Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 76–150

934 questions total · 13pages · All types, answers revealed

Page 1

Page 2 of 13

Page 3
76
Multi-Selectmedium

A cloud security team is implementing a DevSecOps pipeline. Which TWO of the following are examples of shift-left security practices? (Select two.)

Select 2 answers
A.Conducting penetration testing after deployment
B.Scanning Infrastructure as Code with Checkov before deployment
C.Performing Dynamic Application Security Testing (DAST) on a running application
D.Running Static Application Security Testing (SAST) during code commit
E.Implementing Runtime Application Self-Protection (RASP) in production
AnswersB, D

Scanning Infrastructure as Code with Checkov before deployment catches misconfigurations at the source, satisfying the shift-left requirement to detect flaws before resources reach production. Checkov statically analyses Terraform, CloudFormation and Kubernetes manifests, so defects are remediated in version control rather than after provisioning, when fixes cost more and expose live environments.

Why this answer

Shift-left security means moving security activities earlier in the software development lifecycle, before code reaches production. Option B is correct because scanning Infrastructure as Code with Checkov before deployment catches misconfigurations in Terraform, CloudFormation, or Kubernetes manifests at the earliest possible stage, preventing insecure infrastructure from ever being provisioned. Option D is correct because running SAST during code commit analyzes source code for vulnerabilities like injection flaws or insecure patterns as developers write it, giving immediate feedback before the code is merged or built.

Option A is not shift-left because penetration testing after deployment is a late-stage, post-release activity. Option C is not shift-left because DAST tests a running application, which occurs after the code is deployed to a test or staging environment. Option E is not shift-left because RASP operates at runtime in production, protecting the application only after it is live.

Exam trap

CCSP often tests whether candidates can distinguish 'shift-left' (pre-deployment, code/IaC analysis) from 'shift-right' (runtime, production monitoring) — DAST and RASP are the classic distractors.

77
MCQmedium

A company uses a cloud-based data loss prevention (DLP) tool to monitor data access. They notice that a user is bypassing DLP by accessing data directly via cloud APIs from a non-corporate device. What is the most effective way to prevent this?

A.Deploy a virtual private network (VPN) and require all API traffic to originate from within the VPN
B.Configure the cloud service to require all API requests to go through a proxy that enforces DLP
C.Implement a conditional access policy to block non-corporate devices
D.Use tokenization to replace sensitive data before allowing API access
AnswerB

Routing all API requests through a DLP-enforcing proxy means policy inspection happens regardless of device or network, closing the direct-API bypass. Non-corporate devices can no longer reach the cloud service's APIs without passing through the control point.

Why this answer

Routing all API traffic through a proxy that enforces DLP ensures that every API request is inspected for sensitive data before reaching the cloud service. This approach closes the gap where a user bypasses the DLP tool by accessing data directly via cloud APIs from a non-corporate device, as the proxy acts as a mandatory intermediary that can apply content inspection, policy enforcement, and logging regardless of the device or network.

Exam trap

ISC2 often tests the misconception that network-level controls like VPNs or device-based conditional access are sufficient to prevent data exfiltration via APIs, when in fact only content-aware inspection at the API layer can enforce DLP on the actual data being transferred.

How to eliminate wrong answers

Option A is wrong because a VPN only encrypts traffic and provides a corporate IP address; it does not inspect API payloads for sensitive data, so DLP policies are not enforced on the content of API requests. Option C is wrong because blocking non-corporate devices via conditional access does not prevent the user from accessing data from a corporate device that is compromised or from using a different method to bypass DLP; it also does not address the core issue of API-level data exfiltration. Option D is wrong because tokenization replaces sensitive data with tokens, but if the user already has access to the original sensitive data via API calls, tokenization does not prevent them from retrieving the actual data; it is a data masking technique, not a DLP enforcement mechanism for API traffic.

78
MCQhard

A multinational corporation stores trade secrets in a cloud object storage bucket. The security team wants to ensure that even if the cloud provider's internal systems are compromised, the data remains confidential. They also need to maintain the ability to revoke access to specific data objects without affecting other objects. Which combination of techniques should they implement?

A.Transport-layer encryption (TLS) and identity-based access policies.
B.Client-side encryption with per-object keys and a key management system that supports granular key revocation.
C.Server-side encryption with customer-provided keys (SSE-C) and object-level ACLs.
D.Server-side encryption with provider-managed keys and bucket-level access policies.
AnswerB

Client-side encryption ensures data is encrypted before reaching the cloud, so provider compromise does not expose plaintext. Using per-object keys allows revoking access to a specific object by revoking its key, without impacting other objects. A key management system that supports granular revocation enables this fine-grained control, meeting both confidentiality and selective revocation requirements.

Why this answer

Client-side encryption with per-object keys ensures that data is encrypted before it reaches the cloud, so a provider compromise does not expose plaintext. Per-object keys allow revoking access to a specific object by revoking its key, without affecting other objects. This provides both confidentiality against provider compromise and granular revocation, which are the core requirements.

Exam trap

The trap here is confusing server-side encryption with customer-provided keys (SSE-C) as equivalent to client-side encryption; SSE-C still exposes keys to the provider during processing.

79
MCQmedium

A cloud operations team runs a production Kubernetes cluster on Amazon EKS. During a security review, they discover that the cluster's control plane audit logs are not being captured, preventing investigation of suspicious API server activity. The team must enable audit logging with the least operational overhead while retaining logs for 90 days. Which action should they take?

A.Install the Amazon CloudWatch agent on each worker node and configure it to tail the kubelet and container runtime logs, then set a 90-day retention policy on the log group.
B.Modify the EKS cluster configuration to enable control plane logging for the 'audit' log type, and configure a CloudWatch Logs retention policy of 90 days on the resulting log group.
C.Enable AWS CloudTrail data events for the EKS cluster and set a 90-day retention period in the S3 bucket that receives the trails.
D.Deploy a DaemonSet that runs a Fluent Bit container on every node to collect /var/log/kube-apiserver/audit.log and forward it to CloudWatch Logs.
AnswerB

EKS control plane logging can be enabled per log type, including 'audit', directly from the cluster configuration or via the AWS CLI/API. Logs are delivered to CloudWatch Logs, where a retention policy can be set to 90 days. This requires no agents on nodes and is the native, lowest-overhead method for capturing Kubernetes API server audit events.

Why this answer

The native way to capture Kubernetes API server audit events on EKS is to enable the 'audit' control plane log type on the cluster, which streams events to CloudWatch Logs. Setting a retention policy of 90 days satisfies the retention requirement without deploying agents or managing additional infrastructure. Node-based collection and CloudTrail do not capture control plane audit data.

Exam trap

The trap here is assuming worker nodes host the Kubernetes API server and its audit logs, when on EKS the control plane is fully managed by AWS.

80
MCQhard

A cloud security manager is designing an exit strategy for a critical SaaS application. The provider's contract permits data export only through a proprietary API that returns records in a non-standard binary format. The manager must reduce the risk of being unable to move data to another provider. Which action BEST addresses this risk?

A.Enable multi-factor authentication for all administrative accounts on the SaaS platform
B.Negotiate a contractual right to receive data in a documented, non-proprietary format at any time
C.Require the provider to publish its API documentation to the customer's security team
D.Replicate the SaaS data nightly to an on-premises backup appliance using the same API
AnswerB

Contractual guarantees of portable, documented, non-proprietary export formats directly mitigate lock-in by ensuring data can be consumed by another provider's tools. Because the technical export path is proprietary, only a negotiated right to standard formats removes the dependency, making this the most effective control for the stated risk.

Why this answer

The core risk is that data can only be extracted in a proprietary binary format, which prevents migration to another provider. The strongest mitigation is a contractual right to receive the data in a documented, non-proprietary format on demand. Authentication hardening, backups through the same API, and API documentation do not remove the format dependency, so they cannot resolve the portability problem.

Exam trap

The trap here is treating a nightly backup through the same proprietary API as a portability control, when it only replicates the lock-in.

81
MCQeasy

Which API Gateway security feature limits the number of requests from a client to prevent abuse or DoS attacks?

A.Rate limiting
B.JWT validation
C.WAF integration
D.Mutual TLS
AnswerA

Rate limiting caps how many requests a client may issue per time window, throttling abusive bursts before they exhaust backend capacity. This directly satisfies the stem's constraint of preventing abuse or denial-of-service attacks, unlike authentication or encryption features that address identity and confidentiality instead.

Why this answer

Rate limiting (also called throttling) caps the number of requests a client can make within a defined time window, protecting backend services from abuse, brute-force attempts, and denial-of-service floods. API gateways implement this with token bucket or leaky bucket algorithms, returning HTTP 429 Too Many Requests when the limit is exceeded. It is the primary control for request-volume abuse.

Exam trap

The trap is that all four options are legitimate API security features, so candidates must match the specific control to the specific threat — volume abuse maps to rate limiting, not authentication or content inspection.

How to eliminate wrong answers

Option B is wrong because JWT validation verifies the integrity and claims of a token to authenticate and authorise a caller — it does not limit request volume, and a valid token can still be used for a flood. Option C is wrong because WAF integration inspects HTTP payloads for attack signatures such as SQL injection or XSS; it filters malicious content, not request frequency. Option D is wrong because mutual TLS authenticates both client and server via certificates, providing strong identity assurance but no volume control.

82
MCQeasy

A cloud security team is implementing a key management system for encrypting data in a multi-cloud environment. They need to ensure that keys are available even if one cloud provider experiences an outage. What is the BEST approach?

A.Implement a multi-cloud key management system that replicates keys across providers
B.Use a single cloud provider's key management service
C.Store encryption keys in the same storage as encrypted data
D.Use hardware security modules (HSMs) in one data center
AnswerA

Replicating keys across multiple providers removes the single-provider dependency, so an outage at one cloud does not render encrypted data inaccessible. This directly satisfies the availability constraint, unlike single-provider key stores, which fail when that provider's key service becomes unavailable.

Why this answer

A multi-cloud key management system that replicates keys across providers ensures high availability and fault tolerance. If one cloud provider experiences an outage, the keys remain accessible from another provider, preventing data decryption failures. This approach aligns with the principle of avoiding a single point of failure in key distribution, which is critical for maintaining continuous data access in a multi-cloud architecture.

Exam trap

ISC2 often tests the misconception that storing keys with data or using a single provider's KMS is acceptable for availability, but the trap here is that candidates overlook the need for geographic and provider-level redundancy to ensure continuous key access during an outage.

How to eliminate wrong answers

Option B is wrong because using a single cloud provider's key management service creates a single point of failure; if that provider experiences an outage, all keys become unavailable, blocking access to encrypted data. Option C is wrong because storing encryption keys in the same storage as encrypted data violates the fundamental security principle of separation of duties and key management best practices, as an attacker who compromises the storage can access both the ciphertext and the keys. Option D is wrong because using hardware security modules (HSMs) in one data center still presents a single point of failure; if that data center goes offline, keys are inaccessible, and this approach does not address multi-cloud availability requirements.

83
MCQmedium

During a code review, a developer discovers hardcoded AWS access keys in a configuration file that was committed to the repository. Which tool is specifically designed to detect such secrets in code repositories?

A.GitGuardian
B.tfsec
C.Checkov
D.Snyk
AnswerA

GitGuardian scans repository history and commits specifically for exposed secrets such as AWS access keys, alerting on hardcoded credentials. This directly satisfies the stem's requirement for a tool designed to detect secrets committed to code repositories, rather than general static analysis.

Why this answer

GitGuardian is a security platform specifically designed to detect secrets such as API keys, passwords, and tokens in source code repositories, including historical commits. It integrates with version control systems and CI/CD pipelines to scan for hardcoded credentials, making it the correct tool for this scenario.

Exam trap

CCSP often tests the difference between secret-scanning tools and IaC misconfiguration scanners — candidates who see 'code review' and 'configuration file' may incorrectly pick tfsec or Checkov, which target infrastructure misconfigurations, not hardcoded secrets.

How to eliminate wrong answers

Option B is wrong because tfsec is a static analysis tool for Terraform infrastructure-as-code, focused on misconfigurations like open security groups, not secret detection in application code. Option C is wrong because Checkov is a policy-as-code scanner for IaC (Terraform, CloudFormation, Kubernetes), also aimed at misconfigurations rather than secrets. Option D is wrong because Snyk is primarily a vulnerability scanner for dependencies and container images, and while it has some secret detection capabilities, it is not specifically designed for that purpose like GitGuardian.

84
MCQeasy

A startup is using a cloud-based SaaS CRM to store customer contact information. The security policy requires that data be encrypted both in transit and at rest. The SaaS provider states that it encrypts data in transit using TLS and at rest using AES-256. What should the startup do to verify these claims?

A.Request the provider's SOC 2 Type II report and review the encryption controls.
B.Use a network sniffer to capture traffic between the startup and the SaaS provider.
C.Perform a penetration test against the SaaS provider's application.
D.Ask the provider to send the encryption keys so the startup can decrypt data.
AnswerA

A SOC 2 Type II report provides an independent auditor's opinion on the effectiveness of the provider's controls over a period, including encryption. Reviewing it verifies that the provider's claims about TLS and AES-256 are accurate and consistently applied. This is the appropriate way to gain assurance without direct access to the provider's infrastructure.

Why this answer

Independent audit reports such as SOC 2 Type II are designed to provide assurance about a service provider's controls, including encryption. They cover both in-transit and at-rest encryption and are based on evidence gathered by auditors. This is the standard method for verifying a SaaS provider's security claims without requiring direct access to their systems.

Exam trap

The trap here is thinking that technical testing like packet capture can fully verify a provider's encryption at rest, when only independent audits provide comprehensive assurance.

85
MCQeasy

Which of the following is the correct order of phases in the cloud data lifecycle?

A.Store, Create, Use, Share, Destroy, Archive
B.Create, Store, Use, Share, Archive, Destroy
C.Create, Use, Store, Share, Archive, Destroy
D.Create, Share, Store, Use, Archive, Destroy
AnswerB

This sequence matches the CSA cloud data lifecycle: data is created, stored, used, shared, archived, then destroyed. It satisfies the stem's ordering constraint by placing Destroy last, after Archive, reflecting that secure deletion is the terminal phase once retention obligations end.

Why this answer

The cloud data lifecycle follows the sequence Create, Store, Use, Share, Archive, Destroy. Data must first be created or captured, then persisted in storage, actively used or processed, shared with other parties, moved to long-term archival storage when access frequency drops, and finally securely destroyed at end of life. This ordering reflects the natural progression of data from inception through active use to eventual disposal.

Exam trap

The trap is reordering Store and Use or moving Destroy before Archive — candidates often assume data is used before it is stored, but the CCSP canonical sequence places Store immediately after Create.

How to eliminate wrong answers

Option A is wrong because it places Store before Create, which is impossible — data cannot be stored before it exists, and it also places Destroy before Archive, reversing the end-of-life sequence. Option C is wrong because it places Use before Store; while data can be used in memory immediately after creation, the lifecycle model treats storage as the phase that precedes sustained use and sharing, and the canonical CCSP ordering is Create, Store, Use, Share, Archive, Destroy. Option D is wrong because it places Share before Store and Use, which skips the persistence and active-use phases that logically precede sharing data with third parties.

86
MCQmedium

A company is required by a data sovereignty law to ensure that all data generated by its EU customers is stored and processed within the EU. The company uses a cloud provider with data centers in multiple regions. Which cloud storage configuration should they implement?

A.Enable cross-region replication to a region in the same country.
B.Select a cloud region located in the EU and disable cross-region replication.
C.Use client-side encryption for all EU data.
D.Apply data classification labels to all EU data.
AnswerB

Pinning storage to an EU region satisfies the residency requirement, since object data physically resides on EU soil. Disabling cross-region replication prevents automatic copying of objects to non-EU regions, closing the secondary path by which data could leave the jurisdiction.

Why this answer

Data sovereignty requires that data remains within a specific legal jurisdiction. By selecting a cloud region physically located in the EU and disabling cross-region replication, the company ensures that data is stored and processed only within EU borders, satisfying the legal requirement. Cross-region replication, even within the same country, could still violate the law if the replication target is outside the EU or if the law requires strict in-region processing.

Encryption and classification do not change the physical location of data, so they do not address sovereignty.

Exam trap

CCSP often tests the misconception that encryption or data classification alone can satisfy data sovereignty requirements, when in fact they do not control data location; the key is to ensure data remains within the required legal jurisdiction by selecting appropriate regions and disabling cross-region replication.

How to eliminate wrong answers

Option A is wrong because cross-region replication, even to a region in the same country, may still involve data leaving the EU if the country is not an EU member or if the replication crosses EU borders; moreover, the question specifies EU customers, so replication must be within the EU, not just the same country. Option C is wrong because client-side encryption protects data confidentiality but does not control where data is stored or processed; encrypted data can still be stored outside the EU, violating sovereignty. Option D is wrong because data classification labels are metadata used for governance and do not enforce or guarantee that data remains within a specific geographic region.

87
MCQmedium

A cloud architect is designing a disaster recovery plan for a financial application with RTO of 15 minutes and RPO of 5 minutes. Which recovery strategy is most appropriate?

A.Multi-region active-active
B.Backup and restore
C.Pilot light
D.Warm standby
AnswerA

Multi-region active-active keeps synchronised replicas serving traffic in multiple regions simultaneously, so failover is near-instant and data loss stays within seconds. This meets the 15-minute RTO and 5-minute RPO, which warm standby or backup-restore strategies cannot reliably achieve.

Why this answer

Multi-region active-active is the only strategy that can meet both a 15-minute RTO and a 5-minute RPO because it maintains synchronous or near-synchronous replication between two or more regions, allowing traffic to be instantly redirected with zero or minimal data loss. This approach eliminates the recovery time needed to spin up infrastructure or restore data, as the application is already fully operational in multiple regions.

Exam trap

ISC2 often tests the distinction between RTO and RPO by presenting a scenario where candidates confuse warm standby (which can meet a low RTO but not a tight RPO) with active-active, leading them to choose warm standby despite its inability to guarantee the 5-minute RPO.

How to eliminate wrong answers

Option B (Backup and restore) is wrong because restoring from backups typically takes hours, far exceeding the 15-minute RTO, and the RPO of 5 minutes cannot be guaranteed with periodic backups. Option C (Pilot light) is wrong because while it can achieve a low RTO, the RPO is often higher than 5 minutes due to the need to replicate data and start application servers, and the failover process introduces delay. Option D (Warm standby) is wrong because even though it has a reduced recovery time compared to pilot light, the RPO of 5 minutes is difficult to achieve consistently without active-active replication, and the failover still requires time to promote the standby environment.

88
Multi-Selectmedium

A company is building a cloud-native API that uses OAuth 2.0 for delegated authorization. The security team wants to harden the authorization code flow against token interception and misuse. Which two measures should be implemented to protect the authorization code and tokens? (Choose two.)

Select 2 answers
A.Enable PKCE so the client sends a code challenge and later proves possession of the corresponding verifier when exchanging the code.
B.Require the authorization server to issue the authorization code with a short lifetime and bind it to the client identifier and redirect URI.
C.Store refresh tokens in browser local storage to allow the client to silently renew access tokens without user interaction.
D.Configure the resource server to accept access tokens in query string parameters so that clients can easily include them in requests.
E.Use the implicit grant so that tokens are returned directly from the authorization endpoint without an intermediate code.
AnswersA, B

PKCE binds the authorization code to the client that initiated the request by requiring a verifier that matches the earlier challenge. An attacker who intercepts the code cannot redeem it without the verifier, which is never sent through the browser redirect. This directly mitigates authorization code interception, especially for public clients, and is a recommended hardening measure.

Why this answer

Hardening the authorization code flow focuses on preventing intercepted codes from being redeemed by an attacker. Binding the code to the client and redirect URI, combined with a short lifetime, limits replay. PKCE adds proof of possession so a stolen code is useless without the verifier.

Together they address interception and misuse without exposing tokens to the browser or weakening transport protections.

Exam trap

The trap here is confusing the implicit grant or query-string tokens as simplifications that improve security, when both actually increase token exposure.

89
MCQeasy

An organization wants to classify data in the cloud and assign labels such as 'Public', 'Internal', 'Confidential', and 'Restricted'. What is the primary purpose of this classification scheme?

A.To reduce cloud storage costs by moving data to cheaper tiers
B.To enable public sharing of data
C.To comply with data localization laws
D.To apply appropriate security controls based on sensitivity
AnswerD

Labels drive protection: sensitivity tiers determine which encryption, access and handling controls apply. Classification exists precisely so that 'Restricted' data receives stricter safeguards than 'Public', satisfying the stem's requirement to classify data and assign labels. Microsoft Entra ID and similar tools then enforce those label-based controls.

Why this answer

Data classification assigns sensitivity labels so that security controls — encryption, access control, retention, DLP, and monitoring — can be applied proportionally to the data's value and risk. Labeling data as Public, Internal, Confidential, or Restricted lets the organization map each tier to a defined control baseline, ensuring the most sensitive data receives the strongest protection.

Exam trap

CCSP often tests the misconception that classification is about cost, sharing, or residency — the trap is missing that its primary purpose is to drive proportionate security controls based on sensitivity.

How to eliminate wrong answers

Option A is wrong because classification is a security/governance function, not a storage-cost optimization; tiering data to cheaper storage is a lifecycle management concern, not the purpose of sensitivity labels. Option B is wrong because classification restricts rather than enables sharing — 'Public' is one tier, but the scheme's purpose is to prevent inappropriate exposure, not promote it. Option C is wrong because data localization concerns where data resides geographically, which is a residency control, not the primary purpose of a sensitivity classification scheme.

90
MCQhard

A cloud-native SaaS provider uses OpenID Connect (OIDC) for user authentication. The security architect wants to reduce the impact of stolen authorization codes and ensure that tokens issued to a single-page application cannot be replayed by a different client. Which OIDC mechanism should be implemented?

A.Configure the authorization server to use the implicit flow so that no authorization code is ever issued.
B.Require the authorization server to issue sender-constrained access tokens using Demonstrating Proof of Possession (DPoP).
C.Use PKCE with the S256 code challenge method and validate the redirect URI against a registered value.
D.Enable refresh token rotation and bind refresh tokens to the client's IP address.
AnswerC

PKCE binds the authorization code to the client that initiated the request by requiring the code verifier at token exchange, preventing a different client from redeeming a stolen code. Combined with strict redirect URI validation, it protects public clients such as SPAs. This directly addresses code interception and client binding, which are the stated concerns.

Why this answer

PKCE with S256 ties the authorization code to the initiating client via the code verifier, so a stolen code cannot be redeemed by an attacker who does not possess the verifier. Strict redirect URI validation further constrains where codes and tokens can be delivered. Together they directly mitigate code interception and cross-client replay for public clients like SPAs.

Exam trap

The trap here is confusing token replay mitigations such as DPoP with authorization code protection, when the scenario specifically targets stolen codes and client binding.

91
MCQmedium

A healthcare SaaS provider is deploying a new application that processes protected health information (PHI). The application uses a microservices architecture running on Kubernetes. Each microservice stores its data in a separate database. The compliance team requires that all data at rest be encrypted and that encryption keys be managed by the customer (CMEK). The cloud provider supports KMS with CMEK. However, the development team wants to use a single customer-managed key for all databases to simplify key management. The security architect is concerned about the blast radius if the key is compromised. Which of the following recommendations best balances security and operational efficiency?

A.Use the cloud provider's default encryption keys for all databases
B.Use a separate customer-managed key for each database, with automated key rotation
C.Disable encryption to improve performance and use network segmentation instead
D.Use one customer-managed key for all databases, but enable automatic key rotation
AnswerB

Per-database customer-managed keys contain the blast radius: compromising one key exposes only that microservice's data, satisfying the architect's isolation concern. Automated rotation limits exposure windows without manual overhead, preserving the operational efficiency the single-key approach sought. This balances both constraints better than one shared key.

Why this answer

It minimizes the blast radius by ensuring that compromise of one key does not expose data in other databases, while automated key rotation reduces the window of vulnerability and operational overhead. This aligns with the principle of least privilege and the compliance requirement for customer-managed encryption keys (CMEK). Using separate keys per database is a standard security best practice for microservices architectures, especially when handling PHI.

Exam trap

ISC2 often tests the tension between operational simplicity and security blast radius, where candidates may choose a single key with rotation (Option D) thinking it balances both, but fail to recognize that rotation does not shrink the blast radius of a compromised key that has already been used to encrypt data.

How to eliminate wrong answers

Option A is wrong because using the cloud provider's default encryption keys violates the compliance requirement that encryption keys be managed by the customer (CMEK), and it does not allow the customer to control key lifecycle or rotation. Option C is wrong because disabling encryption for PHI at rest is a direct violation of compliance mandates (e.g., HIPAA) and security best practices; network segmentation alone does not protect data at rest. Option D is wrong because using a single customer-managed key for all databases creates a single point of failure and a large blast radius—if that key is compromised, all databases are exposed, and automatic rotation does not mitigate the risk of a key already being compromised.

92
Multi-Selecthard

A Kubernetes cluster is being hardened. Which THREE measures should be implemented to restrict container capabilities and reduce the risk of privilege escalation? (Select three.)

Select 3 answers
A.Enabling privileged mode for containers that need host access
B.Running containers as root
C.Running containers as a non-root user
D.Applying AppArmor or SELinux profiles
E.Dropping all Linux capabilities and adding only required ones
AnswersC, D, E

Running containers as a non-root user removes UID 0 inside the container, so a breakout or exploited process lacks root privileges on the host mount namespace. This directly reduces privilege-escalation risk, satisfying the hardening requirement alongside capability dropping and mandatory access controls.

Why this answer

Option C is correct because running containers as a non-root user (e.g., via securityContext.runAsNonRoot: true or a USER directive in the Dockerfile) prevents processes inside the container from having UID 0, which is the primary enabler of privilege-escalation exploits and container-escape techniques. Option D is correct because AppArmor or SELinux profiles enforce mandatory access control that confines container processes to a limited set of files, paths, and operations, blocking actions that even a compromised process could otherwise attempt. Option E is correct because dropping all Linux capabilities and adding back only those explicitly required (e.g., using cap-drop: ALL with a minimal cap-add list) removes dangerous privileges such as CAP_SYS_ADMIN, CAP_NET_RAW, and CAP_SYS_PTRACE that are commonly abused for privilege escalation.

Option A is incorrect because privileged mode grants the container nearly all host capabilities and device access, dramatically increasing the attack surface rather than restricting it. Option B is incorrect because running containers as root gives the process full UID 0 privileges inside the container, which is exactly the risk the hardening measures are meant to eliminate.

93
MCQmedium

A cloud security engineer is reviewing the authentication mechanism for a web application. The application currently uses API keys transmitted in the URL query string. What is the primary security concern with this approach?

A.API keys in URLs are often logged in plaintext in server logs and browser history.
B.API keys in query strings are not encrypted, even with HTTPS.
C.API keys provide weak authentication because they are not tied to a user session.
D.API keys are not valid for use in query strings; they require a certificate.
AnswerA

Query strings are captured verbatim by web servers, proxies and browsers, so the key lands in access logs and history in cleartext. Anyone with log or shared-device access replays it. This directly satisfies the stem's concern about the transmission location of the credential.

Why this answer

The primary security concern with transmitting API keys in URL query strings is that URLs are frequently logged in plaintext by web servers, proxies, and browsers. This means the API key can be inadvertently exposed in server access logs, browser history, and referrer headers, making it accessible to anyone with access to those logs. Even with HTTPS encrypting the data in transit, the URL itself is often logged before decryption or after encryption at the termination point, so the key remains visible in log files.

Exam trap

ISC2 often tests the misconception that HTTPS fully protects the URL from all exposure, but the trap here is that while HTTPS encrypts data in transit, it does not prevent logging, caching, or referrer leakage of the URL.

How to eliminate wrong answers

Option B is wrong because HTTPS does encrypt the entire HTTP request, including the query string, during transit; the issue is not lack of encryption on the wire but exposure in logs and history. Option C is wrong because API keys are a valid authentication method and can be tied to a user session or application identity; the weakness here is not about session binding but about exposure in URLs. Option D is wrong because API keys are valid for use in query strings; they do not require a certificate, and certificates are used for TLS mutual authentication, not for API key transmission.

94
MCQmedium

A financial services firm stores sensitive customer records in a cloud object storage bucket. The security team wants to ensure that even if the cloud provider's internal staff or a compromised administrative account attempts to access the data, they cannot read it. The firm already uses provider-managed encryption at rest. Which additional control BEST achieves this requirement?

A.Configure a bucket policy that denies access to all principals except a specific IAM role.
B.Enable bucket versioning and object lock to prevent unauthorized deletion.
C.Enable default encryption with a customer-provided key stored in the cloud provider's KMS.
D.Implement client-side encryption where keys are managed by the firm and never shared with the provider.
AnswerD

Client-side encryption ensures data is encrypted before it reaches the cloud, and the firm retains sole control of the keys. Even provider staff or a compromised admin cannot decrypt without the firm's keys. This directly addresses the requirement that the provider cannot read the data, unlike provider-managed encryption where the provider holds the keys.

Why this answer

The requirement is to prevent the cloud provider from reading the data. Provider-managed encryption does not meet this because the provider holds the keys. Client-side encryption with firm-controlled keys ensures the provider only sees ciphertext.

Other options address access control, integrity, or key management within the provider, but none remove the provider's ability to decrypt.

Exam trap

The trap here is assuming that provider-managed encryption at rest prevents the cloud provider from accessing data, when in fact the provider holds the keys and can decrypt.

95
MCQmedium

A cloud customer stores data in a SaaS application that replicates across multiple jurisdictions. The customer's legal team must respond to a subpoena for data stored in a specific region. Which concept determines the legal authority over the data?

A.Data residency
B.Data localization
C.Data sovereignty
D.Data portability
AnswerC

Data sovereignty refers to the principle that data is subject to the laws and regulations of the country in which it is stored. In this scenario, the replication across jurisdictions means the data may be subject to multiple legal authorities. The subpoena's enforceability depends on which jurisdiction has sovereignty over the data at the time of the request, making this the key concept.

Why this answer

Data sovereignty is the legal principle that data is governed by the laws of the country where it resides. When data is replicated across regions, each copy may fall under different sovereign laws. A subpoena from one jurisdiction may not be enforceable in another, and the cloud provider may be caught between conflicting legal demands.

Understanding sovereignty helps legal teams navigate cross-border data requests and design compliance strategies.

Exam trap

The trap here is equating data residency with data sovereignty; residency is about physical location, while sovereignty is about which laws apply.

96
MCQmedium

A developer configures an AWS S3 bucket to allow public access by setting a bucket policy that grants 's3:GetObject' to 'Principal: *'. Which vulnerability does this introduce?

A.Mass assignment
B.SSRF vulnerability
C.Exposed S3 bucket
D.Over-permissive IAM
AnswerC

Granting `s3:GetObject` to `Principal: *` in a bucket policy authorises anonymous, unauthenticated reads of every object, directly satisfying the stem's public-access configuration. This is the defining mechanism of an exposed S3 bucket: no IAM identity, signed request, or credential is required, so anyone with the object URL retrieves the data.

Why this answer

Exposing an S3 bucket to anonymous access allows anyone to read objects, leading to data exposure. This is a common cloud misconfiguration.

97
Multi-Selectmedium

A cloud security manager is implementing data discovery and classification for a multi-cloud environment. The organization needs to automatically identify and tag sensitive data such as personally identifiable information (PII) and protected health information (PHI) across cloud storage services. Which two capabilities are essential for an effective data classification solution? (Choose two.)

Select 2 answers
A.Full-disk encryption of all cloud storage volumes to prevent unauthorized access to data at rest.
B.Pattern matching and regular expressions to detect structured data formats like credit card numbers and social security numbers.
C.A data loss prevention (DLP) policy that blocks all outbound traffic from cloud workloads to external networks.
D.Manual sampling of files by security analysts to determine data sensitivity based on business context.
E.Integration with cloud provider APIs to access and scan data across multiple storage services without requiring agents on every resource.
AnswersB, E

Pattern matching and regular expressions are essential for detecting structured sensitive data with known formats, such as credit card numbers and social security numbers. They enable automated scanning and tagging without manual review, which is critical for large-scale multi-cloud environments where data volume is high.

Why this answer

An effective data classification solution requires automated detection using pattern matching for structured data and API-based scanning to cover multi-cloud storage without agents. These capabilities enable scalable, consistent identification and tagging of sensitive data, which is the foundation for applying appropriate protections.

Exam trap

The trap here is confusing data protection controls like encryption or DLP blocking with the discovery and tagging capabilities that define classification.

98
MCQhard

During incident response in a cloud environment, a team needs to collect evidence from a compromised EC2 instance without altering the system. Which of the following is the best method to obtain a forensic memory dump?

A.Create an AMI of the instance
B.Enable detailed billing reports
C.Use the AWS CLI to execute a memory dump script on the instance (e.g., via AWS Systems Manager Run Command)
D.Take a snapshot of the root EBS volume
AnswerC

AWS Systems Manager Run Command executes the dump script remotely through the agent, so no interactive login, SSH session or local tooling alters the instance's volatile state. The memory image is written to an attached EBS volume, preserving evidence integrity for later analysis.

Why this answer

Using AWS Systems Manager Run Command to execute a memory dump script on the instance allows the team to capture volatile memory (RAM) while the instance is still running, preserving the system state. This method does not require stopping or modifying the instance, and it can be done remotely via the AWS CLI, making it the best option for forensic memory acquisition.

Exam trap

The trap is selecting disk-based methods (AMI, EBS snapshot) for memory capture; candidates must remember that AMIs and snapshots only capture disk, not RAM, and that memory forensics requires live acquisition.

How to eliminate wrong answers

Option A is wrong because creating an AMI captures the disk state, not memory, and may require stopping the instance, altering its state. Option B is wrong because detailed billing reports are for cost tracking, not forensic evidence. Option D is wrong because an EBS snapshot captures disk data, not volatile memory, and does not preserve running processes or network connections.

99
Multi-Selectmedium

A financial institution is evaluating a community cloud deployment shared with other banks. Which TWO security considerations are MOST important for this deployment model?

Select 2 answers
A.Minimizing network bandwidth to reduce costs
B.The provider assumes full responsibility for all security controls
C.Use of dedicated physical servers for each tenant
D.Ensuring strong isolation between tenant data and workloads
E.Compliance with common regulatory standards (e.g., PCI-DSS, SOX)
AnswersD, E

Tenant isolation is critical in a community cloud because multiple banks share the same infrastructure. Strong logical separation of data and workloads prevents one tenant from accessing another's resources, satisfying the constraint that shared infrastructure must not compromise confidentiality between competing financial institutions.

Why this answer

In a community cloud shared by multiple banks, option D is essential because tenants share the same underlying infrastructure, so strong logical isolation of data and workloads (via mechanisms like VLANs, hypervisor isolation, encryption, and access controls) is required to prevent cross-tenant data leakage or interference. Option E is also critical because a community cloud serving financial institutions must satisfy shared regulatory obligations such as PCI-DSS for cardholder data and SOX for financial reporting, and the provider and tenants must jointly demonstrate compliance. Option A is not a security consideration but a cost/performance concern, and minimizing bandwidth could even undermine security monitoring and logging.

Option B is incorrect because in cloud deployments security responsibility is shared, not fully transferred to the provider. Option C is not required for a community cloud, since multi-tenancy on shared physical servers is normal as long as isolation is enforced.

Exam trap

CCSP often tests the misconception that community cloud providers assume full security responsibility, when in fact the shared responsibility model still applies and tenants must secure their own data and configurations.

100
Multi-Selecteasy

A security team is reviewing controls for a cloud application that transmits personally identifiable information (PII) over the internet. Which TWO controls are essential for protecting data in transit?

Select 2 answers
A.Use of signed certificates from a trusted CA
B.Regular penetration testing
C.Implementation of IPsec VPNs
D.Use of TLS 1.2 or higher
E.Encryption at rest using AES-256
AnswersA, D

Signed certificates from a trusted certificate authority let the client verify the server's identity during the TLS handshake, preventing man-in-the-middle interception of PII in transit. Without this authentication, encryption alone cannot confirm the endpoint, so it satisfies the stem's essential control for protecting data in transit.

Why this answer

Option A is correct because signed certificates from a trusted Certificate Authority authenticate the server's identity and enable the client to establish a trusted TLS session, preventing man-in-the-middle attacks on PII in transit. Option D is correct because TLS 1.2 or higher provides strong, modern cryptographic protection (e.g., AES-GCM, ECDHE key exchange) for data transmitted over untrusted networks like the internet. Together, these controls directly secure data in transit by ensuring both endpoint authenticity and encryption.

Option B (penetration testing) is a validation activity, not a protective in-transit control. Option C (IPsec VPNs) can encrypt traffic but is not essential for a cloud application exposed to arbitrary internet clients, where TLS is the appropriate mechanism. Option E (AES-256 at rest) protects stored data, not data in transit.

Exam trap

ISC2 often tests the distinction between 'essential' controls for data in transit versus 'helpful' or 'related' controls, so candidates mistakenly pick IPsec VPNs (Option C) because they associate VPNs with secure transmission, even though TLS is the standard and essential control for web-based cloud applications.

101
MCQeasy

A cloud customer is evaluating a provider's compliance with the Payment Card Industry Data Security Standard (PCI DSS). The customer plans to store cardholder data in the provider's IaaS environment. Which responsibility does the customer retain under PCI DSS?

A.The customer is responsible only for physical security of the data center because the provider handles all logical controls.
B.The customer is responsible for configuring and managing the guest operating system, applications, and cardholder data environment, including access controls and encryption.
C.The customer is responsible for nothing because the provider's PCI DSS attestation covers all systems storing cardholder data.
D.The customer is responsible for all PCI DSS requirements because PCI DSS does not recognize shared responsibility models.
AnswerB

In IaaS, the customer controls the guest OS and above, so it must implement PCI DSS requirements for those layers, such as access control, encryption of cardholder data, and vulnerability management. The provider is responsible for the physical and hypervisor layers. PCI DSS requires each party to attest to the controls it operates, and the customer cannot outsource its compliance obligations for its own cardholder data environment.

Why this answer

Under PCI DSS in IaaS, the customer is responsible for the guest operating system, applications, and cardholder data environment, including access controls and encryption. The provider secures the physical and hypervisor layers. Each party must validate its own controls, and the customer cannot rely solely on the provider's attestation for its own compliance obligations.

Exam trap

The trap here is assuming that the provider's PCI DSS attestation absolves the customer of all responsibility, when the customer must still secure its own cardholder data environment.

102
Multi-Selecthard

A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The customer must ensure compliance with legal and regulatory requirements. Which TWO factors are most important to address in the contract with the provider? (Choose two.)

Select 2 answers
A.Require the provider to delete data from all backups and replicas within a specified timeframe
B.Require the provider to notify the customer before deleting data due to a legal hold
C.Specify the retention period and deletion timeline for data upon contract termination
D.Allow the provider to retain data for its own analytics purposes
E.Ensure the provider gives the customer a discount for early deletion
AnswersA, C

Cloud data is often replicated across multiple locations and backups. If deletion does not cover all copies, residual data could remain accessible or subject to legal discovery. Requiring deletion from all backups and replicas ensures complete data destruction, which is essential for meeting regulatory erasure requirements and avoiding unintended data retention.

Why this answer

The two most important factors are specifying retention and deletion timelines and ensuring deletion covers all backups and replicas. These directly address legal requirements for data minimization and secure disposal. The other options introduce financial incentives, provider data use, or legal hold notifications, which do not ensure compliant deletion and could create additional risks.

Exam trap

The trap here is focusing on cost or provider convenience instead of the legal necessity to delete all copies of data within defined timelines.

103
MCQhard

An incident response team is investigating a potential breach in a cloud environment. They have collected logs from various sources. Which of the following is the MOST critical factor to ensure the admissibility of digital evidence in court?

A.Maintaining a documented chain of custody for all evidence
B.Encrypting all evidence during collection and transport
C.Using automated tools for log analysis
D.Ensuring logs are in their original format
AnswerA

Chain of custody is crucial for admissibility.

Why this answer

Maintaining the chain of custody ensures evidence integrity and admissibility. Option B is wrong while important for investigation, admissibility depends on custody. Option C is wrong because logs may not be original but certified copies can be used if chain of custody is maintained.

Option D is wrong because encryption does not guarantee authenticity.

104
Multi-Selectmedium

A cloud architect is designing a multi-tenant SaaS application. Which TWO isolation mechanisms are essential to prevent tenant data leakage? (Choose two.)

Select 2 answers
A.Geographic isolation
B.Network isolation (e.g., VLANs, VPCs)
C.Shared storage volume encryption
D.Logical data isolation (e.g., database per tenant)
E.Hypervisor isolation
AnswersB, D

VLANs and VPCs segment tenant traffic at the network layer, preventing one tenant's workloads from reaching another's and blocking lateral movement. This satisfies the stem's requirement for essential isolation mechanisms preventing tenant data leakage in the multi-tenant SaaS application.

Why this answer

Option B (Network isolation, e.g., VLANs, VPCs) is correct because segmenting tenant traffic at Layer 2/Layer 3 with VLANs or cloud VPCs and security groups prevents cross-tenant lateral movement and unauthorized access to another tenant's resources, which is a foundational control against data leakage in multi-tenant SaaS. Option D (Logical data isolation, e.g., database per tenant) is correct because separating tenant records through per-tenant databases, schemas, or tenant-ID row-level filtering ensures that queries and application logic cannot read or modify another tenant's data even if a request is misrouted. Option A (Geographic isolation) is not essential here because placing tenants in different regions addresses residency and latency, not the core logical separation needed to stop data leakage between tenants sharing the same application.

Option C (Shared storage volume encryption) is insufficient because encrypting a shared volume protects data at rest but does not prevent one tenant's application context from accessing another tenant's records on that same volume. Option E (Hypervisor isolation) is not the essential mechanism for this scenario because it separates VMs at the virtualization layer, whereas multi-tenant SaaS typically shares application and database tiers where network and logical data isolation are the decisive controls.

Exam trap

CCSP often tests the misconception that encryption or hypervisor isolation alone prevents tenant data leakage, when logical and network isolation are the controls that actually enforce tenant boundaries.

105
MCQeasy

Which of the following is the primary security risk associated with VM escape in a cloud environment?

A.Performance degradation of the VM
B.Loss of network connectivity
C.Data corruption within the VM
D.Unauthorized access to other tenants' VMs and the hypervisor
AnswerD

VM escape exploits a hypervisor or virtualisation flaw so code inside a guest breaks isolation and executes at the hypervisor layer. From there an attacker reads or controls other tenants' VMs on the same host, defeating multi-tenancy separation.

Why this answer

VM escape occurs when an attacker breaks out of the guest VM's isolation boundary and gains access to the hypervisor or other tenants' VMs. The primary security risk is therefore unauthorized access to other tenants' workloads and the hypervisor itself, which can lead to full compromise of the multi-tenant host. This breaks the fundamental isolation guarantee that cloud providers rely on.

Exam trap

The trap is selecting a performance or availability symptom — candidates must recognize that VM escape is fundamentally a confidentiality and isolation breach affecting other tenants and the hypervisor, not a local VM issue.

How to eliminate wrong answers

Option A is wrong because performance degradation is an availability concern, not the security consequence of escaping the isolation boundary; a VM escape is about confidentiality and integrity of other tenants. Option B is wrong because loss of network connectivity is a functional disruption, not the core security risk of hypervisor breakout. Option C is wrong because data corruption within the same VM is contained to that tenant and does not represent the cross-tenant or hypervisor-level compromise that defines VM escape.

106
MCQeasy

An organization uses a cloud-based SIEM solution. Which cloud service provides native integration to stream audit logs into the SIEM?

A.Security monitoring service
B.Centralized logging service
C.Policy management service
D.Recommendation service
AnswerB

A centralised logging service natively collects and forwards audit trails from cloud resources, providing the direct streaming integration the SIEM consumes. It removes the need for custom agents or polling, satisfying the native-integration constraint in the stem.

Why this answer

A centralized logging service is the cloud service that natively aggregates audit logs from multiple sources and can stream them into a SIEM, because its core function is to collect, store, and forward log data. Native integration to stream audit logs into a SIEM is a defining capability of centralized logging services such as AWS CloudTrail with CloudWatch Logs, Azure Monitor Logs, or Google Cloud Logging. The other options describe different security functions that do not provide the log-streaming pipeline the SIEM needs.

Exam trap

CCSP often tests the confusion between log aggregation services and detection or policy services, so candidates must pick the service whose primary purpose is collecting and streaming logs, not one that analyzes or recommends.

How to eliminate wrong answers

Option A is wrong because a security monitoring service focuses on detecting threats and generating findings (for example, Amazon GuardDuty or Security Hub), not on being the native log aggregation and streaming source for a SIEM. Option C is wrong because a policy management service enforces and audits configuration and compliance rules (for example, AWS Config or Azure Policy); it evaluates resource state rather than streaming raw audit logs. Option D is wrong because a recommendation service provides best-practice suggestions (for example, AWS Trusted Advisor or Azure Advisor) and has no role in log ingestion or SIEM integration.

107
MCQeasy

A company wants to ensure that its cloud provider's data deletion process is verifiable. Which of the following should the company require in the service level agreement?

A.Service level credits
B.Certificate of destruction
C.Annual penetration testing
D.Right to audit
AnswerB

A certificate of destruction is a formal attestation that data was securely erased, providing auditable evidence the provider's deletion process actually occurred. This satisfies the requirement for verifiable deletion, unlike contractual wording or encryption alone.

Why this answer

A Certificate of Destruction (CoD) is a formal, signed document from the cloud provider that attests to the secure deletion or sanitization of the customer's data at the end of its lifecycle. It provides verifiable evidence that the deletion process occurred as specified, which is critical for compliance with regulations like GDPR, HIPAA, and PCI DSS. Without such a certificate, the company has no independent proof that data was actually destroyed, making it impossible to demonstrate due diligence to auditors or regulators.

Exam trap

CCSP often tests the difference between contractual rights (right to audit) and verifiable evidence (certificate of destruction); candidates may choose 'right to audit' thinking it provides proof, but it only grants permission to check, not proof itself.

How to eliminate wrong answers

Option A is wrong because service level credits are financial penalties or refunds for failing to meet performance metrics (e.g., uptime), not evidence of data deletion. Option C is wrong because annual penetration testing assesses security vulnerabilities but does not verify data deletion processes or provide proof of destruction. Option D is wrong because the right to audit allows the company to inspect the provider's controls and processes, but it does not itself constitute verifiable proof that deletion occurred; it is a contractual right, not a certification of an event.

108
MCQhard

A financial services firm runs a multi-tenant SaaS platform on AWS. A penetration test reveals that a compromised container on one tenant's node was able to read environment variables belonging to another tenant's pods scheduled on the same node. The platform uses Kubernetes with default settings, and pods are not configured with any security context. Which control most directly addresses this isolation failure?

A.Configure pod security contexts to run containers as non-root with readOnlyRootFilesystem and drop all Linux capabilities.
B.Encrypt all Kubernetes Secrets at rest using a KMS provider and rotate the encryption keys quarterly.
C.Enable Kubernetes Network Policies that deny all ingress and egress by default between namespaces.
D.Deploy each tenant's workloads using a dedicated container runtime sandbox such as gVisor or Kata Containers, or enforce pod-level isolation with user namespaces and separate runtime classes.
AnswerD

The leak occurred because containers on the same node share kernel and, in some configurations, process namespaces that allow visibility into sibling workloads. Stronger isolation boundaries such as gVisor, Kata Containers, or user namespaces with distinct runtime classes prevent one tenant's container from observing another's process environment. This directly closes the cross-tenant visibility path observed by the penetration test.

Why this answer

When containers share a node without strong isolation, one workload can sometimes observe another's process environment or runtime metadata. Enforcing dedicated sandboxes such as gVisor or Kata Containers, or isolating with user namespaces and distinct runtime classes, creates a hard boundary between tenants. This is the control that directly addresses the cross-tenant environment variable exposure described.

Exam trap

The trap here is assuming that pod-level hardening or network policies solve a node-level namespace isolation problem; those controls harden a single workload but do not separate tenants sharing a kernel.

109
MCQmedium

A multinational corporation must store customer data in specific geographic regions to comply with data sovereignty laws. Which cloud storage feature should they configure to ensure data does not leave a designated region?

A.Signed URLs
B.Cross-region replication
C.Object versioning
D.Region selection for storage buckets
AnswerD

Selecting a region for storage buckets pins object data and replicas to that geography, so customer data is written and remains within the designated jurisdiction. This directly satisfies the data sovereignty constraint that data must not leave the specified region.

Why this answer

Region selection for storage buckets allows the organization to choose the geographic region where data is stored, ensuring it does not leave the designated jurisdiction. This directly addresses data sovereignty requirements. Signed URLs, cross-region replication, and object versioning do not control the geographic location of stored data.

Exam trap

The trap is choosing cross-region replication because it sounds like a resilience feature — but replication moves data across regions, directly violating data sovereignty, whereas region selection keeps data in place.

How to eliminate wrong answers

Option A is wrong because signed URLs grant temporary access to objects but do not determine where data is stored. Option B is wrong because cross-region replication actively copies data to another region, which would violate data sovereignty by moving data outside the designated region. Option C is wrong because object versioning retains multiple versions of an object in the same region, which does not address geographic placement.

110
MCQeasy

Which hypervisor type is most commonly deployed in production cloud data centers to host multiple tenant virtual machines?

A.Type 1 bare-metal hypervisor like VMware ESXi
B.Container runtime like Docker
C.Para-virtualization interface
D.Type 2 hosted hypervisor like VirtualBox
AnswerA

Type 1 hypervisors such as VMware ESXi run directly on hardware and are the standard production platform in cloud data centres, hosting many tenant VMs per physical host. Type 2 hypervisors run atop a host OS and are unsuitable for that scale and isolation.

Why this answer

Type 1 (bare-metal) hypervisors run directly on hardware and are used in cloud environments for better performance and isolation.

111
MCQmedium

An organization uses Azure Defender for Cloud to protect their hybrid environment. They want to receive alerts about suspicious activities on their Azure Key Vault. Which Defender plan should they enable?

A.Defender for Databases
B.Defender for Containers
C.Defender for Servers
D.Defender for Key Vault
AnswerD

Defender for Key Vault monitors Azure Key Vault control-plane and data-plane operations, detecting anomalous access, suspicious secret retrieval and unusual vault activity. It satisfies the stem's requirement for alerts on suspicious Key Vault activity within the hybrid environment, unlike plans scoped to servers, storage or containers.

Why this answer

Defender for Key Vault is the specific plan designed to provide advanced threat protection for Azure Key Vault. It monitors access patterns and operations on the vault to detect suspicious activities such as unauthorized access attempts, credential theft, or anomalous secret retrieval, and generates security alerts accordingly.

Exam trap

A common trap is that candidates may assume a general plan like Defender for Servers covers all Azure services, but each Defender plan is scoped to a specific service category, such as Defender for Key Vault for Key Vault security.

How to eliminate wrong answers

Option A is wrong because Defender for Databases protects Azure SQL, SQL Server on VMs, and other database services, not Key Vault. Option B is wrong because Defender for Containers secures containerized environments like AKS, ACR, and Kubernetes workloads, not Key Vault. Option C is wrong because Defender for Servers provides threat detection for virtual machines and on-premises servers, not for Key Vault.

112
MCQeasy

A development team is working with production-like data in a non-production cloud environment. To comply with data privacy regulations, sensitive fields must be obscured without being retrievable. Which technique should they apply?

A.Format-preserving encryption
B.Reversible masking
C.Irreversible masking
D.Tokenization
AnswerC

Irreversible masking permanently replaces sensitive values so the original data cannot be reconstructed, satisfying the non-retrievable requirement. Reversible techniques such as tokenisation or encryption preserve recoverability, which would breach the privacy constraint in this non-production environment.

Why this answer

Irreversible masking (C) is correct because it transforms sensitive data into a non-reversible format, ensuring that the original values cannot be retrieved. This meets the requirement of obscuring production-like data in a non-production environment while complying with data privacy regulations that prohibit reversible transformations. Unlike encryption or tokenization, irreversible masking does not provide any decryption or mapping mechanism, making it suitable for scenarios where data must be permanently de-identified.

Exam trap

ISC2 often tests the distinction between reversible and irreversible data protection methods, and the trap here is that candidates confuse 'masking' (which can be reversible or irreversible) with 'encryption' or 'tokenization,' assuming any transformation that hides data is sufficient, without recognizing the critical requirement of non-retrievability.

How to eliminate wrong answers

Option A is wrong because format-preserving encryption (FPE) is a reversible cryptographic technique that allows the original data to be recovered with the correct key, which violates the requirement that sensitive fields must be obscured without being retrievable. Option B is wrong because reversible masking, by definition, includes a method to restore the original data (e.g., via a lookup table or deterministic algorithm), which does not satisfy the 'not retrievable' condition. Option D is wrong because tokenization replaces sensitive data with a token that is mapped back to the original value in a secure vault, providing reversibility and thus failing the requirement for irreversible obscuration.

113
MCQmedium

An incident response playbook for a cloud environment includes containment steps. For a compromised IAM user in AWS, which action is least likely to be effective for containment?

A.Disable the IAM user
B.Change the IAM user's password
C.Attach a DenyAll policy to the user
D.Disable the IAM user's access keys
AnswerB

Changing the password does not revoke existing credentials. An attacker holding active access keys or session tokens continues operating, so this containment step fails. Deactivating the user, deleting access keys and revoking sessions are required to actually cut off access.

Why this answer

Changing the IAM user's password does not invalidate existing authenticated sessions or tokens (such as temporary credentials from STS or access keys). An attacker who has already established a session or obtained access keys can continue to use them until they expire or are explicitly revoked. Therefore, password change alone is ineffective for immediate containment.

Exam trap

The misconception that changing a password is a universal containment action is common, but in cloud environments with multiple credential types (access keys, STS tokens), password changes alone are insufficient to stop ongoing abuse.

How to eliminate wrong answers

Option A is wrong because disabling the IAM user immediately revokes all permissions and terminates any active sessions, making it a highly effective containment step. Option C is wrong because attaching a DenyAll policy explicitly denies all actions for that user, effectively blocking any further malicious activity even if the user remains enabled. Option D is wrong because disabling the user's access keys prevents any API calls signed with those keys, cutting off a common attack vector for programmatic access.

114
MCQhard

A cloud security operations team is evaluating SIEM solutions. They need to minimize false positives while ensuring critical security events are not missed. Which of the following is the MOST effective technique to achieve this balance?

A.Implement context-aware correlation and tune rules based on feedback loops
B.Aggregate all security events into a single correlation rule
C.Increase the alert threshold for all event types to reduce noise
D.Rely exclusively on signature-based detection
AnswerA

Context-aware correlation links events across sources and entities, so alerts are judged against asset criticality and user behaviour rather than isolated signatures. Feedback-loop tuning then adjusts thresholds from analyst verdicts, cutting false positives without suppressing genuine critical events, which is the balance the stem requires.

Why this answer

Context-aware correlation leverages environmental context (e.g., asset value, user behavior) to reduce false positives while maintaining sensitivity. Feedback loops allow continuous tuning based on actual incidents. Option B is incorrect because aggregating all events into a single rule increases noise and makes analysis difficult.

Option C is incorrect because increasing thresholds may cause true positives to be missed. Option D is incorrect because signature-based detection alone cannot detect novel attacks and may miss critical events.

115
MCQmedium

A security team is implementing Data Loss Prevention (DLP) for a SaaS application that stores customer PII. They want to detect when sensitive data is shared externally via email. Which is the best approach?

A.Implement database DLP to monitor queries to the PII database
B.Install endpoint DLP agents on all user devices
C.Use the SaaS application's API DLP rules to scan email content and attachments
D.Deploy network DLP at the cloud provider's network perimeter
AnswerC

API-based DLP inspects email content and attachments directly within the SaaS platform, catching external shares regardless of endpoint or transport. This satisfies the constraint of detecting sensitive PII leaving via the application's own email channel.

Why this answer

SaaS application API DLP rules can inspect email content and attachments directly within the application, effectively detecting sensitive data shared externally via email. Option A is wrong because database DLP monitors queries to the database, not email communications. Option B is wrong because endpoint DLP agents on user devices may not be able to inspect cloud-based email traffic that is accessed via browser.

Option D is wrong because network DLP at the cloud provider's perimeter cannot inspect encrypted email traffic (e.g., TLS) and is less effective for SaaS-based email.

116
MCQeasy

A cloud operations team is deploying a new web application on Google Cloud Platform (GCP). They need to ensure that all incoming traffic to their Compute Engine instances is inspected for common web attacks such as SQL injection and cross-site scripting. They also want to minimize latency and management overhead. Which GCP service should they use?

A.VPC Service Controls
B.Cloud Armor
C.Identity-Aware Proxy (IAP)
D.Cloud IDS
AnswerB

Cloud Armor is GCP's web application firewall (WAF) and DDoS protection service. It provides preconfigured WAF rules to mitigate OWASP Top 10 risks like SQL injection and XSS. It integrates with HTTP(S) load balancing, inspecting traffic at the edge, which minimizes latency. It is fully managed, reducing operational overhead.

Why this answer

Cloud Armor is the GCP service designed to protect web applications from application-layer attacks. It provides WAF rules that can block SQL injection and XSS, and it integrates with load balancing to inspect traffic at the edge. This minimizes latency and is fully managed, meeting the requirements for security and low overhead.

Exam trap

The trap here is confusing network-level security services like Cloud IDS or access control services like IAP with a web application firewall, which operates at the application layer.

117
MCQhard

A cloud customer is subject to an eDiscovery request and stores business records in a cloud object storage service. The legal team needs to preserve potentially relevant data and prevent it from being altered or deleted while the matter is active. Which cloud capability should the customer configure to meet this obligation?

A.Enable versioning on the bucket so previous object versions remain available after overwrite or deletion.
B.Enable cross-region replication so a secondary copy exists in another region if the primary copy is deleted.
C.Apply an object lock with a retention mode and legal hold to prevent deletion or overwrite for the required period.
D.Configure a lifecycle policy that transitions objects to cold storage after 30 days to reduce cost.
AnswerC

Object lock provides write-once-read-many (WORM) protection and, in governance or compliance mode, prevents objects from being deleted or overwritten until the retention period expires. A legal hold can also be applied independently to prevent deletion. This directly satisfies the duty to preserve data during active litigation.

Why this answer

A legal hold requires that potentially relevant data be preserved and protected from alteration or deletion. Object lock, especially in compliance mode, enforces immutability for a defined retention period, and a legal hold flag prevents deletion regardless of retention expiry. These controls give the customer a defensible preservation mechanism that survives administrative actions and supports eDiscovery obligations.

Exam trap

The trap here is confusing backup or replication features, which aid recovery, with immutability controls that legally prevent deletion or modification.

118
Multi-Selectmedium

A cloud security team is deploying a web application with an API Gateway. Which TWO mechanisms should be implemented to protect against API abuse and unauthorized access?

Select 2 answers
A.Rate limiting
B.TLS enforcement
C.Resource tagging
D.VPC peering
E.Authentication (e.g., JWT validation)
AnswersA, E

Rate limiting caps request volume per client or API key, throttling brute-force attempts, credential stuffing and volumetric abuse before they reach backend services. It directly addresses the API abuse constraint by bounding how many calls an attacker can issue.

Why this answer

Rate limiting (A) is correct because it throttles the number of requests a client can make in a given time window, directly mitigating API abuse such as brute-force attempts, credential stuffing, and denial-of-service floods that would otherwise overwhelm the gateway and backend. Authentication with JWT validation (E) is correct because it verifies the identity and integrity of the caller by validating the token's signature, issuer, audience, and expiry before granting access, thereby preventing unauthorized access to protected API routes. TLS enforcement (B) only encrypts data in transit and does not by itself stop abuse or authenticate API clients, so it does not satisfy the requirement.

Resource tagging (C) is a metadata and governance mechanism for cost allocation and organization, not a runtime access control. VPC peering (D) provides private network connectivity between VPCs but does not protect an internet-facing API Gateway against abuse or unauthorized callers.

Exam trap

The trap here is selecting TLS enforcement as a security control for API abuse, confusing confidentiality with availability and access control.

119
MCQmedium

An organization uses cloud object storage with versioning enabled. After a ransomware attack, they discover that many objects were encrypted by the attacker. How does versioning help in this scenario?

A.It allows restoration of the previous unencrypted version of each object
B.It replicates objects to a different region for disaster recovery
C.It prevents any object from being overwritten or deleted
D.It automatically encrypts all objects with customer-managed keys
AnswerA

Versioning retains prior copies of an object rather than overwriting them, so the attacker's encrypted write becomes a new version while the original unencrypted version remains intact. The analyst can restore that earlier version, recovering the data without paying a ransom.

Why this answer

Object versioning retains multiple versions of an object, so if a current version is encrypted by ransomware, the previous unencrypted version can be restored. This provides a recovery mechanism without paying a ransom. Versioning is a key data protection feature in cloud object storage.

Exam trap

The trap is confusing versioning with replication or immutability, or assuming versioning prevents deletion; the exam tests that versioning enables restoration of previous versions.

How to eliminate wrong answers

Option B is wrong because replication is a separate feature (e.g., S3 Cross-Region Replication) and not a function of versioning. Option C is wrong because versioning does not prevent overwrites or deletions; it only preserves previous versions. Option D is wrong because versioning does not automatically encrypt objects; encryption is a separate configuration.

120
MCQhard

An organization is designing a multi-cloud strategy using containers to avoid vendor lock-in. Which of the following approaches BEST ensures portability of containerized applications across different cloud providers?

A.Use cloud provider-specific container services like Amazon ECS with proprietary APIs.
B.Use nested containers to abstract the underlying cloud provider.
C.Standardize on Docker images and Kubernetes orchestration with open-source tooling.
D.Deploy containers directly on virtual machines without an orchestration layer.
AnswerC

Standardising on Docker images with Kubernetes orchestration and open-source tooling removes provider-specific dependencies, so the same artefacts deploy unchanged across clouds. This directly satisfies the stem's portability requirement, unlike managed proprietary services that bind workloads to one vendor.

Why this answer

Standardizing on Docker images and Kubernetes orchestration with open-source tooling (C) best ensures portability because Docker images are OCI-compliant and Kubernetes is a CNCF-graduated project supported by all major cloud providers. This combination avoids proprietary APIs and allows workloads to be moved between AWS EKS, Azure AKS, Google GKE, or on-premises clusters with minimal changes. Open-source tooling further reduces lock-in by providing consistent APIs and configuration formats.

Exam trap

CCSP often tests the assumption that using containers automatically guarantees portability, when in fact proprietary orchestration services and cloud-specific integrations can reintroduce lock-in.

How to eliminate wrong answers

Option A is wrong because using cloud provider-specific services like Amazon ECS with proprietary APIs creates vendor lock-in — migrating to another cloud would require rewriting task definitions, IAM policies, and networking configurations. Option B is wrong because nested containers add complexity and do not abstract the underlying cloud provider; they still run on the provider's infrastructure and do not solve portability of orchestration or networking. Option D is wrong because deploying containers directly on VMs without an orchestration layer lacks the abstraction and automation needed for portability; it ties deployments to specific VM configurations and manual processes, making cross-cloud migration difficult.

121
MCQhard

During a threat modeling session for a cloud application, the team identifies a risk where an attacker could trick the application into making HTTP requests to the cloud metadata endpoint (e.g., http://169.254.169.254). What is the most critical impact of this attack?

A.Denial of service to the metadata service
B.Modification of the cloud instance's configuration
C.Retrieval of temporary IAM credentials for the instance
D.Exposure of the application's source code
AnswerC

The instance metadata service answers unauthenticated requests from the instance itself, so server-side request forgery reaches it and returns the attached role's temporary IAM credentials. Those credentials permit API calls at the instance profile's privilege level, making credential theft the critical impact.

Why this answer

The cloud metadata endpoint (169.254.169.254) is a link-local address accessible from within the instance, and it serves temporary IAM credentials to the instance's role. If an attacker can trick the application into making HTTP requests to this endpoint (via SSRF), they can retrieve those credentials and use them to access cloud resources with the instance's permissions. This is the most critical impact because it leads to privilege escalation and potential full account compromise, far exceeding DoS, configuration modification, or source code exposure.

Exam trap

CCSP often tests the misconception that SSRF to metadata only leads to information disclosure of instance details, when in fact the most critical impact is the retrieval of temporary IAM credentials that can be used for lateral movement and privilege escalation.

How to eliminate wrong answers

Option A is wrong because denial of service to the metadata service is a minor availability issue and not the primary goal of such an attack; the metadata service is not typically a target for DoS. Option B is wrong because modification of the instance's configuration is not directly achieved through SSRF to the metadata endpoint; the endpoint primarily provides read access to credentials and instance data, not write access to configuration. Option D is wrong because exposure of the application's source code is unrelated to the metadata endpoint; source code is not stored there, and SSRF to metadata does not inherently expose application code.

122
MCQeasy

A company must ensure that cloud storage data is retained even if authorized users attempt to delete it, to comply with a legal hold. Which configuration is most effective?

A.Implement data classification labels
B.Enable immutable storage (WORM) on the bucket
C.Enable versioning on the storage bucket
D.Encrypt data with customer-managed keys
AnswerB

WORM immutability enforces retention at the storage layer, so objects cannot be overwritten or deleted until the retention period expires, even by privileged users. This satisfies the legal hold requirement, unlike IAM policies or soft delete, which authorised users can still circumvent or reverse.

Why this answer

Immutable storage (WORM) on a bucket prevents any object from being deleted or overwritten for a specified retention period, even by authorized users or the root account. This directly enforces legal hold requirements by making data tamper-proof and deletion-proof at the storage layer, regardless of user permissions.

Exam trap

ISC2 often tests the misconception that versioning alone provides legal hold protection, but versioning only preserves previous versions and does not block deletion of the current version or all versions via a lifecycle policy.

How to eliminate wrong answers

Option A is wrong because data classification labels only tag data with metadata (e.g., sensitivity level) but do not enforce any retention or deletion prevention; they are a governance tool, not a technical control. Option C is wrong because versioning retains overwritten or deleted object versions but still allows deletion of the current version and does not prevent permanent deletion of all versions; it is not a legal hold mechanism. Option D is wrong because encryption with customer-managed keys protects data confidentiality but does not prevent deletion of the encrypted objects; the storage system can still delete the ciphertext and keys.

123
MCQmedium

A cloud security manager is implementing a data retention policy for a SaaS CRM that stores customer contact records. Regulations require that records be irreversibly destroyed after seven years, but the SaaS provider's recycle bin retains deleted records for 30 days and backups persist for 90 days. Which cloud data disposal approach best satisfies the regulatory requirement?

A.Use crypto-shredding by deleting the per-tenant data encryption key and allowing key material to be destroyed after the retention period.
B.Overwrite the CRM database fields containing contact records with null values using the provider's bulk update API.
C.Configure the SaaS recycle bin to empty automatically every 30 days and rely on the provider's backup expiration after 90 days.
D.Issue a formal written request to the SaaS provider asking them to delete all customer records and confirm completion in a service report.
AnswerA

Crypto-shredding renders data unrecoverable by destroying the keys that protect it, which is effective even when residual copies exist in backups or recycle bins. In this scenario, the provider's recycle bin and backup retention windows mean logical deletion alone is insufficient, so destroying the per-tenant key after seven years ensures the records cannot be reconstructed, satisfying the irreversible destruction requirement.

Why this answer

Crypto-shredding is the most reliable cloud disposal method when data may persist in backups, replicas, or provider recycle bins. By destroying the per-tenant encryption key after the seven-year retention period, the records become cryptographically unrecoverable regardless of residual copies. Logical deletion, provider attestations, and field overwrites do not guarantee irreversible destruction in a shared-responsibility SaaS environment.

Exam trap

The trap here is assuming that deleting records through the application or asking the provider to delete them satisfies irreversible destruction, when residual backups and recycle bins can keep the data recoverable.

124
Drag & Dropmedium

Drag and drop the steps for implementing a data retention policy for cloud storage (e.g., Amazon S3) into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First classify data, then define retention, configure lifecycle, enable immutability, and test.

125
MCQhard

A U.S. financial services firm uses a cloud provider with data centers in the EU. The firm must comply with both SEC regulations requiring books and records preservation and the GDPR. A data subject requests erasure of personal data that is also subject to a legal hold. What should the firm do?

A.Immediately erase all personal data to comply with the GDPR erasure request, because data subject rights override legal retention obligations.
B.Assess the scope of the legal hold, retain only the data subject to the hold under restricted processing, and erase or anonymize other personal data as required by the GDPR request.
C.Transfer all personal data to a third country outside the EU to avoid GDPR jurisdiction, then erase it there.
D.Deny the erasure request entirely and retain all data indefinitely, because legal holds always supersede data subject rights.
AnswerB

This approach respects both regimes. GDPR Article 17(3)(b) permits retention when necessary for legal obligations, but the firm should limit retention to data actually subject to the hold and restrict its processing. Data outside the hold should be erased or anonymized to satisfy the erasure request. This balanced, documented approach is the legally sound method for conflicting obligations.

Why this answer

When GDPR erasure requests conflict with legal holds, the firm must apply GDPR Article 17(3)(b), which permits retention when necessary to comply with a legal obligation. The correct approach is to scope the hold, retain only the data subject to it under restricted processing, and erase or anonymize the rest. This satisfies both the legal hold and the data subject's rights to the extent possible.

Exam trap

The trap here is assuming either that GDPR erasure always overrides legal holds or that legal holds always override erasure; the correct approach requires scoping and balancing both obligations.

126
Multi-Selecteasy

An organization wants to ensure compliance with industry regulations by implementing data classification in the cloud. Which two actions should the organization take? (Choose two.)

Select 2 answers
A.Implement auditing of access to sensitive data.
B.Store all data in a single repository for easy management.
C.Define data sensitivity levels and apply labels.
D.Encrypt all data regardless of classification.
E.Automatically tag all data as it is created.
AnswersA, C

Auditing access to sensitive data provides the evidentiary trail regulators require, recording who accessed which classified resource and when. This directly satisfies the compliance constraint in the stem: classification alone is static, whereas audit logging proves ongoing enforcement and supports incident investigation, demonstrating accountability to auditors.

Why this answer

Option A is correct because implementing auditing of access to sensitive data provides the traceability and accountability records required to demonstrate regulatory compliance, capturing who accessed which classified data and when. Option C is correct because data classification must begin with defined sensitivity levels (for example, Public, Internal, Confidential, Restricted) and labels applied to data so that handling, protection, and retention policies can be enforced consistently. Together, these two actions establish both the classification scheme and the monitoring needed to prove compliance.

Option B is not appropriate because consolidating all data into a single repository increases blast radius and does not by itself satisfy classification or regulatory requirements. Option D is wrong because encrypting all data indiscriminately ignores classification-based handling and can be impractical or unnecessary for public data. Option E is wrong because automatically tagging all data at creation without a defined sensitivity scheme produces unreliable labels and does not establish meaningful classification.

Exam trap

ISC2 often tests the misconception that encryption alone satisfies compliance requirements, but the trap here is that encryption is a control, not a classification mechanism, and without auditing and defined sensitivity levels, compliance cannot be proven.

127
MCQeasy

A company wants to ensure that their cloud deployment has the highest level of isolation between tenants. Which deployment model is most appropriate?

A.Public cloud
B.Hybrid cloud
C.Private cloud
D.Community cloud
AnswerC

A private cloud dedicates compute, storage and networking to a single organisation, eliminating the shared hypervisor, hardware and network paths that multi-tenant public clouds rely on. This delivers the strongest tenant isolation, satisfying the requirement for the highest level of separation between tenants.

Why this answer

Private cloud (Option C) is correct because it is a single-tenant environment where the cloud infrastructure is dedicated exclusively to one organization, providing the highest level of isolation between tenants. In a private cloud, network segmentation is achieved through technologies such as VLANs (IEEE 802.1Q), VXLANs (RFC 7348), and dedicated hypervisor-level resource pools, ensuring that no other tenant's workloads share the same physical or virtual resources. This eliminates the multi-tenancy risks inherent in public and community clouds, where isolation relies on shared infrastructure and logical separation mechanisms like hypervisor-enforced memory isolation and network overlays.

Exam trap

ISC2 often tests the misconception that hybrid cloud provides the highest isolation because it includes a private component, but the trap is that hybrid cloud still incorporates a public cloud element, which inherently introduces multi-tenancy and reduces overall isolation compared to a fully private cloud.

How to eliminate wrong answers

Option A is wrong because public cloud deployments rely on multi-tenant architectures where multiple customers share the same physical infrastructure, with isolation achieved through logical controls such as hypervisor memory isolation, network ACLs, and tenant-specific encryption keys; this inherently provides lower isolation compared to a dedicated private cloud. Option B is wrong because hybrid cloud combines private and public cloud resources, and while the private portion offers high isolation, the public cloud component introduces multi-tenancy, reducing the overall isolation level across the deployment. Option D is wrong because community cloud is a multi-tenant model shared among several organizations with common concerns (e.g., regulatory compliance), and while it offers some isolation via policy-based segmentation, it does not achieve the dedicated, single-tenant isolation of a private cloud.

128
MCQmedium

A security engineer is evaluating vulnerability management options for cloud workloads and wants to identify vulnerabilities without installing agents on the operating system. Which approach should be used?

A.Network-based vulnerability scanning
B.Agentless scanning using cloud API-based assessment
C.Agent-based scanning using a cloud-specific vulnerability scanner
D.Container image scanning in a registry
AnswerB

Agentless scanning queries the cloud provider's APIs to enumerate resources and compare their configurations against vulnerability and patch baselines, so no software is installed on the guest OS. This directly satisfies the stem's constraint of identifying vulnerabilities without deploying agents.

Why this answer

Agentless scanning leverages cloud provider APIs (e.g., for configuration and asset inventory) to assess the configuration and patch state of cloud workloads without requiring an OS-level agent. This approach directly meets the requirement of identifying vulnerabilities without installing agents on the operating system, as it reads metadata and configuration snapshots from the cloud control plane.

Exam trap

The trap here is that candidates often confuse 'agentless scanning' with 'network-based scanning,' assuming that any scan without an OS agent must be network-based, but the CCSP exam specifically tests the cloud-native API-driven assessment model as the correct agentless approach for cloud workloads.

How to eliminate wrong answers

Option A is wrong because network-based vulnerability scanning (e.g., Nmap, Nessus) requires network connectivity and often relies on OS fingerprinting or banner grabbing, but it cannot reliably assess internal OS-level vulnerabilities (e.g., missing patches, registry misconfigurations) without agent-based or authenticated access, and it still does not avoid the need for some form of OS interaction. Option C is wrong because agent-based scanning using AWS Inspector explicitly requires installing an agent on the EC2 instance to collect OS-level telemetry, which contradicts the requirement to avoid agents. Option D is wrong because container image scanning in a registry (e.g., Amazon ECR scanning, Trivy) only analyzes static images at rest, not running cloud workloads, and does not address vulnerabilities in the OS of running instances or virtual machines.

129
MCQeasy

A security architect is designing a multi-tenant cloud environment. Which type of hypervisor provides the strongest isolation for tenant virtual machines by running directly on the hardware without a host operating system?

A.Type 1 hypervisor
B.Type 2 hypervisor
C.Virtual machine monitor in user space
D.Container runtime
AnswerA

A Type 1 hypervisor runs directly on bare-metal hardware without an underlying host OS, eliminating the host kernel as a shared attack surface and providing stronger isolation between tenant virtual machines than hosted Type 2 hypervisors.

Why this answer

A Type 1 hypervisor runs directly on the hardware without a host operating system, providing stronger isolation for tenant virtual machines. This bare-metal architecture reduces the attack surface and prevents tenant VMs from interfering with each other through a host OS. Therefore, it is the correct answer for the strongest isolation in a multi-tenant cloud environment.

Exam trap

The trap is confusing Type 1 and Type 2 hypervisors, or assuming containers provide equivalent isolation; candidates must remember that Type 1 runs on bare metal and offers the strongest isolation.

How to eliminate wrong answers

Option B is wrong because a Type 2 hypervisor runs on top of a host operating system, which introduces additional overhead and potential vulnerabilities, making isolation weaker. Option C is wrong because a virtual machine monitor in user space is essentially a Type 2 hypervisor, which does not provide the same level of isolation as Type 1. Option D is wrong because a container runtime shares the host OS kernel, providing less isolation than a Type 1 hypervisor, as containers are not fully isolated VMs.

130
Multi-Selecthard

Which THREE components are essential for establishing a secure baseline configuration for a cloud virtual machine? (Choose three.)

Select 3 answers
A.Running applications as a service account.
B.Removing unnecessary software and services from the OS.
C.Configuring network security groups at the subnet level.
D.Implementing least privilege for local user accounts.
E.Enabling a host-based firewall to restrict inbound and outbound traffic.
AnswersB, D, E

Hardening by disabling unused services reduces attack surface.

Why this answer

Removing unnecessary software and services from the OS reduces the attack surface by eliminating potential vulnerabilities and backdoors. A secure baseline configuration must minimize the number of running components to only those required for the VM's intended function, following the principle of least functionality.

Exam trap

ISC2 often tests the distinction between OS-level hardening (baseline) and network-level controls (like NSGs), so candidates may mistakenly include subnet-level security groups as part of the VM's baseline configuration.

131
MCQhard

A SaaS provider uses a customer-managed encryption key (CMEK) model for data-at-rest. The provider's application runs in a multi-tenant cloud environment. Which attack surface is MOST directly mitigated by this approach?

A.Misconfigured storage buckets exposing data
B.Insider threats from cloud provider employees
C.SQL injection vulnerabilities in the application
D.Side-channel attacks on shared physical hardware
AnswerB

CMEK prevents provider access to customer data without the key.

Why this answer

A customer-managed encryption key (CMEK) model gives the customer control over the key used to encrypt data at rest. This directly mitigates the risk of a cloud provider employee accessing the plaintext data, because even if the employee has administrative access to the storage infrastructure, they cannot decrypt the data without the customer's key. The provider holds the encrypted data, but the decryption key is managed and controlled by the customer, creating a logical separation that protects against insider threats from the provider's personnel.

Exam trap

ISC2 often tests the misconception that encryption alone prevents all data exposure, but the trap here is that candidates confuse data-at-rest encryption with access control or application security, failing to recognize that CMEK specifically addresses the insider threat from the cloud provider's staff who might otherwise access raw storage.

How to eliminate wrong answers

Option A is wrong because misconfigured storage buckets expose data through incorrect access control policies (e.g., public read/write ACLs), which encryption does not prevent—encryption protects data at rest but does not enforce access controls. Option C is wrong because SQL injection is an application-layer attack that exploits improper input validation in the application code, and encryption of data at rest does not prevent injection or protect data while it is being processed in memory. Option D is wrong because side-channel attacks on shared physical hardware exploit timing, power consumption, or electromagnetic leaks to infer data; encryption keys managed by the customer do not prevent these physical-layer attacks, which target the compute or memory operations rather than the stored encrypted data.

132
MCQmedium

A cloud customer receives a legal hold notice for pending litigation. The data resides in multi-tenant storage. What is the most appropriate initial action?

A.Do nothing until the provider issues a notice
B.Rely on the provider's backup retention cycle
C.Alert all other tenants about the hold
D.Preserve the relevant data using customer-accessible tools
AnswerD

A legal hold obliges the customer to prevent destruction of potentially relevant data. Using customer-accessible tools to preserve that data in multi-tenant storage satisfies this duty, since the provider cannot selectively freeze one tenant's objects without affecting shared infrastructure.

Why this answer

Preserving all relevant data from the customer's tenant is required. Alerting other tenants violates privacy; relying solely on provider backup may be insufficient as backups might not be retained indefinitely; doing nothing is non-compliant.

133
MCQmedium

A security architect is designing access controls for a cloud-based microservices application. Which approach best aligns with the principle of least privilege for service-to-service authentication?

A.Use long-lived bearer tokens
B.Implement mutual TLS with unique certificates per service
C.Assign IAM roles with broad permissions
D.Use a shared API key across all services
AnswerB

Mutual TLS authenticates both ends using distinct per-service certificates, so each microservice proves its identity and only trusted peers connect. This enforces least privilege for service-to-service authentication rather than relying on shared secrets or network location.

Why this answer

Mutual TLS (mTLS) with unique certificates per service enforces least privilege by ensuring each microservice authenticates with a distinct identity, and access can be scoped to specific certificates. This prevents a compromised service from impersonating others, as each service has its own private key and certificate, and the TLS handshake requires both sides to present and validate certificates.

Exam trap

ISC2 often tests the misconception that shared secrets or broad IAM roles are acceptable for service-to-service communication, but the trap is that candidates overlook the need for per-service identity and cryptographic proof of identity, which mTLS uniquely provides.

How to eliminate wrong answers

Option A is wrong because long-lived bearer tokens, such as static OAuth2 tokens, increase the risk of token theft and reuse; they lack the per-request cryptographic binding of mTLS and violate least privilege by providing persistent access without rotation. Option C is wrong because assigning IAM roles with broad permissions (e.g., wildcard actions or resources) grants excessive privileges, directly contradicting the principle of least privilege by allowing a service to access more than necessary. Option D is wrong because a shared API key across all services creates a single point of failure and common credential; if the key is compromised, all services are exposed, and there is no way to isolate or revoke access per service.

134
Multi-Selecteasy

Which THREE of the following are typical data privacy principles found in most regulations?

Select 3 answers
A.Data minimization
B.Accountability
C.Data retention
D.Purpose limitation
E.Data monetization
AnswersA, B, D

Data minimisation limits collection and retention to what is strictly necessary for the stated purpose. It is a foundational principle in GDPR, ISO 27701 and most privacy regulations, directly satisfying the stem's requirement for typical data privacy principles.

Why this answer

Data minimization, purpose limitation, and accountability are common principles in privacy regulations like GDPR. Data retention is a practice derived from principles, and data monetization is not a privacy principle but a business activity.

135
MCQeasy

A financial services company is migrating its on-premises data center to a public cloud IaaS environment. During the transition, the security team must ensure that the same network segmentation and firewall rules are maintained. Which of the following is the BEST approach to replicate the on-premises network security controls in the cloud?

A.Configure a site-to-site VPN between on-premises and cloud to extend the existing network.
B.Use virtual private clouds (VPCs) with subnets and security groups to enforce segmentation and firewall rules.
C.Implement an intrusion detection and prevention system (IDPS) to monitor traffic.
D.Deploy a software-defined WAN (SD-WAN) to manage network traffic between cloud resources.
AnswerB

VPCs with subnets and security groups reproduce on-premises segmentation and firewall enforcement natively in IaaS, applying stateful, instance-level rules. This maps the existing network security controls directly onto cloud constructs without relying on host-based agents.

Why this answer

VPCs with subnets and security groups provide native, software-defined network segmentation and stateful firewall rules that directly replicate on-premises network segmentation and ACLs. Security groups act as virtual firewalls at the instance level, while network ACLs provide subnet-level stateless filtering, together enabling granular control without extending the on-premises network.

Exam trap

The trap here is that candidates often confuse extending the network via VPN (Option A) with replicating segmentation, not realizing that VPNs merge networks rather than isolating them, while virtual private clouds (VPCs) provide the necessary logical isolation and granular firewall controls.

How to eliminate wrong answers

Option A is wrong because a site-to-site VPN extends the on-premises network into the cloud, which does not replicate segmentation and firewall rules but instead merges the networks, potentially breaking isolation and requiring additional routing and firewall policies. Option C is wrong because an IDPS monitors and alerts on malicious traffic but does not enforce network segmentation or firewall rules; it is a detection control, not a preventive control for segmentation. Option D is wrong because SD-WAN optimizes traffic routing and bandwidth across WAN links but does not provide network segmentation or firewall rule enforcement within the cloud environment.

136
MCQhard

A cloud application team is designing a multi-tenant SaaS platform on a public cloud. Tenant data is stored in a shared database, and the application uses a single service account to connect. During a threat modeling session, the security architect raises concerns that a coding error could allow one tenant to read another tenant's records. Which control should be implemented to provide defense in depth against this cross-tenant data access risk?

A.Create a separate database schema for each tenant and grant the application service account access only to the schema corresponding to the current request.
B.Enforce row-level security policies in the database that filter queries based on a tenant identifier derived from the authenticated session context.
C.Encrypt each tenant's data with a separate customer-managed key and store the key identifier in the application configuration.
D.Implement a Web Application Firewall rule that inspects request parameters for tenant identifiers and blocks requests where the identifier does not match the authenticated user.
AnswerB

Row-level security in the database enforces tenant isolation at the data layer, so even if application code omits a tenant filter, the database restricts rows to the current tenant. Deriving the tenant identifier from the authenticated session context ties the policy to identity rather than trusting application-supplied values. This provides defense in depth against coding errors that could otherwise expose cross-tenant data.

Why this answer

Row-level security enforces tenant boundaries inside the database engine, independent of application query construction. By deriving the tenant identifier from the authenticated session, the policy cannot be bypassed by a forgotten WHERE clause or a manipulated parameter. This creates a reliable second layer of defense that complements application-level checks and encryption, directly mitigating the cross-tenant read risk identified during threat modeling.

Exam trap

The trap here is treating encryption or a WAF as sufficient tenant isolation, when only database-enforced row filtering prevents a coding error from returning another tenant's rows.

137
MCQhard

A cloud security architect is designing a forensics capability for a multi-tenant infrastructure-as-a-service (IaaS) environment. Which of the following is the MOST significant challenge when performing forensic acquisition of virtual machine (VM) memory?

A.High performance overhead caused by memory acquisition
B.Inability to access the hypervisor-level memory of other tenants due to isolation
C.Memory content is not available after the VM is powered off
D.Lack of tools that can capture memory from a running VM in the cloud
AnswerB

Multi-tenancy prevents cross-tenant memory access.

Why this answer

In a multi-tenant IaaS environment, the most significant challenge for forensic acquisition of VM memory is the inability to access the hypervisor-level memory of other tenants due to the strong isolation boundaries enforced by the cloud provider. Option A is not the most significant because memory acquisition overhead is typically manageable and can be performed with tools. Option C is true that memory content is volatile, but the primary challenge for acquisition is access, not volatility.

Option D is less significant because tools for capturing memory from running VMs (e.g., LiME) do exist; the real constraint is that the cloud provider restricts tenant access to hypervisor-level memory for security and multi-tenancy isolation.

138
MCQeasy

In the NIST SP 800-145 definition of cloud computing, which characteristic is described as the capability to rapidly and elastically provision and release resources, often automatically?

A.Rapid elasticity
B.Resource pooling
C.Broad network access
D.Measured service
AnswerA

Rapid elasticity is the NIST SP 800-145 characteristic describing capabilities provisioned and released elastically, often automatically, to scale outward and inward with demand. Measured service, on-demand self-service, and resource pooling describe different aspects of the same definition.

Why this answer

NIST SP 800-145 defines rapid elasticity as the capability to elastically provision and release resources, in some cases automatically, to scale rapidly outward and inward commensurate with demand. The phrase 'rapidly and elastically provision and release resources, often automatically' maps directly to this characteristic. It is one of the five essential characteristics of cloud computing alongside on-demand self-service, broad network access, resource pooling, and measured service.

Exam trap

The trap is that 'elasticity' and 'scalability' are often used interchangeably in casual conversation, but NIST treats rapid elasticity specifically as automatic, bidirectional provisioning and release — candidates who pick 'resource pooling' confuse sharing with scaling.

How to eliminate wrong answers

Option B is wrong because resource pooling describes the provider's multi-tenant model where physical and virtual resources are pooled to serve multiple consumers, with location independence — it is about sharing, not scaling speed. Option C is wrong because broad network access means capabilities are available over the network via standard mechanisms (e.g., HTTP, APIs) from diverse client platforms. Option D is wrong because measured service refers to metering and pay-per-use billing through automatic control and optimization of resource use.

139
Multi-Selecthard

A cloud security architect is evaluating a public cloud provider for a new workload that will process regulated data. The architect must document which security responsibilities remain with the cloud customer under the shared responsibility model. Which TWO of the following are customer responsibilities in a public cloud IaaS deployment? (Choose two.)

Select 2 answers
A.Managing guest operating system patches and updates
B.Maintaining the provider's hypervisor and virtualization platform
C.Ensuring the physical network backbone between data centers is redundant
D.Securing the physical facilities that house the servers
E.Configuring identity and access management policies for cloud resources
AnswersA, E

In IaaS, the customer is responsible for the guest operating system, including patching, hardening, and updates. The provider secures the virtualization layer and physical infrastructure, but the customer must maintain the OS inside its virtual machines. This responsibility is a core part of the shared responsibility model for IaaS and must be documented accordingly.

Why this answer

In public cloud IaaS, the provider secures facilities, hardware, and the virtualization platform, while the customer secures the guest operating system and its own identity and access management configurations. Guest OS patching and IAM policy management are therefore customer responsibilities, whereas physical facilities, hypervisor maintenance, and physical network redundancy remain with the provider.

Exam trap

The trap here is assuming that because the provider owns the cloud, it also owns every layer above the hypervisor, including guest OS patching and customer IAM policies.

140
MCQmedium

A company wants to avoid vendor lock-in when adopting cloud services. Which strategy is most effective for achieving portability?

A.Using proprietary APIs from the cloud provider
B.Subscribing to a single cloud provider's managed services
C.Using proprietary data formats
D.Adopting open standards and open-source APIs like Kubernetes and Terraform
AnswerD

Open standards and open-source APIs such as Kubernetes and Terraform decouple workloads from any single provider's proprietary interfaces, so components can be redeployed elsewhere. This directly satisfies the stem's portability constraint by removing the vendor-specific dependencies that cause lock-in.

Why this answer

Using open standards and APIs ensures that workloads can be moved between providers. Using proprietary APIs, single provider services, or managed services increases lock-in.

141
MCQeasy

A company runs a regulated workload in Microsoft Azure and must retain all administrative activity logs for seven years to satisfy an auditor. The logs must be immutable and retrievable even if the original resource is deleted. Which Azure capability should the team implement?

A.Azure Storage immutable blob storage with a time-based retention policy
B.Azure Event Hubs streaming activity logs to a third-party SIEM
C.A Log Analytics workspace with a 30-day interactive retention and archive tier
D.Azure Monitor activity log with the default 90-day retention setting
AnswerA

Immutable blob storage with a time-based retention policy written in legal-hold or locked policy mode prevents modification or deletion of blobs for the specified interval, and the policy can be set to seven years. Diagnostic settings can export activity logs to the storage account, meeting the immutability and retrievability requirements.

Why this answer

The requirement combines long retention, immutability, and availability after resource deletion. Azure Storage immutable blob storage with a locked time-based retention policy holds blobs unalterable for the configured interval, and diagnostic settings can route activity logs there. That pairing meets the seven-year immutability mandate in a way plain log retention or streaming pipelines cannot.

Exam trap

The trap here is treating long Log Analytics retention or Event Hubs streaming as equivalent to immutability, when only a locked immutability policy on blob storage actually prevents deletion or alteration of the retained logs.

142
Multi-Selecthard

A financial services company is implementing a data loss prevention (DLP) solution to protect sensitive data in cloud storage. They need to identify and classify data containing personally identifiable information (PII) such as credit card numbers and social security numbers. Which three capabilities should the DLP solution provide? (Choose three.)

Select 3 answers
A.Encryption at rest using AES-256
B.Classification of data based on content
C.De-identification transforms such as masking and tokenization
D.Blocking public access to buckets
E.Automated scanning for sensitive data patterns
AnswersB, C, E

Content-based classification inspects object contents against pattern and context rules to identify PII such as card numbers and social security numbers. This is the detection foundation the DLP solution needs before it can label, report or protect sensitive data held in cloud storage.

Why this answer

Option B is correct because a DLP solution must classify data based on content, inspecting files and objects to determine whether they contain regulated data types such as PII, credit card numbers, or social security numbers. Option C is correct because de-identification transforms such as masking and tokenization are core DLP remediation capabilities that replace or obscure sensitive values so the data can be used or shared while reducing exposure. Option E is correct because automated scanning for sensitive data patterns (for example, regex or pattern matching for 16-digit card numbers and SSN formats) is how the solution discovers and inventories sensitive data across cloud storage at scale.

Option A does not belong because AES-256 encryption at rest protects confidentiality but does not identify or classify PII content. Option D does not belong because blocking public access to buckets is an access-control hardening measure, not a data identification or classification capability.

Exam trap

CCSP often tests the distinction between DLP capabilities (discovery, classification, de-identification) and general security controls (encryption, access blocking); candidates may pick encryption or access controls thinking they are part of DLP.

143
MCQhard

A financial institution uses a cloud-based data warehouse to store customer transaction records. They must comply with a regulation that requires deletion of data after 7 years. Which approach should they use to ensure data is irrecoverably destroyed?

A.Overwrite the data with multiple patterns of zeros and ones
B.Encrypt the data and then destroy the encryption keys (cryptographic erasure)
C.Tokenize the data and retain the token mapping
D.Delete the data using the cloud provider's API and remove pointers
AnswerB

Cryptographic erasure renders data unrecoverable by destroying the keys protecting it, rather than overwriting every stored object. This satisfies the seven-year deletion mandate across a cloud warehouse where physical media cannot be accessed or reliably wiped.

Why this answer

Cryptographic erasure (Option B) is the correct approach because it renders the encrypted data irrecoverable by securely destroying the encryption keys, making the ciphertext permanently undecipherable. This method is recognized by standards like NIST SP 800-88 as an effective sanitization technique for data at rest, especially in cloud environments where physical access to storage media is unavailable. It ensures compliance with the 7-year deletion requirement without needing to overwrite or physically destroy the underlying cloud storage.

Exam trap

ISC2 often tests the misconception that simply deleting data via the cloud provider's API or overwriting data is sufficient for irrecoverable destruction, but the trap is that cloud storage systems maintain multiple copies, snapshots, and version histories that are not addressed by these methods, making cryptographic erasure the only practical option for compliance.

How to eliminate wrong answers

Option A is wrong because overwriting data with multiple patterns of zeros and ones (e.g., DoD 5220.22-M) is impractical in a cloud data warehouse where data is stored on distributed, shared, and often versioned storage systems; the cloud provider may retain snapshots, replicas, or previous versions that are not overwritten, leaving residual data recoverable. Option C is wrong because tokenization replaces sensitive data with tokens but retains the token mapping, which does not destroy the original data; the mapping can be reversed, and the original data remains stored elsewhere, failing to achieve irrecoverable deletion. Option D is wrong because deleting data via the cloud provider's API and removing pointers only removes logical references; the underlying data blocks remain on physical media and can be recovered through forensic techniques or provider-side snapshots, making it insufficient for compliance with irrecoverable destruction requirements.

144
MCQeasy

Refer to the exhibit. A log entry shows a suspected SQL injection attack. Which security control would have prevented this attack?

A.Encrypt the database connection
B.Implement rate limiting on the login endpoint
C.Enforce strong password policies
D.Use parameterized SQL queries
AnswerD

Parameterised queries bind user input as data rather than concatenating it into SQL text, so injected syntax never becomes executable code. This eliminates the injection vector at source, which no signature or input-filtering control achieves as reliably.

Why this answer

SQL injection attacks exploit unsanitized user input that is concatenated into SQL queries. Parameterized queries (also known as prepared statements) separate SQL logic from data by using placeholders, ensuring that user input is always treated as data, not executable code. This prevents an attacker from injecting malicious SQL commands, regardless of the input content.

Exam trap

ISC2 often tests the distinction between network-layer controls (like encryption) and application-layer controls (like input validation), and the trap here is that candidates confuse encryption of the connection with prevention of injection, thinking encrypted traffic cannot carry malicious payloads.

How to eliminate wrong answers

Option A is wrong because encrypting the database connection (e.g., using TLS/SSL) protects data in transit from eavesdropping but does not prevent the execution of malicious SQL statements; the injection still occurs at the application layer. Option B is wrong because rate limiting on the login endpoint only mitigates brute-force or credential-stuffing attacks by restricting request frequency; it has no effect on the content of a single request that contains SQL injection payload. Option C is wrong because enforcing strong password policies (e.g., complexity, length) reduces the risk of credential compromise but does not address the vulnerability of unsanitized input in SQL queries; an attacker can still inject SQL without needing valid credentials.

145
MCQhard

A logistics firm runs a customer portal on a public cloud provider. The board wants assurance that a provider outage will not halt order intake. The architect proposes an active-passive deployment in a second region of the same provider. Which design element is MOST critical to validate the recovery time objective?

A.A documented failover runbook that has never been executed
B.Regularly scheduled failover tests that measure actual recovery time and data loss
C.A service level agreement from the provider guaranteeing 99.99 percent regional availability
D.Cross-region replication of the database with asynchronous commit enabled
AnswerB

The only credible way to validate a recovery time objective and recovery point objective is to exercise the failover and measure how long the standby region takes to serve production traffic and how much data is missing. Scheduled game days expose stale DNS records, replication lag, and capacity shortfalls, and the measured results become the evidence the board needs.

Why this answer

Recovery objectives are validated by measurement, not by documentation or provider guarantees. Scheduled failover exercises reveal the real elapsed time to restore service and the true data loss window, accounting for DNS time-to-live, database promotion, and application reconnection. Replication and agreements enable recovery, but only testing produces the evidence that the stated recovery time objective is achievable.

Exam trap

The trap here is treating a provider availability commitment or a configured replication link as proof of business continuity, when only an executed failover measures real recovery time.

146
MCQeasy

A financial services company uses a hybrid cloud environment with an on-premises data center and AWS. They have deployed a Cloud Access Security Broker (CASB) to enforce data loss prevention (DLP) policies for SaaS applications. Recently, the security team noticed that sensitive customer data is being exfiltrated via encrypted traffic to a sanctioned cloud storage application. The CASB logs show the traffic is identified as HTTPS, but the DLP policy is not blocking it. The team verifies that the CASB is configured with a forward proxy and SSL inspection is enabled. Which action should the security team take to prevent this exfiltration?

A.Block all HTTPS traffic to the cloud storage application
B.Ensure the CASB's SSL certificate is deployed to all endpoint devices
C.Configure the CASB to log only metadata for encrypted traffic
D.Disable HTTPS for the cloud storage application and force HTTP
AnswerB

Deploying the CASB's SSL certificate to all endpoints lets the forward proxy decrypt and re-encrypt HTTPS sessions without clients rejecting the certificate, so DLP can inspect payloads sent to the sanctioned storage app. Without this trust, TLS interception fails silently and encrypted exfiltration continues uninspected.

Why this answer

The CASB is configured as a forward proxy with SSL inspection enabled, but for SSL inspection to work, the CASB's certificate must be trusted by the endpoint devices. Without the CASB's certificate deployed to the endpoints, the SSL inspection fails (the CASB cannot decrypt the traffic), so the DLP policy cannot inspect the payload of HTTPS traffic, allowing sensitive data to be exfiltrated. Deploying the CASB's certificate to all endpoint devices ensures that the endpoints trust the CASB's man-in-the-middle decryption, enabling the CASB to decrypt, inspect, and enforce DLP policies on encrypted traffic.

Exam trap

The trap here is that candidates assume SSL inspection is automatically effective once enabled in the CASB configuration, overlooking the critical prerequisite that the CASB's certificate must be trusted by the endpoints for decryption to occur.

How to eliminate wrong answers

Option A is wrong because blocking all HTTPS traffic to the cloud storage application is an overly broad and disruptive measure that would break legitimate business use of the sanctioned application, and it does not address the root cause of the DLP policy not being enforced on encrypted traffic. Option C is wrong because logging only metadata for encrypted traffic would reduce visibility and prevent the CASB from inspecting the payload, making it impossible to enforce DLP policies on the content of the traffic. Option D is wrong because disabling HTTPS and forcing HTTP would expose the data in transit to interception and tampering, violating security best practices and potentially regulatory compliance requirements, and it does not leverage the existing SSL inspection capability of the CASB.

147
MCQeasy

A financial services company is migrating a critical application to the cloud. They must ensure that the cloud provider supports the ability to conduct forensic investigations in case of a security incident. Which of the following is the MOST important requirement to include in the contract?

A.The provider must guarantee 99.999% uptime for all cloud services used.
B.The provider must automatically patch all virtual machines within 24 hours of patch release.
C.The provider must grant the customer access to raw logs and the ability to perform memory captures on virtual instances.
D.The provider must store data only in data centers located within the country of operation.
AnswerC

Forensic investigation requires evidence the customer can actually examine. Raw logs and memory captures on virtual instances give the customer direct artefacts, whereas provider-only summaries or notifications would not satisfy the requirement to conduct investigations themselves.

Why this answer

Forensic investigations require access to raw logs and the ability to capture memory from virtual instances to analyze incidents. Option A is incorrect because uptime guarantees (99.999%) relate to availability, not forensic capability. Option B is incorrect because automatic patching is a security measure but not specific to forensics.

Option D is incorrect because data residency restrictions address data sovereignty, not forensic access.

148
MCQeasy

A developer wants to ensure that sensitive data in a cloud database is protected even if the database backup files are stolen. Which best practice should be implemented?

A.Restrict access to the backup files using IAM roles.
B.Use a virtual private cloud (VPC) to isolate the database from the internet.
C.Enable transparent data encryption (TDE) with customer-managed keys for the database and its backups.
D.Implement data tokenization for all sensitive fields.
AnswerC

TDE encrypts database files and their backups at rest, so stolen backup media yields only ciphertext. Customer-managed keys keep control of decryption outside the provider, satisfying the requirement that sensitive data stays protected even when backup files are exfiltrated.

Why this answer

Transparent Data Encryption (TDE) with customer-managed keys encrypts the database at rest and, when properly configured, also encrypts backup files. This ensures that even if backup files are stolen, the data remains unreadable without the decryption keys, providing a strong defense against data breaches involving physical or logical theft of backups.

Exam trap

The trap here is that candidates often confuse network-level controls (VPC isolation) or access controls (IAM) with data-at-rest encryption, failing to recognize that backup files are a separate attack surface requiring encryption specifically applied to the backup media.

How to eliminate wrong answers

Option A is wrong because restricting access with IAM roles protects against unauthorized access to the backup files but does not encrypt the data within them; if the files are stolen (e.g., via physical theft or a compromised storage layer), the data is still readable. Option B is wrong because using a VPC isolates the database from the internet but does not encrypt backup files; a VPC controls network traffic, not data at rest, so stolen backups remain unprotected. Option D is wrong because data tokenization replaces sensitive data with tokens, but it requires an external tokenization service and does not inherently protect backup files; if the token mapping is compromised or the backup contains tokens, the original data may still be exposed, and tokenization is not a direct backup encryption mechanism.

149
Multi-Selectmedium

Which TWO of the following are valid methods to protect data at rest in a cloud environment?

Select 2 answers
A.Client-side encryption
B.Data loss prevention (DLP) policies
C.Tokenization
D.Server-side encryption
E.Transport Layer Security (TLS)
AnswersA, D

Encrypts data before sending to cloud.

Why this answer

Client-side encryption (A) is a valid method to protect data at rest because the data is encrypted by the client before being transmitted to the cloud provider. This ensures that the cloud provider never has access to the plaintext data or the encryption keys, which remain under the customer's control. It is a strong approach for maintaining data confidentiality and compliance with regulatory requirements.

Exam trap

ISC2 often tests the distinction between data at rest and data in transit, so the trap here is that candidates may incorrectly select TLS (Option E) as a method for protecting data at rest, confusing it with encryption of data in transit.

150
MCQmedium

An organization attempts to launch an instance in a specific availability zone but the launch fails. What is the most likely cause of the failure?

A.Instance type not available in that region
B.Resource exhaustion in the availability zone
C.Incorrect region
D.Insufficient CPU quota
AnswerB

Each availability zone has finite compute capacity; when its pool of instances or associated resources is fully consumed, further launches in that zone fail. Capacity is isolated per zone, so exhaustion there is the most likely cause rather than a broader regional outage.

Why this answer

The most likely cause is resource exhaustion in the availability zone. This occurs when the cloud provider has insufficient capacity in a specific zone to fulfill a request, even if the requested resource type is available in the region. This is a transient condition, unlike quotas which are static limits.

Instance type availability and region correctness would typically result in different error messages and are less likely to be the cause.

Exam trap

ISC2 often tests the distinction between resource exhaustion (capacity) and quota limits, where candidates mistakenly select quota errors when the real issue is transient capacity unavailability in a specific Availability Zone.

How to eliminate wrong answers

Option A is wrong because the instance type not being available in the region would typically result in a different error message indicating the instance type is not supported in that region, and the error would occur regardless of the specific Availability Zone selected. Option C is wrong because an incorrect region would cause a different failure, such as the region not being found or the resource not existing, not a capacity-related error. Option D is wrong because insufficient CPU quota would produce a quota exceeded error, which is distinct from a capacity or resource exhaustion error; quota limits are account-level, not zone-level.

Page 1

Page 2 of 13

Page 3