Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 826–900

934 questions total · 13pages · All types, answers revealed

Page 11

Page 12 of 13

Page 13
826
MCQhard

An organization is designing a cloud application that must remain available even if an entire AWS availability zone fails. Which architecture pattern should they implement?

A.Single region with multiple AZs active-active
B.Single region with multiple AZs active-standby
C.Active-passive in a single region
D.Multi-region active-active
AnswerA

Running active-active across multiple availability zones within one region lets traffic fail over instantly when an entire AZ becomes unavailable, because each AZ has independent power, cooling and networking. This satisfies the requirement to survive a full AZ failure without regional latency penalties.

Why this answer

The correct architecture is a single region with multiple Availability Zones (AZs) in an active-active configuration. This ensures that if one AZ fails, the application continues to serve traffic from the remaining AZs without any manual intervention, as all AZs are actively handling requests. AWS Availability Zones are physically separate data centers within a region, and an active-active pattern distributes the workload across them to achieve high availability and fault tolerance.

Exam trap

ISC2 often tests the distinction between surviving an AZ failure versus a region failure, and the trap here is that candidates may overcomplicate the solution by choosing multi-region active-active, not realizing that a single region with multiple AZs is sufficient and more cost-effective for the given requirement.

How to eliminate wrong answers

Option B (Single region with multiple AZs active-standby) is wrong because it introduces a standby component that is not actively serving traffic, leading to potential downtime during failover and resource underutilization; the question requires continuous availability even during an AZ failure, which active-standby does not guarantee without a failover delay. Option C (Active-passive in a single region) is wrong because it typically relies on a single AZ for the active component, making it vulnerable to AZ failure, and the passive component requires manual or automated failover, which introduces downtime. Option D (Multi-region active-active) is wrong because while it provides high availability, it is over-engineered for the requirement of surviving a single AZ failure; it adds unnecessary complexity, latency, and cost, and the question specifically asks for an architecture that remains available if an entire AWS availability zone fails, not a full region failure.

827
MCQmedium

A startup is building a SaaS product on a public cloud. The security team wants to ensure that virtual machines belonging to different customers cannot access each other's memory or network traffic, even though they may share the same physical host. Which cloud architectural concept MOST directly addresses this requirement?

A.Broad network access
B.Hypervisor-based virtualization and network segmentation
C.Resource pooling
D.Measured service
AnswerB

The hypervisor enforces memory and CPU isolation between virtual machines on the same host, while virtual network segmentation controls traffic between tenants. Together they directly prevent one customer's VM from reading another's memory or reaching its network segments, which is exactly the isolation the security team requires in a multi-tenant public cloud.

Why this answer

Multi-tenant isolation on shared hardware is achieved through the hypervisor, which partitions memory and CPU, and through network segmentation, which restricts traffic flows between tenants. These architectural controls directly satisfy the requirement that different customers' virtual machines cannot access each other's memory or network traffic even when co-located.

Exam trap

The trap here is confusing essential cloud characteristics such as resource pooling or measured service with the security controls that actually enforce tenant isolation.

828
MCQhard

An organization experiences a data breach in the cloud. The CSP claims they are not liable because the breach was due to customer misconfiguration. The customer disagrees. What document should be reviewed to determine liability?

A.The CSP's privacy policy
B.The SOC 2 Type II report from the CSP
C.The incident response plan
D.The shared responsibility matrix in the service contract
AnswerD

The shared responsibility matrix in the service contract allocates security and compliance duties between provider and customer. Reviewing it establishes which party owned the misconfigured control, providing the contractual basis for determining liability in this dispute.

Why this answer

The shared responsibility matrix (SRM) is the definitive contractual document that delineates which security controls are managed by the cloud service provider (CSP) and which are the customer's obligation. In a breach caused by misconfiguration, the SRM specifies whether the configuration of the affected resource (e.g., an S3 bucket ACL or a security group rule) falls under the customer's responsibility. Without reviewing the SRM, liability cannot be determined because the matrix explicitly maps each control layer (e.g., network, compute, data) to the responsible party.

Exam trap

ISC2 often tests the misconception that a SOC report or privacy policy defines liability, when in fact only the contractual shared responsibility matrix legally allocates responsibility for specific security controls.

How to eliminate wrong answers

Option A is wrong because a privacy policy describes how the CSP handles personal data (e.g., GDPR compliance), not the operational security responsibilities for configuration management. Option B is wrong because a SOC 2 Type II report provides an independent audit of the CSP's controls over a period of time, but it does not define contractual liability boundaries or assign responsibility for specific misconfigurations. Option C is wrong because an incident response plan outlines the steps to detect, contain, and recover from a breach, not the pre-defined allocation of liability between the CSP and the customer.

829
MCQeasy

A cloud security professional is evaluating container runtime security. Which Linux capability should be dropped from a container to prevent it from loading kernel modules?

A.CAP_DAC_OVERRIDE
B.CAP_CHOWN
C.CAP_SYS_MODULE
D.CAP_NET_RAW
AnswerC

CAP_SYS_MODULE grants a process the ability to load and unload kernel modules via init_module and delete_module. Dropping it directly satisfies the stem's constraint: without this capability, the container cannot insert code into the host kernel, closing a critical container-escape and persistence vector.

Why this answer

CAP_SYS_MODULE is the Linux capability that permits a process to load and unload kernel modules via init_module() and delete_module() syscalls. Dropping it from a container's capability set prevents the containerized process from inserting malicious kernel code, which would otherwise be a direct path to host compromise. This is a standard hardening step in container security profiles (e.g., Docker's default seccomp/capability drop list).

Exam trap

The trap here is confusing file-system capabilities (DAC_OVERRIDE, CHOWN) with kernel-level capabilities (SYS_MODULE, SYS_ADMIN); candidates who don't memorize the capability-to-operation mapping often pick a familiar-sounding name.

How to eliminate wrong answers

Option A is wrong because CAP_DAC_OVERRIDE bypasses file read/write/execute permission checks — it has nothing to do with kernel module loading. Option B is wrong because CAP_CHOWN only allows changing file ownership (chown), which is unrelated to kernel module operations. Option D is wrong because CAP_NET_RAW permits use of raw sockets (e.g., for packet crafting/ping), not loading kernel modules.

830
MCQmedium

A company experiences a security breach in its cloud environment, and the security team needs to preserve evidence for legal proceedings. Which of the following is the MOST important step to take first?

A.Disable all logging to prevent the attacker from seeing detection efforts.
B.Isolate the compromised systems from the network to prevent lateral movement.
C.Notify all affected customers of the breach.
D.Contact the legal department to obtain a warrant before any action.
AnswerB

Isolating compromised systems halts active lateral movement, preserving volatile evidence such as memory and running processes that would otherwise be altered or destroyed. Containment must precede forensic acquisition, since ongoing attacker activity continually overwrites artefacts. This satisfies the stem's requirement to preserve evidence for legal proceedings by securing the environment first.

Why this answer

The immediate priority in a cloud security incident is to contain the breach and prevent lateral movement, which preserves the integrity of the evidence by stopping further compromise. Isolating compromised systems (e.g., via network security groups or virtual network segmentation) ensures that volatile data, such as memory contents and active connections, is not altered by ongoing attacker activity. This step aligns with the NIST SP 800-61 incident response framework, which emphasizes containment before evidence collection.

Exam trap

ISC2 often tests the misconception that preserving evidence means immediately collecting logs or notifying stakeholders, when in fact the first step is to contain the incident to prevent evidence from being altered or destroyed by ongoing attacker activity.

How to eliminate wrong answers

Option A is wrong because disabling all logging destroys the very evidence needed for legal proceedings and violates the principle of preserving forensic artifacts; logging should be enabled and protected to capture attacker actions. Option C is wrong because notifying affected customers prematurely can compromise the investigation, alert the attacker, and violate data breach notification laws that require a thorough forensic analysis first. Option D is wrong because obtaining a warrant is not a prerequisite for internal incident response actions; the company owns the cloud environment and can take immediate containment steps without a warrant, and waiting for legal authorization could allow the attacker to destroy evidence.

831
Multi-Selectmedium

A cloud security architect is designing a key management strategy to meet regulatory requirements for key separation and tamper evidence. Which TWO of the following are benefits of using hardware security modules (HSMs) backing a cloud KMS? (Select TWO.)

Select 2 answers
A.Compliance with FIPS 140-2 Level 3 or higher
B.Eliminates the need for customer-managed keys
C.Reduced latency for encryption operations
D.Automatic key rotation without customer intervention
E.Tamper-resistant key storage that prevents key extraction
AnswersA, E

HSMs validated to FIPS 140-2 Level 3 or higher provide physical tamper evidence and identity-based authentication, directly satisfying the stem's tamper-evidence requirement. Level 3's tamper-response mechanisms destroy keys on intrusion attempts, unlike software-based key stores. This certification also underpins key separation by enforcing cryptographic boundaries between tenants and roles within Microsoft Entra ID-integrated KMS deployments.

Why this answer

Option A is correct because HSMs backing a cloud KMS are validated to FIPS 140-2 (or FIPS 140-3) Level 3 or higher, which requires physical tamper resistance, identity-based authentication, and role separation — directly satisfying the regulatory key-separation and tamper-evidence requirements described. Option E is correct because HSM hardware is tamper-resistant and tamper-evident: keys are generated and used inside the cryptographic boundary and cannot be extracted in plaintext, with mechanisms that zeroize keys and leave evidence if the module is physically breached. Option B is wrong because HSMs protect keys but do not remove the need for customer-managed keys — in fact, customer-managed keys are often used with HSM-backed KMS to meet separation-of-duties requirements.

Option C is wrong because HSM-backed operations typically add network and hardware round-trip latency compared with software-only key stores, not reduce it. Option D is wrong because automatic key rotation is a KMS policy feature, not an inherent benefit of HSM backing, and many regulations still require customer-controlled or explicitly configured rotation.

Exam trap

The trap is selecting plausible-sounding but incorrect benefits like 'reduced latency' or 'automatic rotation.' Candidates must distinguish inherent HSM properties (tamper resistance, FIPS validation) from KMS policy features (rotation) and from performance claims that are usually false.

832
MCQmedium

A cloud architect is designing a data loss prevention (DLP) solution for a SaaS application. The DLP must inspect data in transit between end users and the cloud as well as data at rest. Which combination of controls is most appropriate?

A.Use network segmentation and security groups.
B.Deploy a cloud DLP service for content inspection and enforce encryption at rest.
C.Use encryption at rest and backup retention policies.
D.Implement a web application firewall (WAF) and a VPN.
AnswerB

Cloud DLP inspects data in transit and at rest; encryption protects at rest.

Why this answer

A cloud DLP service (e.g., AWS Macie, Microsoft Purview) can inspect data in transit by analyzing API calls or traffic patterns, and encryption at rest (e.g., AES-256) protects stored data. This combination directly addresses both inspection of data in transit and protection of data at rest, which is the core requirement of the question.

Exam trap

The trap here is that candidates confuse a WAF (which inspects for attacks) with a DLP service (which inspects for sensitive data content), leading them to choose Option D despite it lacking content inspection for data in transit.

How to eliminate wrong answers

Option A is wrong because network segmentation and security groups control traffic flow and access, but they do not inspect the content of data in transit or protect data at rest. Option C is wrong because encryption at rest protects stored data, but backup retention policies only manage data lifecycle, not inspect data in transit. Option D is wrong because a WAF inspects HTTP traffic for web attacks, not data content for DLP, and a VPN encrypts the tunnel but does not inspect the data payload.

833
MCQeasy

A cloud security engineer is configuring network security for a web application hosted on AWS. The application runs on EC2 instances behind an Application Load Balancer (ALB). The engineer needs to allow HTTP and HTTPS traffic from the internet to the ALB and restrict direct access to the EC2 instances. Which AWS service should be used to control inbound traffic to the ALB?

A.AWS Shield
B.Network ACLs
C.AWS WAF
D.Security groups
AnswerD

Security groups act as virtual firewalls for AWS resources, including ALBs and EC2 instances. They control inbound and outbound traffic at the instance level. For an ALB, you attach a security group to allow HTTP/HTTPS from the internet, and you can restrict EC2 instances to only accept traffic from the ALB's security group.

Why this answer

Security groups are stateful virtual firewalls that control inbound and outbound traffic for AWS resources such as ALBs and EC2 instances. They are the correct tool to allow HTTP/HTTPS to an ALB and to restrict EC2 instances to only accept traffic from the ALB. Network ACLs operate at the subnet level and are stateless, AWS WAF is for layer 7 protection, and AWS Shield is for DDoS mitigation, so none of these fulfill the basic network access control requirement.

Exam trap

The trap here is assuming that any security service (like WAF or Shield) can replace the fundamental network access control provided by security groups.

834
MCQmedium

A security engineer is concerned about a scenario where a malicious process inside a VM breaks out of the virtualized environment to compromise the hypervisor. What is this attack called and what is the primary mitigation?

A.VM sprawl; use resource limits
B.Side-channel attack; disable hyperthreading
C.Privilege escalation; enable SELinux inside VM
D.VM escape; regularly patch the hypervisor
AnswerD

VM escape occurs when a guest process exploits a hypervisor vulnerability to reach the host or other guests. Patching the hypervisor closes those flaws, which is the primary mitigation since the hypervisor is the isolation boundary being breached.

Why this answer

A VM escape is the class of attack where code running inside a guest VM exploits a vulnerability in the hypervisor (or virtual hardware emulation) to execute on the host. Because the hypervisor is the trust boundary, the primary mitigation is keeping it patched against known escape CVEs (e.g., VENOM, Xen XSA advisories). Regular hypervisor patching closes the specific flaws attackers leverage to break isolation.

Exam trap

The trap is conflating side-channel attacks (data leakage) with VM escape (isolation breach); both involve cross-VM concerns but only escape compromises the hypervisor itself.

How to eliminate wrong answers

Option A is wrong because VM sprawl refers to uncontrolled proliferation of VMs (a management/governance issue), and resource limits address DoS, not hypervisor breakout. Option B is wrong because side-channel attacks (e.g., Spectre, cache timing) leak data across VMs but are not the same as escaping to compromise the hypervisor, and disabling hyperthreading is only one partial mitigation. Option C is wrong because privilege escalation inside the guest OS (mitigated by SELinux) stays within the VM and does not cross the hypervisor boundary.

835
MCQhard

A multinational company is evaluating a cloud provider for a workload that processes personal data of employees in several countries. The company wants to ensure that cross-border data transfers comply with legal requirements. Which consideration is MOST important when assessing the provider's data transfer mechanisms?

A.Whether the provider's employees who may access the data are located in the same country as the data subjects.
B.Whether the provider can contractually commit to a recognized transfer mechanism, such as standard contractual clauses or an approved certification, for each transfer.
C.Whether the provider offers the lowest latency by storing data in the region closest to each employee.
D.Whether the provider's data centers are certified to ISO/IEC 27001 in every region where data is stored.
AnswerB

Cross-border transfers of personal data require a valid legal mechanism. Standard contractual clauses, adequacy decisions, or approved certification mechanisms provide that basis. The provider must be able to commit contractually to the applicable mechanism for each transfer path, and the customer must verify that the mechanism covers all countries where data is processed or stored.

Why this answer

Cross-border data transfers require a recognized legal mechanism, such as standard contractual clauses, an adequacy decision, or an approved certification. The provider must be able to contractually commit to the applicable mechanism for every country where personal data is processed or stored. Technical factors like latency or staff location do not satisfy the legal requirement, and security certifications alone do not authorize a transfer.

Exam trap

The trap here is confusing security certifications or performance factors with the legal transfer mechanisms required for cross-border personal data flows.

836
MCQhard

Refer to the exhibit. A cloud security administrator is reviewing the following network firewall rule configuration associated with a web server instance. What security best practice is being violated?

A.Outbound traffic should be allowed to any destination.
B.Inbound SSH should not be allowed from any source.
C.Inbound HTTPS should be allowed from any source.
D.Security groups should not be used for web servers.
AnswerB

Allowing SSH from 0.0.0.0/0 exposes the management port to the entire internet, enabling brute-force and exploitation attempts. Administrative access should be restricted to trusted CIDR ranges or a bastion, so the any-source inbound rule violates least-privilege network exposure.

Why this answer

Allowing inbound SSH (TCP port 22) from any source (0.0.0.0/0) violates the security best practice of least privilege. SSH should only be permitted from specific administrative IP ranges or bastion hosts to prevent unauthorized access and brute-force attacks. In a cloud environment, network firewall rules should restrict SSH to known management networks, not the entire internet.

Exam trap

ISC2 often tests the misconception that allowing inbound HTTPS from any source is a violation, but for a public web server, this is correct; the trap is confusing the need for open HTTPS with the need to restrict administrative protocols like SSH.

How to eliminate wrong answers

Option A is wrong because outbound traffic should be restricted to only necessary destinations (e.g., specific update servers or databases), not allowed to any destination, as unrestricted outbound traffic can facilitate data exfiltration. Option C is wrong because inbound HTTPS (TCP port 443) should be allowed from any source for a public web server; this is a standard requirement for serving web content securely. Option D is wrong because security groups are the primary and recommended mechanism for controlling traffic to cloud instances like web servers; they are stateful and provide granular access control.

837
Multi-Selectmedium

Which THREE of the following are commonly required when conducting a cloud vendor risk assessment?

Select 3 answers
A.Security certifications (e.g., ISO 27001)
B.Financial stability of the vendor
C.Vendor's incident response plan
D.Pricing compared to competitors
E.Marketing materials and brand reputation
AnswersA, B, C

Security certifications such as ISO 27001 provide independently audited evidence of a vendor's control environment, satisfying the due-diligence requirement to verify security posture without onsite inspection. They let assessors map vendor controls to their own framework, confirming Microsoft Entra ID, encryption and access controls meet recognised baselines before data is entrusted to the provider.

Why this answer

Financial stability, certifications, and incident response plans are standard vendor risk assessment items. Pricing comparison is procurement, not risk; marketing materials are irrelevant.

838
MCQeasy

A cloud operations team is deploying a web application that stores configuration files and application logs in an object storage bucket. The security policy requires that data be encrypted at rest, and the team wants the cloud provider to manage the encryption keys with minimal operational overhead. The bucket must remain accessible to the application without code changes. Which approach should the team use?

A.Use server-side encryption with customer-provided keys, supplying the key in each request so the provider does not store it.
B.Rely on transport layer security for data in transit and document that encryption at rest is not required for configuration files.
C.Implement client-side encryption in the application so that objects are encrypted before upload, using keys stored in the application configuration.
D.Enable server-side encryption with provider-managed keys on the bucket, which automatically encrypts objects at rest.
AnswerD

Server-side encryption with provider-managed keys encrypts objects at rest and the cloud provider handles key storage, rotation, and access transparently. The application continues to read and write objects without modification, meeting the minimal-overhead and no-code-change requirements. This directly satisfies the policy that data be encrypted at rest while keeping operations simple.

Why this answer

Provider-managed server-side encryption is the lowest-overhead way to meet an encryption-at-rest requirement because the cloud service handles key storage, rotation, and cryptographic operations automatically. The application's read and write operations remain unchanged, so no code modifications are needed. This satisfies both the security policy and the operational constraints described by the team.

Exam trap

The trap here is assuming that encryption at rest always requires customer-managed keys or client-side code, when provider-managed server-side encryption already satisfies the policy with less overhead.

839
MCQhard

In a public cloud IaaS environment, which of the following is the customer responsible for securing, according to the shared responsibility model?

A.Operating system and applications
B.Virtualization hypervisor
C.Network infrastructure
D.Physical security of data centers
AnswerA

In IaaS the provider secures the physical hosts, network and hypervisor, while the customer retains responsibility for everything above it: guest operating system patching, middleware, applications and data. That division satisfies the stem's IaaS shared responsibility question.

Why this answer

In the IaaS shared responsibility model, the cloud provider secures the physical facilities, hardware, hypervisor, and network fabric, while the customer is responsible for everything from the guest operating system upward, including patching, applications, and data. Therefore the customer must secure the operating system and applications they deploy on IaaS instances.

Exam trap

The trap is over-attributing security to the cloud provider; candidates often think the provider secures the OS because it secures the hypervisor, but in IaaS the guest OS is squarely the customer's responsibility.

How to eliminate wrong answers

Option B is wrong because the virtualization hypervisor is part of the provider's managed infrastructure in IaaS; the customer does not control or patch it. Option C is wrong because the underlying network infrastructure (routers, switches, physical links) is owned and secured by the cloud provider. Option D is wrong because physical security of data centers is always the provider's responsibility under every cloud service model.

840
MCQmedium

A security analyst notices that an IAM user from a cloud account has logged in from two different countries within a span of 10 minutes. Which type of detection mechanism is most likely to flag this activity as suspicious?

A.A cloud configuration management database (CMDB)
B.A vulnerability scanner
C.An agent-based intrusion detection system (IDS)
D.A correlation rule in a SIEM
AnswerD

A SIEM correlation rule joins disparate events across a time window, so it can compare two authentication logs from different countries ten minutes apart and raise an alert. Single-event detections, such as signature or anomaly checks, evaluate each login in isolation and miss the geographic impossibility.

Why this answer

A correlation rule in a SIEM is designed to aggregate and analyze log data from multiple sources, such as cloud IAM logs, to detect anomalous patterns. The specific scenario of a user logging in from two geographically distant countries within 10 minutes is a classic example of an impossible travel time anomaly, which SIEM correlation rules are built to flag by comparing login timestamps and IP geolocation data.

Exam trap

The CCSP exam often tests the distinction between detection mechanisms that analyze static configurations (CMDB, vulnerability scanners) versus those that analyze dynamic behavioral patterns (SIEM correlation rules), leading candidates to confuse a CMDB's asset inventory function with real-time anomaly detection.

How to eliminate wrong answers

Option A is wrong because a cloud configuration management database (CMDB) is a repository for storing metadata about IT assets and their relationships, not a real-time detection mechanism for user login anomalies. Option B is wrong because a vulnerability scanner is designed to identify security weaknesses in systems (e.g., missing patches, misconfigurations), not to analyze user behavior or login patterns. Option C is wrong because an agent-based intrusion detection system (IDS) monitors network traffic or host-level events for known attack signatures, but it does not typically correlate geolocation data from cloud IAM logs to detect impossible travel scenarios.

841
MCQeasy

Which cloud characteristic allows a user to automatically provision computing resources without requiring human interaction with the service provider?

A.Broad network access
B.Rapid elasticity
C.Resource pooling
D.On-demand self-service
AnswerD

On-demand self-service lets the consumer unilaterally provision computing capabilities, such as server time and storage, automatically as needed without human interaction with each provider. This directly matches the stem's requirement for provisioning without human interaction.

Why this answer

On-demand self-service is the NIST-defined cloud characteristic that lets consumers unilaterally provision computing capabilities, such as server time and storage, automatically without requiring human interaction with the service provider. This is exactly what the question describes.

Exam trap

The trap is confusing rapid elasticity with on-demand self-service; both involve automation, but elasticity is about scaling with demand, while self-service is about provisioning without provider interaction.

How to eliminate wrong answers

Option A is wrong because broad network access means services are available over the network via standard mechanisms, not that provisioning is automated. Option B is wrong because rapid elasticity refers to scaling capabilities outward and inward commensurate with demand, not the self-provisioning act itself. Option C is wrong because resource pooling describes the provider's multi-tenant model where resources are dynamically assigned, not the customer's ability to self-provision.

842
MCQmedium

Which of the following is a best practice for managing secrets in cloud-native applications?

A.Hardcode secrets in environment variables
B.Include secrets in container images
C.Use the same secret across all environments
D.Store secrets in a dedicated secrets management service
AnswerD

A dedicated secrets management service stores credentials encrypted, issues them at runtime via short-lived tokens or dynamic generation, and provides audit logging and rotation. This removes secrets from source code, container images and environment variables, satisfying the constraint of secure secret handling in cloud-native applications.

Why this answer

Using a cloud secret manager (like AWS Secrets Manager or HashiCorp Vault) to inject secrets at runtime avoids hardcoding and enables rotation. Least privilege IAM and environment variables are also good but using a dedicated service is best.

843
MCQmedium

A data classification scheme for a cloud environment defines labels such as Public, Internal, Confidential, and Restricted. Which label should be applied to data that, if disclosed, would cause severe damage to the organization and is subject to regulatory fines?

A.Restricted
B.Public
C.Confidential
D.Internal
AnswerA

Restricted fits because the stem demands the highest sensitivity tier for severe damage plus regulatory penalties. Unlike Confidential, which covers unauthorised disclosure causing damage, Restricted is reserved for data whose compromise triggers legal sanctions, so it satisfies the classification scheme's top-level handling, encryption and access-control requirements.

Why this answer

The Restricted label is reserved for the most sensitive data whose unauthorized disclosure would cause severe damage and trigger regulatory penalties. Data classification schemes typically escalate from Public → Internal → Confidential → Restricted, with Restricted representing the highest tier requiring the strictest controls (encryption, least privilege, audit logging). Because the question specifies 'severe damage' plus 'regulatory fines,' this maps directly to the top classification tier.

Exam trap

CCSP often tests the distinction between Confidential and Restricted, luring candidates who assume 'confidential' means maximum sensitivity when the exam expects Restricted for severe-damage, regulator-fined data.

How to eliminate wrong answers

Option B is wrong because Public data is intended for open disclosure and carries no confidentiality requirement, so it cannot describe data whose exposure causes severe damage. Option C is wrong because Confidential typically covers sensitive internal data whose disclosure causes moderate harm, but it sits below Restricted in most schemes and does not imply the highest protection tier. Option D is wrong because Internal merely denotes data not meant for external release but with low sensitivity, far below the severe-damage threshold described.

844
MCQeasy

A company is migrating sensitive customer data to a public cloud storage service. They want to ensure that even the cloud provider cannot access the plaintext data. Which encryption strategy should they implement?

A.Client-side encryption before uploading data
B.Server-side encryption with cloud-provider-managed keys
C.Tokenization of sensitive fields at the application layer
D.Enforcing role-based access control (RBAC) on the storage bucket
AnswerA

Encrypting data before it leaves the customer's environment means the provider only ever stores ciphertext, and keys never reach the provider. This satisfies the constraint that the cloud provider cannot access plaintext, unlike provider-managed server-side encryption where the provider holds keys.

Why this answer

Client-side encryption ensures that data is encrypted before it leaves the customer's environment, so the cloud provider only ever receives ciphertext. This means the cloud provider cannot access the plaintext data, even if the storage service is compromised or the provider is legally compelled to disclose data. The encryption keys are managed and stored by the customer, not the cloud provider.

Exam trap

ISC2 often tests the distinction between encryption at rest (server-side) and encryption in transit or before upload (client-side), and the trap is that candidates confuse server-side encryption with the ability to prevent provider access, not realizing that the provider still holds the keys.

How to eliminate wrong answers

Option B is wrong because server-side encryption with cloud-provider-managed keys means the cloud provider holds the encryption keys and can decrypt the data on demand, which does not prevent the provider from accessing plaintext. Option C is wrong because tokenization replaces sensitive data with tokens, but the token mapping and original data are typically stored elsewhere and may still be accessible to the provider; it also does not encrypt the entire data payload, leaving other fields in plaintext. Option D is wrong because RBAC controls access to the storage bucket but does not encrypt the data; the cloud provider can still read the plaintext data stored in the bucket.

845
MCQmedium

During a code review, a developer identifies that an application uses input from an HTTP request to generate a SQL query string. What is the primary security concern?

A.Buffer overflow
B.Insecure deserialization
C.Cross-site scripting (XSS)
D.SQL injection
AnswerD

Concatenating HTTP request input into a SQL query string lets attacker-supplied syntax alter the query's structure, so the database executes unintended statements. This is SQL injection, the direct consequence of mixing untrusted input with query code without parameterisation.

Why this answer

Directly concatenating user-supplied input from an HTTP request into a SQL query string allows an attacker to inject arbitrary SQL commands. This can lead to unauthorized data access, data manipulation, or even complete database compromise. The primary security concern is SQL injection, which violates the confidentiality and integrity of cloud-hosted databases.

Exam trap

ISC2 often tests the distinction between input validation issues (like SQL injection) and output encoding issues (like XSS), so the trap here is confusing a server-side injection attack with a client-side script injection attack.

How to eliminate wrong answers

Option A is wrong because buffer overflow exploits typically target memory corruption in low-level languages like C/C++, not SQL query string generation in application code. Option B is wrong because insecure deserialization involves untrusted data being deserialized into objects, not the direct injection of SQL syntax into a query string. Option C is wrong because cross-site scripting (XSS) involves injecting client-side scripts into web pages viewed by other users, whereas this scenario directly manipulates a server-side SQL query.

846
MCQmedium

A cloud architect is designing a multi-tier application in a public cloud. The web tier must be accessible from the internet, while the application and database tiers must only be reachable from the web tier. The architect needs to ensure that even if the web server is compromised, the attacker cannot directly access the database. Which architecture BEST meets this requirement?

A.Place all tiers in the same subnet and use a single security group to control inbound traffic.
B.Place all tiers in the same VPC but different subnets, and use network ACLs to restrict traffic.
C.Place the web tier in a public subnet with a security group allowing HTTP/HTTPS from 0.0.0.0/0, and place the app and database tiers in private subnets with security groups allowing traffic only from the web tier's security group.
D.Use a VPN to connect the tiers and rely on IPsec policies for segmentation.
AnswerC

Security-group referencing means the database accepts traffic only from instances carrying the web tier's group identity, not from any IP in the subnet. A compromised web server therefore cannot pivot directly to the database, satisfying the lateral-movement constraint.

Why this answer

It implements defense-in-depth by placing the web tier in a public subnet with a security group that allows inbound HTTP/HTTPS from the internet, while the app and database tiers reside in private subnets with security groups that only permit traffic from the web tier's security group. This ensures that even if the web server is compromised, the attacker cannot directly reach the database because the database security group explicitly denies traffic from any source other than the web tier's security group, and the private subnets have no direct internet route.

Exam trap

The trap here is that candidates often confuse network ACLs (stateless, IP-based) with security groups (stateful, can reference other security groups), leading them to choose Option B because they think ACLs provide sufficient segmentation, but they overlook the need for group-based source references to prevent lateral movement from a compromised host.

How to eliminate wrong answers

Option A is wrong because placing all tiers in the same subnet with a single security group provides no network segmentation; if the web server is compromised, the attacker can directly access the database on the same subnet without any additional controls. Option B is wrong because while different subnets provide network segmentation, network ACLs are stateless and evaluate rules in order, but they do not support source-group-based references (like security group IDs), so they cannot restrict traffic to only the web tier's security group; they can only filter by IP ranges, which is less precise and could allow lateral movement if the web server's IP is spoofed or if multiple instances are used. Option D is wrong because a VPN with IPsec policies connects the tiers over an encrypted tunnel but does not enforce internal segmentation within the VPC; it would still require additional security groups or ACLs to restrict database access, and the VPN itself does not prevent a compromised web server from directly reaching the database if both are on the same network segment.

847
Matchingmedium

Match each key management solution to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Hardware-based key generation and storage

Software-based key lifecycle management

Customer-managed keys in cloud provider HSM

Customer holds and manages own keys

Why these pairings

Key management is critical for data protection; BYOK and KYOK offer different levels of customer control.

848
Multi-Selectmedium

A cloud security architect is designing a multi-tenant SaaS application. Which TWO isolation mechanisms should be implemented to prevent data leakage between tenants?

Select 2 answers
A.API rate limiting
B.Network isolation using virtual networks
C.Storage isolation through separate databases or schemas
D.Data encryption at rest
E.Identity federation
AnswersB, C

Virtual networks segment tenant traffic so one tenant's workloads cannot reach another's at the network layer, blocking lateral movement and cross-tenant access. This satisfies the stem's requirement for isolation mechanisms preventing data leakage between tenants in the multi-tenant SaaS application.

Why this answer

Network isolation using virtual networks (B) is correct because placing each tenant's workloads in separate VNets/subnets (or separate VPCs) with security groups/NSGs and peering rules prevents cross-tenant network traffic and lateral movement, which is a primary vector for data leakage in multi-tenant SaaS. Storage isolation through separate databases or schemas (C) is correct because logically or physically partitioning tenant data (dedicated database per tenant, or schema-per-tenant with strict access controls) enforces a hard data boundary so one tenant's queries cannot read another tenant's records. API rate limiting (A) only protects availability and throttles abuse; it does not create a data boundary.

Data encryption at rest (D) protects data confidentiality if the storage medium is compromised but does not prevent one tenant from accessing another tenant's data through the application. Identity federation (E) addresses authentication and SSO, not tenant data separation.

Exam trap

The trap is selecting encryption at rest as an isolation mechanism; candidates assume encryption prevents data leakage, but it only protects data at the storage layer and does not stop an application from accessing another tenant's records.

849
MCQmedium

A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is cryptographically isolated so that even a compromised application process cannot read another tenant's data. The architect plans to use AWS Key Management Service (KMS) with tenant-specific keys. Which of the following is the MOST critical security control to implement to achieve this isolation?

A.Store all tenant data in a single S3 bucket with a bucket policy that restricts access by tenant ID prefix.
B.Enable automatic key rotation for all KMS customer managed keys.
C.Use a separate KMS customer managed key per tenant and enforce strict IAM policies that limit each tenant's application role to only its own key.
D.Enable AWS CloudTrail logging for all KMS API calls and monitor for anomalous decrypt operations.
AnswerC

Using a distinct KMS key per tenant creates a cryptographic boundary: data encrypted under one key cannot be decrypted with another. Coupling this with least-privilege IAM policies ensures that a compromised process can only access its own tenant's key. This directly prevents cross-tenant data access, satisfying the isolation requirement.

Why this answer

The scenario requires cryptographic isolation so that a compromised process cannot read another tenant's data. Using a separate KMS customer managed key per tenant ensures that data is encrypted with distinct keys, and strict IAM policies limit each tenant's role to only its own key. This combination creates a strong boundary.

Other options are either hygiene practices or detective controls that do not prevent cross-tenant access.

Exam trap

The trap here is assuming that access control policies alone (like bucket policies or IAM) provide sufficient isolation, when cryptographic separation via distinct keys is required to prevent a compromised process from decrypting other tenants' data.

850
MCQmedium

A cloud-native application stores sensitive user files in an Amazon S3 bucket. Which misconfiguration poses the greatest risk of data exposure?

A.Bucket versioning enabled
B.Bucket ACL set to public read
C.Default encryption enabled
D.Bucket policy with a condition for source IP
AnswerB

A public-read bucket ACL grants anonymous principals GetObject on every object, directly exposing sensitive user files to anyone on the internet. This satisfies the stem's greatest-risk constraint because the exposure is immediate and requires no authentication or exploitation.

Why this answer

Setting the S3 bucket ACL to public read allows anyone on the internet to access files, leading to data exposure.

851
MCQhard

A healthcare cloud tenant must ensure that when a physical host is decommissioned, residual data in storage cannot be reconstructed. The provider offers self-encrypting drives. Which property most directly guarantees that cryptographic erasure is effective?

A.The media encryption key is wrapped by a key-encryption key that is destroyed on decommission
B.The drive firmware performs a multi-pass overwrite of all sectors
C.The drive is physically shredded at an approved destruction facility
D.The storage array keeps redundant copies of the data on mirrored volumes
AnswerA

Cryptographic erasure works by destroying the key that protects the media encryption key, rendering all ciphertext on the drive permanently undecryptable. If the key-encryption key is reliably destroyed and never escrowed elsewhere, the data becomes unrecoverable even if the platters are later read, which is the property the tenant needs contractually guaranteed.

Why this answer

Cryptographic erasure depends entirely on the irrecoverability of the key material protecting the drive. Only destroying the wrapping key that protects the media encryption key ensures that ciphertext on retired media can never be decrypted, which is precisely the guarantee a healthcare tenant needs for decommissioned storage.

Exam trap

The trap here is conflating physical sanitization methods like overwriting or shredding with cryptographic erasure, which is defined by destruction of the key rather than the data.

852
MCQmedium

Which of the following is a cloud-specific threat that should be included in a threat model for a cloud application?

A.Exposed S3 bucket
B.Cross-site scripting (XSS)
C.SQL injection
D.Buffer overflow
AnswerA

An exposed S3 bucket is a cloud-specific threat because it arises from object-storage ACL and policy misconfiguration unique to cloud provider services, not traditional on-premises infrastructure. Including it in the threat model addresses the stem's requirement for cloud-specific rather than generic threats.

Why this answer

An exposed S3 bucket is a cloud-specific threat because it arises from the cloud provider's object storage service and its IAM/bucket-policy misconfiguration model, which has no direct on-premises equivalent. Threat models for cloud applications must account for provider-managed services where a single ACL or bucket policy mistake can publicly expose data at internet scale. XSS, SQL injection, and buffer overflow are classic application-layer vulnerabilities that exist regardless of hosting environment.

Exam trap

The trap here is that candidates pick a familiar OWASP vulnerability (XSS, SQLi, buffer overflow) because it sounds like a serious threat, missing that the question asks specifically for a cloud-specific threat tied to a provider service.

How to eliminate wrong answers

Option B is wrong because cross-site scripting (XSS) is a generic web application vulnerability (injection of client-side script) that exists on any web server, not a cloud-specific threat. Option C is wrong because SQL injection is a database query manipulation flaw catalogued in OWASP Top 10 and is platform-agnostic, not unique to cloud. Option D is wrong because buffer overflow is a memory-safety defect in native code (e.g., C/C++), unrelated to cloud service configuration.

853
Multi-Selecthard

A cloud architect is designing a multi-cloud solution that must maintain high availability and disaster recovery across two cloud providers. Which three key considerations should be included in the architecture? (Choose three.)

Select 3 answers
A.Rely on each provider's native high-availability features.
B.Use a single networking interface to simplify connectivity.
C.Use a single DNS provider for failover.
D.Implement consistent identity and access management across providers.
E.Ensure application code is cloud-agnostic.
AnswersA, D, E

Leveraging each provider's native high-availability features satisfies the multi-cloud resilience constraint by exploiting independent, provider-managed redundancy domains. Because the two clouds share no control plane or failure boundary, an outage in one cannot cascade to the other, delivering the cross-provider disaster recovery the stem demands without bespoke tooling.

Why this answer

Option A is correct because leveraging each provider's native high-availability features (such as AWS Multi-AZ deployments, Azure Availability Zones, or GCP regional resources) provides resilient, provider-optimized redundancy within each cloud without reinventing failover mechanisms. Option D is correct because implementing consistent identity and access management across providers (for example, federating with SAML 2.0/OIDC to a central IdP like Azure AD or Okta) ensures uniform authentication, authorization, and least-privilege policies across both environments, which is essential for secure multi-cloud operations. Option E is correct because cloud-agnostic application code (e.g., using containers, Kubernetes, or abstraction layers instead of proprietary PaaS APIs) enables portability and failover between providers, which is fundamental to a multi-cloud DR strategy.

Option B does not belong because a single networking interface creates a single point of failure and does not address cross-provider connectivity or redundancy. Option C does not belong because relying on a single DNS provider for failover introduces a single point of failure; a resilient multi-cloud design should use multiple DNS providers or health-check-based global traffic management.

Exam trap

ISC2 often tests the misconception that a single DNS provider or single network interface is acceptable for multi-cloud HA, when in reality these create critical single points of failure that violate the redundancy principle.

854
Multi-Selecthard

A security team is reviewing the software development lifecycle for a cloud-native application. They want to shift security left and reduce the cost of remediating defects. Which two practices best support this goal? (Choose two.)

Select 2 answers
A.Add infrastructure as code scanning that detects misconfigurations in templates before they are deployed to any environment.
B.Conduct annual security awareness training for all engineers and track completion in the learning management system.
C.Require developers to submit a written security exception form for every new cloud resource they provision.
D.Integrate static application security testing into the build pipeline so that code is analyzed automatically on every commit.
E.Perform a full penetration test of the application only after it has been deployed to the production environment.
AnswersA, D

Scanning infrastructure as code templates before deployment catches insecure settings such as public buckets or permissive security groups at authoring time. Because the fix is a template change reviewed like any other code, remediation is cheap and consistent across environments. This is a concrete shift-left control that prevents misconfigurations from ever reaching the cloud account.

Why this answer

Shifting security left means embedding automated checks into the earliest stages of development so defects are found and fixed while changes are small. Static analysis on every commit and infrastructure as code scanning before deployment both deliver immediate, low-cost feedback in the developer workflow. Late penetration tests, manual exception forms, and annual training do not detect defects at authoring time and therefore do not lower remediation cost.

Exam trap

The trap here is equating any security activity added to the lifecycle with shifting left, when the defining characteristic is early automated detection in the developer workflow.

855
Multi-Selectmedium

A company is negotiating a cloud contract and wants to ensure data ownership and deletion. Which TWO clauses should be included? (Select two.)

Select 2 answers
A.Right to audit clause
B.Non-disclosure agreement
C.Data ownership clause
D.Service level agreement
E.Data deletion clause
AnswersC, E

A data ownership clause contractually confirms the customer retains all rights to its data stored or processed in the cloud, preventing the provider from claiming or exploiting it. This directly satisfies the stated requirement to ensure data ownership.

Why this answer

Option C, the data ownership clause, is correct because it contractually establishes that the company retains legal ownership of its data stored or processed by the cloud provider, preventing the provider from claiming rights over that data. Option E, the data deletion clause, is correct because it specifies the provider's obligations to securely and verifiably delete the company's data upon contract termination or on request, including timelines and certification of destruction. Option A, the right to audit clause, is not among the marked correct answers because while it supports compliance verification, it does not directly address ownership or deletion of data.

Option B, the non-disclosure agreement, is not marked correct because it protects confidentiality of shared information but does not establish data ownership or mandate deletion. Option D, the service level agreement, is not marked correct because it defines performance metrics such as uptime and availability, not data ownership or deletion rights.

Exam trap

The trap is selecting clauses that are generally important (like right to audit or SLA) but do not specifically address the question's focus on data ownership and deletion.

856
MCQmedium

A cloud security engineer is reviewing a serverless application built with AWS Lambda. The function processes messages from an Amazon SQS queue and writes to an Amazon DynamoDB table. The engineer needs to ensure that the Lambda function has only the necessary permissions to perform its tasks. Which approach best follows the principle of least privilege?

A.Store AWS credentials in environment variables and use them in the Lambda function code.
B.Attach a managed policy like AmazonSQSFullAccess and AmazonDynamoDBFullAccess to the Lambda execution role.
C.Create a custom IAM policy that allows sqs:ReceiveMessage on the specific queue and dynamodb:PutItem on the specific table, and attach it to the Lambda execution role.
D.Use AWS IAM roles for service accounts (IRSA) to assign permissions to the Lambda function.
AnswerC

A custom IAM policy scoped to the exact actions and resources required adheres to least privilege. The Lambda function needs to receive messages from the designated SQS queue and put items into the designated DynamoDB table. This granular policy minimizes permissions and reduces risk, ensuring the function cannot perform other actions or access other resources.

Why this answer

The principle of least privilege requires granting only the permissions necessary for the function's operation. A custom IAM policy that allows sqs:ReceiveMessage on the specific queue and dynamodb:PutItem on the specific table ensures the Lambda function can perform its tasks without excess permissions. This minimizes the potential impact of a compromised function and aligns with AWS security best practices.

Exam trap

The trap here is assuming that managed policies or storing credentials in environment variables are acceptable for least privilege, when they grant excessive permissions or introduce security risks.

857
MCQeasy

A cloud security team is reviewing access controls for a storage bucket containing sensitive data. They want to ensure that only authorized users can access the data and that access is logged for auditing. Which cloud-native mechanism should they implement?

A.Encryption at rest with key rotation
B.Network Access Control Lists (ACLs) with flow logs
C.Identity and Access Management (IAM) policies with logging enabled
D.Storage bucket policies with versioning enabled
AnswerC

IAM policies define who can access resources, and enabling logging (e.g., cloud audit logs) records access attempts. This combination ensures both access control and auditability, directly meeting the scenario's requirements. It is a fundamental cloud security practice.

Why this answer

IAM policies with logging enabled provide both access control and auditability by defining permissions and recording access events. Network ACLs, bucket policies without logging, and encryption do not fully satisfy the requirement to control and log user access to the data.

Exam trap

The trap here is confusing data protection mechanisms like encryption with access control and auditing, which are separate concerns.

858
MCQmedium

An organization is looking for a cloud deployment model that is provisioned for exclusive use by a single organization, but may be owned, managed, and operated by the organization, a third party, or some combination. Which deployment model is this?

A.Hybrid cloud
B.Private cloud
C.Community cloud
D.Public cloud
AnswerB

A private cloud is provisioned for exclusive use by a single organisation, and may be owned, managed, and operated by that organisation, a third party, or a combination, whether on or off premises. This exactly matches the stem's exclusivity and ownership wording.

Why this answer

Private cloud is defined as provisioned for exclusive use by a single organization. It can be on-premises or hosted, and managed by the organization or a third party.

859
Multi-Selectmedium

Which TWO statements about data masking are correct?

Select 2 answers
A.Data masking is a form of encryption.
B.Data masking is primarily used for production environments.
C.Data masking is reversible.
D.Data masking replaces sensitive data with realistic fictional data.
E.Data masking can be static or dynamic.
AnswersD, E

It produces realistic data for development and testing.

Why this answer

Data masking replaces sensitive data (e.g., credit card numbers, SSNs) with realistic but fictitious data that preserves the original data's format and referential integrity, ensuring that the masked data remains usable for testing or analytics without exposing actual sensitive information. This is distinct from encryption, as masking does not use a key to transform data but rather substitutes it with a non-sensitive equivalent.

Exam trap

The trap here is that candidates often confuse data masking with encryption, assuming both are reversible, or mistakenly think masking is used in production environments, whereas the CCSP emphasizes that masking is for non-production use and is irreversible by design.

860
MCQeasy

Which cloud characteristic refers to the ability to automatically scale resources up or down based on demand?

A.Resource pooling
B.Rapid elasticity
C.Broad network access
D.Measured service
AnswerB

Rapid elasticity describes resources scaling automatically up or down to match demand, appearing unlimited to the consumer. This directly satisfies the stem's automatic scaling characteristic, distinguishing it from measured service, on-demand self-service and broad network access, which address provisioning, metering and connectivity instead.

Why this answer

Rapid elasticity is the cloud characteristic that allows resources to be automatically scaled up or down based on demand. It enables cloud consumers to quickly provision and release resources to match workload fluctuations, often in an automated manner. This is a core tenet of cloud computing as defined by NIST.

Exam trap

The trap is that candidates might confuse rapid elasticity with other characteristics like resource pooling or measured service, especially since all are fundamental to cloud computing.

How to eliminate wrong answers

Option A is wrong because resource pooling refers to the sharing of physical resources among multiple tenants, not automatic scaling. Option C is wrong because broad network access means services are available over the network via standard mechanisms, not scaling. Option D is wrong because measured service refers to monitoring and metering resource usage for billing, not scaling.

861
MCQmedium

During a CI/CD pipeline, a developer wants to automatically block builds if Terraform configuration files contain security misconfigurations. Which tool is best suited for this task?

A.Snyk
B.GitGuardian
C.Checkov
D.OWASP ZAP
AnswerC

Checkov performs static analysis of Terraform configurations, scanning for security misconfigurations before deployment. This directly satisfies the pipeline constraint of blocking builds automatically, since Checkov returns non-zero exit codes on failed checks, enabling CI/CD gates to halt the build. It parses HCL natively, unlike generic scanners.

Why this answer

Checkov is a static analysis tool specifically designed to scan Infrastructure as Code (IaC) files — including Terraform, CloudFormation, Kubernetes, and ARM templates — for security and compliance misconfigurations. It integrates directly into CI/CD pipelines and can fail builds when policy violations are detected, making it the best fit for blocking Terraform misconfigurations.

Exam trap

The trap is confusing IaC scanning with other security scanning types — candidates may pick Snyk (dependency scanning) or GitGuardian (secret scanning) when the question specifically asks about Terraform misconfigurations.

How to eliminate wrong answers

Option A is wrong because Snyk focuses on application dependencies, container images, and code vulnerabilities (SAST/SCA), not on Terraform IaC misconfiguration scanning — although Snyk has some IaC capabilities, Checkov is the purpose-built tool for this task. Option B is wrong because GitGuardian is a secrets-detection tool that scans repositories for leaked credentials and API keys, not for Terraform configuration misconfigurations. Option D is wrong because OWASP ZAP is a dynamic application security testing (DAST) tool that probes running web applications for vulnerabilities, not static IaC files.

862
MCQhard

A financial services company uses a multi-region cloud deployment for its trading application. The application consists of a web frontend, a REST API, and a relational database. Recently, a penetration test revealed that an attacker could perform a time-based blind SQL injection through the API's search functionality. The injection allows the attacker to enumerate database contents by observing response times. The development team was already aware of the issue but had prioritized other features. The security team now demands immediate remediation. The application is critical and cannot be taken offline. Which of the following is the most effective immediate action to mitigate the risk without modifying the application code?

A.Deploy a Web Application Firewall (WAF) with a rule to block SQL injection patterns
B.Implement rate limiting on the API endpoint
C.Enable DDoS protection on the cloud load balancer
D.Enable transparent data encryption (TDE) on the database
AnswerA

A WAF inspects HTTP requests at the edge and blocks SQL injection signatures before they reach the API, satisfying the no-code-change constraint. Because the flaw is exploitable through the search parameter, virtual patching neutralises the time-based blind injection immediately while the application stays online.

Why this answer

A WAF can inspect incoming HTTP requests and block those matching SQL injection patterns (e.g., SQL keywords, special characters) without modifying application code. Since the vulnerability is a time-based blind SQL injection, a WAF with a dedicated SQL injection rule set can immediately stop the attack vector by filtering malicious payloads at the edge, providing a virtual patch while the code fix is developed. This is the only option that directly addresses the injection vector without requiring code changes or downtime.

Exam trap

ISC2 often tests the misconception that rate limiting or DDoS protection can mitigate application-layer attacks like SQL injection, but these controls address availability threats, not data exfiltration or injection vulnerabilities.

How to eliminate wrong answers

Option B is wrong because rate limiting only restricts the number of requests per time window, which does not prevent a single crafted SQL injection payload from executing; it merely slows down enumeration but does not block the injection itself. Option C is wrong because DDoS protection mitigates volumetric attacks aimed at overwhelming resources, not application-layer attacks like SQL injection; it does not inspect payload content. Option D is wrong because transparent data encryption (TDE) protects data at rest in the database, but the SQL injection attack exploits the API to extract data in transit or via response timing, so encryption does not prevent the injection or the data exfiltration.

863
MCQmedium

A security architect is designing a container runtime security strategy. Which of the following controls is most effective at preventing a container from compromising the host kernel?

A.Seccomp profile
B.Read-only root filesystem
C.Resource limits (CPU/memory)
D.Image vulnerability scanning
AnswerA

Seccomp profiles filter the system calls a container may invoke, blocking the specific kernel interfaces an exploit needs to escalate to the host. This directly satisfies the stem's constraint of preventing host kernel compromise, since container escapes depend on unmediated syscalls rather than on network or filesystem configuration.

Why this answer

Seccomp (secure computing mode) profiles restrict the system calls a container can make to the host kernel, directly reducing the kernel attack surface. By filtering out dangerous syscalls, seccomp is the most effective control for preventing a compromised container from exploiting kernel vulnerabilities. It operates at the syscall boundary, which is the primary interface between containers and the host kernel.

Exam trap

CCSP often tests the misconception that filesystem or resource controls provide kernel-level protection, when in fact only syscall-filtering mechanisms like seccomp directly reduce the kernel attack surface from a container.

How to eliminate wrong answers

Option B (Read-only root filesystem) is wrong because it prevents filesystem writes within the container but does nothing to restrict syscall access to the kernel — an attacker can still invoke dangerous syscalls. Option C (Resource limits) is wrong because CPU/memory limits only prevent resource exhaustion (DoS) and have no bearing on kernel exploitation via syscalls. Option D (Image vulnerability scanning) is wrong because scanning identifies known vulnerabilities in image layers at build time but does not enforce runtime syscall restrictions, so it cannot prevent exploitation of a zero-day or unpatched kernel flaw.

864
MCQeasy

A cloud customer receives a litigation hold notice requiring preservation of data stored in an object storage service. Which service feature should the customer use to ensure data cannot be modified or deleted until the hold is released?

A.Apply a retention policy using Object Lock
B.Set a lifecycle policy to transition to archival storage
C.Enable versioning on the bucket
D.Configure server-side encryption
AnswerA

Object Lock enforces write-once-read-many (WORM) protection at the object level, preventing modification or deletion for a defined retention period. This directly satisfies the litigation hold's requirement that data remain immutable until the hold is formally released, independent of user permissions.

Why this answer

Object Lock is the S3-compatible feature that enforces WORM (Write Once, Read Many) protection by applying a retention policy (governance or compliance mode) or a legal hold to objects. When a retention period or legal hold is in place, the object cannot be overwritten or deleted by any user, including the root account, until the hold is released. This directly satisfies the litigation hold requirement to preserve data in an immutable state.

Exam trap

CCSP often tests the misconception that versioning or encryption provides immutability; candidates must recognize that only Object Lock (WORM) enforces non-modification and non-deletion for litigation holds.

How to eliminate wrong answers

Option B is wrong because lifecycle policies only move or expire objects (e.g., transition to Glacier or delete after N days) and do not prevent modification or deletion; in fact, a lifecycle rule could delete the very data under hold. Option C is wrong because versioning only preserves prior versions of an object — a user can still delete the current version or overwrite it, and without Object Lock a delete marker can be placed, so it does not guarantee immutability. Option D is wrong because server-side encryption protects confidentiality of data at rest but does nothing to prevent an authorized user from modifying or deleting the object.

865
MCQmedium

A security architect is designing a multi-cloud data protection strategy. They need to give a third-party auditor time-limited, read-only access to a specific file in a cloud storage bucket. Which access control method is most appropriate?

A.Cloud VPN connection for the auditor
B.Bucket ACL granting read access to the auditor's cloud account
C.IAM policy granting read access to the auditor's user
D.Pre-signed URL with an expiration time
AnswerD

A pre-signed URL embeds temporary credentials and an expiry directly into the link, granting read-only access to one specific object without creating an identity or sharing bucket keys. This satisfies the auditor's time-limited, single-file requirement, unlike broader role-based or bucket-level permissions.

Why this answer

A pre-signed URL is a time-limited, cryptographically signed URL that grants temporary access to a specific object without requiring the auditor to have an identity in the cloud provider's IAM system. It is generated by a principal with permission to the object and embeds an expiration timestamp and signature, making it ideal for granting an external third party scoped, read-only, time-bound access to a single file. This satisfies least privilege and avoids creating persistent identities or network paths.

Exam trap

The trap is confusing network-level access (VPN) or identity-level access (IAM/ACL) with object-level temporary delegation; candidates often pick IAM because it sounds most 'secure,' missing that pre-signed URLs are the canonical least-privilege answer for third-party single-object access.

How to eliminate wrong answers

Option A is wrong because a Cloud VPN connection grants network-level access to the VPC, not object-level access to a specific file, and it is heavyweight and persistent rather than time-limited. Option B is wrong because a bucket ACL granting read to the auditor's cloud account gives access to the entire bucket, not a single file, and persists until explicitly revoked. Option C is wrong because an IAM policy granting read to the auditor's user requires creating or federating an identity in your cloud account, which is more complex and broader than necessary for a one-off audit.

866
Multi-Selectmedium

A cloud operations team is implementing a disaster recovery plan. Which of the following are valid strategies for data replication in a cloud environment? (Choose three.)

Select 3 answers
A.Asynchronous replication across regions
B.Synchronous replication within the same region
C.Periodic snapshots to object storage
D.Replication via cloud provider's managed replication service
E.Active-active replication with load balancing
AnswersA, B, D

Asynchronous replication handles geographic distance with eventual consistency.

Why this answer

Asynchronous replication across regions is a valid DR strategy because it allows data to be copied to a geographically distant region without requiring an immediate acknowledgment from the target, which minimizes latency impact on the primary site. This approach is suitable for cloud environments where recovery point objectives (RPOs) of minutes to hours are acceptable, and it leverages the cloud provider's high-latency inter-region network links without stalling write operations.

Exam trap

ISC2 often tests the distinction between replication (continuous data copying) and backup (point-in-time snapshots), so candidates mistakenly select periodic snapshots as a replication strategy when it is actually a backup method.

867
MCQmedium

During a cloud migration, a company discovers that data stored in a specific region must remain there per contract. The cloud provider offers data replication across regions. What is the best practice to ensure compliance?

A.Use data residency controls provided by the cloud provider
B.Negotiate a new contract to allow replication
C.Disable all data replication features
D.Encrypt data before storing it
AnswerA

Data residency controls pin storage and replication to the contracted region, preventing the provider's cross-region replication from moving data outside its required jurisdiction. This directly satisfies the contractual constraint that data must remain in a specific region.

Why this answer

Data residency controls (such as AWS SCPs, Azure Policy, or GCP Organization Policies with location constraints) are the cloud-native mechanism designed to enforce where data can be stored and replicated. They provide policy-based guardrails that prevent replication to unauthorized regions, satisfying the contractual requirement without disabling legitimate functionality. This is the standard best practice because it enforces compliance at the platform level rather than relying on manual processes.

Exam trap

The trap here is confusing data protection (encryption) with data location control — candidates often pick encryption because it sounds like a compliance measure, but residency is about where data lives, not how it's protected.

How to eliminate wrong answers

Option B is wrong because renegotiating the contract changes the business requirement rather than solving the technical compliance problem, and it may not be feasible or desirable. Option C is wrong because disabling all replication is overly broad — it may break availability, DR, and backup strategies that are contractually required, and it doesn't selectively enforce residency. Option D is wrong because encryption protects confidentiality of data in transit or at rest but does nothing to prevent data from being physically stored or replicated in a non-compliant region.

868
MCQmedium

A security architect is designing a VPC for a three-tier web application. Which of the following VPC subnet designs provides the most secure isolation for the database tier?

A.Database tier in a private subnet with security group allowing only the application tier
B.Database tier in a separate VPC with VPC peering
C.Database tier in a public subnet with security group allowing only the application tier
D.Database tier in the same subnet as the application tier
AnswerA

Placing the database tier in a private subnet removes any route to the internet, and a security group permitting only the application tier enforces least-privilege, tier-to-tier access. This satisfies the isolation requirement by ensuring no other subnet or external source can reach the database.

Why this answer

Placing the database tier in a private subnet with a security group that only allows traffic from the application tier's security group enforces both network-layer isolation (no route to the internet) and identity-based access control (SG-to-SG referencing). This is the AWS-recommended pattern for three-tier architectures because it minimizes the attack surface and prevents lateral movement from compromised web-tier instances. The database has no public IP and no route to an internet gateway, so it cannot be reached directly from outside the VPC.

Exam trap

CCSP often tests the misconception that VPC peering or public subnets with tight security groups provide equivalent isolation, when subnet-level private placement plus SG chaining is the canonical secure design.

How to eliminate wrong answers

Option B is wrong because a separate VPC with peering adds operational complexity and still requires security groups/NACLs to restrict access — peering alone does not provide more isolation than a properly configured private subnet, and it can widen the blast radius if peering routes are misconfigured. Option C is wrong because a public subnet exposes the database to internet-routable addressing, and a security group alone is a weaker control than subnet-level isolation. Option D is wrong because co-locating the database with the application tier removes network segmentation entirely, allowing any compromised app instance to reach the database directly.

869
MCQeasy

A cloud security engineer reviews this Terraform configuration for a security group. Which change is necessary to improve security?

A.Use a broader CIDR for ingress.
B.Restrict egress to specific ports.
C.Change protocol to UDP.
D.Remove the ingress rule.
AnswerB

Default security groups permit all outbound traffic, so an attacker with a foothold can exfiltrate data or reach command-and-control hosts on any port. Narrowing egress to only the ports the workload genuinely requires enforces least privilege outbound, directly satisfying the stem's demand to improve the configuration's security posture.

Why this answer

The default egress rule in Terraform's AWS security group allows all outbound traffic (0.0.0.0/0, all ports, all protocols). This violates the principle of least privilege. Restricting egress to only specific ports and protocols (e.g., TCP/443 for HTTPS) reduces the attack surface and prevents data exfiltration or unintended outbound connections.

Exam trap

Candidates often focus solely on ingress rules in security groups, neglecting the security risk of overly permissive egress rules, which can lead to data exfiltration.

How to eliminate wrong answers

Option A is wrong because using a broader CIDR (e.g., 0.0.0.0/0) for ingress would increase the attack surface, allowing traffic from any IP address, which is less secure. Option C is wrong because changing the protocol to UDP does not inherently improve security; UDP is connectionless and can be used for attacks like amplification, and the protocol choice should be based on application requirements, not security generalization. Option D is wrong because removing the ingress rule entirely would block all inbound traffic, which may break legitimate application functionality; the issue is with overly permissive egress, not ingress.

870
MCQeasy

What is a Software Bill of Materials (SBOM) primarily used for?

A.Documenting all open-source and third-party components in an application
B.Tracking user access to cloud resources
C.Recording incident response procedures
D.Listing security controls implemented in the cloud environment
AnswerA

An SBOM enumerates every open-source and third-party component and version inside an application, giving visibility into the software supply chain. That inventory lets teams identify affected components quickly when a vulnerability such as Log4Shell is disclosed.

Why this answer

An SBOM is a formal, machine-readable inventory of all software components, libraries, and dependencies that make up an application, with particular emphasis on open-source and third-party elements. It exists so organizations can quickly identify whether a newly disclosed CVE affects any component in their supply chain, which is why SBOMs became a mandate under US Executive Order 14028 and are central to supply chain risk management in cloud environments.

Exam trap

CCSP often tests whether candidates confuse an SBOM (a component inventory for supply chain risk) with IAM logs, IR runbooks, or control frameworks, so the trap is picking any option that sounds like 'documentation' without matching the specific purpose of software composition transparency.

How to eliminate wrong answers

Option B is wrong because tracking user access to cloud resources is the function of IAM policies, access logs, and CloudTrail/Activity Logs, not an SBOM. Option C is wrong because incident response procedures are documented in runbooks and IR playbooks, which describe human actions during a breach rather than software composition. Option D is wrong because listing implemented security controls is the purpose of a control matrix or compliance framework mapping (e.g., SOC 2, ISO 27001), not an SBOM, which inventories components rather than controls.

871
MCQmedium

A security architect is designing a CI/CD pipeline for a cloud-native application. The team wants to automatically scan container images for vulnerabilities before deployment. Which of the following is the most effective approach?

A.Manually review images before each deployment
B.Integrate a container image scanner into the pipeline
C.Perform vulnerability scanning at runtime using a host-based agent
D.Scan the network for open ports on the container hosts
AnswerB

Embedding a container image scanner as a pipeline stage inspects each built image for known CVEs before deployment, failing the build on policy violations. This shifts detection left, blocking vulnerable images from reaching the cluster rather than scanning after release.

Why this answer

Integrating a container image scanner into the CI/CD pipeline ensures that vulnerabilities are detected early, before the image is deployed to production. This approach automates security checks as part of the build process, aligning with DevSecOps principles by shifting security left. Tools like Trivy, Clair, or Anchore can be configured to fail the pipeline if critical vulnerabilities are found, preventing insecure images from reaching runtime.

Exam trap

The trap here is that candidates confuse runtime host-based scanning (Option C) with image scanning, but the question specifically asks for scanning before deployment, making pipeline integration the only correct choice that enforces security gates early in the lifecycle.

How to eliminate wrong answers

Option A is wrong because manual review is not scalable, error-prone, and cannot keep pace with the frequency of deployments in a CI/CD pipeline, violating the automation principle of secure DevOps. Option C is wrong because runtime scanning with a host-based agent detects vulnerabilities only after the container is already running, missing the opportunity to block deployment of vulnerable images and potentially exposing the environment to exploitation. Option D is wrong because scanning the network for open ports on container hosts addresses network-level exposure, not the vulnerabilities within the container image itself, and is a reactive measure unrelated to image security.

872
MCQeasy

A startup is deploying a new web application and wants to avoid managing servers, operating systems, or runtime updates. The developers only want to upload code and have the provider handle scaling, patching, and availability. They do not need control over the underlying infrastructure. Which cloud service model is MOST appropriate?

A.DaaS
B.IaaS
C.SaaS
D.PaaS
AnswerD

PaaS lets developers deploy code while the provider manages the underlying servers, operating systems, runtime, scaling, and patching. This matches the startup's requirement to avoid infrastructure management and focus only on application code, making it the most appropriate service model for the described workload.

Why this answer

PaaS abstracts the infrastructure and runtime so developers can focus on code while the provider handles patching, scaling, and availability. Because the startup does not want to manage servers, operating systems, or runtime updates, PaaS aligns directly with its operational and development needs.

Exam trap

The trap here is confusing PaaS with SaaS, since both reduce management burden, but only PaaS lets the organization deploy its own custom application code.

873
Multi-Selecthard

A cloud data architect is designing a tokenization solution for a payment processing platform hosted in a public cloud. The platform must store primary account numbers (PANs) while minimizing PCI DSS scope and preventing raw PAN exposure in application logs and analytics pipelines. Which TWO design elements are most critical to achieve these goals? (Choose two.)

Select 2 answers
A.Use a format-preserving token that replaces the PAN with a value of similar length and character set, stored in a separate token vault with strict access controls.
B.Apply the tokenization at the point of data capture, before the PAN enters application logs, message queues, or analytics pipelines.
C.Ensure the tokenization service is deployed in the same network subnet as the analytics platform to reduce latency for token lookups.
D.Use reversible encryption with a shared symmetric key for the PAN and store the key in the application configuration file for operational simplicity.
E.Store the token-to-PAN mapping in the same database as the tokenized transaction records to simplify joins and reporting.
AnswersA, B

A format-preserving token maintains the data format so existing applications and databases can process it without schema changes, while the token vault isolates the mapping to the original PAN. Strict access controls on the vault limit exposure and reduce PCI DSS scope because most systems handle only tokens. This design directly minimizes raw PAN propagation into logs and analytics.

Why this answer

Tokenization at the point of capture and a format-preserving token stored in an isolated vault are the two critical elements. Early tokenization keeps raw PANs out of logs, queues, and analytics, while format preservation allows existing systems to process tokens without redesign. The vault separation ensures that even if downstream systems are compromised, the original PANs remain protected.

Exam trap

The trap here is treating tokenization as simply encrypting data, when the essential design is early substitution plus isolation of the token-to-PAN mapping from the systems that process tokens.

874
MCQmedium

A cloud architect is designing a data classification scheme for a SaaS provider. The provider handles customer data that includes public marketing materials, internal policies, and sensitive customer financial records. Which classification level should be assigned to customer financial records to enforce the highest level of protection?

A.Internal
B.Public
C.Restricted
D.Confidential
AnswerC

Restricted is the highest classification tier, reserved for data whose disclosure causes severe harm, such as customer financial records. Assigning it satisfies the stem's requirement to enforce the strongest protection, exceeding Confidential or Internal levels used for policies and marketing material.

Why this answer

Customer financial records represent the most sensitive data class in the scenario, requiring the highest protection tier, which is Restricted. Restricted classification enforces strict access controls, encryption, and monitoring appropriate for regulated financial data. Since the question explicitly asks for the highest level of protection, Restricted is the correct mapping.

Exam trap

CCSP often tests the tier hierarchy by presenting Confidential as a plausible 'high' answer, trapping candidates who forget that Restricted is the top classification for regulated, severe-impact data.

How to eliminate wrong answers

Option A is wrong because Internal is a low-sensitivity label for data not intended for public release but not requiring strong protection, far below financial records. Option B is wrong because Public data is deliberately open and requires no confidentiality controls. Option D is wrong because Confidential is a mid-to-high tier that covers sensitive business data but is not the top classification; the question demands the highest protection level, which is Restricted.

875
MCQmedium

A financial services company is migrating its legacy on-premises application to a public cloud IaaS environment. The application currently uses a shared file system that requires strong consistency and low-latency access for transaction processing. The cloud architect must choose a storage solution that meets these performance requirements. Which cloud storage type is MOST appropriate?

A.Object storage
B.Block storage
C.File storage
D.Archive storage
AnswerC

File storage, often provided as a managed Network File System (NFS) service in the cloud, supports shared access from multiple instances and can provide strong consistency and low latency when provisioned with appropriate performance tiers. It is designed for file-based workloads that require concurrent access, making it suitable for a shared file system used by transaction processing applications.

Why this answer

The application requires a shared file system with strong consistency and low latency. Cloud file storage services, such as Amazon EFS or Azure Files, provide shared NFS or SMB access with configurable performance and strong consistency. Block storage is not inherently shared, object storage is not low-latency or strongly consistent, and archive storage is for cold data.

Therefore, file storage is the most appropriate choice.

Exam trap

The trap here is assuming that block storage is always the best for performance, but block storage is not designed for shared access. File storage is the correct choice when multiple instances need concurrent access to the same file system with strong consistency.

876
MCQhard

A security architect is designing a cloud-native application using microservices. They decide to implement mutual TLS (mTLS) for service-to-service communication in a Kubernetes cluster with hundreds of services. What is the primary challenge in managing mTLS certificates in this dynamic environment?

A.High latency due to encryption overhead
B.Certificate revocation and rotation
C.Incompatibility with HTTP/2
D.Increased complexity in load balancer configuration
AnswerB

Hundreds of short-lived pods mean certificates expire and rotate constantly, so revocation and rotation at scale becomes the operational bottleneck. Manual or static PKI cannot track ephemeral workload identities, making automated issuance and revocation the primary management challenge in this dynamic Kubernetes environment.

Why this answer

In a dynamic Kubernetes environment with hundreds of microservices, mTLS certificates must be frequently rotated and revoked to maintain security, especially as services scale up/down and pods are replaced. Manual certificate management is impractical, so automated solutions like SPIFFE/SPIRE or Istio’s Citadel are required to handle the lifecycle at scale. The primary challenge is not the encryption overhead but the operational complexity of ensuring every service has a valid, non-expired certificate and that compromised certificates can be promptly revoked across the mesh.

Exam trap

The trap here is that candidates confuse the operational challenge of certificate lifecycle management with perceived performance issues (latency) or compatibility concerns, when in fact mTLS is designed to work efficiently with modern protocols and the real difficulty is maintaining trust in a rapidly changing service mesh.

How to eliminate wrong answers

Option A is wrong because mTLS encryption overhead is minimal with modern hardware and optimized libraries (e.g., AES-NI, TLS 1.3), and latency is not the primary challenge in a dynamic environment. Option C is wrong because mTLS is fully compatible with HTTP/2; in fact, gRPC (which uses HTTP/2) commonly relies on mTLS for secure service-to-service communication. Option D is wrong because mTLS does not inherently increase load balancer configuration complexity; load balancers can terminate or pass-through mTLS, and the challenge lies in certificate lifecycle management, not load balancer setup.

877
MCQhard

A financial services company stores regulated data in Amazon S3 and must prove to auditors that objects cannot be deleted or overwritten for seven years, even by a compromised root account. The security team needs the strongest native control that preserves the data for the retention period. Which S3 feature should they enable?

A.S3 Cross-Region Replication to a second bucket
B.S3 Object Lock in compliance mode
C.Bucket policies that deny s3:DeleteObject to all principals
D.S3 Versioning with a lifecycle rule to transition objects to S3 Glacier Deep Archive
AnswerB

S3 Object Lock in compliance mode prevents any user, including the root account, from overwriting or deleting a protected object version until the retention date passes. This is the strongest native immutability control in S3 and directly satisfies the seven-year retention requirement for regulated data.

Why this answer

S3 Object Lock in compliance mode enforces a write-once-read-many retention that no principal, including the account root, can shorten or remove before the retention date. Versioning and replication improve durability and recoverability but remain mutable by privileged users, so only compliance-mode Object Lock satisfies the immutability proof the auditors demand.

Exam trap

The trap here is treating replication or versioning as equivalent to immutability, when only Object Lock in compliance mode resists even root-level deletion.

878
MCQhard

A financial services firm runs regulated workloads on Microsoft Azure. Auditors require that disk encryption keys for IaaS virtual machines remain under the firm's exclusive control, that the keys never leave a hardware security module, and that the firm can revoke access to the keys at any time, rendering the disks unreadable. The firm does not want Microsoft to be able to decrypt the disks without an explicit grant. Which Azure disk encryption configuration meets these requirements?

A.Azure Disk Encryption with BitLocker keys wrapped by a customer key held in Azure Key Vault Managed HSM
B.Server-side encryption with customer-managed keys stored in Azure Key Vault, using software-protected keys
C.Azure Storage Service Encryption with infrastructure encryption enabled on the managed disks
D.Azure Disk Encryption with BitLocker keys stored in an Azure Key Vault that uses platform-managed keys
AnswerA

Azure Key Vault Managed HSM provides a single-tenant, FIPS 140-2 Level 3 validated hardware security module where the customer's key material never leaves the HSM boundary. Azure Disk Encryption uses BitLocker for Windows or dm-crypt for Linux and wraps the volume keys with the customer's key-encryption key. Revoking or disabling that key makes the disks unreadable, and Microsoft cannot decrypt without an explicit grant, satisfying every stated requirement.

Why this answer

The auditors require customer-exclusive key custody in a hardware security module plus the ability to revoke access and render disks unreadable. Azure Key Vault Managed HSM supplies single-tenant, hardware-backed key storage, and Azure Disk Encryption wraps the volume keys with a customer key from that HSM. Disabling or revoking the key-encryption key effectively crypto-shreds the disks, which platform-managed or software-protected keys cannot achieve.

Exam trap

The trap here is treating any customer-managed key as equivalent to a hardware security module-backed key, when software-protected keys do not meet a strict HSM custody requirement.

879
MCQhard

A company uses a cloud-based intrusion detection system (IDS) that generates logs containing IP addresses. The company is headquartered in a country with data localization laws. What is the primary compliance risk?

A.The logs may be tampered with in transit
B.The IDS logs consume too much storage
C.Log data containing personal data may be processed in a different jurisdiction
D.The IDS may miss certain attack patterns
AnswerC

IDS logs containing IP addresses constitute personal data, so processing them in a cloud region outside the headquarters' jurisdiction breaches data localisation requirements. This cross-border transfer is the primary compliance risk the stem's localisation laws create.

Why this answer

The primary compliance risk is that log data containing personal data (such as IP addresses, which can be considered personal data under GDPR and other laws) may be processed in a different jurisdiction. Data localization laws require that certain data be stored and processed within the country's borders. If the cloud-based IDS processes logs outside the country, it could violate these laws.

Exam trap

The trap here is confusing security risks (like tampering) with compliance risks. Candidates might focus on the technical aspects of IDS logs rather than the legal implications of cross-border data processing.

How to eliminate wrong answers

Option A is wrong because tampering in transit is a security risk, not a compliance risk related to data localization. Option B is wrong because storage consumption is an operational concern, not a compliance risk. Option D is wrong because missing attack patterns is a security effectiveness issue, not a compliance risk.

880
MCQhard

During a security audit, it is discovered that a cloud service provider's infrastructure-as-a-service (IaaS) environment has virtual machines that were provisioned with default firewall rules allowing all inbound traffic from the internet. The organization's cloud security policy requires that all VM firewall rules follow a least-privilege model. What is the most effective approach to enforce this policy going forward?

A.Manually review each VM's firewall rules during deployment
B.Use a configuration management tool to periodically audit and correct firewall rules
C.Implement infrastructure as code templates with built-in security controls that enforce least-privilege firewall rules
D.Use a cloud security posture management (CSPM) tool that continuously monitors and alerts on non-compliant rules
AnswerC

Infrastructure as code templates embed least-privilege firewall rules directly into the provisioning definition, so every VM is created with restrictive inbound rules rather than permissive defaults. This enforces the policy at deployment time, preventing configuration drift and removing reliance on manual post-provisioning remediation, which satisfies the least-privilege requirement going forward.

Why this answer

Infrastructure as code (IaC) templates with built-in security controls enforce least-privilege firewall rules at provisioning time, preventing non-compliant VMs from ever being created. This shifts security left, making the secure configuration the default and removing reliance on manual review or after-the-fact detection. It is the most effective preventive control for enforcing policy going forward.

Exam trap

CCSP often tests the difference between preventive, detective, and corrective controls — candidates pick monitoring tools (CSPM) because they sound comprehensive, but the question asks for the most effective enforcement going forward, which requires prevention.

How to eliminate wrong answers

Option A is wrong because manual review is error-prone, does not scale, and is a detective rather than preventive control — it cannot guarantee enforcement. Option B is wrong because periodic auditing and correction is reactive; non-compliant VMs exist and are exposed until the next audit cycle. Option D is wrong because CSPM tools monitor and alert but do not prevent the misconfiguration from being deployed, so the exposure window remains.

881
Multi-Selectmedium

A cloud security auditor is reviewing container runtime configurations. Which TWO practices help prevent a container from compromising the host operating system?

Select 2 answers
A.Using a read-only root filesystem
B.Disabling SELinux inside the container
C.Running containers in privileged mode
D.Dropping all Linux capabilities
E.Mapping the host's Docker socket into the container
AnswersA, D

A read-only root filesystem prevents processes inside the container from writing to or modifying the underlying host-mounted filesystem, blocking a common container-to-host compromise path. It satisfies the requirement to stop containers compromising the host operating system.

Why this answer

Option A, using a read-only root filesystem, is correct because it prevents a compromised container process from writing malicious files, modifying binaries, or persisting changes to the container's filesystem, which limits the ability to tamper with the host through mounted volumes or writable layers. Option D, dropping all Linux capabilities, is correct because Linux capabilities grant fine-grained kernel privileges (e.g., CAP_SYS_ADMIN, CAP_NET_ADMIN); dropping all of them removes the ability to perform privileged operations like mounting filesystems, loading kernel modules, or manipulating network stacks that could be leveraged to escape the container and affect the host. Option B is wrong because disabling SELinux removes a mandatory access control layer that confines container processes, weakening host protection rather than strengthening it.

Option C is wrong because privileged mode gives the container nearly all host capabilities and device access, dramatically increasing the risk of host compromise. Option E is wrong because mapping the host's Docker socket into a container effectively grants control over the Docker daemon, allowing the container to launch privileged containers or access the host, which is a well-known container escape vector.

882
Multi-Selecthard

Which THREE of the following are key components of a secure cloud SDLC that support shift-left security? (Select THREE)

Select 3 answers
A.Post-deployment penetration testing
B.Infrastructure as Code (IaC) security scanning
C.Annual security awareness training
D.Threat modeling during the design phase
E.Automated SAST and DAST in the CI/CD pipeline
AnswersB, D, E

IaC scanning inspects Terraform, CloudFormation and similar templates for misconfigurations before deployment, embedding security checks in the earliest pipeline stages. This directly satisfies the shift-left requirement by catching flaws at code authoring rather than runtime.

Why this answer

Option B is correct because IaC security scanning (e.g., tools like Checkov, tfsec, or KICS) detects misconfigurations in Terraform, CloudFormation, or ARM templates before resources are provisioned, embedding security controls early in the development lifecycle as shift-left demands. Option D is correct because threat modeling during the design phase (using frameworks such as STRIDE or PASTA) identifies architectural weaknesses and attack surfaces before any code is written, which is the earliest possible point to remediate design-level risks. Option E is correct because automated SAST and DAST integrated into the CI/CD pipeline (e.g., SonarQube, Checkmarx, OWASP ZAP) continuously analyze source code and running applications on every build, providing fast feedback to developers rather than waiting for release.

Option A does not belong because post-deployment penetration testing occurs after the application is live, which is a reactive, right-side activity rather than shift-left. Option C does not belong because annual security awareness training is a periodic, organization-wide control that is not a technical component of the cloud SDLC pipeline and does not provide continuous, code-level security feedback.

Exam trap

The CCSP exam often tests the distinction between 'shift-left' (pre-deployment) and 'shift-right' (post-deployment) activities, so candidates mistakenly select post-deployment penetration testing (A) because they think all security testing is shift-left, but the key is that shift-left specifically means moving security earlier in the lifecycle, not after deployment.

883
Multi-Selecthard

A multinational corporation is implementing a multi-cloud strategy to avoid concentration risk. The risk management team is evaluating the inherent risks of using multiple cloud providers. Which THREE risks are specifically associated with a multi-cloud strategy? (Choose three.)

Select 3 answers
A.Higher likelihood of vendor lock-in due to proprietary services
B.Expanded attack surface due to more entry points and APIs
C.Increased complexity in managing consistent security policies across providers
D.Greater difficulty in meeting data sovereignty requirements across jurisdictions
E.Need for specialized skills and expertise for each cloud platform
AnswersB, C, E

Each additional provider introduces its own public endpoints, management APIs and identity planes, multiplying the number of exploitable entry points an attacker can target. This directly reflects the expanded attack surface inherent to spanning multiple cloud environments.

Why this answer

Option B is correct because a multi-cloud strategy adds more entry points and APIs, since each provider exposes its own management consoles, IAM endpoints, and service APIs, expanding the attack surface that must be monitored and secured. Option C is correct because consistent security policies must be enforced across heterogeneous providers with different native controls, identity models, and configuration semantics, making uniform governance and compliance far more complex. Option E is correct because each cloud platform has its own tooling, services, and operational model, so the organization needs specialized skills and expertise for each provider rather than a single unified skill set.

Option A is not correct because multi-cloud generally reduces vendor lock-in rather than increasing it, since workloads can be distributed and portability is improved. Option D is not correct because data sovereignty challenges stem from where data is stored and processed across jurisdictions, which is not inherently a risk specific to using multiple cloud providers.

Exam trap

The trap is confusing single-cloud risks (lock-in, sovereignty) with multi-cloud-specific risks; candidates must distinguish risks that are amplified or introduced by using multiple providers from those that exist regardless.

884
MCQmedium

A cloud team is integrating a third-party analytics service into its application. The vendor requires access to data in the organization's object storage bucket. Security policy forbids sharing long-lived cloud credentials with third parties. Which approach best satisfies the policy while granting the vendor the required access?

A.Create an IAM user for the vendor and issue an access key, then rotate the key every 90 days through a documented process.
B.Generate a pre-signed URL for the bucket with a long expiration and send it to the vendor so they can retrieve the objects.
C.Configure a cross-account IAM role in the organization's account that trusts the vendor's account, and have the vendor assume it to obtain temporary credentials scoped to the bucket.
D.Enable public read access on the bucket and rely on the vendor's network allowlist to restrict who can retrieve the objects.
AnswerC

Cross-account role assumption lets the vendor's principals obtain short-lived credentials through STS, with permissions limited to the bucket and actions required. No long-lived secret is shared, the trust relationship can be revoked centrally, and every assumption is logged. This aligns with the policy and with least privilege for third-party access.

Why this answer

The policy requires that third parties never hold long-lived cloud credentials. Cross-account role assumption issues temporary, scoped credentials through the cloud provider's token service, so the vendor authenticates to its own identity and receives access only to the designated bucket. Access keys, long-lived pre-signed URLs, and public buckets all create durable or unauthenticated access paths that the policy prohibits.

Exam trap

The trap here is treating credential rotation or a long-lived pre-signed URL as equivalent to eliminating shared long-lived credentials.

885
MCQmedium

Which of the following is a key consideration when evaluating a cloud service provider's ability to meet compliance requirements for data sovereignty?

A.The provider's support tier
B.The provider's data center locations and geographic restrictions
C.The provider's penetration testing policy
D.The provider's SOC 2 Type II report
AnswerB

Data sovereignty depends on where data physically resides and which jurisdictions govern it. A provider's data centre locations and geographic restrictions determine whether residency obligations can actually be met, making this the decisive compliance consideration.

Why this answer

Data sovereignty requires that data remains subject to the laws of the country where it is stored or processed. Therefore, the provider's data center locations and any geographic restrictions on where data can be stored, processed, or replicated are the primary considerations. This directly determines which legal jurisdictions can claim authority over the data.

Exam trap

CCSP often tests the confusion between data residency (physical location) and data sovereignty (legal jurisdiction), so candidates pick SOC 2 or support tier thinking it covers compliance, when the question specifically asks about geographic restrictions.

How to eliminate wrong answers

Option A is wrong because support tier affects service responsiveness, not legal jurisdiction over data. Option C is wrong because penetration testing policy addresses security assurance, not where data resides or which laws apply. Option D is wrong because a SOC 2 Type II report attests to security controls over time but does not address geographic data residency or sovereignty requirements.

886
MCQmedium

A cloud service provider (CSP) offers a shared infrastructure where multiple customers' virtual machines run on the same physical host but are isolated by the hypervisor. Which cloud deployment model does this represent?

A.Hybrid cloud
B.Private cloud
C.Public cloud
D.Community cloud
AnswerC

Public cloud matches because the CSP owns the shared infrastructure and serves multiple tenants from one pooled environment. Hypervisor-level isolation between customers' virtual machines on the same physical host is the defining multi-tenancy mechanism of the public deployment model, satisfying the stem's shared-host, provider-operated constraint.

Why this answer

The scenario describes a public cloud deployment model, where a CSP owns and operates the infrastructure and offers services to multiple customers (tenants) over the internet. The key characteristic is multi-tenancy: multiple customers' virtual machines share the same physical host but are logically isolated by the hypervisor. This is the defining trait of a public cloud, as opposed to private, hybrid, or community clouds, which have different ownership and access boundaries.

Exam trap

CCSP often tests the misconception that any shared infrastructure implies a community cloud, but the key differentiator is whether the tenants are a specific group with common interests (community) or the general public (public).

How to eliminate wrong answers

Option A is wrong because a hybrid cloud combines two or more distinct deployment models (e.g., public and private) with technology enabling data and application portability; the scenario describes a single shared infrastructure, not a combination. Option B is wrong because a private cloud is provisioned for exclusive use by a single organization, not multiple customers on shared hardware. Option D is wrong because a community cloud is shared by several organizations with common concerns (e.g., same compliance requirements), but the scenario explicitly states 'multiple customers' without any shared community purpose, and the CSP offers it to the general public.

887
MCQmedium

A container image is built and scanned in a CI pipeline. Which practice should be implemented to ensure that the image has not been tampered with before deployment?

A.Using a minimal base image
B.Scanning the image with a vulnerability scanner
C.Signing the image with a private key and verifying the signature
D.Storing the image in a private registry
AnswerC

Signing the image with a private key and verifying that signature at deployment proves integrity and origin, detecting any tampering after the CI scan. This satisfies the stem's requirement that the image remains unmodified between build and deployment.

Why this answer

Signing the image with a private key and verifying the signature before deployment provides cryptographic assurance of integrity and authenticity. The signature proves the image was produced by a trusted builder and has not been altered since signing. This directly addresses tampering, which scanning and registry controls do not detect after the fact.

Exam trap

CCSP often tests the distinction between integrity verification (signing) and vulnerability detection (scanning), causing candidates to choose scanning when the question specifically asks about tampering.

How to eliminate wrong answers

Option A is wrong because a minimal base image reduces attack surface but does nothing to detect tampering after the build. Option B is wrong because vulnerability scanning identifies known CVEs in packages, not unauthorized modifications to the image layers. Option D is wrong because a private registry controls access and distribution but does not cryptographically verify that the image content matches what was originally built.

888
MCQmedium

A company is using a single cloud provider for all critical services. What is the primary risk this company faces?

A.Data sovereignty risk
B.Compliance risk
C.Insider threat risk
D.Concentration risk
AnswerD

Relying on a single cloud provider creates concentration risk: an outage, breach, or provider failure disrupts all critical services simultaneously, with no failover path. This dependency, rather than portability or lock-in alone, is the primary risk.

Why this answer

Concentration risk is the risk that reliance on a single provider, vendor, region, or service creates a single point of failure — an outage, bankruptcy, or contractual dispute with that provider can disrupt all critical services simultaneously. Using one cloud provider for all critical services is the textbook definition of concentration risk in cloud governance.

Exam trap

The trap is selecting a risk that sounds severe (sovereignty, compliance) when the question specifically describes reliance on a single provider — the key signal is 'single' or 'all critical services,' which maps to concentration risk.

How to eliminate wrong answers

Option A is wrong because data sovereignty risk relates to where data is stored and which laws apply, not to the number of providers; a single provider can still host data in compliant jurisdictions. Option B is wrong because compliance risk depends on whether the provider and configuration meet regulatory requirements, which is independent of provider count. Option C is wrong because insider threat risk exists in any environment, single or multi-cloud, and is not specifically caused by using one provider.

889
MCQmedium

A healthcare provider is planning to migrate its electronic health records (EHR) system to a public cloud infrastructure. The system will store protected health information (PHI). Under HIPAA, what must the healthcare provider obtain from the cloud service provider before beginning the migration?

A.A Business Associate Agreement (BAA) that outlines the permitted uses of PHI and the security safeguards in place
B.A signed letter of attestation that the cloud provider is HIPAA-compliant
C.A Data Processing Agreement (DPA) as defined under GDPR
D.A Service Organization Control (SOC) 2 Type II report
AnswerA

HIPAA requires a Business Associate Agreement before a covered entity shares PHI with a business associate such as a cloud provider. The BAA contractually binds permitted uses and required safeguards, satisfying the pre-migration obligation the stem describes.

Why this answer

Under HIPAA, a covered entity must enter into a Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits protected health information on its behalf. A cloud provider hosting an EHR system is a business associate, so a BAA is legally required before PHI can be migrated to the cloud.

Exam trap

CCSP often tests whether candidates confuse a BAA with a DPA or SOC 2 report — only the BAA is the legally required HIPAA contract with a cloud provider handling PHI.

How to eliminate wrong answers

Option B is wrong because a letter of attestation is not a recognized HIPAA legal instrument — only a BAA establishes the required contractual obligations and safeguards. Option C is wrong because a GDPR Data Processing Agreement addresses EU data protection law, not HIPAA, and does not satisfy HIPAA's business associate requirements. Option D is wrong because a SOC 2 Type II report is an audit attestation of controls, not a contract — it can support due diligence but does not replace the BAA.

890
Multi-Selectmedium

A security architect is designing a logging strategy for a multi-cloud environment using AWS and Azure. Which TWO practices should be implemented to ensure log integrity and prevent tampering? (Choose two.)

Select 2 answers
A.Store logs in a publicly readable S3 bucket for transparency
B.Encrypt logs using server-side encryption with AWS KMS
C.Enable CloudTrail log file validation
D.Use S3 Object Lock or Azure Immutable Blob Storage
E.Enable cross-region replication for logs
AnswersC, D

CloudTrail log file validation generates digest files containing hashes of each delivered log, enabling detection of any post-delivery alteration or deletion. This satisfies the log-integrity requirement by cryptographically proving AWS API activity records were not tampered with before forensic review.

Why this answer

Option C is correct because CloudTrail log file validation generates a digitally signed digest file for each log file, allowing you to verify that logs have not been altered or deleted after delivery. Option D is correct because S3 Object Lock (in compliance or governance mode) and Azure Immutable Blob Storage enforce WORM (write once, read many) policies, preventing logs from being modified or deleted during a retention period. Option A is wrong because a publicly readable S3 bucket exposes logs to unauthorized access and tampering, undermining integrity.

Option B is wrong because KMS server-side encryption protects confidentiality at rest but does not prevent an authorized user or attacker with write permissions from altering or deleting log objects. Option E is wrong because cross-region replication improves durability and availability but does not prevent tampering with the source or replicated logs.

Exam trap

The trap is confusing encryption or replication with integrity — candidates must recognize that only cryptographic validation (detection) plus immutability (prevention) actually stop tampering.

891
Multi-Selecthard

An organization is migrating a legacy application to the cloud and wants to maximize elasticity. Which THREE characteristics should the application support to benefit from cloud elasticity?

Select 3 answers
A.Distributed architecture
B.Monolithic architecture
C.Horizontal scaling support
D.Stateless design
E.Vertical scaling capability
AnswersA, C, D

A distributed architecture spreads workload across multiple independent components, so additional instances can be added or removed horizontally as demand changes. This stateless, loosely coupled design lets the application scale out and in automatically, which is the prerequisite for realising cloud elasticity.

Why this answer

Option A (Distributed architecture) is correct because spreading workloads across multiple independent components or nodes lets the cloud platform add or remove capacity in parallel, which is essential for elastic scaling. Option C (Horizontal scaling support) is correct because elasticity is achieved primarily by adding or removing instances (scale out/in), so the application must be designed to run across multiple identical instances. Option D (Stateless design) is correct because stateless components do not hold session or local state, allowing any instance to handle any request and enabling instances to be created or destroyed freely during elastic scaling.

Option B (Monolithic architecture) is not correct because a single tightly coupled deployment unit cannot be scaled or updated granularly, limiting elasticity. Option E (Vertical scaling capability) is not correct because vertical scaling means resizing a single server (scale up/down), which is constrained by hardware limits and does not provide the rapid, automated elasticity that horizontal scaling delivers.

Exam trap

CCSP often tests the misconception that vertical scaling (scaling up) is a valid cloud elasticity strategy, but elasticity primarily relies on horizontal scaling and statelessness to achieve dynamic, automated resource adjustments.

892
MCQeasy

Which security testing technique is most effective at identifying vulnerabilities early in the development lifecycle by analyzing source code without executing it?

A.Runtime Application Self-Protection (RASP)
B.Dynamic Application Security Testing (DAST)
C.Interactive Application Security Testing (IAST)
D.Static Application Security Testing (SAST)
AnswerD

SAST examines source code, bytecode or binaries without executing the program, so flaws such as injection and unsafe deserialisation surface during coding rather than testing. This satisfies the requirement to find vulnerabilities early in the development lifecycle.

Why this answer

SAST analyzes source code, bytecode, or binaries without executing the application, which allows vulnerabilities to be found during coding and build phases — the earliest possible point in the SDLC. Because it inspects the code statically, it can flag issues like SQL injection, hardcoded secrets, and insecure crypto before the code ever runs. This makes it the most effective technique for shifting security left.

Exam trap

CCSP often tests the confusion between SAST (static, no execution, early) and DAST (dynamic, execution required, later), so candidates must anchor on the phrase 'without executing it' to select SAST.

How to eliminate wrong answers

Option A is wrong because RASP runs inside the application at runtime and protects against attacks in production rather than identifying vulnerabilities early in development. Option B is wrong because DAST tests a running application from the outside and therefore occurs later in the lifecycle, after deployment to a test environment. Option C is wrong because IAST combines static and dynamic analysis but still requires the application to be executing (instrumented runtime), so it is not purely non-executing source analysis.

893
MCQhard

A cloud customer is subject to the Payment Card Industry Data Security Standard (PCI DSS) and uses a cloud provider to store cardholder data. The customer wants to reduce its PCI DSS scope. Which of the following provider attestations would best support scope reduction for the customer?

A.A self-assessment questionnaire completed by the cloud provider
B.A PCI DSS Attestation of Compliance (AOC) and Report on Compliance (ROC) for the relevant services
C.A SOC 2 Type I report covering security
D.An ISO/IEC 27001 certificate covering the provider's data centers
AnswerB

The PCI DSS Attestation of Compliance and Report on Compliance are the formal documents that demonstrate a provider's compliance with PCI DSS. When a provider is a PCI DSS validated service provider, the customer can leverage that validation to reduce its own scope, provided the services used are within the provider's assessment. This is the most direct and recognized evidence for PCI DSS scope reduction.

Why this answer

To reduce PCI DSS scope, the customer needs evidence that the provider's environment meets PCI DSS requirements for the services used. A PCI DSS Attestation of Compliance and Report on Compliance provide that assurance. SOC 2 Type I, ISO 27001, and self-assessments do not specifically demonstrate PCI DSS compliance and are not sufficient for scope reduction.

Exam trap

The trap here is assuming that any security certification, such as ISO 27001 or SOC 2, is enough for PCI DSS scope reduction, when PCI DSS specifically requires its own attestation and report.

894
Multi-Selecthard

A company is implementing a software-defined perimeter (SDP) for their cloud environment. Which THREE characteristics are typical of an SDP? (Choose three.)

Select 3 answers
A.Static IP whitelisting.
B.Dynamic firewall rules based on user identity.
C.Application-layer access control.
D.Mutual authentication between client and controller.
E.Single-factor authentication.
AnswersB, C, D

SDP adjusts rules dynamically based on user identity.

Why this answer

Software-defined perimeter (SDP) architecture uses dynamic firewall rules that are created on-the-fly based on user identity and device posture, rather than static IP addresses. The SDP controller authenticates the user and then dynamically provisions a firewall rule to allow the user's specific IP address to access the requested application, ensuring zero-trust network access.

Exam trap

The trap here is that candidates confuse SDP's dynamic, identity-based firewall rules with traditional static IP whitelisting (Option A), failing to recognize that SDP eliminates reliance on IP addresses for access control.

895
MCQeasy

An organization uses cloud storage and wants to protect against accidental deletion of objects. They also want to be able to recover previous versions of objects in case of unintended modifications. Which feature should they enable?

A.Bucket policies
B.Access logs
C.Versioning
D.Server-side encryption
AnswerC

Versioning retains prior and deleted object states within the same bucket, letting you recover overwritten or removed objects without separate backups. It directly addresses both accidental deletion and unintended modification by preserving each object's earlier versions for restoration.

Why this answer

Versioning is the cloud storage feature that retains multiple variants of an object, allowing recovery from accidental deletion or modification. When versioning is enabled, overwriting or deleting an object creates a new version or a delete marker, and previous versions remain accessible. This directly meets the requirement to recover previous versions and protect against accidental deletion.

Exam trap

The trap is confusing versioning with backup or replication; candidates might choose access logs or bucket policies thinking they enable recovery, but only versioning retains previous object versions.

How to eliminate wrong answers

Option A is wrong because bucket policies define access permissions, not data retention or version recovery. Option B is wrong because access logs record requests made to the bucket, which is useful for auditing but does not enable recovery of deleted or modified objects. Option C is correct.

Option D is wrong because server-side encryption protects data confidentiality at rest, but does not provide versioning or recovery capabilities.

896
MCQeasy

A developer accidentally uploaded a file containing API credentials to a public cloud storage bucket. The cloud provider states they cannot guarantee deletion of the object. Which practice could have prevented this incident?

A.Data loss prevention for cloud storage
B.Bucket versioning
C.Access control lists
D.Server-side encryption
AnswerA

Data loss prevention for cloud storage inspects content and blocks uploads containing credential patterns before the object is written. This prevents the exposure entirely, unlike remediation after upload, which cannot guarantee deletion once the provider loses control.

Why this answer

Data Loss Prevention (DLP) for cloud storage can automatically scan objects for sensitive content, such as API credentials, before or after upload. When configured with policies to block or quarantine files containing patterns like access keys, DLP prevents the data from ever being stored in a public bucket, eliminating the risk even if the provider cannot guarantee deletion. This proactive control addresses the root cause—sensitive data exposure—rather than relying on post-incident remediation.

Exam trap

ISC2 often tests the distinction between preventive controls (DLP) and detective/reactive controls (versioning, encryption, ACLs), leading candidates to choose bucket versioning because it allows rollback, but versioning does not prevent the initial exposure of sensitive data.

How to eliminate wrong answers

Option B (Bucket versioning) is wrong because versioning retains multiple copies of an object, which would actually increase the exposure by preserving the compromised file even after deletion attempts, and does not prevent the initial upload. Option C (Access control lists) is wrong because ACLs only restrict who can access the bucket after the file is stored; they do not prevent a developer from uploading sensitive content to a publicly accessible bucket. Option D (Server-side encryption) is wrong because encryption protects data at rest from unauthorized access but does not prevent the upload of plaintext credentials; the credentials would still be readable by anyone with access to the bucket.

897
MCQhard

A cloud provider operates a public IaaS environment. A customer's legal team is reviewing the provider's audit rights clause and wants to ensure the provider will cooperate with a regulatory examination by a financial services regulator. The provider's standard contract currently states that customers may review SOC 2 reports annually but does not grant any right to audit. Which action should the customer's legal team take to best satisfy the regulator's expectations while maintaining a workable relationship with the provider?

A.Request that the provider undergo a third-party audit against a recognized framework and share the resulting report under NDA, supplemented by a right to receive audit summaries and to conduct audits only when required by the regulator
B.Rely solely on the provider's published marketing materials and self-assessment questionnaires
C.Demand an unlimited right to audit the provider's data centers at any time without notice
D.Insist that the regulator conduct the audit directly against the provider without any customer involvement
AnswerA

This approach balances regulatory expectations with cloud operational realities. Independent third-party attestations such as SOC 2 Type II or ISO/IEC 27001 certificates provide assurance without disrupting the provider. A contractual right to receive summaries and to conduct audits when a regulator specifically requires it ensures cooperation. This is a common and defensible cloud contract structure that regulators accept.

Why this answer

A practical audit rights clause in cloud contracts usually combines independent third-party attestations with a limited right for the customer to audit or receive audit results when required by a regulator. This satisfies oversight without demanding unlimited access. The other options either overreach, rely on insufficient evidence, or misunderstand the regulator's role.

Exam trap

The trap here is believing that a customer must have an unrestricted right to audit the provider's premises, when in public cloud the standard and more realistic approach is to rely on independent attestations and a regulator-triggered audit right.

898
MCQmedium

A DevOps team deploys workloads on a public cloud using infrastructure as code. A security review finds that a developer's pipeline credentials can both modify production network security groups and read secrets from the key management service. Which cloud infrastructure security principle is most directly violated?

A.Immutable infrastructure with version-controlled deployment artifacts
B.Separation of duties enforced through least-privilege IAM roles
C.Data residency controls restricting where tenant data is stored
D.Defense in depth using layered network and host controls
AnswerB

Separation of duties requires that no single identity hold both the ability to change protective controls and the ability to access the assets those controls protect. A pipeline credential that can alter production security groups and read secrets can silently disable defenses before exfiltrating data, which is exactly the toxic combination this principle is designed to prevent.

Why this answer

The pipeline identity combines the power to weaken production network controls with the power to read protected secrets, so a single compromised credential can both disable defenses and steal data. Enforcing separation of duties through least-privilege IAM roles splits these capabilities across distinct identities, removing the toxic combination the review uncovered.

Exam trap

The trap here is reaching for a broad architectural principle like defense in depth when the finding is specifically about one identity holding conflicting privileges that defeat separation of duties.

899
MCQmedium

A cloud customer operates a SaaS-based HR platform in the EU and receives a data subject access request (DSAR) from an employee. The provider's standard contract states it will only assist with DSARs on a 'reasonable efforts' basis and bills hourly for that assistance. Under GDPR Article 28, which contractual element must the customer ensure is in place before relying on this SaaS platform?

A.A Standard Contractual Clause (SCC) module three signed with the SaaS provider to legitimize onward transfers.
B.A data processing agreement (DPA) that obligates the processor to assist the controller in responding to data subject requests.
C.A binding corporate rules (BCR) approval from the lead supervisory authority covering the provider's intra-group transfers.
D.A certification under an approved Article 42 code of conduct demonstrating the provider's accountability framework.
AnswerB

Article 28(3)(e) requires the processor to assist the controller by appropriate technical and organisational measures in responding to data subject requests, and Article 28(3) requires the processing to be governed by a binding contract. A DPA is therefore the mandatory instrument, and reasonable-efforts language plus hourly billing does not discharge the provider's Article 28 duty to assist.

Why this answer

GDPR Article 28(3) requires the controller and processor to be bound by a contract or other legal act that sets out the processor's obligations, including assisting the controller with data subject requests. Without a DPA containing that assistance obligation, the customer has no enforceable basis to compel the provider's help, regardless of the provider's internal practices or certification status.

Exam trap

The trap here is assuming that a transfer mechanism such as SCCs or BCRs, or a voluntary certification, substitutes for the mandatory Article 28 processing contract that establishes the processor's assistance duties to the controller.

900
MCQmedium

What is the primary purpose of a Software Bill of Materials (SBOM) in cloud application security?

A.To scan infrastructure as code
B.To inventory all dependencies and facilitate vulnerability management
C.To automate deployment of containers
D.To document software licensing
AnswerB

An SBOM enumerates every component, library and transitive dependency in the application, giving a machine-readable inventory. When a new CVE is disclosed, teams can query that inventory to identify affected artefacts immediately, which is the constraint driving rapid vulnerability management.

Why this answer

The primary purpose of an SBOM is to inventory all software components and dependencies, enabling vulnerability management and supply chain security. It provides a formal, machine-readable list of components, their versions, and relationships. This helps organizations identify and remediate vulnerabilities like Log4Shell quickly.

Exam trap

CCSP often tests the misconception that SBOMs are for license compliance only—candidates must recognize their primary role in vulnerability and supply chain risk management.

How to eliminate wrong answers

Option A is wrong because scanning infrastructure as code is a different practice (e.g., using tools like Checkov), not the purpose of an SBOM. Option C is wrong because automating container deployment is done by orchestration tools like Kubernetes, not SBOMs. Option D is wrong because documenting software licensing is a secondary benefit; the primary purpose is security and vulnerability management.

Page 11

Page 12 of 13

Page 13