatched protocol versions or cipher suites between client and server, not from the key vault key used for client-side data encryption. Since the stem specifies HTTPS communication, the negotiation failure points to incompatible TLS parameters, making this the most likely cause.

Why this answer

The handshake failure occurs at the transport layer (TLS/SSL), which is independent of client-side encryption using a key vault key. The most likely cause is a mismatch in TLS versions or cipher suites between the client and server, as HTTPS relies on a successful TLS handshake. Options A, B, and D relate to the key vault key's availability or configuration, which would not cause a TLS handshake failure.

Exam trap

The trap here is that candidates confuse client-side encryption (using a key vault key) with transport-layer security (TLS), assuming a key-related issue causes the handshake failure, when in fact the handshake is a separate protocol layer.

How to eliminate wrong answers

Option A is wrong because using the wrong key version would cause decryption failures on the client side, not a TLS handshake failure during HTTPS communication. Option B is wrong because network restrictions to the key vault would result in an access denied or timeout error when the application tries to retrieve the key, not a handshake failure in the TLS layer. Option D is wrong because if the key vault key is not enabled for encryption, the application would fail to encrypt data locally, but the HTTPS handshake is a separate process that does not depend on the key's encryption status.

774
MCQmedium

A financial institution is subject to strict regulatory requirements that mandate data residency and physical control over its infrastructure. At the same time, it wants to leverage cloud bursting for peak loads. Which deployment model should the institution adopt?

A.Hybrid cloud
B.Private cloud
C.Community cloud
D.Public cloud
AnswerA

Hybrid cloud keeps regulated data on institution-controlled infrastructure, satisfying data residency and physical control mandates, while public cloud capacity absorbs peak loads through bursting. Neither pure public nor private cloud alone meets both constraints simultaneously.

Why this answer

A hybrid cloud combines a private cloud (or on-premises infrastructure) with public cloud resources, letting the institution keep regulated data and physical control in its private environment while bursting to public cloud for peak loads. This satisfies data residency and physical control requirements while providing elasticity. Private cloud alone cannot burst to public capacity, and public/community clouds do not give the required physical control.

Exam trap

The trap is focusing only on 'cloud bursting' and picking public cloud, or focusing only on 'physical control' and picking private cloud; the correct answer must satisfy both requirements simultaneously, which only hybrid cloud does.

How to eliminate wrong answers

Option B is wrong because a private cloud provides dedicated, controlled infrastructure but lacks the on-demand public capacity needed for cloud bursting during peak loads. Option C is wrong because a community cloud is shared among several organizations with common concerns; it does not give the institution sole physical control over its infrastructure and may not meet strict data residency mandates. Option D is wrong because a public cloud is multi-tenant and provider-controlled, failing the requirement for physical control over infrastructure and often complicating data residency compliance.

775
MCQhard

A cloud security team wants to enforce that only signed container images are deployed in their Kubernetes cluster. Which admission controller can validate image signatures at deploy time?

A.HashiCorp Vault
B.Consul
C.Trivy
D.Kyverno
AnswerD

Kyverno is a Kubernetes admission controller that evaluates policies at deploy time, including verifying container image signatures against trusted keys. It satisfies the requirement to block unsigned images before they are admitted to the cluster.

Why this answer

Kyverno is a Kubernetes-native policy engine that functions as a validating admission controller. It can enforce policies that check container image signatures (e.g., using Cosign) at deploy time by validating the image's signature against a public key before allowing the pod to be created. This directly satisfies the requirement to only allow signed images.

Exam trap

CCSP often tests the confusion between security tools that scan images (like Trivy) and those that enforce policies at admission time (like Kyverno), so candidates must distinguish between detection and enforcement.

How to eliminate wrong answers

Option A is wrong because HashiCorp Vault is a secrets management tool, not a Kubernetes admission controller; it cannot validate image signatures at deploy time. Option B is wrong because Consul is a service mesh and service discovery tool, not an admission controller for image signature validation. Option C is wrong because Trivy is a vulnerability scanner for container images, not an admission controller; it can scan images but does not enforce policies during deployment.

776
MCQhard

During a security incident in a multi-tenant cloud environment, the cloud provider's logging system indicates that a virtual machine (VM) on a shared hypervisor has been compromised. The provider wants to assist the customer with forensic analysis while minimizing impact to other tenants. Which approach is most appropriate?

A.Rebuild the VM from a known good image and then run security scans.
B.Provide the customer with a memory snapshot of the compromised VM.
C.Clone the entire hypervisor and give the customer access to the clone.
D.Power off the VM immediately to contain the incident.
AnswerB

A memory snapshot captures volatile artefacts — running processes, network connections, encryption keys — that disk imaging misses, directly satisfying the forensic analysis requirement. Because it is taken from the compromised VM's own allocated memory, other tenants on the shared hypervisor remain untouched, meeting the constraint of minimising impact to them.

Why this answer

Providing a memory snapshot of the compromised VM preserves volatile forensic data (e.g., running processes, network connections, encryption keys) without disrupting the hypervisor or other tenants. This approach adheres to the cloud provider's responsibility to isolate forensic evidence while maintaining multi-tenant isolation, as memory snapshots can be taken via hypervisor-level APIs (e.g., VMware VMotion or libvirt) without powering off the VM or cloning the entire host. Option A is incorrect because rebuilding the VM from a known good image destroys the compromised state, overwriting volatile evidence that is critical for forensic analysis.

Option C is incorrect because cloning the entire hypervisor introduces significant performance overhead and security risks to other tenants, potentially violating isolation boundaries. Option D is incorrect because powering off the VM immediately may cause loss of volatile memory data crucial for investigation, such as running processes and encryption keys.

Exam trap

ISC2 often tests the distinction between forensic acquisition (preserving evidence) and incident containment/remediation, where candidates mistakenly choose immediate power-off (Option D) or rebuild (Option A) instead of the correct memory snapshot approach that balances evidence preservation with multi-tenant isolation.

How to eliminate wrong answers

Option A is wrong because rebuilding the VM from a known good image destroys all volatile evidence (e.g., memory-resident malware, active network connections) and is a remediation step, not a forensic acquisition step. Option C is wrong because cloning the entire hypervisor is excessively disruptive, exposes other tenants' data to the customer, and violates the shared responsibility model by breaking tenant isolation at the hypervisor level. Option D is wrong because powering off the VM immediately destroys volatile memory evidence and may trigger anti-forensic mechanisms in malware (e.g., self-deletion on shutdown), while also causing unnecessary downtime for the customer.

777
MCQmedium

A cloud security team needs to ensure that an Amazon EC2 instance hosting a regulated workload cannot communicate with the public internet, but the instance must still be able to download OS patches from an internal repository and retrieve secrets from AWS Secrets Manager. The workload runs in a private subnet with no NAT gateway or internet gateway route. Which combination of configurations will meet these requirements with the LEAST operational overhead?

A.Attach an internet gateway to the VPC and use a security group that allows only outbound HTTPS to the patch server and Secrets Manager endpoints.
B.Place the instance in a public subnet and use an AWS Network Firewall policy to block all outbound traffic except the patch server and Secrets Manager IP ranges.
C.Deploy a NAT gateway in a public subnet and update the private subnet route table to direct 0.0.0.0/0 through the NAT gateway, then restrict outbound traffic using network ACLs.
D.Create VPC interface endpoints (AWS PrivateLink) for Secrets Manager and an S3 gateway endpoint for the patch repository, and associate the endpoints with the private subnet's route table and security group.
AnswerD

Interface endpoints for Secrets Manager and a gateway endpoint for S3 keep traffic on the AWS private network without any internet gateway or NAT device. Associating the endpoints with the subnet route table and allowing the endpoint security group to accept traffic from the instance satisfies both patch retrieval and secret access while eliminating public exposure. This is the lowest-overhead, most auditable design.

Why this answer

VPC interface endpoints (AWS PrivateLink) and S3 gateway endpoints let resources in private subnets reach AWS services entirely over the AWS private network, with no internet gateway, NAT, or public IP required. This satisfies the no-internet constraint, supports both patch retrieval and secret access, and requires minimal ongoing operational effort compared to firewall or NAT-based designs.

Exam trap

The trap here is assuming that a NAT gateway or restrictive firewall rules satisfy a 'no public internet' requirement, when in fact any route to an internet gateway or NAT device still constitutes public internet connectivity.

778
MCQmedium

A cloud operations team runs a web tier on 40 Amazon EC2 instances behind an Application Load Balancer. Auditors require that administrators never hold long-lived SSH keys and that every login to an instance is logged with the identity of the human who initiated it. The team already uses an external SAML 2.0 identity provider for console access. Which approach BEST satisfies the auditors' requirements?

A.Deploy a bastion host with SSH certificate authority signing and rotate host certificates every 24 hours.
B.Enable AWS Systems Manager Session Manager with the instances managed by SSM Agent, and grant access through the federated IAM role.
C.Store a shared PEM key pair in AWS Secrets Manager and issue it to administrators through a break-glass runbook.
D.Move the instances into a private subnet, restrict port 22 to the corporate CIDR range, and enable VPC Flow Logs on the subnet.
AnswerB

Session Manager tunnels interactive shell sessions through the SSM service without opening inbound ports or distributing key pairs. Because authorization flows through IAM roles assumed from the SAML identity provider, each session is recorded in CloudTrail and Session Manager session history with the originating federated principal, giving auditors per-human attribution and eliminating long-lived SSH credentials entirely.

Why this answer

Session Manager provides keyless, auditable interactive access that inherits the federated IAM identity, so every session is attributable to a named administrator and no standing SSH keys exist. The other designs either retain long-lived key material or produce only network-level telemetry that cannot identify the human operator, which fails the auditors' attribution and key-elimination requirements.

Exam trap

The trap here is assuming that tightening network access or rotating SSH keys satisfies an identity-attribution requirement, when the auditors actually demanded elimination of long-lived credentials tied to a federated human identity.

779
MCQhard

Which audit report provides the most comprehensive assurance regarding a cloud provider's controls over a period of time, including controls related to security, availability, processing integrity, confidentiality, and privacy?

A.ISO 27001 certification
B.SOC 2 Type I
C.CSA STAR self-assessment
D.SOC 2 Type II
AnswerD

SOC 2 Type II tests control design and operating effectiveness across a defined review period, covering the five trust services criteria named in the stem. Type I only reports design at a single point in time, so it cannot evidence sustained assurance over time.

Why this answer

SOC 2 Type II reports provide assurance over the design AND operating effectiveness of controls across a defined audit period (typically 3–12 months), covering the five Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. This period-based testing makes it the most comprehensive assurance option for evaluating a cloud provider's sustained control environment.

Exam trap

CCSP often tests the confusion between SOC 2 Type I (point-in-time design) and Type II (period-based operating effectiveness), and candidates frequently select ISO 27001 thinking certification equals comprehensive control assurance.

How to eliminate wrong answers

Option A is wrong because ISO 27001 certification validates that an information security management system (ISMS) is in place, but it does not provide a detailed audit opinion on the operating effectiveness of specific controls over time. Option B is wrong because SOC 2 Type I only evaluates control design at a single point in time, not operating effectiveness over a period. Option C is wrong because a CSA STAR self-assessment is completed by the cloud provider itself and carries no independent auditor attestation, making it the weakest form of assurance.

780
MCQeasy

A healthcare organization is storing patient records in a cloud object storage service. They must encrypt data at rest with keys they control and rotate regularly, but they do not want to manage the encryption process themselves. Which encryption option should they use?

A.Server-side encryption with cloud provider default keys
B.Customer-managed encryption keys (CMEK)
C.Customer-supplied encryption keys (CSEK)
D.Client-side encryption
AnswerB

Customer-managed encryption keys let the organisation retain sole control over key material and rotation schedules, while the cloud provider performs the actual cryptographic operations. This satisfies the stem's dual constraint: keys the healthcare organisation controls, without managing the encryption process itself.

Why this answer

Customer-managed encryption keys (CMEK) allow the organization to control the encryption keys (including rotation) while the cloud provider manages the encryption/decryption process. This meets the requirement of using keys they control without managing the encryption process itself. CMEK is supported by major cloud providers (e.g., AWS KMS, Azure Key Vault, Google Cloud KMS) and integrates with object storage services.

The organization retains control over key lifecycle but delegates cryptographic operations to the provider.

Exam trap

CCSP often tests the distinction between key control and encryption process management, and candidates may confuse CMEK with CSEK or client-side encryption, incorrectly assuming that controlling keys means managing the encryption process.

How to eliminate wrong answers

Option A is wrong because provider default keys are fully managed by the cloud provider, so the organization does not control the keys or their rotation. Option C is wrong because customer-supplied encryption keys (CSEK) require the organization to supply and manage the keys entirely, including rotation, which means they are managing the encryption process. Option D is wrong because client-side encryption requires the organization to encrypt data before uploading, thus managing the encryption process themselves.

781
MCQmedium

A security engineer is reviewing a cloud application that uses AWS S3 buckets. Which vulnerability is most specific to cloud environments and is often exploited to access sensitive data?

A.Buffer overflow
B.SQL injection
C.Exposed S3 buckets with public read access
D.Cross-site scripting (XSS)
AnswerC

Public read access on an S3 bucket exposes objects directly to unauthenticated internet users, bypassing application controls entirely. This cloud-specific misconfiguration is the most common cause of sensitive data exposure, since bucket policies and ACLs are frequently set permissively during development.

Why this answer

Exposed S3 buckets with public read access are a cloud-specific misconfiguration vulnerability because they rely on the AWS S3 bucket policy or ACL settings that grant unauthenticated access to objects. Unlike traditional on-premises vulnerabilities, this arises from improper cloud resource configuration, allowing attackers to enumerate and download sensitive data directly via HTTP/HTTPS requests without any authentication.

Exam trap

ISC2 CCSP often tests the distinction between cloud-specific misconfigurations (like exposed S3 buckets) and traditional application vulnerabilities (like SQL injection or XSS), trapping candidates who confuse general web app flaws with cloud-native risks.

How to eliminate wrong answers

Option A is wrong because buffer overflow is a memory corruption vulnerability in software code, not a cloud-specific misconfiguration; it requires exploiting a programming flaw in an application, not a cloud storage setting. Option B is wrong because SQL injection is a web application vulnerability that targets database queries through user input, not a cloud environment's storage service like S3. Option D is wrong because cross-site scripting (XSS) is a client-side injection attack that executes malicious scripts in a user's browser, unrelated to cloud storage bucket permissions.

782
MCQhard

A financial services firm runs a regulated workload on a public cloud. Auditors require evidence that the cloud provider's physical security controls meet the firm's requirements. Which artifact provides the MOST direct evidence?

A.The cloud provider's SOC 2 Type II report covering the relevant data center and service scope.
B.A penetration test report commissioned by the cloud provider for its data centers.
C.The cloud provider's marketing security whitepaper describing data center protections.
D.The provider's ISO 27001 certificate displayed on its trust portal.
AnswerA

A SOC 2 Type II report includes an independent auditor's opinion on the design and operating effectiveness of controls, including physical security, over a period. It provides direct, time-bound evidence that the provider's controls were tested, which is exactly what the firm's auditors need.

Why this answer

A SOC 2 Type II report gives independent, period-based assurance over control design and operating effectiveness, including physical security, which directly satisfies auditor evidence requirements. Whitepapers, ISO certificates, and penetration test reports either lack independent testing, lack control-effectiveness detail, or address different scopes.

Exam trap

The trap here is equating any certification or security document with audit-grade evidence, when only a Type II report demonstrates that controls operated effectively over a defined period.

783
MCQmedium

In the shared responsibility model for public cloud IaaS, which of the following is typically the responsibility of the cloud customer?

A.Network infrastructure redundancy
B.Managing virtual machine guest OS patches
C.Physical security of data centers
D.Patching the hypervisor
AnswerB

In IaaS, the provider secures the physical hosts, hypervisor and network fabric, while the customer controls everything from the guest OS upward. Patching the guest operating system is therefore the customer's task, since the provider has no access to or control over that layer.

Why this answer

In the IaaS shared responsibility model, the cloud provider secures the physical facilities, network backbone, and hypervisor, while the customer is responsible for everything from the guest OS upward — including patching the guest operating system, middleware, and applications. Managing VM guest OS patches is therefore a customer responsibility.

Exam trap

The trap is assuming the provider handles all patching in the cloud; candidates must remember that in IaaS the line is drawn at the hypervisor, so guest OS patching belongs to the customer, while hypervisor and physical security belong to the provider.

How to eliminate wrong answers

Option A is wrong because network infrastructure redundancy (physical routers, switches, backbone) is managed by the cloud provider under IaaS. Option C is wrong because physical security of data centers is always the provider's responsibility in public cloud IaaS. Option D is wrong because patching the hypervisor is the provider's responsibility, since the hypervisor is part of the virtualization layer the provider controls.

784
MCQmedium

A cloud security team is implementing a data loss prevention (DLP) solution for data stored in a cloud object storage service. They need to detect and prevent the upload of files containing personally identifiable information (PII). The DLP solution must inspect file contents in near real-time as objects are uploaded. Which approach is MOST effective?

A.Enable bucket logging and periodically scan logs for PII patterns.
B.Implement client-side encryption so that PII is encrypted before upload.
C.Use a cloud-native DLP service integrated with the storage service to scan objects on upload.
D.Configure a web application firewall (WAF) to inspect uploads for PII.
AnswerC

A cloud-native DLP service can be configured to trigger on object creation events, inspect contents for PII, and take actions such as blocking or alerting. This provides near real-time detection and prevention. Integration with the storage service enables automatic scanning without manual intervention.

Why this answer

A cloud-native DLP service integrated with the storage service can automatically scan objects as they are uploaded, detect PII, and enforce policies in near real-time. Other options either do not inspect content, prevent inspection, or use inappropriate tools. Thus, the integrated DLP service is the most effective approach.

Exam trap

The trap here is thinking that encryption or logging can substitute for content inspection when the requirement is to detect PII in files.

785
MCQhard

A security engineer is hardening a Kubernetes cluster that runs multi-tenant workloads. The team wants to ensure that a compromised pod cannot reach the cloud provider's instance metadata service to steal node credentials. Which control BEST addresses this?

A.Rotate node IAM credentials every 24 hours using the cloud provider's rotation service.
B.Enable PodSecurity admission with the restricted profile on all namespaces.
C.Use a service mesh with mutual TLS between all workloads in the cluster.
D.Enforce a NetworkPolicy that denies egress to the link-local address 169.254.169.254 from all pods.
AnswerD

The instance metadata service is reachable at 169.254.169.254 from the node network namespace, and pods on the node can often reach it. A default-deny egress NetworkPolicy targeting that link-local address blocks pods from retrieving node IAM credentials, directly mitigating the credential theft scenario.

Why this answer

Blocking egress to 169.254.169.254 with a NetworkPolicy directly prevents pods from reaching the instance metadata service, which is the specific vector for stealing node credentials. PodSecurity, credential rotation, and service mesh mTLS address different risks and do not stop a pod from querying the metadata endpoint.

Exam trap

The trap here is assuming that workload hardening controls such as PodSecurity or mTLS also restrict network paths to the metadata service, when only explicit egress filtering addresses that link-local access.

786
Multi-Selectmedium

Which THREE of the following are essential components of a Secure Software Development Lifecycle (SSDLC) in the cloud? (Choose three.)

Select 3 answers
A.Static application security testing (SAST) in CI/CD
B.Dynamic application security testing (DAST) in staging
C.Manual code reviews without automation
D.Threat modeling during design phase
E.Annual penetration testing only
AnswersA, B, D

SAST finds vulnerabilities in source code early.

Why this answer

SAST tools scan source code, bytecode, or binaries for vulnerabilities like SQL injection or buffer overflows early in the development cycle. Integrating SAST into the CI/CD pipeline enables automated, continuous security checks on every commit or build, which is a core practice of a Secure Software Development Lifecycle (SSDLC) in the cloud. This shift-left approach catches flaws before they reach production, reducing remediation cost and risk.

Exam trap

ISC2 often tests the misconception that manual reviews are a primary or essential component of an SSDLC in the cloud, when in fact automation is critical for speed and consistency, and they also test the trap that annual penetration testing is sufficient for cloud environments, which require continuous security validation.

787
MCQeasy

A security engineer is reviewing container security practices. Which tool is specifically designed to scan container images for Common Vulnerabilities and Exposures (CVEs)?

A.Kubernetes RBAC
B.Trivy
C.Seccomp
D.OPA Gatekeeper
AnswerB

Trivy is an open-source scanner built specifically to inspect container images (and filesystems, repositories) for known CVEs in OS packages and language dependencies. It satisfies the stem's requirement for a tool designed for image vulnerability scanning, unlike general-purpose registries or orchestrators.

Why this answer

Trivy is an open-source vulnerability scanner specifically designed to scan container images, filesystems, and Git repositories for CVEs and misconfigurations. It integrates directly with container registries and CI/CD pipelines, making it the go-to tool for image security in cloud-native environments. Unlike the other options, Trivy's core function is vulnerability detection, not access control or runtime enforcement.

Exam trap

CCSP often tests the confusion between security tools that operate at different layers: candidates may mistake runtime security tools (Seccomp) or policy engines (OPA Gatekeeper) for vulnerability scanners, overlooking that Trivy is purpose-built for CVE detection in images.

How to eliminate wrong answers

Option A is wrong because Kubernetes RBAC is an authorization mechanism that controls access to Kubernetes API resources, not a vulnerability scanner. Option C is wrong because Seccomp is a Linux kernel feature used to restrict system calls made by a process, providing runtime sandboxing, not CVE scanning. Option D is wrong because OPA Gatekeeper is a policy enforcement tool that uses Open Policy Agent to validate and mutate Kubernetes resources based on custom policies, not a vulnerability scanner.

788
Multi-Selectmedium

Which TWO of the following are key elements of a cloud service agreement (CSA) for legal compliance?

Select 2 answers
A.Audit rights
B.Encryption key management
C.Data portability tools
D.Service level agreements (SLA) uptime guarantee
E.Data processing terms (DPA)
AnswersA, E

Audit rights let the cloud customer verify provider controls and evidence compliance with contractual, regulatory and security obligations. Without them, the customer cannot independently confirm the CSA is being honoured, so audit rights are a core legal-compliance element of the agreement.

Why this answer

Audit rights (A) are a key legal-compliance element of a cloud service agreement because they contractually grant the customer the right to verify the provider's security controls, often via third-party audits such as SOC 2 or ISO/IEC 27001 reports, which is essential for demonstrating regulatory due diligence. Data processing terms (E), typically embodied in a Data Processing Agreement (DPA), are equally essential because they define the controller-processor relationship, lawful processing purposes, subprocessor approvals, breach notification, and cross-border transfer mechanisms like EU Standard Contractual Clauses required by GDPR and similar laws. The other options, while important operationally, are not the legal-compliance cornerstones asked for: encryption key management (B) is a technical security control, data portability tools (C) are a functional/exit-management capability, and an SLA uptime guarantee (D) is a performance commitment rather than a compliance obligation.

Exam trap

CCSP often tests the confusion between technical controls (encryption, portability) and legal/compliance elements (audit rights, DPA), leading candidates to pick operational features.

789
MCQmedium

A company is negotiating a cloud service agreement and wants to ensure it can verify the provider's security controls independently. Which contractual clause is essential for this purpose?

A.Data deletion clause
B.Right to audit clause
C.Service Level Agreement (SLA) on uptime
D.Data portability clause
AnswerB

A right to audit clause contractually grants the customer the ability to independently verify the provider's security controls, through assessments or evidence review. Without it, assurance rests solely on provider assertions, so it directly satisfies the requirement for independent verification.

Why this answer

A right to audit clause is essential because it contractually grants the customer the ability to independently verify the provider's security controls, either through direct audits or by accepting third-party audit reports. This clause ensures transparency and accountability, which is critical for compliance and risk management in cloud services.

Exam trap

CCSP often tests the distinction between contractual clauses, and candidates may confuse the right to audit with SLAs or data deletion, overlooking that only the right to audit enables independent verification.

How to eliminate wrong answers

Option A is wrong because a data deletion clause specifies how data is removed at contract termination, but it does not enable verification of security controls. Option C is wrong because an SLA on uptime focuses on availability guarantees, not security control verification. Option D is wrong because data portability ensures the ability to move data, but it does not provide audit rights.

790
MCQhard

An organization uses a cloud-based data analytics platform with data stored in a data warehouse. The security team discovers that some tables contain unencrypted personally identifiable information (PII). They need to automatically scan the data warehouse for PII and apply pseudonymization to protect sensitive columns. Which cloud service should be used?

A.Cloud Storage bucket policies
B.Cloud Access Security Broker (CASB)
C.Cloud Data Loss Prevention (DLP) API
D.Cloud Key Management Service (KMS)
AnswerC

The Cloud DLP API inspects data at rest, using infoType detectors to identify PII such as names, emails and national identifiers, then applies de-identification transforms like pseudonymisation via crypto-based tokenisation or format-preserving encryption directly to matched columns.

Why this answer

Cloud Data Loss Prevention (DLP) API is designed to discover, classify, and protect sensitive data such as PII across cloud storage and data warehouses. It can automatically scan tables, identify PII using built-in infoType detectors, and apply de-identification transformations like pseudonymization (e.g., replacing values with surrogate tokens) directly. This matches the requirement to automatically scan and pseudonymize sensitive columns without manual intervention.

Exam trap

CCSP often tests the confusion between encryption (KMS) and pseudonymization (DLP), or between access control (bucket policies) and data inspection (DLP), causing candidates to pick KMS or CASB when the question explicitly asks for automatic PII scanning and pseudonymization.

How to eliminate wrong answers

Option A is wrong because Cloud Storage bucket policies control access to objects (IAM and ACLs) but do not inspect data content for PII or perform pseudonymization. Option B is wrong because a CASB provides visibility and policy enforcement for cloud service usage (e.g., shadow IT, access control) but does not natively scan data warehouse tables for PII or apply column-level pseudonymization. Option D is wrong because Cloud KMS manages encryption keys for data at rest or in transit; it does not discover PII or perform pseudonymization—it only encrypts data, which is not the same as pseudonymization.

791
Multi-Selecthard

A cloud customer is subject to the EU GDPR and stores personal data with a provider that replicates it across data centers in several countries. The customer's legal team must confirm that appropriate safeguards exist for each international transfer. Which TWO elements are required for a valid transfer under GDPR Chapter V? (Choose two.)

Select 2 answers
A.A transfer impact assessment documenting the destination country's laws and any supplementary measures
B.A lawful transfer mechanism such as an adequacy decision or Standard Contractual Clauses
C.A SOC 2 Type II report covering the provider's security controls in each region
D.Registration of the cloud provider as a data controller with the customer's supervisory authority
E.An ISO/IEC 27701 certification held by the cloud provider
AnswersA, B

Following the Schrems II judgment, controllers must assess whether the destination country's surveillance and access laws undermine the chosen safeguard, and if so, adopt supplementary measures such as encryption or pseudonymization. This assessment must be documented and reviewed, especially when data is replicated to several countries with differing legal regimes.

Why this answer

A valid Chapter V transfer needs a legal mechanism, such as an adequacy decision or Standard Contractual Clauses, plus a documented transfer impact assessment that evaluates destination-country laws and any supplementary measures. Certifications and registrations may support due diligence but are not transfer mechanisms. When data is replicated across several countries, both elements must cover every jurisdiction where personal data resides or is accessible.

Exam trap

The trap here is treating a security or privacy certification as a substitute for a Chapter V transfer mechanism, when certifications support due diligence but do not authorize the transfer.

792
MCQhard

During a threat modeling session for a cloud-native application, which cloud-specific attack path is most critical to identify?

A.Cross-Site Scripting (XSS) in a web form
B.SQL injection in a legacy database
C.Server-Side Request Forgery (SSRF) to the metadata service
D.Buffer overflow in a compiled binary
AnswerC

Cloud workloads reach instance metadata endpoints such as 169.254.169.254, which can vend temporary IAM credentials. SSRF that reaches this service lets an attacker pivot from a web flaw to full cloud account compromise, making it the cloud-specific path threat modelling must surface first.

Why this answer

SSRF targeting cloud metadata endpoints is a critical cloud-specific threat because it can expose IAM credentials, leading to full account compromise. This is a unique cloud attack path not typically present in on-premises environments.

793
MCQmedium

A financial services company is required to keep customer data within a specific geographic boundary due to regulatory requirements. The company is evaluating cloud deployment models. Which model would best ensure data sovereignty while still providing scalability?

A.Hybrid cloud with public cloud bursting
B.Public cloud with multi-region deployment
C.Community cloud hosted in the required geography
D.Private cloud on-premises
AnswerC

A community cloud is provisioned for exclusive use by a specific community of organisations, so it can be physically hosted within the required geographic boundary, satisfying the data sovereignty constraint. Shared infrastructure among community members still delivers the scalability the company needs.

Why this answer

A community cloud hosted within the required geography is provisioned for exclusive use by a specific community of organizations that share concerns (here, regulatory compliance), and it can be located in the mandated jurisdiction while still offering elastic, multi-tenant-style scalability. This satisfies data sovereignty because the infrastructure and data reside within the geographic boundary, and it provides scalability through shared community resources rather than a single organization bearing the full cost.

Exam trap

The trap is assuming 'private cloud on-premises' is always the most sovereign answer, when the question also demands scalability — community cloud is the model that balances both regulatory boundary and elastic capacity.

How to eliminate wrong answers

Option A is wrong because hybrid cloud with public cloud bursting pushes workloads and potentially data into a public cloud region that may be outside the required geography, violating data sovereignty. Option B is wrong because public cloud multi-region deployment spreads data across regions that may cross national borders, and the customer typically cannot guarantee all replicas stay within the mandated boundary. Option D is wrong because an on-premises private cloud meets sovereignty but does not inherently provide the elastic scalability the question requires, and it is not a cloud deployment model that scales on demand without significant capital investment.

794
MCQmedium

A large enterprise is migrating a legacy .NET application to Azure App Service. The application currently stores session state in-memory on the web server. During the migration, the team plans to horizontally scale the application across multiple instances. The security team requires that session data remain confidential and be available even if an instance fails. Which solution should the team implement?

A.Store session data in Azure SQL Database with column-level encryption
B.Use Azure Redis Cache to store session state with encryption enabled
C.Encrypt session data and store it as a client-side cookie
D.Configure Application Gateway with cookie-based affinity (sticky sessions)
AnswerB

Azure Redis Cache externalises session state from instance memory, so any scaled instance can read the same data and a failed instance loses nothing. Encryption at rest and in transit keeps the session data confidential, meeting both availability and confidentiality constraints.

Why this answer

Azure Redis Cache with encryption enabled provides a secure, centralized session store that persists data independently of individual web server instances. This ensures session data remains available even if an instance fails, and encryption protects confidentiality in transit and at rest, meeting the security team's requirements for horizontal scaling.

Exam trap

ISC2 often tests the distinction between availability and affinity, where candidates mistakenly choose sticky sessions (Option D) thinking they solve availability, but sticky sessions actually create a single point of failure by binding a user to one instance.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database with column-level encryption does not provide the low-latency, in-memory performance needed for session state in a horizontally scaled web application, and it introduces unnecessary database overhead and cost. Option C is wrong because storing encrypted session data as a client-side cookie violates the requirement for availability after instance failure, as the data is tied to the client and not centrally managed, and cookies have size limits (typically 4 KB) that cannot accommodate large session states. Option D is wrong because Application Gateway with cookie-based affinity (sticky sessions) pins a client to a specific instance, which prevents true horizontal scaling and does not ensure session data availability if that instance fails, as the session remains in-memory on that single server.

795
MCQmedium

A financial services company stores regulated transaction logs in a cloud object storage bucket. The security team must ensure that even the cloud provider's administrators cannot access the plaintext data, and that the company can immediately revoke access for a compromised internal user without re-encrypting all objects. Which approach BEST meets these requirements?

A.Enable provider-managed server-side encryption with a customer-managed key stored in the cloud provider's KMS.
B.Implement server-side encryption with provider-managed keys and enable bucket versioning and object lock.
C.Apply server-side encryption with customer-provided keys (SSE-C) and store the keys in the cloud provider's secret manager.
D.Use client-side encryption where the company retains sole control of the keys in an on-premises HSM and issues short-lived data keys to authorized users.
AnswerD

Client-side encryption with keys held exclusively in an on-premises HSM ensures the cloud provider never possesses the key material, so provider administrators cannot decrypt the data. Issuing short-lived data keys allows immediate revocation for a compromised user without re-encrypting all objects, satisfying both requirements.

Why this answer

Client-side encryption with keys held exclusively by the customer in an on-premises HSM ensures that the cloud provider never has access to the plaintext or the key material, which is essential when even provider administrators must be excluded. Short-lived data keys enable immediate revocation of a compromised user without re-encrypting the entire data set, meeting both the confidentiality and agility requirements.

Exam trap

The trap here is assuming that server-side encryption with customer-managed keys in the cloud KMS prevents provider administrators from accessing plaintext, when in fact the provider still controls the underlying key infrastructure.

796
MCQhard

A company is designing a multi-cloud strategy to avoid vendor lock-in and ensure portability. They are considering using containers and an open-source orchestration platform. Which of the following is the BEST choice to achieve workload portability across different cloud providers?

A.Kubernetes
B.Azure Functions
C.AWS Lambda
D.VMware vSphere
AnswerA

Kubernetes is an open-source orchestration platform supported by every major provider, so containerised workloads run identically anywhere. This directly satisfies the stem's portability and anti-lock-in constraint, unlike proprietary orchestrators tied to a single vendor's APIs.

Why this answer

Kubernetes is an open-source container orchestration platform that runs on any cloud or on-premises infrastructure, providing a consistent API and workload abstraction that makes containers portable across providers. Because it is not tied to a single vendor, workloads packaged as Kubernetes manifests or Helm charts can be moved between AWS EKS, Azure AKS, Google GKE, or self-managed clusters with minimal changes, directly addressing vendor lock-in and portability.

Exam trap

The trap is picking a serverless service (Lambda, Azure Functions) as a portability solution, when proprietary FaaS platforms are the opposite of vendor-neutral and increase lock-in.

How to eliminate wrong answers

Option B is wrong because Azure Functions is a proprietary serverless platform tied to Microsoft Azure, which increases lock-in rather than reducing it. Option C is wrong because AWS Lambda is a proprietary AWS serverless service, also creating vendor lock-in. Option D is wrong because VMware vSphere is a virtualization platform, not a container orchestration system, and does not provide the multi-cloud workload portability the company seeks.

797
MCQeasy

The exhibit shows the versioning configuration for an S3 bucket. What effect does enabling MFADelete have on data protection?

A.It automatically encrypts all new object versions
B.It requires MFA to permanently delete an object version
C.It prevents any version of an object from being overwritten
D.It requires MFA for all operations on the bucket
AnswerB

MFADelete adds a second authentication factor to version deletion. With it enabled, a delete request must include a valid MFA token, so a compromised credential alone cannot permanently remove an object version, strengthening protection against destructive or ransomware actions.

Why this answer

Enabling MFADelete on an S3 bucket requires multi-factor authentication to permanently delete an object version or to suspend versioning on the bucket. This adds a critical layer of protection against accidental or malicious deletion of object versions, ensuring that even with administrative credentials, a second factor is needed to complete the destructive operation. It does not affect encryption, overwrite prevention, or all operations—only permanent deletion and versioning suspension.

Exam trap

ISC2 often tests the misconception that MFADelete applies to all bucket operations, when in fact it only applies to permanent deletion of object versions and suspension of versioning, not to reads, writes, or other management actions.

How to eliminate wrong answers

Option A is wrong because MFADelete does not automatically encrypt objects; encryption is managed separately via server-side encryption (SSE-S3, SSE-KMS, SSE-C) or client-side encryption. Option C is wrong because MFADelete does not prevent overwriting an object version; it only protects against permanent deletion of a version, while new versions can still be written (overwriting the current version). Option D is wrong because MFADelete does not require MFA for all operations; it only applies to two specific actions: permanently deleting an object version and suspending versioning on the bucket.

798
MCQhard

Which runtime security control monitors application behavior and can block attacks by analyzing application logic and context?

A.Web application firewall (WAF)
B.Intrusion detection system (IDS)
C.Runtime application self-protection (RASP)
D.Static application security testing (SAST)
AnswerC

RASP instruments the running application and its runtime, inspecting calls and data flow in context to detect and block attacks such as injection in real time. Unlike perimeter controls, it analyses application logic, satisfying the requirement to block based on behaviour and context.

Why this answer

C is correct because Runtime Application Self-Protection (RASP) is a security technology that is integrated into an application's runtime environment, allowing it to monitor actual application behavior and context (e.g., input validation, SQL queries, API calls) in real time. Unlike external controls, RASP can understand the application's logic and data flow, enabling it to block attacks such as SQL injection or command injection by analyzing the specific context of each request.

Exam trap

The CCSP exam often tests the distinction between network-layer controls (WAF) and application-layer controls (RASP), and the trap here is that candidates mistakenly choose WAF because they think it 'analyzes application logic' when in fact WAFs rely on signatures and patterns, not runtime context.

How to eliminate wrong answers

Option A is wrong because a Web Application Firewall (WAF) operates at the network or HTTP layer, inspecting traffic patterns and signatures (e.g., OWASP ModSecurity rules) without understanding the application's internal logic or runtime context. Option B is wrong because an Intrusion Detection System (IDS) passively monitors network or host events for known attack signatures or anomalies, but it cannot block attacks inline or analyze application-specific logic and context. Option D is wrong because Static Application Security Testing (SAST) analyzes source code or binaries at rest, not during runtime, and thus cannot monitor or block live application behavior.

799
MCQhard

A company uses a cloud key management service (KMS) with an HSM-backed key for encrypting sensitive data. They want to ensure that the key is automatically rotated every 90 days and that older key versions are retained for decryption of previously encrypted data. Which KMS feature should be configured?

A.Automatic key rotation with version retention
B.Key aliasing
C.Key destruction schedule
D.Key revocation policy
AnswerA

Automatic key rotation with version retention satisfies both constraints: it rotates the HSM-backed key on the 90-day schedule while preserving prior key versions, so data encrypted under earlier versions remains decryptable. Rotation alone would render old ciphertext unreadable without retained versions.

Why this answer

Automatic key rotation with version retention is the correct KMS feature because it enables the system to generate a new cryptographic key version on a defined schedule (e.g., every 90 days) while preserving all previous versions. The old versions remain available for decrypting data that was encrypted under them, ensuring backward compatibility. This directly satisfies both requirements: automatic rotation and retention of older key versions for decryption.

Exam trap

CCSP often tests the misconception that key rotation requires re-encrypting all data or that old key versions are automatically deleted, leading candidates to choose key destruction or revocation instead of version retention.

How to eliminate wrong answers

Option B is wrong because key aliasing is simply a human-friendly name that points to a key, and it does not perform rotation or retain old versions for decryption. Option C is wrong because a key destruction schedule permanently deletes key material after a set period, which would make previously encrypted data unrecoverable and directly contradicts the need to retain older versions. Option D is wrong because a key revocation policy disables or revokes a key, preventing its use for both encryption and decryption, which again conflicts with the requirement to decrypt older data.

800
Multi-Selectmedium

Which TWO statements about data classification are correct?

Select 2 answers
A.Data classification is performed once at creation.
B.Data classification must be automated to be effective.
C.Data classification can be based on context and content.
D.Data classification is solely based on regulatory requirements.
E.Data classification labels determine access controls.
AnswersC, E

Classification uses both content inspection and contextual metadata.

Why this answer

Data classification can be based on both context (e.g., source, creator, location) and content (e.g., keywords, patterns, data values). This dual approach allows organizations to apply classification rules that consider the environment and the actual data, enabling more accurate and granular protection. For example, a document containing a credit card number (content) created by the finance department (context) could be classified as 'Confidential'.

Exam trap

ISC2 often tests the misconception that data classification is a static, one-time activity (Option A) or that automation is mandatory (Option B), when in reality classification is a continuous process and can be manual or hybrid.

801
Multi-Selectmedium

Which THREE of the following are benefits of using a hybrid cloud deployment model?

Select 3 answers
A.Elasticity to burst to public cloud during peak demand
B.Simplified SLA management across environments
C.Ability to keep sensitive workloads on-premises while using public cloud for less sensitive ones
D.Consistent security policies can be applied across both environments
E.Eliminates data sovereignty concerns
AnswersA, C, D

Hybrid cloud lets workloads scale into public cloud capacity on demand, so peak loads are absorbed without permanently provisioning on-premises hardware. This elasticity directly delivers the burst capability the stem asks about as a hybrid benefit.

Why this answer

Option A is correct because a hybrid cloud lets workloads that exceed on-premises capacity burst into the public cloud on demand, providing elasticity during peak periods without permanently over-provisioning private infrastructure. Option C is correct because the hybrid model explicitly supports workload placement decisions, allowing sensitive or regulated data to remain on-premises while less sensitive workloads run in the public cloud. Option D is correct because hybrid cloud management tooling and unified control planes (e.g., Azure Arc, AWS Outposts, or VMware vSphere/vCloud integrations) allow consistent security policies, identity controls, and compliance configurations to be applied across both environments.

Option B is not correct because SLAs typically differ between on-premises infrastructure and public cloud providers, and managing them across a hybrid estate is generally more complex, not simplified. Option E is not correct because data sovereignty concerns are not eliminated by hybrid cloud; they must still be addressed through careful workload placement, data residency controls, and jurisdictional compliance, and hybrid deployments can even complicate them.

Exam trap

CCSP often tests the misconception that hybrid cloud simplifies governance and SLAs, when in fact it multiplies the number of trust boundaries and contracts that must be managed.

802
Multi-Selectmedium

Which THREE of the following are typical responsibilities of a cloud customer under the shared responsibility model?

Select 3 answers
A.Classifying data and managing data encryption.
B.Physical security of data centers.
C.Managing user identities and access permissions.
D.Patching the hypervisor.
E.Patching operating systems on virtual machines.
AnswersA, C, E

Data classification and encryption are customer responsibilities.

Why this answer

Under the shared responsibility model, the cloud customer is responsible for classifying their data and managing encryption (both at rest and in transit) using tools like AWS KMS, Azure Key Vault, or client-side encryption libraries. The provider secures the infrastructure, but the customer controls access to the data itself.

Exam trap

ISC2 often tests the misconception that customers are responsible for patching the hypervisor or physical security, when in fact those are always provider obligations under the shared responsibility model.

803
MCQeasy

A customer requires complete control over encryption keys used to protect data at rest in the cloud. Which cloud service model provides the most direct control?

A.Infrastructure as a Service (IaaS)
B.Anything as a Service (XaaS)
C.Platform as a Service (PaaS)
D.Software as a Service (SaaS)
AnswerA

IaaS grants the customer control over the operating system, applications, and underlying encryption mechanisms, including key management, unlike PaaS or SaaS where the provider manages keys. This directly satisfies the requirement for complete control over keys protecting data at rest.

Why this answer

IaaS gives customers control over the entire infrastructure stack, including encryption key management. PaaS and SaaS abstract away much of that control, limiting customer-managed key options.

804
Multi-Selecteasy

A cloud security team needs to ensure that all data in transit between on-premises systems and the cloud is encrypted. Which TWO options should they consider? (Choose two.)

Select 2 answers
A.Set up a VPN between on-premises and cloud
B.Use signed URLs for access
C.Enable bucket versioning
D.Enable server-side encryption with CMEK
E.Use TLS 1.2+ for all API calls
AnswersA, E

An IPsec VPN encrypts all traffic traversing the tunnel between on-premises gateways and cloud networks, covering every protocol rather than individual sessions. This satisfies the requirement that all data in transit be encrypted, since the tunnel provides blanket protection regardless of application.

Why this answer

Option A is correct because a VPN (typically IPsec or SSL/TLS-based) creates an encrypted tunnel over the public internet between on-premises networks and the cloud, protecting all data in transit at the network layer. Option E is correct because enforcing TLS 1.2 or higher on all API calls encrypts application-layer traffic end-to-end, ensuring data in transit between clients and cloud services is protected with strong ciphers. Option B is incorrect because signed URLs only grant time-limited access to specific resources; they do not encrypt the data in transit.

Option C is incorrect because bucket versioning preserves object versions for recovery and durability, not encryption. Option D is incorrect because server-side encryption with CMEK protects data at rest, not data in transit.

Exam trap

CCSP often tests the distinction between encryption in transit and at rest, and candidates may mistakenly select server-side encryption with CMEK (which is for data at rest) or signed URLs (which are for access control) when asked about data in transit.

805
MCQmedium

A company runs its production workloads on a cloud platform. The security team wants to ensure that all compute instances are patched within 30 days of a patch release. Which of the following is the BEST approach to enforce this requirement?

A.Use an automated patch management tool that deploys patches to all instances within 30 days
B.Configure vulnerability scanning to identify unpatched instances and notify administrators
C.Create a change management process that requires approval for all patches
D.Implement a manual patching policy and require each team to submit a patch report monthly
AnswerA

Automated patch management enforces the 30-day window consistently across all instances, removing manual tracking gaps. It directly satisfies the stated remediation deadline, whereas manual patching or detection-only tooling cannot guarantee every instance is patched within the required timeframe.

Why this answer

An automated patch management tool ensures that patches are deployed consistently and within the required timeframe across all instances, reducing human error and providing centralized control. This is the best approach to enforce the 30-day patching requirement because it can schedule and apply patches automatically, and provide reporting on compliance.

Exam trap

CCSP often tests the difference between detection (vulnerability scanning) and enforcement (automated patching), and the trap is choosing a notification-based approach when enforcement is required.

How to eliminate wrong answers

Option B is wrong because vulnerability scanning only identifies unpatched instances and notifies administrators; it does not enforce patching within 30 days. Option C is wrong because a change management process requiring approval for all patches may introduce delays and does not guarantee timely patching. Option D is wrong because a manual patching policy with monthly reports relies on human action and does not ensure patches are applied within 30 days.

806
MCQhard

A company uses AWS and needs to allow a Lambda function in a VPC to access an S3 bucket without traversing the internet. Which solution meets this requirement securely?

A.Configure a NAT gateway in the VPC and route traffic through it
B.Create a VPC endpoint for S3 and attach it to the Lambda's VPC
C.Use VPC peering to connect to the S3 bucket's VPC
D.Assign a public IP to the Lambda and use an internet gateway
AnswerB

A VPC endpoint for S3 routes traffic privately through the AWS network to the bucket, so the Lambda function never traverses the internet. This satisfies the no-internet constraint while keeping access controlled by endpoint and bucket policies rather than public exposure.

Why this answer

A VPC endpoint for S3 (gateway endpoint) allows resources in a VPC, including Lambda functions, to reach S3 privately without traversing the internet, NAT, or an internet gateway. Traffic stays on the AWS backbone and can be controlled with endpoint policies.

Exam trap

CCSP often tests whether candidates confuse NAT gateway (internet-bound) with VPC endpoints (private AWS service access) and mistakenly try to peer with an AWS-managed service VPC.

How to eliminate wrong answers

Option A is wrong because a NAT gateway routes traffic to the internet, which violates the requirement to avoid internet traversal and adds cost. Option C is wrong because VPC peering connects two VPCs, but S3 is not in a customer VPC — it is an AWS service, so peering does not apply. Option D is wrong because assigning a public IP and using an internet gateway sends traffic over the public internet, which is insecure and unnecessary.

807
Multi-Selecthard

An organization is migrating a legacy application to the cloud and requires reversibility. Which THREE of the following should be considered to ensure the application can be migrated away from the cloud provider in the future?

Select 3 answers
A.Using containerization with Kubernetes for workload portability
B.Designing the application to use open standards (e.g., OAuth, REST)
C.Using proprietary APIs for storage and compute
D.Implementing auto-scaling policies
E.Ensuring data can be exported in standard formats (e.g., CSV, JSON)
AnswersA, B, E

Containers package the application and its dependencies into a portable image, so Kubernetes can orchestrate that same workload on another provider's cluster. This avoids proprietary runtime lock-in, directly satisfying the reversibility requirement that the application can be migrated away later.

Why this answer

Option A is correct because containerizing workloads with Kubernetes abstracts the application from the underlying cloud infrastructure, so the same container images and manifests can be redeployed on another provider or on-premises cluster, directly supporting reversibility. Option B is correct because designing with open standards such as OAuth for authentication and REST for service interfaces avoids dependence on a single vendor's proprietary protocols, making it feasible to re-host or re-integrate the application elsewhere. Option E is correct because ensuring data can be exported in standard formats like CSV or JSON prevents data lock-in, allowing the organization to move its data to another platform without loss or costly transformation.

Option C is incorrect because proprietary storage and compute APIs increase vendor lock-in and make migration away from the provider harder, which is the opposite of the goal. Option D is incorrect because auto-scaling policies address elasticity and performance, not portability or the ability to exit the cloud provider.

Exam trap

The trap is that auto-scaling sounds like good cloud architecture, so candidates select it as a 'best practice' without checking whether it actually supports the stated goal (reversibility). Always map each option back to the specific requirement.

808
MCQeasy

A cloud administrator is configuring log retention for a financial application that must comply with PCI DSS. What is the minimum log retention period required by PCI DSS?

A.At least 90 days.
B.At least six months.
C.At least five years.
D.At least one year with the most recent three months available online.
AnswerD

PCI DSS requires audit trail history to be retained for at least twelve months, with the most recent three months immediately available for analysis. This satisfies the financial application's compliance constraint, so the administrator must configure retention accordingly.

Why this answer

PCI DSS requirement 10.7 mandates that audit trail history must be retained for at least one year, with the most recent three months of logs immediately available for analysis. This ensures that historical data is preserved for forensic investigation while maintaining quick access to recent activity. Option D correctly states this dual requirement.

Exam trap

The trap here is that candidates often confuse the 'immediately available' 90-day requirement with the total retention period, leading them to incorrectly select Option A instead of recognizing the full one-year retention mandate with the three-month online subset.

How to eliminate wrong answers

Option A is wrong because 90 days is only the minimum period for which the most recent logs must be immediately available, not the total retention period. Option B is wrong because six months is not a PCI DSS retention requirement; the standard requires one year total. Option C is wrong because five years exceeds the PCI DSS minimum; that duration is more typical of HIPAA or other regulatory frameworks, not PCI DSS.

809
MCQmedium

A cloud administrator applies the bucket policy shown in the exhibit to an S3 bucket. What is the expected outcome?

A.All objects uploaded must be encrypted using server-side encryption with S3-managed keys (SSE-S3)
B.All upload requests will be denied unless they include encryption metadata
C.All objects must be encrypted with AWS KMS keys
D.All objects uploaded must be client-side encrypted before uploading
AnswerA

The bucket policy's Deny effect on s3:PutObject applies when the request lacks the s3:x-amz-server-side-encryption header set to AES256, so uploads must use SSE-S3. Requests encrypted with SSE-KMS or customer-provided keys fail the condition and are rejected.

Why this answer

The bucket policy explicitly denies uploads unless the `x-amz-server-side-encryption` header is set to `AES256`, which corresponds to SSE-S3. This ensures all objects uploaded to the bucket are encrypted at rest using server-side encryption with S3-managed keys, as the policy condition enforces the presence of that specific encryption header.

Exam trap

The trap here is that candidates often confuse the requirement for any encryption metadata (option B) with the specific requirement for SSE-S3 (AES256), or they mistakenly think the policy enforces KMS (option C) because they overlook the exact header value `AES256` in the condition.

How to eliminate wrong answers

Option B is wrong because the policy does not merely require encryption metadata; it specifically requires the `x-amz-server-side-encryption` header to be set to `AES256`, not just any encryption metadata. Option C is wrong because the policy enforces SSE-S3 (AES256), not AWS KMS keys (which would require `aws:kms` in the header). Option D is wrong because the policy enforces server-side encryption, not client-side encryption; client-side encryption is performed before upload and does not involve the `x-amz-server-side-encryption` header.

810
MCQhard

An enterprise uses a Cloud Access Security Broker (CASB) to monitor cloud application usage. The CASB generates alerts about potential data loss prevention events. What is the primary purpose of the CASB's DLP capabilities?

A.To block all uploads of sensitive data to cloud apps
B.To classify data automatically using machine learning
C.To detect and prevent unauthorized sharing of sensitive data based on policies
D.To encrypt data before it is sent to cloud apps
AnswerC

CASB DLP inspects traffic and content flowing to cloud services, applying policy rules to identify sensitive data such as PII or credentials and block or alert on its unauthorised sharing, satisfying the requirement to detect and prevent exfiltration via sanctioned and unsanctioned applications.

Why this answer

The primary purpose of a CASB's DLP capabilities is to enforce policies that detect and prevent unauthorized sharing of sensitive data. This is achieved by inspecting content in transit (e.g., via API or proxy) and applying rules such as blocking, quarantining, or alerting on policy violations. Option C correctly captures this core function of policy-based detection and prevention, which goes beyond simple blocking or classification.

Exam trap

ISC2 often tests the misconception that DLP's primary purpose is to block all sensitive data or to classify data, when in fact it is to enforce granular policies that detect and prevent unauthorized sharing based on context (e.g., user, location, device).

How to eliminate wrong answers

Option A is wrong because blocking all uploads of sensitive data is too restrictive and not the primary purpose; CASB DLP uses granular policies to allow legitimate transfers while blocking only unauthorized ones. Option B is wrong because automatic classification using machine learning is a feature of data discovery and classification tools, not the primary DLP purpose; DLP focuses on enforcing policies on already-classified or pattern-matched data. Option D is wrong because encryption is a separate control often handled by key management or tokenization services, not the primary DLP function; CASB DLP may trigger encryption but its core role is policy enforcement, not encryption itself.

811
Multi-Selectmedium

An organization is evaluating techniques to protect data while it is being processed in memory. The goal is to prevent unauthorized access even if the operating system or hypervisor is compromised. Which TWO techniques are suitable for protecting data in use?

Select 2 answers
A.Hashing
B.Data masking
C.Secure enclaves (e.g., Intel SGX)
D.Homomorphic encryption
E.Tokenization
AnswersC, D

Hardware-based isolation for code and data in memory.

Why this answer

Secure enclaves, such as Intel SGX, provide hardware-enforced isolation by creating trusted execution environments (TEEs) that encrypt memory pages in use, protecting data even if the OS or hypervisor is compromised. This makes them suitable for protecting data in use because the CPU itself enforces access controls, preventing any privileged software from reading the enclave's memory.

Exam trap

ISC2 often tests the distinction between 'data at rest' and 'data in use' protections, and candidates mistakenly choose hashing or tokenization because they associate them with security, but neither protects data during active processing in memory.

812
MCQeasy

A cloud team is building a web application that stores user session tokens in the browser. A security review recommends that the tokens be inaccessible to JavaScript to reduce the impact of cross-site scripting attacks. Which cookie attribute should be set on the session token?

A.Secure
B.SameSite=Strict
C.HttpOnly
D.Domain
AnswerC

HttpOnly prevents client-side scripts from accessing the cookie through the Document Object Model, so a cross-site scripting flaw cannot directly read the session token. This directly mitigates the risk described in the security review while the cookie remains usable for server-side session management.

Why this answer

HttpOnly instructs the browser to hide the cookie from client-side scripts, so a cross-site scripting vulnerability cannot directly exfiltrate the session token. Secure, SameSite, and Domain attributes address transport, cross-site request behaviour, and scope respectively, but none prevents script access.

Exam trap

The trap here is conflating Secure with HttpOnly, assuming that HTTPS-only transmission also stops JavaScript from reading the cookie, when only HttpOnly controls script access.

813
MCQhard

During a security assessment of a Kubernetes cluster, you discover that a container is running as root with privileged mode enabled. Which of the following is the most critical risk associated with this configuration?

A.Network policy bypass allowing unauthorized pod communication
B.Potential for container escape to the host OS
C.Increased memory consumption due to lack of resource limits
D.Inability to mount volumes for persistent storage
AnswerB

Privileged mode grants the container broad Linux capabilities and direct access to host devices, so a compromise lets an attacker break out of the container namespace and execute code on the host OS, escalating from workload compromise to full node takeover.

Why this answer

Running a container as root with privileged mode enabled grants the container almost all the capabilities of the host's root user, including access to host devices and kernel features. This significantly increases the attack surface, making it easier for an attacker to exploit kernel vulnerabilities or misconfigurations to escape the container and gain control of the host OS. While other risks exist, container escape is the most critical because it compromises the entire node and potentially the whole cluster.

Exam trap

CCSP often tests the misconception that network policy bypass or resource limits are the primary risks of privileged containers, when the most critical risk is container escape leading to host compromise.

How to eliminate wrong answers

Option A is wrong because network policy bypass is a separate concern related to network policies and CNI plugins, not directly caused by privileged mode; privileged mode primarily affects host access, not network segmentation. Option C is wrong because increased memory consumption is due to lack of resource limits, which is unrelated to running as root or privileged mode. Option D is wrong because inability to mount volumes is typically due to missing volume mounts or permissions, not privileged mode; in fact, privileged mode often allows more mounting capabilities, not less.

814
Multi-Selectmedium

A cloud security architect is concerned about potential side-channel attacks against VMs running on a shared hypervisor. Which TWO of the following measures would be most effective in mitigating such attacks?

Select 2 answers
A.Use dedicated (single-tenant) hosts for sensitive workloads.
B.Encrypt all data at rest using AES-256.
C.Disable hyper-threading on the physical hosts.
D.Implement network segmentation using VLANs.
E.Enable multi-factor authentication for all cloud administrative accounts.
AnswersA, C

Dedicated hosts guarantee no other VMs on the same hypervisor, eliminating shared-resource side channels.

Why this answer

Using dedicated (single-tenant) hosts ensures that the physical server is not shared with any other customer's VMs. This eliminates the possibility of a co-resident attacker exploiting shared hardware resources (such as CPU caches, memory buses, or branch predictors) to launch side-channel attacks like Prime+Probe or Flush+Reload. By removing the shared hypervisor layer between tenants, the attack surface for cross-VM side channels is effectively nullified.

Exam trap

ISC2 often tests the distinction between data protection controls (encryption, MFA, network segmentation) and compute-level isolation controls, leading candidates to mistakenly select network or access controls that do not address the shared hardware attack surface.

815
MCQhard

An organization wants to ensure that its CSP does not access customer data for any purpose other than providing the service. Which clause should be included?

A.Right to audit
B.Security incident response
C.Data use restriction
D.Non-disclosure agreement
AnswerC

A data use restriction clause contractually limits the CSP to processing customer data solely for delivering the agreed service, prohibiting secondary uses such as analytics, marketing or profiling. This directly satisfies the requirement that the provider accesses data for no purpose beyond service provision.

Why this answer

A data use restriction clause explicitly limits the provider's use of customer data to only what is necessary to provide the service. Non-disclosure agreements protect confidentiality but don't restrict use. Right to audit provides oversight, and security incident response addresses breach management.

816
MCQhard

In a cloud environment, a data subject exercises their right to erasure under GDPR. The cloud provider has multiple replicas and backups. What is the primary technical challenge in fulfilling this request?

A.Transferring data to another controller
B.Ensuring deletion from backups and replicas within retention periods
C.Obtaining consent from other data subjects
D.Identifying the data subject's data across all systems
AnswerB

Erasure must propagate across every replica and backup copy, yet immutable or air-gapped backups and fixed retention schedules often prevent immediate purging. Satisfying the GDPR right to erasure therefore depends on deletion mechanisms that reach archived copies within their retention windows.

Why this answer

The primary technical challenge is ensuring deletion from backups and replicas within retention periods because GDPR's right to erasure (Article 17) requires data to be erased without undue delay, but cloud environments often have multiple replicas and backups that may not be immediately deletable due to retention policies or immutability. This creates a conflict between the legal obligation to erase and the technical reality that backups are typically retained for disaster recovery, requiring mechanisms to ensure data is not restored or that deletion is propagated once backups are restored. Thus, the correct answer focuses on the complexity of coordinating deletion across all copies while respecting retention schedules.

Exam trap

CCSP often tests the misconception that data deletion is straightforward in the cloud, but the presence of backups and replicas introduces complexity; candidates may overlook the retention period constraint and choose identification as the primary challenge.

How to eliminate wrong answers

Option A is wrong because transferring data to another controller relates to data portability (Article 20), not erasure, and does not address the challenge of deleting data from backups and replicas. Option C is wrong because obtaining consent from other data subjects is irrelevant to the right to erasure; erasure requests are made by the data subject whose data is being erased, and consent from others is not required. Option D is wrong because identifying the data subject's data across all systems, while a challenge, is not the primary technical challenge in this scenario; the question specifically highlights multiple replicas and backups, which points to the deletion propagation issue rather than identification.

817
MCQhard

A cloud security architect is designing a key management strategy for a hybrid cloud environment. The organization requires that encryption keys never leave their on-premises hardware security module (HSM) due to strict regulatory mandates, yet cloud services must be able to perform encryption operations on data at rest. Which key management approach meets these requirements?

A.Customer-managed encryption keys (CMEK)
B.Hold Your Own Key (HYOK)
C.Cloud provider default encryption
D.Bring Your Own Key (BYOK)
AnswerB

HYOK retains key material within the customer's on-premises HSM, with cryptographic operations performed locally or via a proxy, so keys never leave the HSM. This satisfies the regulatory mandate while still permitting encryption of cloud data at rest.

Why this answer

HYOK (Hold Your Own Key) keeps the master key material inside the customer's on-premises HSM and never exports it to the cloud provider. The cloud service sends cryptographic operations (encrypt/decrypt) to the on-prem HSM via a secure channel, so keys never leave the customer's control while still enabling encryption of cloud data at rest. This satisfies the regulatory mandate that keys remain on-premises.

Exam trap

The trap is conflating BYOK with HYOK — both involve 'your own key,' but only HYOK keeps the key physically on-premises. Candidates who skim the question miss the phrase 'keys never leave their on-premises HSM.'

How to eliminate wrong answers

Option A is wrong because CMEK (Customer-Managed Encryption Keys) still stores key material in the cloud provider's KMS/HSM — the customer manages the key lifecycle but the key resides in the provider's infrastructure, violating the 'never leave on-prem' requirement. Option C is wrong because provider default encryption uses provider-managed keys entirely, giving the customer no control over key custody at all. Option D is wrong because BYOK imports customer-generated key material into the cloud provider's KMS, so after import the key lives in the provider's HSM — it does not stay on-premises.

818
Multi-Selectmedium

In the context of eDiscovery, a legal hold must be placed on data stored in a cloud environment. Which THREE actions should the cloud customer take to ensure the legal hold is effective?

Select 3 answers
A.Ensure the legal hold prevents both deletion and modification of the data.
B.Delete any non-relevant data to reduce storage costs.
C.Rely solely on the cloud provider's default backup retention policies.
D.Apply the legal hold to all copies of the data, including backups and replicas in different regions.
E.Notify the cloud provider of the legal hold and request technical enforcement such as object lock.
AnswersA, D, E

A legal hold must preserve data in its original state, so the mechanism must block both deletion and alteration; otherwise spoliation occurs and the evidence loses integrity. Ensuring the hold prevents deletion and modification satisfies the stem's requirement that the cloud legal hold be effective.

Why this answer

Option A is correct because an effective legal hold must preserve data in its original state, meaning it must block both deletion and modification (e.g., via WORM/immutability controls) so the evidence remains authentic and unaltered for litigation. Option D is correct because eDiscovery obligations extend to every copy of potentially relevant data, so the hold must cover backups, snapshots, and cross-region replicas, otherwise a spoliation risk remains in those secondary locations. Option E is correct because the customer typically does not control the underlying cloud infrastructure, so notifying the provider and requesting technical enforcement such as S3 Object Lock, retention policies, or legal-hold flags ensures the hold is actually implemented at the platform level.

Option B is wrong because deleting non-relevant data during a hold risks destroying potentially relevant evidence and can constitute spoliation. Option C is wrong because default backup retention policies are provider-controlled, time-limited, and not a substitute for a case-specific legal hold.

Exam trap

CCSP often tests legal hold requirements, and candidates may overlook the need to apply holds to backups and replicas or to notify the provider for technical enforcement.

819
MCQmedium

A healthcare organization is migrating patient records to a public cloud provider. Which of the following is the most critical consideration regarding shared responsibility when using IaaS?

A.The cloud provider is responsible for all security controls because they own the infrastructure.
B.The customer has no responsibility for network security because the provider manages the hypervisor.
C.The cloud provider automatically encrypts all data at rest and in transit by default.
D.The customer is responsible for securing the operating system, applications, and data they deploy on the IaaS platform.
AnswerD

Under the IaaS shared responsibility model the provider secures the physical hosts, hypervisor and facility, while the customer secures everything above: guest operating systems, middleware, applications and patient data. For healthcare records, that customer-side obligation is the most critical consideration.

Why this answer

In IaaS, the provider secures the physical hosts, hypervisor, and network fabric, but the customer retains responsibility for the guest OS, middleware, applications, and data — including patching, hardening, and encryption choices. For a healthcare workload, that means the customer must secure the OS and application layer even though the provider owns the hardware.

Exam trap

CCSP often tests the misconception that the provider handles 'most' security in IaaS, when in fact the customer carries the majority of operational security responsibility for the guest stack.

How to eliminate wrong answers

Option A is wrong because the provider never assumes all security controls in IaaS — that would describe a fully managed SaaS model, not IaaS. Option B is wrong because while the provider manages the hypervisor, the customer is still responsible for guest-level network security such as security groups, host firewalls, and OS-level controls. Option C is wrong because automatic encryption at rest and in transit is not a default guarantee across all IaaS services; encryption is often optional and must be configured by the customer.

820
MCQmedium

A company wants to migrate a legacy application to the cloud with minimal re-architecture. They need control over the operating system and middleware but do not want to manage physical hardware. Which service model is most suitable?

A.FaaS
B.SaaS
C.IaaS
D.PaaS
AnswerC

IaaS delivers virtualised compute, storage and networking while the customer retains control of the operating system and middleware, avoiding physical hardware management. That preserves the legacy application's stack with minimal re-architecture, matching the stem's requirement for OS-level control without hardware ownership.

Why this answer

IaaS provides virtualized compute, storage, and networking where the customer controls the OS and middleware but does not manage physical hardware, matching the requirement for minimal re-architecture with OS-level control. It is the lowest-level cloud service model that still abstracts hardware.

Exam trap

CCSP often tests the boundary between IaaS and PaaS — candidates pick PaaS when the question explicitly requires OS and middleware control, which only IaaS provides.

How to eliminate wrong answers

Option A is wrong because FaaS (serverless) abstracts the OS and runtime entirely, requiring re-architecture into event-driven functions. Option B is wrong because SaaS delivers a finished application with no OS or middleware control. Option D is wrong because PaaS manages the OS and middleware for you, removing the control the company explicitly wants.

821
MCQeasy

Which NIST SP 800-145 cloud service model provides the consumer with the ability to deploy applications onto a cloud infrastructure where the consumer does not manage the underlying cloud infrastructure, including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment?

A.Platform as a Service (PaaS)
B.Function as a Service (FaaS)
C.Software as a Service (SaaS)
D.Infrastructure as a Service (IaaS)
AnswerA

Platform as a Service (PaaS) satisfies the stem's constraint: the consumer deploys applications onto provider-managed infrastructure without controlling network, servers, operating systems or storage, yet retains control over deployed applications and possibly application-hosting environment configuration. This matches NIST SP 800-145's PaaS definition precisely, distinguishing it from IaaS, where the consumer manages the operating system.

Why this answer

NIST SP 800-145 defines PaaS as the model where the consumer deploys applications onto cloud infrastructure but does not manage the underlying network, servers, operating systems, or storage. The consumer controls the deployed applications and possibly application-hosting environment configurations — exactly matching the question's description. This is the canonical PaaS definition.

Exam trap

CCSP often tests the precise NIST 800-145 wording — candidates confuse PaaS with IaaS because both allow application deployment, but IaaS requires the consumer to manage the OS and storage, which the question explicitly excludes.

How to eliminate wrong answers

Option B is wrong because FaaS (serverless functions) is a subset of PaaS where the consumer only deploys function code and does not manage any hosting environment configuration — NIST 800-145 does not define FaaS as a separate model. Option C is wrong because SaaS provides the consumer with access to a provider's applications, not the ability to deploy their own applications onto the infrastructure. Option D is wrong because IaaS gives the consumer control over operating systems, storage, and deployed applications — the question explicitly states the consumer does NOT manage the OS or storage.

822
Multi-Selecthard

A DevSecOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and trust from build to deployment?

Select 3 answers
A.Signing container images with Cosign
B.Storing images in a private registry without scanning
C.Using admission controller (e.g., Kyverno) to verify signatures
D.Allowing any image with a :latest tag
E.Scanning images for vulnerabilities using Trivy
AnswersA, C, E

Cosign attaches cryptographic signatures to container images at build time, binding an image digest to a trusted signing identity. This gives downstream admission checks verifiable provenance, satisfying the integrity and trust requirement across the supply chain.

Why this answer

Option A is correct because Cosign (part of the Sigstore project) cryptographically signs container images using keyless or key-based signatures, producing a verifiable signature stored in the OCI registry that establishes provenance and integrity from build time. Option C is correct because an admission controller such as Kyverno (or OPA Gatekeeper) enforces policy at deploy time by verifying Cosign signatures before allowing a pod to be admitted, ensuring only trusted, signed images run in the cluster. Option E is correct because Trivy scans image layers against vulnerability databases (e.g., CVE feeds) and can fail CI/CD pipelines on critical findings, catching known flaws before an image is promoted.

Option B is not appropriate because a private registry alone provides no integrity verification, and skipping scanning removes a key detection control. Option D is wrong because the mutable :latest tag offers no immutability or traceability, undermining supply-chain trust and reproducibility.

823
MCQmedium

A cloud architect is mapping security responsibilities for a SaaS customer relationship management deployment. The provider manages the application, runtime, middleware, operating system, and physical infrastructure. Which security task remains the responsibility of the customer organization?

A.Maintaining the physical security of the data center hosting the application
B.Managing user identities, access entitlements, and authentication configuration
C.Patching the operating system and runtime hosting the application
D.Applying firmware updates to the hypervisor and host servers
AnswerB

Even in SaaS, the customer controls who within its organization can access the application, what roles and entitlements they hold, and how authentication integrates with its identity provider. Managing accounts, enforcing least privilege, and revoking access for departing staff remain customer duties because the provider cannot know the organization's business roles or personnel changes.

Why this answer

In every cloud service model, the customer retains responsibility for its own data governance and access management. With SaaS, the provider covers the stack from physical facilities through the application, but identity lifecycle, entitlement decisions, and authentication configuration require knowledge of the customer's personnel and business roles, so those tasks cannot be delegated to the provider.

Exam trap

The trap here is assuming that SaaS means the provider secures everything, when the customer always retains responsibility for identity, access, and its own data handling.

824
MCQeasy

An organization uses a cloud key management service (KMS) for encryption keys. The security policy requires automatic rotation of keys every 90 days. Which rotation strategy best balances security and operational impact?

A.Retain the original key for decryption and use a new key only for new data.
B.Have administrators manually create new keys every 90 days and update applications.
C.Configure the KMS to automatically generate new key versions and retire old ones with no application changes.
D.Re-encrypt all data with a new master key each rotation to ensure full key separation.
AnswerC

KMS automatic rotation creates new key versions on a 90-day schedule while retaining old versions for decryption, so existing ciphertext stays readable. Applications reference the key alias, meaning no code changes and no operational disruption.

Why this answer

Cloud KMS services (e.g., AWS KMS, Azure Key Vault, GCP Cloud KMS) support automatic key rotation by creating new key versions while retaining previous versions for decryption of existing data. This approach satisfies the 90-day rotation policy without requiring application changes, as the KMS handles versioning transparently and the encryption context or key ID abstraction allows seamless use of the latest key for encryption.

Exam trap

The trap here is that candidates often confuse key rotation with re-encryption, assuming that rotating a key requires re-encrypting all existing data, when in fact cloud KMS versioning allows old keys to remain available for decryption without re-encrypting the entire dataset.

How to eliminate wrong answers

Option A is wrong because retaining the original key for decryption while using a new key only for new data does not rotate the original key; it merely adds a new key, leaving the original key active indefinitely, which violates the 90-day rotation policy. Option B is wrong because manual key creation every 90 days introduces operational overhead, risk of human error, and requires application updates to reference new keys, which contradicts the goal of minimizing operational impact. Option D is wrong because re-encrypting all data with a new master key each rotation is impractical and resource-intensive; cloud KMS rotation typically uses versioned keys where old versions remain available for decryption without re-encrypting existing ciphertext.

825
MCQeasy

A cloud security engineer is tasked with ensuring that all API calls made to AWS resources are logged for audit purposes. Which AWS service should be enabled to capture management events such as creating or deleting EC2 instances?

A.AWS Config
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Security Hub
AnswerB

CloudTrail records API activity across AWS services, capturing management events such as RunInstances or TerminateInstances with caller identity, source IP and timestamp. Enabling it in each region and account provides the audit trail the stem requires, which service-level logs alone cannot deliver.

Why this answer

AWS CloudTrail is the correct service because it is specifically designed to record API activity in an AWS account, including management events such as creating or deleting EC2 instances. It captures the who, what, when, and source IP for every API call, which is essential for audit logging and compliance. AWS Config, by contrast, records resource configuration changes and compliance history, not API call logs.

Exam trap

The trap here is that candidates confuse AWS Config (which tracks configuration history) with CloudTrail (which tracks API calls), leading them to select AWS Config for audit logging of management events.

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and evaluates compliance rules, but it does not capture API call logs or management events like creating or deleting EC2 instances. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not itself generate or store API audit logs. Option D is wrong because AWS Security Hub aggregates security findings from multiple services (including CloudTrail) and provides a compliance dashboard, but it is not a logging service and does not capture raw API events.

Page 10

Page 11 of 13

Page 12