Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 901–934

934 questions total · 13pages · All types, answers revealed

Page 12

Page 13 of 13

901
MCQmedium

During an eDiscovery process, a company needs to preserve data stored in AWS S3 that may be relevant to a lawsuit. Which AWS feature should be used to implement a legal hold?

A.AWS CloudTrail
B.S3 Object Lock
C.S3 Versioning
D.AWS Config
AnswerB

S3 Object Lock enforces a write-once-read-many retention period or legal hold on individual object versions, preventing deletion or alteration for the hold's duration. This preserves potentially relevant S3 data against tampering or removal during eDiscovery.

Why this answer

S3 Object Lock is the AWS feature designed to implement legal holds. It allows you to place a legal hold on an object version, preventing it from being overwritten or deleted for a specified period or indefinitely. This is specifically used for compliance and legal scenarios like eDiscovery.

Exam trap

CCSP often tests the confusion between versioning and object lock, where candidates think versioning alone provides legal hold capabilities.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity but does not preserve data; it is for auditing, not legal holds. Option C is wrong because S3 Versioning protects against accidental deletion by keeping versions, but it does not prevent deletion of the object or versions; a legal hold requires explicit prevention. Option D is wrong because AWS Config assesses resource configurations and compliance, but it does not enforce data retention or legal holds.

902
Multi-Selectmedium

Which TWO of the following are required for GDPR compliance when processing personal data in the cloud?

Select 2 answers
A.Appoint a Data Protection Officer (DPO) for all organizations
B.Store data only within the European Union
C.Use only ISO 27001 certified cloud service providers
D.Conduct a Data Protection Impact Assessment (DPIA) when processing is likely to result in high risk
E.Maintain a record of processing activities
AnswersD, E

A Data Protection Impact Assessment is mandatory under GDPR Article 35 whenever processing, particularly using new technologies, is likely to result in a high risk to data subjects' rights and freedoms. It documents risks and mitigations before processing begins.

Why this answer

Option D is correct because GDPR Article 35 mandates a Data Protection Impact Assessment (DPIA) whenever a type of processing—especially using new technologies and on a large scale—is likely to result in a high risk to the rights and freedoms of natural persons, and cloud processing of personal data frequently meets this threshold. Option E is correct because GDPR Article 30 requires controllers (and, in many cases, processors) to maintain records of processing activities, documenting purposes, categories of data and recipients, retention periods, and security measures. Option A is wrong because a DPO is mandatory only under Article 37 conditions (public authority, large-scale regular and systematic monitoring, or large-scale special-category data), not for all organizations.

Option B is wrong because GDPR permits transfers of personal data outside the EU under Chapter V mechanisms such as adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules; EU-only storage is not required. Option C is wrong because ISO 27001 certification is not a GDPR legal requirement—compliance rests on meeting GDPR obligations, and other frameworks or certifications may also demonstrate appropriate safeguards.

Exam trap

CCSP often tests the specific conditions under which a DPO is required and the difference between mandatory and optional GDPR requirements; candidates may incorrectly assume a DPO is always required or that data must stay in the EU.

903
Multi-Selectmedium

Which TWO of the following are best practices for securing a cloud-based container orchestration platform?

Select 2 answers
A.Use minimal base images to reduce the attack surface.
B.Store secrets in environment variables for ease of use.
C.Run containers with root privileges by default.
D.Enable audit logging for all administrative actions.
E.Disable TLS certificate validation for internal communications.
AnswersA, D

Minimal images reduce vulnerabilities.

Why this answer

Using minimal base images (e.g., Alpine or distroless images) reduces the number of installed packages and libraries, thereby shrinking the attack surface. This practice limits the potential vectors for privilege escalation or remote code execution within containers, which is a core security principle for containerized workloads in platforms like Kubernetes.

Exam trap

ISC2 often tests the misconception that environment variables are a safe place for secrets because they are 'not stored on disk,' but in reality they are accessible to any process or user with access to the container's runtime environment.

904
MCQhard

After a security incident involving a compromised access key, a security engineer needs to collect forensic evidence from the cloud environment. Which of the following actions would be most useful for determining the timeline of the compromise?

A.Taking a memory dump of the compute instance
B.Reviewing cloud audit logs for the compromised key
C.Analyzing network flow logs for data exfiltration
D.Checking configuration management logs for resource changes
AnswerB

Cloud audit logs record every API call made with the compromised access key, including timestamps, source IPs and requested actions. This chronological record directly establishes when the key was first misused and the sequence of attacker activity, satisfying the need to determine the compromise timeline.

Why this answer

Cloud audit logs contain detailed records of all API calls, including the identity, timestamp, and source IP. Analyzing these logs helps establish the timeline of when the key was used.

905
MCQhard

A company uses a cloud provider's organization management with multiple accounts. A security team wants to ensure that a specific storage bucket in the production account cannot be deleted by anyone, including the account administrator. Which control should be implemented?

A.Use notifications to alert when a delete is attempted.
B.Enable versioning on the bucket.
C.Enable audit logging to log any deletion attempt.
D.Apply an organization-level policy to deny the delete action on the bucket for the production account.
AnswerD

An organization-level policy overrides account-level permissions, so even the production account administrator cannot delete the bucket. This satisfies the stem's constraint that nobody, including that administrator, may delete it. Service control policies in AWS Organizations or equivalent deny rules enforce this centrally across accounts.

Why this answer

An organization-level policy can be applied to an account (or organizational unit) to restrict permissions for all users, roles, and even the account administrator. By attaching a policy that denies the action to delete a storage bucket, the security team ensures that no principal in the production account can delete the specified bucket. This provides a preventive control that overrides any allow permissions within the account.

Exam trap

ISC2 often tests the distinction between preventive controls (like organization-level policies) and detective/reactive controls (like audit logging or notifications), and the trap here is that candidates confuse logging or versioning with actual deletion prevention.

How to eliminate wrong answers

Option A is wrong because S3 event notifications are only reactive alerts; they do not prevent the deletion from occurring, so the bucket can still be deleted. Option B is wrong because S3 Versioning protects objects within the bucket from being overwritten or deleted, but it does not prevent the bucket itself from being deleted. Option C is wrong because AWS CloudTrail logs API calls for auditing purposes but does not block the deletion action; it only records it after the fact.

906
MCQeasy

Which of the following is the best way to protect a web application from cross-site scripting (XSS) attacks?

A.Encode all output that is rendered in HTML.
B.Implement a Content Security Policy (CSP) as the sole defense.
C.Use a combination of input validation, output encoding, and Content Security Policy.
D.Validate all user input on the server side.
AnswerC

XSS arises from untrusted data reaching the browser as markup, so layered defences are needed: validation rejects malformed input, output encoding neutralises injected script, and Content Security Policy restricts what executes. No single control covers stored, reflected and DOM-based variants, satisfying the best-practice requirement.

Why this answer

Cross-site scripting (XSS) attacks exploit multiple vectors, and no single defense is sufficient. Input validation prevents malicious payloads from being stored or processed, output encoding ensures that any residual dangerous characters are rendered inert in the HTML context, and Content Security Policy (CSP) provides a robust, browser-enforced layer that can block inline scripts and restrict script sources even if other defenses fail. This defense-in-depth approach aligns with the OWASP XSS prevention cheat sheet and is the recommended strategy for cloud-hosted web applications.

Exam trap

ISC2 often tests the misconception that a single security control (like output encoding or CSP alone) is sufficient, when the correct answer always requires a defense-in-depth combination of input validation, output encoding, and CSP.

How to eliminate wrong answers

Option A is wrong because output encoding alone does not prevent XSS in all contexts (e.g., JavaScript event handlers, CSS, or URL contexts require context-specific encoding) and does not address stored XSS where the payload is executed before encoding is applied. Option B is wrong because implementing CSP as the sole defense is insufficient; CSP can be bypassed if the application has JSONP endpoints, unsafe-inline fallbacks, or misconfigured directives, and it does not remediate existing XSS vulnerabilities in the application code. Option D is wrong because server-side input validation alone cannot stop XSS; it can be bypassed with encoding variations (e.g., double URL encoding, Unicode escapes) and does not protect against reflected or DOM-based XSS where the payload is generated client-side without server validation.

907
MCQhard

A financial services company stores sensitive data in a cloud provider's object storage. The security team wants to enforce that all data is encrypted at rest using keys that the company controls, and that the cloud provider cannot access the plaintext keys. Which cloud data security control should they implement?

A.Server-side encryption with provider-managed keys (SSE-CMK) where the provider generates and stores the keys in its own KMS.
B.Server-side encryption with a hardware security module (HSM) where the provider manages the HSM and the keys are stored in the provider's key store.
C.Server-side encryption with customer-provided keys (SSE-C) where the company supplies the key with each request but the provider stores it temporarily.
D.Client-side encryption where the company encrypts data before uploading and manages its own keys outside the cloud provider's infrastructure.
AnswerD

Client-side encryption ensures that data is encrypted before it reaches the cloud provider, and the company retains sole control of the keys. The provider only stores ciphertext and cannot access plaintext keys, satisfying the requirement for exclusive control and preventing provider access.

Why this answer

Client-side encryption is the only option that guarantees the cloud provider never has access to plaintext keys, because encryption and key management occur entirely within the company's environment. Server-side options, even with customer-provided keys or HSMs, involve the provider in key handling, which introduces potential access.

Exam trap

The trap here is believing that server-side encryption with customer-provided keys (SSE-C) gives the customer sole control, when the provider still handles the key in plaintext.

908
Multi-Selectmedium

An organization wants to prevent secrets from being exposed in source code. Which two practices should they adopt? (Choose TWO.)

Select 2 answers
A.Implement secret scanning in the CI/CD pipeline
B.Encrypt all source code files
C.Use a firewall to block access to code repositories
D.Use a secrets management service to retrieve credentials at runtime
E.Disable git history
AnswersA, D

Automated secret scanning inspects commits and pipeline artefacts for hard-coded credentials such as API keys and tokens, catching exposure before code merges or deploys. This directly satisfies the goal of preventing secrets from reaching source code, since detection occurs within the CI/CD workflow rather than after release.

Why this answer

Option A is correct because implementing secret scanning in the CI/CD pipeline automatically detects hardcoded credentials (API keys, tokens, passwords) in commits and pull requests before they are merged or deployed, using tools like GitGuardian, TruffleHog, or GitHub secret scanning to fail the build and alert developers. Option D is correct because a secrets management service (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) stores credentials centrally and injects them at runtime via API calls or environment variables, so secrets never appear in source code or version control. Option B is not appropriate because encrypting source files does not prevent secrets from being committed and exposed; the plaintext secrets still exist in the repository and can be decrypted or leaked via build artifacts.

Option C is wrong because a firewall controls network access to repositories but does nothing to stop developers from hardcoding secrets into code that is later pushed. Option E is incorrect because disabling git history destroys auditability and collaboration, and it does not prevent secrets from being written into new commits in the first place.

Exam trap

CCSP often tests the misconception that encrypting code or blocking network access protects secrets — the exam expects you to recognize that secrets must never be in code and must be scanned for continuously.

909
MCQeasy

A development team is adopting a DevSecOps approach for a cloud-native application. Which practice best exemplifies the shift-left security principle?

A.Reviewing logs for security incidents weekly
B.Scanning Infrastructure as Code (IaC) templates with Checkov before deployment
C.Configuring a cloud WAF after the application is live
D.Performing runtime penetration testing after deployment
AnswerB

Scanning IaC templates with Checkov before deployment detects misconfigurations at authoring time, shifting security left into the development phase rather than runtime. This satisfies the stem's shift-left principle by embedding automated checks early in the pipeline.

Why this answer

Scanning Infrastructure as Code (IaC) templates with Checkov before deployment embodies the shift-left security principle by identifying and remediating misconfigurations early in the development lifecycle. This proactive approach prevents security issues from reaching production, reducing risk and cost compared to post-deployment fixes.

Exam trap

ISC2 often tests the misconception that shift-left means any security activity performed early in the lifecycle, but the trap here is that candidates may confuse post-deployment controls (like WAF or pen testing) with true shift-left practices, which must occur before code is deployed or infrastructure is provisioned.

How to eliminate wrong answers

Option A is wrong because reviewing logs for security incidents weekly is a reactive, post-deployment monitoring practice that does not shift security left; it detects issues after they have occurred. Option C is wrong because configuring a cloud WAF after the application is live is a runtime security control applied after deployment, not an early-stage preventive measure. Option D is wrong because performing runtime penetration testing after deployment is a late-stage validation activity that does not catch vulnerabilities during development or build phases.

910
MCQhard

A cloud security analyst is investigating a potential data breach. They discover that an employee's credentials were used to access a cloud storage bucket containing sensitive files. The access logs show the employee accessed the bucket from an IP address in a different country during the time of the incident. Which of the following is the MOST likely attack vector?

A.The employee intentionally accessed the data from that country
B.A distributed denial-of-service (DDoS) attack overwhelmed access controls
C.The cloud storage bucket was misconfigured as public
D.The employee's credentials were stolen via a phishing attack
AnswerD

Credentials valid for the employee account, combined with access from a foreign IP inconsistent with normal behaviour, indicate the account was compromised rather than misused legitimately. Phishing captures credentials directly, enabling the attacker to authenticate as the employee and reach the bucket.

Why this answer

The scenario describes a classic credential theft attack: an employee's credentials are used from an anomalous geographic location to access sensitive cloud storage. Phishing is the most common vector for stealing credentials, as it tricks users into revealing their passwords, which are then reused by attackers to authenticate to cloud services like AWS S3 or Azure Blob Storage. The access logs showing a foreign IP address strongly indicate the credentials were compromised and used by an unauthorized party, not the employee.

Exam trap

ISC2 often tests the distinction between credential theft and misconfiguration; the trap here is that candidates see 'different country' and assume a public bucket (option C) because they confuse geographic anomaly with open access, but the logs explicitly show credential usage, ruling out anonymous access.

How to eliminate wrong answers

Option A is wrong because the employee intentionally accessing data from a different country would not constitute a breach unless they were acting maliciously, but the scenario is about investigating a potential breach, and the anomalous IP suggests unauthorized use, not a routine business trip. Option B is wrong because a DDoS attack overwhelms network resources or application availability, not access controls; it does not grant an attacker valid credentials to authenticate to a cloud storage bucket. Option C is wrong because a misconfigured public bucket would allow anonymous access without requiring any credentials, but the logs show the employee's credentials were used, indicating authentication occurred, not anonymous public access.

911
MCQmedium

A cloud security team needs to ensure that all AWS API activity across a multi-account organization is captured in a tamper-evident, immutable log that can be queried later for forensic analysis. The organization uses AWS Organizations with a dedicated security account. Which approach BEST meets these requirements?

A.Configure each member account to send AWS CloudTrail events to a local CloudWatch Logs group and rely on the default 90-day retention.
B.Use AWS Config to record configuration changes across accounts and store the configuration history in the security account for later retrieval.
C.Enable AWS CloudTrail as an organization trail that delivers logs to a centralized S3 bucket with S3 Object Lock in compliance mode and validate log file integrity.
D.Enable Amazon GuardDuty in the security account and export its findings to an S3 bucket with versioning enabled for long-term storage.
AnswerC

An organization trail automatically applies to all accounts in AWS Organizations, delivering a single consolidated record of API activity. Delivering to a centralized S3 bucket protected by S3 Object Lock in compliance mode prevents deletion or alteration, and CloudTrail log file integrity validation provides cryptographic proof that logs were not tampered with, satisfying forensic-grade requirements.

Why this answer

Centralized, tamper-evident API logging in AWS Organizations is achieved with an organization trail that aggregates events into a single S3 bucket. S3 Object Lock in compliance mode prevents anyone, including the root user, from deleting or overwriting objects for the retention period, while CloudTrail log file integrity validation uses digest files to prove logs were not altered, which is essential for forensic admissibility.

Exam trap

The trap here is assuming that enabling CloudTrail in each account or exporting GuardDuty findings provides a centralized, immutable audit trail, when only an organization trail with S3 Object Lock and integrity validation meets tamper-evident, organization-wide forensic requirements.

912
Drag & Dropmedium

Drag and drop the steps for managing identity and access in a multi-cloud environment using a centralized identity provider (IdP) into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First integrate IdP, then create groups/roles, configure mapping, assign users with MFA, and audit.

913
MCQmedium

A financial services company is migrating a customer analytics platform to a public cloud IaaS environment. The security team must ensure that sensitive data at rest in the cloud provider's block storage volumes is encrypted and that the company retains sole control over the encryption keys, even from the cloud provider. Which approach BEST meets these requirements?

A.Enable cloud provider volume encryption with customer-managed keys stored in the provider's KMS.
B.Implement client-side encryption before writing data to the block storage volumes, managing keys in an on-premises HSM.
C.Use the cloud provider's native volume encryption with provider-managed keys.
D.Use transport-layer encryption (TLS) for all data written to the block storage volumes.
AnswerB

Client-side encryption encrypts data before it reaches the cloud, and storing keys in an on-premises HSM ensures the company retains exclusive control. The cloud provider only sees ciphertext and never has access to the plaintext or the keys. This satisfies both encryption at rest and sole key control requirements.

Why this answer

Client-side encryption with keys stored in an on-premises HSM ensures that data is encrypted before it leaves the company's control and that the cloud provider never has access to the encryption keys. This provides the strongest level of key control and meets both the encryption at rest and sole key control requirements. Provider-managed or customer-managed keys in the cloud still involve the provider in key management.

Exam trap

The trap here is assuming that customer-managed keys in the cloud provider's KMS give the same level of control as keys held entirely outside the provider's environment.

914
MCQeasy

A security engineer needs to ensure that all API calls made to AWS resources are logged for auditing purposes. Which AWS service should be enabled to capture management events, data events, and provide log file validation?

A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.AWS Config
D.AWS GuardDuty
AnswerB

AWS CloudTrail captures API activity across AWS resources, covering both management events and, when configured, data events such as S3 object operations. Its log file validation feature produces digest files proving logs were not altered after delivery, satisfying the auditing and tamper-evidence requirements stated in the stem.

Why this answer

AWS CloudTrail is the correct service because it is specifically designed to log API calls and actions taken within an AWS account, capturing management events (e.g., creating or deleting resources) and data events (e.g., S3 object-level operations). It also provides log file validation through digital signatures using SHA-256 hashing and RSA, ensuring the integrity and authenticity of the log files after they have been delivered.

Exam trap

A common mistake is to confuse the service that generates logs (CloudTrail) with services that store or analyze logs (CloudWatch Logs, GuardDuty), leading candidates to select CloudWatch Logs as the primary logging service for API calls.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs is a service for monitoring, storing, and accessing log files from various AWS resources (e.g., EC2, Lambda), but it does not natively capture AWS API calls or provide log file validation; it can only ingest CloudTrail logs if configured as a destination. Option C is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking configuration changes, not for logging API calls or providing log file validation. Option D is wrong because AWS GuardDuty is a threat detection service that analyzes CloudTrail logs, VPC Flow Logs, and DNS logs for malicious activity, but it does not itself capture or log API calls nor provide log file validation.

915
MCQhard

A security engineer reviews the S3 bucket policy shown in the exhibit. Which security concern should be addressed immediately?

A.The principal "*" grants access to all AWS services
B.The second statement allows unrestricted public read access to all objects
C.The policy version is outdated and should be updated
D.The resource ARN does not include the bucket itself, only objects
AnswerB

The second statement's Principal wildcard combined with Effect Allow and no restricting condition grants anonymous read access to every object in the bucket. This exposes all stored data publicly, which is the immediate concern requiring remediation ahead of any other policy issue in the exhibit.

Why this answer

The second statement in the S3 bucket policy uses `"Effect": "Allow"` with `"Principal": "*"` and `"Action": "s3:GetObject"` without any condition restricting access (e.g., `IpAddress` or `Referer`). This effectively grants anonymous, unauthenticated read access to every object in the bucket, which is a critical data exposure risk. Such a policy violates the principle of least privilege and should be remediated immediately by removing the statement or adding a condition to restrict access.

Exam trap

ISC2 often tests the misconception that `"Principal": "*"` only applies to AWS services, when in fact it grants access to all principals including anonymous users, and candidates may overlook the missing condition that would otherwise restrict access.

How to eliminate wrong answers

Option A is wrong because `"Principal": "*"` grants access to all AWS users and anonymous users, not just AWS services; the misconception is that `*` limits to services, but it actually means any principal (including unauthenticated users). Option C is wrong because the policy version `"2012-10-17"` is the current and valid version for S3 bucket policies; an outdated version would be `"2008-10-17"`, but that is not a security concern here. Option D is wrong because the resource ARN `"arn:aws:s3:::example-bucket/*"` correctly specifies objects within the bucket; while it does not include the bucket itself, this is intentional for object-level permissions and is not a security issue—the bucket ARN would be needed only for bucket-level actions like `s3:ListBucket`, which is not the concern in this policy.

916
MCQhard

A financial services company runs a critical workload on AWS. The security team must ensure that all data at rest in Amazon S3 is encrypted with keys that the company controls and that the keys are stored in a hardware security module (HSM) separate from the cloud provider's default HSM. The company also requires the ability to immediately revoke access to the keys. Which solution meets these requirements?

A.Use S3 server-side encryption with AWS KMS custom key store backed by AWS CloudHSM (SSE-KMS with custom key store).
B.Use S3 server-side encryption with Amazon S3 managed keys (SSE-S3).
C.Use S3 server-side encryption with AWS KMS customer managed keys (SSE-KMS).
D.Use S3 client-side encryption with a customer-provided key stored in AWS Secrets Manager.
AnswerA

A KMS custom key store allows you to use AWS CloudHSM clusters that you control, providing a dedicated HSM separate from the default AWS KMS HSMs. You can immediately revoke access by removing the key from the custom key store or deleting the key. This satisfies both the separate HSM and immediate revocation requirements.

Why this answer

The requirement is for customer-controlled keys stored in a dedicated HSM separate from the cloud provider's default HSM, with immediate revocation. AWS KMS custom key store backed by AWS CloudHSM provides exactly this: you control the HSM cluster, and you can revoke access by disassociating the key or deleting it. Other options either use provider-managed HSMs or lack HSM separation.

Exam trap

The trap here is confusing customer managed keys in AWS KMS with customer-controlled HSMs; a custom key store is required to use your own CloudHSM cluster, not just any KMS key.

917
MCQhard

A cloud security engineer needs to ensure that a containerized application running in a Kubernetes cluster securely stores and rotates database credentials. Which is the most appropriate solution?

A.Store credentials as environment variables in the pod manifest
B.Embed credentials in the container image during build
C.Use a secrets management system integrated with Kubernetes, such as HashiCorp Vault with CSI driver
D.Use Kubernetes Secrets without encryption at rest
AnswerC

Vault's CSI driver mounts secrets directly into pods as ephemeral volumes, so credentials never persist in etcd or manifest files, and Vault's lease mechanism rotates them automatically. This satisfies the requirement for secure storage and rotation of database credentials within Kubernetes.

Why this answer

HashiCorp Vault integrated with the Kubernetes CSI (Container Storage Interface) driver allows dynamic, short-lived database credentials to be injected into pods as volumes, enabling automatic rotation without application changes. This approach ensures secrets are never stored in the cluster's etcd or exposed in environment variables, aligning with the principle of least privilege and compliance requirements for credential rotation.

Exam trap

ISC2 often tests the misconception that Kubernetes Secrets are inherently secure because they are base64-encoded, but the trap is that base64 is not encryption, and without encryption at rest or an external secrets manager, they are vulnerable to etcd compromise.

How to eliminate wrong answers

Option A is wrong because storing credentials as environment variables in the pod manifest exposes them in plaintext in the cluster's etcd and in any logs or dumps that capture environment variables, violating security best practices for secret management. Option B is wrong because embedding credentials in the container image during build makes them immutable and accessible to anyone with image pull access, preventing rotation without rebuilding and redeploying the image. Option D is wrong because Kubernetes Secrets without encryption at rest store secrets in base64-encoded plaintext in etcd, which is not secure against unauthorized access to the underlying storage, and they lack native rotation capabilities.

918
MCQmedium

A cloud operations team at a healthcare company runs a multi-account AWS organization. Compliance requires that all Amazon S3 server access logs and AWS CloudTrail management events are retained for 7 years and cannot be altered or deleted by any account administrator, including the account that owns the bucket. The security architect must design a storage solution that enforces write-once-read-many (WORM) immutability at the storage layer. Which approach BEST satisfies these requirements?

A.Replicate logs to a second S3 bucket in a different Region using S3 Cross-Region Replication and apply a restrictive bucket policy on the replica.
B.Enable S3 Versioning and a bucket policy that denies s3:DeleteObject for all principals except the organization's root user.
C.Store logs in an S3 bucket encrypted with AWS KMS customer managed keys and rotate the keys every 90 days.
D.Configure an S3 bucket with S3 Object Lock in compliance mode and a default retention period of 7 years, then centralize logs into that bucket.
AnswerD

S3 Object Lock in compliance mode enforces WORM semantics for the specified retention period; no principal, including the root user of the owning account, can overwrite or delete a locked object version until the retention date passes. A default retention rule applies the 7-year period automatically to every new object, satisfying the healthcare retention and immutability mandate.

Why this answer

The scenario demands storage-layer immutability that survives even privileged administrators and enforces a fixed 7-year retention. S3 Object Lock in compliance mode is the only mechanism here that makes object versions unalterable and undeletable for the retention period, and a default retention rule automates the 7-year window for all ingested logs. Encryption, versioning, replication, and bucket policies govern access or durability but do not deliver WORM guarantees.

Exam trap

The trap here is assuming that a deny-delete bucket policy or S3 Versioning provides true immutability, when only S3 Object Lock in compliance mode prevents privileged principals from altering or removing locked objects.

919
MCQmedium

A financial institution requires a cloud environment that is shared by multiple organizations with common regulatory compliance needs, such as PCI DSS. Which deployment model is most appropriate?

A.Private cloud
B.Public cloud
C.Community cloud
D.Hybrid cloud
AnswerC

A community cloud is shared by several organisations with common concerns such as PCI DSS compliance, letting the financial institution share infrastructure and cost while meeting its regulatory needs. This matches the stem's requirement for shared infrastructure among organisations with common compliance obligations.

Why this answer

A community cloud is shared by multiple organizations that have common regulatory or compliance requirements, such as PCI DSS, making it the ideal model for a financial institution needing a compliant shared environment. It provides the cost and scalability benefits of multi-tenancy while meeting sector-specific controls. This matches the definition of community cloud in NIST SP 800-145.

Exam trap

CCSP often tests the distinction between community and public/private clouds by emphasizing 'shared by multiple organizations with common compliance needs,' trapping candidates who default to public cloud for cost or private cloud for security.

How to eliminate wrong answers

Option A is wrong because a private cloud is dedicated to a single organization, which would not satisfy the requirement for a shared environment across multiple organizations with common compliance needs. Option B is wrong because a public cloud is open to the general public and does not inherently provide the common regulatory governance that a community cloud offers. Option D is wrong because a hybrid cloud combines private and public components for a single organization's workloads; it does not describe a multi-organization shared model with common compliance requirements.

920
MCQeasy

A startup wants to deploy a customer relationship management (CRM) application without managing any servers, operating systems, or middleware. The vendor hosts the application, and the startup's administrators only create user accounts and configure settings through a web interface. Which cloud service category is being used?

A.Software as a Service (SaaS)
B.Infrastructure as a Service (IaaS)
C.Function as a Service (FaaS)
D.Platform as a Service (PaaS)
AnswerA

SaaS delivers a complete, provider-managed application accessed over the network, with the customer responsible only for user administration and configuration. The startup's administrators create accounts and adjust settings through a web interface, exactly matching the SaaS consumption model where no server, OS, or middleware management is performed.

Why this answer

The clue is that the provider hosts the entire application and the customer only manages users and configuration. That is the SaaS model, where the provider owns the application, runtime, middleware, operating system, and infrastructure. IaaS and PaaS leave more layers under customer control, and FaaS is a developer-oriented serverless compute service rather than a finished business application.

Exam trap

The trap here is equating any cloud-hosted application with PaaS, when PaaS still requires the customer to deploy and manage its own application code.

921
Multi-Selecthard

Which THREE of the following are key considerations when conducting a cloud risk assessment?

Select 3 answers
A.Reviewing legal and regulatory requirements applicable to the organization
B.Analyzing network latency between cloud regions
C.Identifying threats specific to cloud deployment models (IaaS, PaaS, SaaS)
D.Evaluating the CSP's physical security controls in detail
E.Assessing the impact of shared tenancy on data isolation
AnswersA, C, E

Compliance with laws is a key risk consideration.

Why this answer

Legal and regulatory requirements (e.g., GDPR, HIPAA, PCI DSS) directly dictate data residency, privacy controls, and breach notification obligations. A cloud risk assessment must map these requirements to the specific cloud deployment to identify compliance gaps and potential liabilities.

Exam trap

ISC2 often tests the distinction between operational metrics (like latency) and risk assessment inputs, tricking candidates into selecting performance-related options as risk factors.

922
MCQmedium

In a DevSecOps pipeline for a cloud application, which practice best ensures that only approved open-source components are used?

A.Signing container images
B.Implementing dependency scanning with Snyk
C.Using a private artifact registry with allow-lists
D.Running SAST scans on all source code
AnswerC

A private artifact registry with allow-lists restricts dependency resolution to vetted components, blocking unapproved open-source packages at the point of retrieval. This enforces the approved-components constraint directly, unlike scanning, which detects problems only after an unapproved component has already been pulled.

Why this answer

A private artifact registry with allow-lists enforces a whitelist of approved open-source components, preventing developers from pulling unvetted dependencies directly from public repositories. This ensures that only components that have passed security and compliance reviews are used in the pipeline, directly addressing the requirement for 'approved' open-source components.

Exam trap

ISC2 often tests the distinction between detection tools (like Snyk or SAST) and enforcement controls (like allow-lists), so candidates mistakenly choose a scanning tool that finds vulnerabilities rather than a policy-based mechanism that prevents unapproved components from being used at all.

How to eliminate wrong answers

Option A is wrong because signing container images ensures integrity and authenticity of the image itself, but does not control which open-source components are included inside the image. Option B is wrong because dependency scanning with Snyk identifies known vulnerabilities in open-source components but does not enforce a policy of only using pre-approved components; it detects issues after the component is already included. Option D is wrong because SAST (Static Application Security Testing) scans analyze custom source code for security flaws, not the approval status or provenance of open-source libraries.

923
MCQmedium

A company is implementing a cloud key management system (KMS) to control encryption keys for sensitive data. Which practice is essential to ensure the security of the keys?

A.Use a single key for all encryption operations to simplify management.
B.Export keys to the cloud provider's hardware security module (HSM).
C.Store encryption keys in the same region as the encrypted data.
D.Periodically rotate the encryption keys.
AnswerD

Key rotation limits the lifetime of exposed keys.

Why this answer

Periodic key rotation is essential because it limits the amount of data encrypted under a single key, reducing the impact of a key compromise and complying with cryptographic best practices (e.g., NIST SP 800-57). In a cloud KMS, rotation can be automated using key versions, where old keys are retained for decryption while new keys are used for encryption, ensuring forward secrecy and operational security.

Exam trap

ISC2 often tests the misconception that key rotation is optional or that storing keys in the same region as data is a security best practice, when in fact rotation is a mandatory control for key hygiene and regional separation is a common architectural pattern for isolation.

How to eliminate wrong answers

Option A is wrong because using a single key for all encryption operations violates the principle of key separation and increases the blast radius of a compromise; it also makes key management and auditing impractical. Option B is wrong because exporting keys to a cloud provider's HSM undermines the security model of a KMS, as keys should remain within the HSM's boundary and never be exported in plaintext; cloud HSMs typically do not allow key export to maintain FIPS 140-2/3 compliance. Option C is wrong because storing encryption keys in the same region as the encrypted data does not inherently improve security; it may actually increase risk if a regional breach occurs, and compliance frameworks often require key separation from data (e.g., storing keys in a different region or account) to provide defense in depth.

924
MCQmedium

A cloud security operations team is configuring AWS Security Hub to automatically send all findings to a third-party ticketing system. They need a solution that requires minimal custom code and supports filtering by severity. Which AWS service should they use to route the findings?

A.AWS CloudTrail
B.Amazon SNS
C.AWS Config
D.Amazon EventBridge
AnswerD

Amazon EventBridge can receive Security Hub findings as events, filter them based on severity or other attributes, and route them to targets such as AWS Lambda or directly to a ticketing system's API endpoint. This requires minimal custom code because EventBridge rules can match patterns and invoke targets without writing complex polling logic.

Why this answer

EventBridge natively integrates with Security Hub, allowing findings to be matched against event patterns and routed to targets. This enables severity-based filtering and delivery to external systems with minimal custom code, making it the ideal choice for automated ticketing integration.

Exam trap

The trap here is assuming that SNS can filter messages by content without additional processing, but SNS only supports attribute-based filtering which requires the publisher to set attributes, not automatically derived from finding severity.

925
MCQhard

An organization wants to ensure that if they decide to migrate away from their current cloud provider, they can retrieve all data in a usable format and delete it from the provider's systems. Which principle does this best describe?

A.Interoperability
B.Portability
C.Elasticity
D.Reversibility
AnswerD

Reversibility covers both data portability and secure deletion on exit, matching the requirement to retrieve data in a usable format and remove it from provider systems. It is the cloud-specific counterpart to avoiding vendor lock-in, ensuring the organisation can terminate the relationship without losing access to its own information.

Why this answer

Reversibility is the principle that ensures an organization can fully exit a cloud provider relationship — retrieving all data in a usable format and confirming its deletion from the provider's systems. It directly addresses the exit/termination scenario described, covering both data extraction and verified destruction. This is a core cloud governance concept tied to avoiding vendor lock-in and satisfying data lifecycle obligations.

Exam trap

The trap here is confusing portability (moving workloads) with reversibility (exiting and reclaiming/deleting data) — CCSP often tests this distinction because both relate to avoiding lock-in but address different lifecycle stages.

How to eliminate wrong answers

Option A is wrong because interoperability refers to the ability of different systems or services to exchange and use information, not the ability to exit a provider and reclaim data. Option B is wrong because portability focuses on moving workloads or applications between environments without major rework, but does not inherently include the deletion/verification of data from the original provider. Option C is wrong because elasticity describes the ability to automatically scale resources up or down based on demand, which is unrelated to data retrieval and deletion on exit.

926
MCQhard

A DevOps team is deploying containers in a Kubernetes cluster. They need to ensure that container images are scanned for vulnerabilities before deployment. Which is the most effective approach?

A.Scan images manually after deployment.
B.Use a container registry with integrated vulnerability scanning and enforce admission controls.
C.Rely on the developer's assurance that images are secure.
D.Use a runtime security tool.
AnswerB

Registry-integrated scanning inspects images at push time, and admission controllers block non-compliant images from ever reaching the cluster. This satisfies the stem's requirement for pre-deployment scanning, shifting enforcement to the admission layer rather than relying on post-deployment detection.

Why this answer

Integrating vulnerability scanning into the container registry (e.g., using tools like Trivy, Clair, or Amazon ECR scanning) combined with admission controllers (e.g., OPA/Gatekeeper or Kyverno) allows automated scanning of images at rest and blocks deployments of non-compliant images before they enter the cluster. This shift-left approach ensures that only images passing security policies are admitted, preventing vulnerable images from reaching production.

Exam trap

ISC2 often tests the distinction between pre-deployment controls (image scanning + admission) and runtime controls, so candidates mistakenly choose runtime tools (Option D) thinking they prevent vulnerabilities, when in fact runtime tools only detect active exploits after deployment.

How to eliminate wrong answers

Option A is wrong because scanning images manually after deployment introduces a delay that allows vulnerable containers to run in the cluster, violating the principle of shift-left security and failing to prevent exploitation. Option C is wrong because relying on developer assurance without automated verification is a security anti-pattern; developers may unknowingly introduce vulnerabilities, and this approach lacks auditability and enforcement. Option D is wrong because runtime security tools (e.g., Falco, Sysdig) monitor container behavior during execution but do not prevent vulnerable images from being deployed; they address post-deployment threats, not pre-deployment image integrity.

927
MCQmedium

A company develops a microservices application and wants to ensure secrets such as API keys and database credentials are not exposed in container images. Which approach best meets this requirement?

A.Hardcode secrets in the application code and obfuscate with encryption.
B.Use a secrets management service such as HashiCorp Vault to inject secrets at runtime.
C.Pass secrets as environment variables during container deployment.
D.Store secrets in a separate configuration file within the image.
AnswerB

HashiCorp Vault stores credentials outside the image and injects them into the container at runtime, so no secret is baked into layers or environment variables. This satisfies the requirement that API keys and database credentials never appear in container images, where they would be extractable.

Why this answer

A secrets management service like HashiCorp Vault allows secrets to be dynamically injected into containers at runtime, ensuring they never reside in the image. This approach decouples secrets from the application artifact, adhering to the principle of least privilege and immutable infrastructure. Vault can inject secrets via sidecar containers, init containers, or API calls, preventing exposure in image layers or configuration files.

Exam trap

ISC2 often tests the misconception that environment variables are a secure way to pass secrets because they are not in the image, but the trap is that environment variables are still exposed in the container's runtime environment and orchestration metadata, making them vulnerable to leakage via logs, debugging tools, or misconfigured RBAC.

How to eliminate wrong answers

Option A is wrong because hardcoding secrets in application code, even with obfuscation, is insecure—encryption keys must still be stored somewhere, and obfuscation can be reversed, violating the core security principle of not embedding secrets in code. Option C is wrong because passing secrets as environment variables during deployment, while better than hardcoding, still exposes them in the container's process list, logs, and orchestration metadata, and they can be read from the host or via /proc. Option D is wrong because storing secrets in a separate configuration file within the image means the secrets are baked into the image layers, making them accessible to anyone who can pull the image, and they persist in registries and caches.

928
MCQmedium

A multinational retailer uses a SaaS e-commerce platform hosted in the EU and serves customers in the EU, the UK, and the US. The legal team must determine which cross-border data transfer mechanism can be used to lawfully move customer personal data from the EU entity to the US parent company for analytics. Which mechanism should the legal team select?

A.Binding Corporate Rules (BCRs) approved only by the US Federal Trade Commission
B.EU-U.S. Data Privacy Framework (DPF) certification of the US parent company
C.The APEC Cross-Border Privacy Rules (CBPR) system certification of the US parent
D.A self-attestation of GDPR compliance signed by the US parent's Chief Privacy Officer
AnswerB

The EU-U.S. Data Privacy Framework is a current adequacy decision adopted by the European Commission in July 2023, allowing personal data to flow from the EU to US companies that self-certify to the US Department of Commerce. If the US parent holds a valid DPF certification covering the relevant data categories, this is the most direct transfer mechanism and avoids the need for SCCs or a TIA.

Why this answer

For an EU-to-US transfer of personal data, the most current and straightforward mechanism is the EU-U.S. Data Privacy Framework, provided the US recipient is certified for the relevant data. BCRs must be approved by EU supervisory authorities, internal attestations have no legal force, and APEC CBPR is not a GDPR transfer mechanism.

The DPF certification directly addresses the scenario.

Exam trap

The trap here is assuming that any privacy certification or internal policy from the US company is enough to legitimize the transfer, when GDPR requires a specific Chapter V mechanism such as an adequacy decision, SCCs, BCRs, or a derogation.

929
MCQmedium

A DevSecOps team is integrating static application security testing (SAST) into their CI/CD pipeline. Which of the following is the PRIMARY benefit of performing SAST during the build phase rather than later in the pipeline?

A.It identifies runtime vulnerabilities such as SQL injection
B.It reduces false positives compared to dynamic analysis
C.It enables early detection of vulnerabilities before deployment
D.It scans running applications to find configuration issues
AnswerC

SAST analyses source code during the build, so flaws are flagged in the commit that introduced them, before artefacts reach staging or production. This shifts remediation left, cutting the cost and risk of fixing defects after deployment, which is the stem's stated build-phase constraint.

Why this answer

Performing SAST during the build phase allows the team to identify security vulnerabilities in the source code before the application is compiled, packaged, or deployed. This early detection reduces the cost and effort of remediation because issues are found at the point of code creation, not after deployment. The primary benefit is shifting security left to catch defects before they reach production.

Exam trap

ISC2 often tests the concept of 'shift left' security, and the trap here is confusing SAST's static analysis capability with runtime detection, leading candidates to incorrectly choose options that describe dynamic or runtime testing benefits.

How to eliminate wrong answers

Option A is wrong because SAST analyzes source code statically and cannot identify runtime vulnerabilities like SQL injection that depend on dynamic input and database interaction; those are better detected by DAST or IAST. Option B is wrong because SAST often produces more false positives than dynamic analysis due to its lack of runtime context, not fewer. Option D is wrong because SAST does not scan running applications; it scans source code or binaries without execution, whereas configuration issues in running apps are found by tools like configuration scanning or DAST.

930
MCQmedium

A cloud security architect is designing a multi-tenant environment using Type 1 hypervisors. Which of the following is the primary security risk associated with this architecture?

A.Insecure VM migration between hosts
B.Insufficient logging of hypervisor events
C.Resource contention leading to denial of service
D.VM escape from guest to hypervisor
AnswerD

A VM escape exploits a hypervisor or virtualisation bug to break out of the guest and execute on the host, compromising every co-resident tenant's VMs. This is the primary risk because the hypervisor is the sole isolation boundary in Type 1 architectures.

Why this answer

In a Type 1 (bare-metal) hypervisor multi-tenant architecture, the hypervisor is the highest-privilege software layer controlling all guest VMs, memory, and virtual devices. A VM escape exploits a hypervisor or virtual-device vulnerability to break out of the guest's isolation boundary and execute code at the hypervisor level, compromising every other tenant on that host. This is the primary and most severe security risk because it defeats the fundamental tenant-isolation guarantee that multi-tenancy depends on.

Exam trap

CCSP often tests the distinction between operational risks (logging, resource contention, migration) and the architectural isolation-breaking risk (VM escape) — candidates pick a plausible-sounding operational issue instead of the fundamental multi-tenancy threat.

How to eliminate wrong answers

Option A is wrong because insecure VM migration (e.g., unencrypted live migration traffic) is a real but secondary risk that can be mitigated with TLS/encryption and is not unique to Type 1 hypervisors. Option B is wrong because insufficient hypervisor event logging is an operational/visibility gap, not the primary architectural security risk of multi-tenancy. Option C is wrong because resource contention causing DoS is an availability concern addressed by resource quotas and QoS, not the core isolation-breaking risk.

931
MCQmedium

An organization is using a public cloud IaaS and wants to ensure they understand which security responsibilities fall on them. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?

A.Hypervisor security
B.Physical security of data centers
C.Security of the guest operating system
D.Network infrastructure hardening
AnswerC

In IaaS, the provider secures the physical hosts, network fabric and hypervisor, while the customer retains control of everything above virtualisation. Patching, hardening and monitoring the guest operating system therefore fall to the organisation, satisfying the stem's requirement to identify customer-side duties.

Why this answer

In an IaaS deployment, the cloud provider secures the physical facility, hardware, and hypervisor, while the customer retains responsibility for everything from the guest OS upward — including OS patching, hardening, host firewalls, and the applications and data running on top. Option C correctly identifies the guest operating system as a customer responsibility. This is the classic 'security OF the cloud vs. security IN the cloud' split defined by the shared responsibility model.

Exam trap

CCSP often tests the boundary of the shared responsibility model — candidates incorrectly assume the provider handles OS or network security in IaaS, when in fact the customer owns everything above the hypervisor.

How to eliminate wrong answers

Option A is wrong because hypervisor security is the cloud provider's responsibility in IaaS — the customer has no access to the hypervisor layer. Option B is wrong because physical security of data centers always belongs to the cloud provider, regardless of service model (IaaS, PaaS, or SaaS). Option D is wrong because the underlying network infrastructure (routers, switches, backbone) is provider-managed in IaaS; the customer only controls virtual network constructs like security groups and NACLs.

932
MCQmedium

A cloud security analyst is reviewing the network architecture of a VPC. The security team wants to block all traffic from a known malicious IP address at the subnet level. Which AWS network security component should they use?

A.Network ACL (NACL)
B.Transit gateway
C.Security group
D.VPC peering connection
AnswerA

Network ACLs are stateless, subnet-level filters that evaluate allow and deny rules against source and destination IP addresses. A deny rule for the malicious IP therefore blocks its traffic before it reaches any instance in the subnet, matching the subnet-level blocking constraint.

Why this answer

NACLs (Network Access Control Lists) are stateless firewalls that operate at the subnet level and support both allow and deny rules. Security groups are stateful and only support allow rules at the instance level.

933
MCQmedium

A cloud security architect is designing a multi-tenant SaaS platform on AWS. The platform must ensure that each tenant's data is logically isolated and that a compromised tenant cannot access another tenant's resources. The architect decides to use separate AWS accounts per tenant and wants to centralize security management. Which AWS service should be used to manage these accounts and apply security policies centrally?

A.AWS IAM Identity Center
B.AWS Organizations
C.AWS Resource Access Manager (RAM)
D.AWS Control Tower
AnswerB

AWS Organizations allows you to centrally manage multiple AWS accounts, apply service control policies (SCPs) to enforce security guardrails, and consolidate billing. It is the correct choice for centralizing security management across many accounts, enabling isolation between tenants while maintaining administrative control.

Why this answer

AWS Organizations is designed to centrally manage multiple AWS accounts, apply service control policies (SCPs) to enforce security boundaries, and simplify billing. It enables logical isolation by placing each tenant in a separate account while allowing centralized security governance. The other services provide access management, governance automation, or resource sharing but do not fulfill the core requirement of central account management and policy enforcement.

Exam trap

The trap here is confusing account access management or governance automation with the foundational service that actually groups and controls multiple accounts.

934
Multi-Selectmedium

A cloud security engineer is reviewing the software development lifecycle for a team building a containerized application on a public cloud. The team wants to shift security left and reduce vulnerabilities in production images. Which two practices should be implemented to achieve this? (Choose two.)

Select 2 answers
A.Integrate static application security testing (SAST) into the CI pipeline
B.Store container images in a private registry with access controls
C.Scan container images for known vulnerabilities in the CI/CD pipeline
D.Perform a penetration test of the production environment annually
E.Enable runtime threat detection in the production Kubernetes cluster
AnswersA, C

SAST analyzes source code or binaries for security flaws early in the development process, before deployment. Integrating it into the CI pipeline ensures every commit is scanned, allowing developers to fix issues quickly. This directly supports shifting security left by catching vulnerabilities such as injection flaws or insecure cryptographic usage before they reach production images.

Why this answer

Shifting security left means embedding security checks early in the development lifecycle. SAST finds code-level flaws at commit time, and container image scanning finds vulnerable packages at build time. Both prevent vulnerable artifacts from reaching production.

Runtime detection, annual penetration tests, and private registries are valuable but operate after deployment or only control access, not vulnerability reduction.

Exam trap

The trap here is confusing post-deployment controls like runtime detection or penetration testing with shift-left practices that prevent vulnerabilities earlier.

Page 12

Page 13 of 13