Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 151–225

934 questions total · 13pages · All types, answers revealed

Page 2

Page 3 of 13

Page 4
151
MCQmedium

Refer to the exhibit. A security analyst is investigating a potential unauthorized key pair creation. The CloudTrail log shows a successful CreateKeyPair event for an admin user. What additional step should the analyst take to determine if this was an authorized action?

A.Immediately revoke all admin privileges for the user.
B.Review the key pair's usage to see if it was used to launch instances.
C.Delete the key pair immediately to prevent any misuse.
D.Check the source IP address against the company's approved IP ranges.
AnswerD

Comparing the event's source IP against approved corporate ranges establishes whether the request originated from a trusted network or an external actor, directly addressing the authorisation question. CloudTrail records the sourceIPAddress field for every CreateKeyPair event, so this check reliably distinguishes legitimate administrative activity from credential compromise or misuse.

Why this answer

The first step in verifying whether a CreateKeyPair event was authorized is to check the source IP address against the company's approved IP ranges. CloudTrail logs include the sourceIPAddress field, which can be compared to a whitelist of administrative jump hosts or corporate VPN ranges. If the IP is outside those ranges, it strongly indicates unauthorized access, even if the user credentials were valid.

Exam trap

ISC2 often tests the misconception that the immediate response to a suspicious event should be a punitive action (like revoking privileges or deleting resources) rather than a methodical investigative step to confirm authorization.

How to eliminate wrong answers

Option A is wrong because immediately revoking all admin privileges is a drastic, premature action that could disrupt legitimate operations; the analyst must first gather evidence to confirm unauthorized activity. Option B is wrong because reviewing the key pair's usage to see if it was used to launch instances is a later forensic step, not the immediate action to determine authorization; a key pair can be created and used maliciously within seconds, and the creation event itself must be validated first. Option C is wrong because deleting the key pair immediately could destroy forensic evidence and alert an attacker, and it does not address the root cause of potential credential compromise.

152
MCQeasy

Which phase of the cloud data lifecycle involves the removal of data in a manner that ensures it cannot be reconstructed, typically using techniques like cryptographic erasure or degaussing?

A.Destroy
B.Store
C.Share
D.Archive
AnswerA

Destroy is the final lifecycle phase, using cryptographic erasure (deleting the wrapping key so ciphertext is unrecoverable) or degaussing to render media magnetically unusable. This guarantees data cannot be reconstructed, satisfying the stem's irreversibility requirement rather than merely deleting pointers or access.

Why this answer

The Destroy phase of the cloud data lifecycle is specifically defined as the permanent removal of data such that it cannot be reconstructed, using methods like cryptographic erasure (destroying the encryption keys) or degaussing (magnetic erasure). Store, Share, and Archive all involve retaining data in some form. Destroy is the only phase focused on irreversible elimination.

Exam trap

The trap is confusing Archive with Destroy — candidates see 'removal' and think archiving removes data from active use, but archiving retains data, whereas Destroy ensures it cannot be reconstructed.

How to eliminate wrong answers

Option B is wrong because Store is the phase where data is persisted in cloud storage, not removed. Option C is wrong because Share is the phase where data is made accessible to other parties, which is the opposite of destruction. Option D is wrong because Archive involves moving data to long-term, lower-cost storage for retention, not eliminating it.

153
Multi-Selecthard

A cloud security engineer is investigating a potential data breach in a cloud environment. The organization uses a cloud access security broker (CASB) and has deployed a security information and event management (SIEM) system. Which of the following are likely indicators that the CASB has detected unauthorized data exfiltration? (Choose two.)

Select 2 answers
A.Anomalous spike in outbound traffic to an unknown IP address
B.A change in the configuration of a firewall rule
C.A large number of file downloads by a single user outside of business hours
D.Multiple failed login attempts to a critical application
E.An alert for a known malware signature in an email attachment
AnswersA, C

Anomalous outbound traffic spikes to unknown IP addresses satisfy the exfiltration detection requirement, since CASBs monitor data flows between the organisation and cloud services, flagging volumetric deviations from established baselines. This behavioural signal directly evidences unauthorised data movement, unlike authentication or configuration events, which indicate access attempts rather than confirmed egress.

Why this answer

Option A is correct because a CASB monitors cloud traffic and would flag an anomalous spike in outbound traffic to an unknown IP address as a strong indicator of unauthorized data exfiltration, since data is being sent to an untrusted external destination. Option C is correct because a large number of file downloads by a single user outside of business hours is a classic user behavior analytics (UBA) anomaly that a CASB detects, indicating possible bulk data theft by an insider or compromised account. Option B is not a CASB exfiltration indicator; firewall rule changes are configuration events typically surfaced by change management or firewall auditing tools, not CASB traffic analysis.

Option D reflects failed authentication attempts, which point to brute-force or credential-stuffing attacks rather than data leaving the environment. Option E is an email security or secure email gateway detection of malware signatures, not a CASB data exfiltration indicator.

Exam trap

The trap is selecting generic security events such as failed logins or malware alerts, which are not exfiltration indicators, instead of the data-movement anomalies a CASB specifically detects.

154
MCQmedium

In a Kubernetes cluster, which resource should be used to restrict network traffic between pods based on source and destination labels?

A.Pod Security Admission
B.Network Policies
C.Secrets management with Vault
D.Role-Based Access Control (RBAC)
AnswerB

Network Policies are Kubernetes objects that select pods by label and define permitted ingress and egress rules, enforced by the CNI plugin. They satisfy the stem's label-based restriction on inter-pod traffic, unlike security groups or firewall rules that operate outside pod identity.

Why this answer

Network policies in Kubernetes act as a firewall for pods, allowing or denying traffic based on selectors.

155
MCQhard

A large healthcare organization uses a hybrid cloud environment with on-premises systems and Microsoft Azure. They store protected health information (PHI) in Azure Blob Storage and use Azure SQL Database for transactional data. The organization must comply with HIPAA and has implemented encryption at rest using Azure Storage Service Encryption and Transparent Data Encryption (TDE) for SQL. During a recent audit, the security team discovered that the organization does not have a formal process to identify and respond to security incidents that involve PHI. Additionally, the organization's backup strategy stores encrypted backups in a separate Azure region, but the backup encryption keys are managed by Azure and are not customer-controlled. The compliance officer is concerned about the ability to demonstrate HIPAA compliance in the event of an audit. Which of the following actions should the organization take FIRST to address the most critical gap?

A.Conduct a vulnerability assessment of all cloud resources to identify and remediate security weaknesses.
B.Develop and implement a formal incident response plan that includes procedures for detecting, reporting, and responding to PHI breaches.
C.Implement customer-managed keys (CMK) for all Azure backups to ensure the organization controls encryption keys.
D.Implement a data classification policy to label all data assets according to sensitivity.
AnswerB

HIPAA requires documented incident detection, reporting and response procedures for PHI breaches; the audit found no formal process, making this the most critical gap. Encryption and backups already exist, so incident response must be addressed first.

Why this answer

The most critical gap is the lack of a formal incident response plan for PHI breaches. HIPAA requires covered entities to have documented policies and procedures for detecting, reporting, and responding to security incidents involving ePHI. Without this plan, the organization cannot demonstrate compliance during an audit, regardless of encryption or backup controls.

Exam trap

ISC2 often tests the distinction between proactive security controls (encryption, vulnerability assessment, data classification) and the mandatory reactive compliance process (incident response plan) required by regulations like HIPAA, leading candidates to prioritize technical fixes over procedural requirements.

How to eliminate wrong answers

Option A is wrong because vulnerability assessment addresses proactive security posture, not the reactive incident response capability that is the immediate compliance gap. Option C is wrong because while customer-managed keys (CMK) improve key control, they are not a substitute for the mandatory incident response process required by HIPAA; the backup encryption key management is a secondary concern. Option D is wrong because data classification supports labeling but does not fulfill the specific regulatory requirement for a documented incident response plan to handle PHI breaches.

156
MCQmedium

A SaaS application allows users to upload profile pictures. The development team wants to prevent upload of malicious files that could compromise the server. Which control is most effective?

A.Store files in a CDN that only serves static content.
B.Set a maximum file size limit to 2 MB.
C.Implement server-side antivirus scanning on all uploaded files before saving.
D.Restrict file uploads to only image file types by checking the file extension.
AnswerC

Server-side scanning intercepts every upload before it reaches storage, catching malware the client cannot be trusted to detect. This directly satisfies the stem's constraint of preventing malicious files from compromising the server, since client-side checks are bypassable and signature-only filtering misses embedded payloads.

Why this answer

Server-side antivirus scanning inspects the actual file content after upload and before it is persisted or served, which is the only control here that detects malicious payloads regardless of file type or extension. It catches malware embedded in files that pass superficial checks, including polyglot files and weaponized images. Because scanning happens on the server, attackers cannot bypass it by manipulating client-side validation.

Exam trap

CCSP often tests the misconception that restricting file extensions or MIME types is sufficient upload protection, when the real control must inspect file content because extensions and headers are attacker-controlled.

How to eliminate wrong answers

Option A is wrong because a CDN serving static content only limits execution context — it does not detect or remove malicious files, and a stored malicious file can still be downloaded and executed by victims. Option B is wrong because a 2 MB size limit only mitigates denial-of-service or storage abuse; a 50 KB web shell or malware-laden image is unaffected. Option D is wrong because checking the file extension is trivially bypassed by renaming a .exe or .php to .jpg, and even magic-byte checks can be defeated with polyglot files — extension validation is not content inspection.

157
Multi-Selectmedium

A cloud security team is evaluating controls for protecting data in a PaaS database service. The database must support tenant isolation, and the team wants to prevent one tenant's queries from accessing another tenant's rows. Which TWO controls BEST achieve row-level tenant isolation? (Choose two.)

Select 2 answers
A.Enable database auditing and alert on queries that return more than a threshold number of rows.
B.Use separate database schemas per tenant with distinct database roles and grant only schema-scoped privileges.
C.Implement row-level security policies in the database engine that filter rows based on the authenticated tenant identity.
D.Enable transparent data encryption on the database so that rows are encrypted at rest with a service-managed key.
E.Configure the application to append a tenant_id filter to every generated SQL statement.
AnswersB, C

Schema-per-tenant with role-scoped grants limits each tenant's session to its own schema, providing a strong boundary. Combined with row-level policies or as an alternative, it prevents cross-tenant access at the privilege layer and reduces the blast radius of a compromised application credential.

Why this answer

Row-level security policies and schema-per-tenant with role-scoped grants both enforce isolation inside the database engine, so cross-tenant access is blocked regardless of application behavior. TDE, application-side filtering, and auditing do not prevent a query from reaching another tenant's rows, making them insufficient as primary isolation controls.

Exam trap

The trap here is treating encryption at rest or application-side filtering as tenant isolation, when only database-enforced controls such as row-level security or schema-scoped privileges actually prevent cross-tenant row access.

158
Multi-Selectmedium

A cloud security team must harden the management plane for a Kubernetes cluster running on Google Kubernetes Engine. They want to limit who can reach the control plane endpoint and ensure that any administrative action taken against the cluster is attributable to a named identity. (Choose two.)

Select 2 answers
A.Enable network policy enforcement on the cluster's node pools
B.Use Binary Authorization to require attestations before workloads deploy
C.Apply PodSecurity admission with the restricted profile to all namespaces
D.Enable Cloud Audit Logs for the GKE cluster's Admin Activity and Data Access logs
E.Configure authorized networks on the cluster to restrict control plane access to approved CIDR ranges
AnswersD, E

Cloud Audit Logs capture administrative actions against the cluster and its resources, recording the calling identity, the API method, and the timestamp. Enabling Admin Activity and Data Access audit logs provides the attribution the team needs to trace any administrative action to a named principal.

Why this answer

Restricting control plane reachability is accomplished with authorized networks, which constrain the source CIDRs permitted to contact the API server. Attribution of administrative actions requires Cloud Audit Logs, specifically Admin Activity and Data Access logs, which record the identity and method for each call. Together they harden the management plane and provide accountability.

Exam trap

The trap here is confusing data-plane hardening controls such as network policy, PodSecurity admission, and Binary Authorization with management-plane controls that limit API server reachability and record administrative identity.

159
MCQmedium

An organization exposes an API via Amazon API Gateway. They need to protect against common web exploits like SQL injection and cross-site scripting. Which integration should they enable?

A.IAM policies
B.Security groups on the API Gateway
C.AWS WAF
D.Network ACLs on the VPC
AnswerC

AWS WAF attaches to API Gateway stages and inspects HTTP requests against managed or custom rules, blocking SQL injection and cross-site scripting payloads before they reach the backend. This satisfies the requirement to protect the exposed API against common web exploits.

Why this answer

AWS WAF is a web application firewall that integrates with Amazon API Gateway to protect against common web exploits like SQL injection and cross-site scripting. It inspects incoming HTTP/HTTPS requests and applies rules to block malicious traffic. Enabling AWS WAF on the API Gateway stage provides the required protection.

Exam trap

CCSP often tests the layer at which security controls operate; candidates may choose network-layer controls (security groups, NACLs) for application-layer threats, confusing the OSI model layers.

How to eliminate wrong answers

Option A is wrong because IAM policies control authentication and authorization for AWS resources, not web exploit filtering; they do not inspect request payloads for SQLi or XSS. Option B is wrong because security groups act at the network layer (IP/port level) and cannot inspect application-layer payloads; API Gateway is a managed service and does not use security groups in the traditional sense. Option D is wrong because network ACLs are stateless subnet-level filters that also operate at the network layer and cannot detect application-layer attacks.

160
MCQeasy

A company's security policy requires that all data stored in the cloud must be encrypted at rest. The cloud provider offers server-side encryption with either cloud-managed keys or customer-managed keys (CMK). Which additional control should the company implement to ensure that the CMK is not compromised and that access is auditable?

A.Enable automatic key rotation and configure detailed audit logging for the key management service.
B.Implement a VPN for all management traffic to the cloud provider's API.
C.Enable multi-factor authentication (MFA) for all cloud console users.
D.Use encryption in transit (TLS) for all data transfers to and from the cloud.
AnswerA

Rotation limits the blast radius of a leaked CMK by shortening its cryptographic lifespan, while audit logging records every key use and policy change. Together they satisfy the stem's dual requirement that the customer-managed key stays uncompromised and that access remains auditable.

Why this answer

Enabling automatic key rotation reduces the risk of key compromise by limiting the exposure window of any single key, while detailed audit logging for the key management service (e.g., AWS CloudTrail for KMS, Azure Monitor for Key Vault) provides an immutable record of all key usage and administrative actions. This combination ensures that even if a CMK is exposed, the window of vulnerability is minimized, and any unauthorized access or misuse is detectable through logs. Without these controls, the customer-managed key could remain static for long periods, increasing risk, and access events would not be auditable, violating the policy requirement.

Exam trap

ISC2 often tests the distinction between controls that protect the key itself (rotation and auditing) versus controls that protect the channel or user access (VPN, MFA, TLS), leading candidates to confuse network or identity safeguards with key management safeguards.

How to eliminate wrong answers

Option B is wrong because a VPN for management traffic protects data in transit to the cloud provider's API but does not address the security or auditability of the customer-managed key itself; it is a network-level control unrelated to key compromise or auditing. Option C is wrong because multi-factor authentication (MFA) for cloud console users protects against unauthorized account access but does not directly secure the CMK or provide audit logging for key usage; it is an identity control, not a key management control. Option D is wrong because encryption in transit (TLS) protects data during transfer but does not affect the security of the key at rest or provide audit trails for key access; it is a data protection control, not a key management control.

161
MCQhard

A cloud customer wants to ensure they can audit their cloud provider's security controls annually. Which contractual provision should be included in the cloud service agreement?

A.Service level agreement (SLA) with uptime guarantees
B.Data deletion clause
C.Data portability clause
D.Right to audit clause
AnswerD

A right to audit clause grants the customer contractual permission to assess the provider's security controls, typically annually, either directly or via an independent third party. Without it, the customer has no enforceable means to verify controls beyond provider-supplied reports.

Why this answer

A right to audit clause contractually grants the cloud customer the ability to audit the provider's security controls, either directly or through third-party assessments, on a defined schedule. This is the specific provision that ensures annual audit capability, so D is correct.

Exam trap

CCSP often tests whether candidates confuse the right to audit with SLAs, data deletion, or portability clauses — the key is recognizing that only the right to audit grants control verification access.

How to eliminate wrong answers

Option A is wrong because an SLA with uptime guarantees addresses availability commitments and remedies (service credits), not the customer's ability to audit security controls. Option B is wrong because a data deletion clause specifies how data is destroyed at contract termination, which is a data lifecycle concern, not an audit right. Option C is wrong because a data portability clause governs the customer's ability to export their data to another provider, addressing lock-in, not audit access.

162
MCQeasy

A startup wants to deploy a new web application without purchasing servers, and it accepts that its workloads will share physical hardware with other tenants. The founders want the lowest possible upfront cost and the ability to release resources when the product is discontinued. Which cloud deployment model matches these requirements?

A.Private cloud
B.Public cloud
C.Community cloud
D.Hybrid cloud
AnswerB

A public cloud is owned by a provider and offers self-service, on-demand resources to any customer over the network, with no capital purchase and pay-per-use billing. Sharing physical infrastructure with other tenants is inherent to the model and is what enables the low entry cost. Resources can be released when the product is discontinued, matching every stated requirement.

Why this answer

The public cloud model is defined by provider ownership, multi-tenant shared infrastructure, self-service provisioning, and consumption-based billing. Those traits deliver the lowest barrier to entry and allow the startup to stop paying when the product ends. Private and community clouds require dedicated or consortium arrangements, while hybrid assumes a pre-existing private footprint to integrate.

Exam trap

The trap here is equating shared physical hardware with inadequate security, when multi-tenancy is a defining economic trait of the public cloud rather than a disqualifying weakness.

163
MCQeasy

A company is implementing a data classification policy for cloud storage. They want to label objects with tags indicating the sensitivity level (e.g., 'Confidential'). Which benefit does tagging resources with classification labels provide?

A.It provides client-side encryption keys
B.It automatically encrypts data at rest
C.It reduces storage costs by moving data to cheaper tiers
D.It allows enforcement of data handling policies based on sensitivity
AnswerD

Classification tags attach sensitivity metadata to objects, enabling policy engines to enforce handling rules such as encryption, access restrictions and retention automatically. This satisfies the stem's requirement that labelling drives enforcement of data handling policies based on sensitivity.

Why this answer

Tags applied to cloud resources act as metadata that policy engines, DLP tools, and automation can evaluate at runtime. By labeling objects as 'Confidential', 'Internal', or 'Public', organizations can attach conditional policies (e.g., deny public access, require encryption, restrict cross-region replication) that enforce handling rules based on the classification. This is the primary governance benefit of classification tagging.

Exam trap

The trap here is conflating classification tagging with encryption or cost optimization — candidates often assume that labeling data 'Confidential' automatically encrypts it, when in fact tags only enable policy enforcement and visibility.

How to eliminate wrong answers

Option A is wrong because tags are metadata and do not generate or store cryptographic key material — client-side encryption keys come from KMS, HSMs, or local key stores. Option B is wrong because tagging does not itself perform encryption; encryption at rest must be explicitly enabled via SSE-S3, SSE-KMS, or client-side encryption. Option C is wrong because lifecycle tiering is driven by lifecycle rules and access patterns, not by classification tags — although tags can be used as conditions in lifecycle policies, the tag alone does not reduce storage cost.

164
Multi-Selectmedium

A security auditor is reviewing a Kubernetes cluster and identifies that containers are running as root with full Linux capabilities. Which TWO security measures would help mitigate container escape risks in this environment?

Select 2 answers
A.Set the container to run as a non-root user
B.Enable host networking mode
C.Use a privileged container
D.Drop all Linux capabilities except those needed
E.Mount the host filesystem as read-write
AnswersA, D

Running the container as a non-root user removes UID 0 inside the container, so a breakout attempt lands with unprivileged rights on the host and cannot modify protected files or kernel interfaces. This directly mitigates the root-with-full-capabilities risk the auditor identified.

Why this answer

Option A is correct because configuring the container to run as a non-root user (e.g., via securityContext.runAsUser or runAsNonRoot: true) removes the root privileges that an attacker could leverage to exploit kernel vulnerabilities or access host resources during a container escape attempt. Option D is correct because dropping all Linux capabilities and then adding back only those explicitly required (using securityContext.capabilities.drop: ["ALL"]) follows the principle of least privilege, eliminating dangerous capabilities like CAP_SYS_ADMIN, CAP_NET_ADMIN, and CAP_SYS_PTRACE that are commonly abused in container escape techniques. Option B is incorrect because enabling host networking mode actually increases risk by removing network namespace isolation, allowing the container to access host network interfaces and services directly.

Option C is incorrect because privileged containers disable nearly all security mechanisms (seccomp, AppArmor, capability restrictions) and grant full access to host devices, dramatically worsening escape risk. Option E is incorrect because mounting the host filesystem as read-write gives the container direct write access to host files, enabling tampering with system binaries or configuration to facilitate escape and persistence.

Exam trap

The trap is that 'privileged container' and 'host networking' sound like advanced features that might improve security, when in fact they are the exact misconfigurations that enable container escapes.

165
MCQmedium

Which design principle is MOST directly concerned with the ability to move workloads between cloud providers or back on-premises without significant re-architecture?

A.Reversibility
B.Portability
C.Isolation
D.Elasticity
AnswerB

Portability directly addresses avoiding provider lock-in by ensuring workloads can migrate between clouds or back on-premises without re-architecture. It satisfies the stem's constraint of relocation without significant redesign, distinguishing it from interoperability, which concerns systems communicating across providers rather than moving between them.

Why this answer

Portability is the design principle concerned with the ability to move workloads, data, and applications between cloud providers or back on-premises without significant re-architecture. It emphasizes avoiding proprietary lock-in through open standards, containers, and abstraction layers. The scenario's phrase 'move workloads between cloud providers or back on-premises without significant re-architecture' is the definition of portability.

Exam trap

The trap is the close pairing of portability and reversibility — candidates often pick reversibility because both involve leaving a provider, but the question's emphasis on moving workloads without re-architecture points to portability.

How to eliminate wrong answers

Option A is wrong because reversibility is the related but distinct principle of being able to exit a cloud provider and return to on-premises or another provider — it focuses on the exit path and data retrieval, while portability focuses on the technical ease of moving the workload itself. Option C is wrong because isolation concerns separating tenants, workloads, or data to prevent cross-contamination and is unrelated to workload mobility. Option D is wrong because elasticity is about automatic scaling of resources with demand, not about moving workloads between environments.

166
Multi-Selectmedium

A security architect is designing network segmentation for a multi-tier application in the cloud. Which TWO configurations help enforce micro-segmentation? (Choose two.)

Select 2 answers
A.Allow all traffic from the internet.
B.Use a bastion host for all administrative access.
C.Use a single network ACL for all subnets.
D.Deploy a virtual firewall between tiers.
E.Implement security groups per application tier.
AnswersD, E

A virtual firewall enforces segmentation and inspection.

Why this answer

Deploying a virtual firewall between tiers (e.g., between web, application, and database tiers) enforces micro-segmentation by inspecting and controlling east-west traffic at the application layer. This allows granular, stateful filtering of traffic based on specific protocols, ports, and even application-level attributes, preventing lateral movement of threats within the cloud environment.

Exam trap

ISC2 often tests the distinction between coarse network controls (like a single ACL) and granular micro-segmentation mechanisms (like virtual firewalls or security groups), trapping candidates who confuse a bastion host or broad ACLs with proper tier isolation.

167
Multi-Selecthard

An organization is evaluating a cloud service provider and reviewing their SLA. Which THREE metrics are most important for assessing the provider's reliability and accountability? (Choose three.)

Select 3 answers
A.Number of data center employees
B.Frequency of performance reporting
C.Service credits or compensation for downtime
D.Provider's stock price
E.Monthly uptime percentage guarantee
AnswersB, C, E

Reporting frequency determines how quickly the consumer detects SLA breaches and holds the provider accountable. Without regular performance data, uptime guarantees and credit mechanisms cannot be verified, so this metric underpins the reliability assessment the stem requires.

Why this answer

Option B (Frequency of performance reporting) is correct because an SLA's reporting cadence determines how often the provider must disclose measured performance against targets, giving the customer the visibility needed to verify reliability and hold the provider accountable. Option C (Service credits or compensation for downtime) is correct because financial remedies such as service credits are the primary contractual enforcement mechanism that makes the provider accountable when availability commitments are missed. Option E (Monthly uptime percentage guarantee) is correct because the uptime percentage (for example, 99.9% or 99.95%) is the core quantitative reliability commitment against which actual availability is measured.

Option A (Number of data center employees) does not belong because headcount is not a defined SLA reliability or accountability metric and does not reflect service availability. Option D (Provider's stock price) does not belong because stock price is a financial-market indicator unrelated to the contractual service levels in an SLA.

168
MCQhard

During litigation, a company receives a legal hold notice for electronically stored information (ESI) in a cloud environment. The cloud provider's standard service agreement includes a clause that automatically deletes data 30 days after termination of service. What should the company do to ensure compliance?

A.Ignore the legal hold notice
B.Download all data immediately
C.Terminate the account to stop further processing
D.Notify the provider to preserve the data
AnswerD

A legal hold overrides the provider's contractual auto-deletion schedule, so the company must issue a preservation notice instructing the provider to suspend its 30-day deletion and retain the ESI for litigation. This satisfies the compliance constraint by preventing spoliation before the hold is lifted.

Why this answer

A legal hold notice imposes a duty to preserve relevant ESI. The company must notify the cloud provider to suspend any automatic deletion policies, such as the 30-day post-termination deletion clause, to ensure data is preserved in accordance with eDiscovery obligations under FRCP Rule 37(e) or similar regulations.

Exam trap

ISC2 often tests the misconception that downloading data is sufficient for preservation, but the trap here is that the original ESI in the cloud must be preserved in place to maintain its native format, metadata, and chain of custody for eDiscovery.

How to eliminate wrong answers

Option A is wrong because ignoring a legal hold notice constitutes spoliation of evidence, which can lead to severe sanctions including adverse inference instructions or monetary penalties. Option B is wrong because downloading all data immediately may not capture metadata, logs, or dynamic data that the provider maintains, and it does not stop the provider's automatic deletion of the original ESI after termination. Option C is wrong because terminating the account triggers the 30-day deletion clause, destroying the very data that must be preserved, and violates the duty to preserve.

169
MCQhard

A company runs its production workloads on a cloud infrastructure-as-a-service (IaaS) platform. The security operations team uses a SIEM to monitor security events. Over the past week, they have observed an increasing number of alerts indicating failed login attempts to a critical database server. The source IP addresses are varied and originate from different geographic regions. The team has also noticed that the database server's CPU usage has spiked during non-business hours. The database is not exposed to the internet; it is in a private subnet. The security team suspects that the database credentials have been compromised. Which of the following actions should the security team take FIRST to mitigate the risk?

A.Conduct a forensic investigation to determine how the credentials were compromised
B.Block the source IP ranges identified in the SIEM alerts at the network firewall
C.Enable multi-factor authentication on the database server
D.Rotate the database credentials immediately
AnswerD

Rotating the database credentials immediately invalidates the compromised credentials, cutting off the attacker's access before further lateral movement or data exfiltration. Containment takes priority over investigation, and rotation is the fastest control given the suspected credential compromise.

Why this answer

The scenario indicates compromised database credentials: failed logins from diverse geographic sources and off-hours CPU spikes on a non-internet-facing database. The FIRST mitigation action is to rotate the database credentials immediately, which invalidates the compromised credentials and stops the attacker's access. This is a containment action that takes precedence over investigation or perimeter blocking because the attacker already has valid credentials that bypass network controls.

Exam trap

CCSP often tests the ordering of incident response actions — candidates pick investigation or perimeter blocking first when the correct priority is containment via credential rotation.

How to eliminate wrong answers

Option A is wrong because conducting a forensic investigation first allows the attacker to continue using the compromised credentials, prolonging the breach; forensics should follow containment. Option B is wrong because blocking source IP ranges is ineffective when the attacker holds valid credentials and can pivot through new IPs or internal hosts — the database is in a private subnet, so external IP blocking may not even apply. Option C is wrong because enabling MFA on the database server is a longer-term hardening measure and may not be supported natively by all database engines; it does not immediately revoke the attacker's current access.

170
Multi-Selecthard

A DevOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and prevent tampering?

Select 3 answers
A.Sign container images using Cosign
B.Use admission controllers like Kyverno to verify signatures
C.Use the 'latest' tag for base images
D.Store images in a public registry
E.Generate attestation using in-toto
AnswersA, B, E

Cosign signs container images with cryptographic keys, producing a signature stored alongside the image in the registry. This gives verifiable provenance, satisfying the supply-chain integrity requirement by letting downstream systems confirm the image was not tampered with after signing.

Why this answer

Option A is correct because Cosign (part of the Sigstore project) cryptographically signs container images, producing a signature that can later be verified to prove the image was built by a trusted identity and has not been altered. Option B is correct because admission controllers such as Kyverno (or OPA Gatekeeper, Connaisseur) enforce policy at the Kubernetes API server, rejecting any pod whose image lacks a valid Cosign signature, thereby blocking tampered or unsigned images from running. Option E is correct because in-toto attestations capture signed, verifiable metadata about the build process (e.g., SLSA provenance), letting the team prove how and from what source an image was produced, which is central to supply-chain integrity.

Option C is not appropriate because the mutable 'latest' tag provides no immutability or version pinning, making it impossible to guarantee which image is deployed and undermining tamper detection. Option D is not appropriate because a public registry exposes images to unauthorized pulls and potential tampering, whereas a private, access-controlled registry with immutable tags is the secure choice.

Exam trap

The trap is that 'latest' tag and 'public registry' sound convenient and are common defaults, so candidates may select them as valid practices when they actually undermine integrity and tamper prevention.

171
MCQhard

An organization uses a CI/CD pipeline that automatically builds and deploys container images to a Kubernetes cluster. A security scanner flags that the base image contains a critical vulnerability. What is the best course of action to prevent vulnerable images from being deployed?

A.Replace the base image with a minimal image like Alpine.
B.Manually review and patch the base image before each build.
C.Integrate a container image scanning tool into the CI/CD pipeline that blocks builds if critical vulnerabilities are found.
D.Configure the scanner to send alerts after deployment.
AnswerC

Embedding scanning directly in the pipeline enforces a fail-closed gate: the build job inspects the image layers and aborts before the artefact reaches the cluster, satisfying the requirement to prevent vulnerable images from being deployed rather than merely detecting them post-deployment.

Why this answer

Integrating a container image scanning tool directly into the CI/CD pipeline and configuring it to block the build when critical vulnerabilities are found ensures that vulnerable images never reach the Kubernetes cluster. This shift-left approach enforces security gates automatically, preventing deployment of non-compliant images without relying on manual intervention or post-deployment alerts.

Exam trap

The trap here is that candidates may think replacing the base image with a minimal one (Option A) is sufficient, but ISC2 often tests that security must be automated and enforced as a gate in the pipeline, not just a manual or reactive measure.

How to eliminate wrong answers

Option A is wrong because simply replacing the base image with a minimal image like Alpine does not guarantee the absence of critical vulnerabilities; Alpine images can also contain vulnerabilities, and the approach does not address the need for automated scanning and blocking in the pipeline. Option B is wrong because manually reviewing and patching the base image before each build is not scalable, error-prone, and contradicts the automation principles of CI/CD; it also introduces delays and does not prevent human oversight. Option D is wrong because configuring the scanner to send alerts after deployment allows vulnerable images to be deployed into production, which defeats the purpose of preventing vulnerable images from being deployed; alerts after the fact do not block the deployment.

172
MCQeasy

A company has implemented a centralized logging solution for its cloud environment. The security team notices that logs from a critical application are missing for the past hour. What is the MOST likely cause?

A.The log retention policy was set to 0 days
B.Log encryption was enabled causing a delay
C.The security team does not have read permission on the log bucket
D.The logging agent on the application server stopped working
AnswerD

Centralised logging depends on the agent forwarding events; if that agent stops, no records reach the collector even though the application keeps running. Missing logs for exactly the past hour, with no other change, points to the local forwarder failing rather than a pipeline or storage issue.

Why this answer

The most likely cause of missing logs from a critical application for the past hour is that the logging agent on the application server stopped working, halting log forwarding. This is a common operational failure point and directly explains a sudden gap in logs from one source.

Exam trap

CCSP often tests the misconception that permission or encryption issues cause missing logs, when the most likely operational cause is a failed logging agent — candidates must distinguish between logs not being collected versus not being readable.

How to eliminate wrong answers

Option A is wrong because a retention policy of 0 days would delete logs immediately, but it would affect all logs consistently, not just the past hour, and is an unusual configuration. Option B is wrong because encryption does not cause a one-hour delay in log delivery; encryption is typically transparent and immediate. Option C is wrong because lack of read permission would prevent the security team from viewing logs, but the logs would still be collected and stored — the scenario says logs are missing, not inaccessible.

173
MCQmedium

A cloud customer is terminating its contract with a cloud provider and needs to ensure all data, including backups, is permanently deleted. Which contractual clause is most relevant?

A.Service Level Agreement
B.Data deletion clause
C.Data portability clause
D.Right to audit clause
AnswerB

A data deletion clause contractually obliges the provider to permanently erase all customer data, including backups, on termination. It directly satisfies the requirement for assured destruction of residual copies rather than merely returning primary data.

Why this answer

A data deletion clause contractually obligates the provider to permanently delete customer data, including backups, upon termination, which is exactly what the customer needs. It specifies timelines, methods, and certification of deletion, giving the customer enforceable assurance. This is the most directly relevant clause for ensuring no residual copies remain.

Exam trap

CCSP often tests the confusion between data portability (getting data out) and data deletion (ensuring data is destroyed), so candidates pick portability when the scenario demands permanent deletion.

How to eliminate wrong answers

Option A is wrong because an SLA defines availability and performance commitments, not data destruction obligations. Option C is wrong because data portability covers exporting data in a usable format, not deleting it. Option D is wrong because the right to audit allows inspection of provider controls, but does not itself mandate deletion of data or backups.

174
Multi-Selecteasy

A cloud security administrator is reviewing the security controls for a SaaS application. Which of the following are typically the responsibility of the cloud customer (tenant) in a SaaS model? (Choose two.)

Select 2 answers
A.Physical security of data center
B.Managing user access and identity
C.Network infrastructure security
D.Patching the underlying operating system
E.Data classification and encryption at rest
AnswersB, E

In SaaS, the provider secures the application and underlying infrastructure, but the tenant retains control of its own user accounts, roles, and authentication configuration. Managing user access and identity therefore sits with the customer, satisfying the shared responsibility split the question tests.

Why this answer

In a SaaS model, the customer is responsible for managing user access and identity (B) and data classification and encryption at rest (E). The provider handles physical security (A), network infrastructure security (C), and patching the underlying operating system (D).

175
MCQmedium

A healthcare organization stores PHI in an Amazon S3 bucket. An auditor finds that objects are encrypted with SSE-S3, and the organization wants to demonstrate that it controls the encryption keys and can audit their use independently of AWS-managed keys. Which change best satisfies this requirement while minimizing application changes?

A.Configure SSE-C with a customer-provided key sent on every request via the x-amz-server-side-encryption-customer-key header.
B.Switch the bucket to SSE-KMS using a customer managed key in AWS KMS, and grant the application role kms:Decrypt and kms:GenerateDataKey permissions.
C.Keep SSE-S3 but enable S3 Object Lock in compliance mode and versioning to prevent unauthorized key access.
D.Enable client-side encryption in the application using a locally stored AES-256 key and upload the encrypted objects to S3.
AnswerB

SSE-KMS with a customer managed key gives the organization control over key policy, rotation, and usage auditing via CloudTrail, which directly satisfies the auditor's requirement. Applications continue to use the standard S3 API; only IAM permissions for the KMS key are added. This minimizes code changes while providing independent key control and auditability.

Why this answer

SSE-KMS with a customer managed key allows the organization to define the key policy, control rotation, and audit every cryptographic operation through CloudTrail. Applications continue to use the standard S3 API with only additional IAM permissions on the KMS key, so code changes are minimal. This is the cleanest way to demonstrate independent key control and usage auditing.

Exam trap

The trap here is confusing 'customer controlled keys' with 'customer managed keys'; SSE-C gives control but shifts all key handling into the application, which is far more invasive than SSE-KMS.

176
Multi-Selectmedium

Which TWO responsibilities are typically shared between the cloud customer and the cloud provider in an IaaS model? (Choose two.)

Select 2 answers
A.Physical security of data centers.
B.Hypervisor security.
C.Management of security group rules.
D.Patching the guest operating system.
E.Configuration of virtual network firewalls.
AnswersC, E

Both customer (defines rules) and provider (enforces them) share this.

Why this answer

In an IaaS model, the cloud customer is responsible for managing security group rules, which act as virtual stateful firewalls controlling inbound and outbound traffic at the instance level. The cloud provider is responsible for the underlying network infrastructure, but the customer must configure these rules to enforce least-privilege access. This shared responsibility is explicitly defined in the AWS Shared Responsibility Model and similar frameworks.

Exam trap

ISC2 often tests the misconception that hypervisor security is a shared responsibility, but in IaaS, the provider alone secures the hypervisor, while the customer is responsible for guest OS and application-level security controls like security groups and virtual firewalls.

177
Multi-Selecthard

A security team is implementing a DevSecOps pipeline for a cloud-native application. Which three practices should be included to enhance application security? (Choose THREE.)

Select 3 answers
A.Static application security testing (SAST) in CI/CD
B.Infrastructure as code (IaC) scanning
C.Dependency scanning for open source components
D.Manual penetration testing only at final stage
E.Runtime application self-protection (RASP) deployment
AnswersA, B, C

SAST scans source code within the CI/CD pipeline, catching injection and insecure coding flaws before artefacts are built or deployed. This shifts detection left, satisfying the requirement to enhance security throughout the DevSecOps lifecycle rather than only at runtime.

Why this answer

SAST (A) is correct because it analyzes source code in the CI/CD pipeline to catch vulnerabilities like injection flaws and insecure coding patterns before the build is deployed, shifting security left. IaC scanning (B) is correct because it examines templates such as Terraform, CloudFormation, or Kubernetes manifests for misconfigurations (e.g., open S3 buckets, overly permissive IAM roles) before infrastructure is provisioned. Dependency scanning (C) is correct because it identifies known CVEs in open source libraries and transitive dependencies, which are a major attack surface in cloud-native applications, and can fail the build on critical findings.

Manual penetration testing only at the final stage (D) is not a DevSecOps practice because it is late, point-in-time, and cannot keep pace with continuous delivery. RASP (E) is a runtime protection control, not a pipeline practice, and it does not prevent vulnerabilities from entering the codebase during development.

178
MCQeasy

A company is contracting with a cloud provider and wants to ensure they have visibility into the provider's security controls. Which contract clause is most important to include?

A.Indemnification clause
B.Right to audit clause
C.Service Level Agreement (SLA) for uptime
D.Data portability clause
AnswerB

A right to audit clause contractually grants the customer the ability to inspect the provider's security controls and evidence, satisfying the stem's goal of visibility into those controls. Without it, the customer relies solely on provider assertions or third-party reports.

Why this answer

A right to audit clause gives the customer the ability to review the provider's security controls, policies, and procedures. The SLA for uptime focuses on availability, not security. Data portability is about moving data.

Indemnification covers liability, not visibility.

179
MCQhard

An organization deploys a serverless application using AWS Lambda functions that access an RDS database. Which practice best ensures that the database credentials are protected?

A.Store credentials in the function code
B.Use AWS Systems Manager Parameter Store with KMS encryption and IAM roles
C.Hardcode credentials in environment variables
D.Use database temporary tokens generated on the fly
AnswerB

Storing credentials in Systems Manager Parameter Store with KMS encryption keeps secrets encrypted at rest, while IAM roles let Lambda retrieve them without embedded static keys. This satisfies the scenario's constraint of protecting database credentials in a serverless environment, since no long-lived secrets reside in function code or environment variables.

Why this answer

AWS Systems Manager Parameter Store, combined with AWS KMS for encryption and IAM roles for access control, provides a secure, auditable, and managed way to store and retrieve database credentials. This approach avoids embedding secrets in code or environment variables, and it integrates natively with AWS Lambda via the IAM execution role, ensuring that only authorized functions can decrypt and access the credentials.

Exam trap

The trap here is that candidates often confuse 'temporary tokens' (Option D) with a secure credential storage method, but the CCSP exam expects you to recognize that managing the initial secret (the token's root of trust) is still required, and Parameter Store with KMS is the definitive best practice for protecting static credentials in serverless architectures.

How to eliminate wrong answers

Option A is wrong because storing credentials directly in the function code exposes them to anyone with read access to the code repository or deployment artifacts, violating the principle of least privilege and making secrets management impossible. Option C is wrong because hardcoding credentials in environment variables is insecure; environment variables can be viewed in the Lambda console, CloudWatch logs, or through AWS CLI, and they are not encrypted by default, leading to potential credential leakage. Option D is wrong because database temporary tokens generated on the fly (e.g., using IAM database authentication for RDS) are a valid security practice for some databases, but the question specifically asks about protecting database credentials; temporary tokens are not credentials themselves but an alternative authentication method, and the option does not specify how the initial secret (e.g., the token generation key) is secured, making it an incomplete or misleading answer in this context.

180
MCQeasy

A small business recently migrated its file server to a cloud storage service like Amazon S3. They use bucket policies to control access. The IT manager, who is not a security expert, configured the bucket policy to allow all users within the company's AWS account to have read and write access. During an internal audit, it was discovered that the bucket also had a public ACL that allowed 'Everyone' to read objects. The security analyst needs to fix the misconfiguration and prevent future occurrences. Which of the following actions should the analyst take first?

A.Delete the bucket and recreate it with default private settings.
B.Set up a notification to alert when bucket policies change.
C.Remove the public ACL and update the bucket policy to enforce least privilege.
D.Enable bucket versioning to recover from accidental public exposure.
AnswerC

Removing the public ACL immediately closes the anonymous read exposure, satisfying the audit's urgent remediation requirement. Updating the bucket policy to least privilege then addresses the over-broad account-wide read/write grant, since S3 evaluates ACLs and bucket policies independently — both must be corrected to eliminate unintended access.

Why this answer

The immediate priority is to remediate the active vulnerability by removing the public ACL that grants 'Everyone' read access, then updating the bucket policy to enforce least privilege for the company's AWS account. This directly addresses the misconfiguration and aligns with the principle of denying public access by default, which is a core security best practice for cloud storage services like Amazon S3.

Exam trap

ISC2 often tests the misconception that deleting and recreating a resource is the safest or quickest fix, when in reality the proper remediation is to modify the existing access controls without destroying the resource.

How to eliminate wrong answers

Option A is wrong because deleting and recreating the bucket is an unnecessarily destructive and time-consuming approach; the misconfiguration can be fixed by simply removing the public ACL and adjusting the bucket policy, and it does not address the root cause of why the public ACL was allowed in the first place. Option B is wrong because setting up a notification for bucket policy changes is a detective control that would alert on future changes, but it does not fix the current public ACL exposure; the immediate action must be to remediate the existing vulnerability. Option D is wrong because enabling bucket versioning helps recover from accidental deletion or overwrite of objects, but it does not prevent or fix public access; versioning does not affect access control permissions and would not remove the existing public ACL.

181
Multi-Selectmedium

A cloud data governance team is defining controls for data remanence in a multi-tenant public cloud environment. They must address both logical and physical media reuse concerns. Which TWO practices are MOST appropriate for managing data remanence risk? (Choose two.)

Select 2 answers
A.Implement cryptographic erasure by destroying tenant-controlled keys when data must be made unrecoverable.
B.Encrypt data with provider-managed keys and assume key rotation eliminates residual data.
C.Overwrite storage blocks with random data using a tenant-installed utility on the provider's physical hosts.
D.Rely on the provider's multi-tenancy to isolate data so remanence is not a concern.
E.Require the provider to supply audit evidence of media sanitization and secure disposal for decommissioned storage hardware.
AnswersA, E

Cryptographic erasure renders data unreadable by destroying the keys, which is effective across replicas and backups that tenants cannot directly purge. It addresses logical remanence in a multi-tenant environment where physical media is shared and managed by the provider. This gives the tenant a direct, verifiable destruction mechanism independent of provider deletion processes.

Why this answer

Managing data remanence in a public cloud requires addressing both layers: physical media sanitization, which tenants cannot perform and must verify through provider audit evidence, and logical destruction, which tenants achieve through cryptographic erasure using keys they control. Tenant-side overwriting is infeasible, isolation is not a sanitization control, and provider-managed key rotation does not destroy data.

Exam trap

The trap here is assuming that logical isolation or provider key rotation eliminates residual data, when remanence requires either verified physical sanitization or tenant-controlled cryptographic erasure.

182
MCQmedium

A company is negotiating a cloud service agreement and wants to ensure it can periodically assess the security of the cloud provider's operations. Which contractual clause is most directly relevant to this requirement?

A.Right to Audit clause permitting the customer to review the provider's security controls and certifications
B.Data portability clause ensuring data can be exported in a usable format
C.Service Level Agreement (SLA) with uptime guarantees
D.Data deletion clause specifying how data is deleted after contract termination
AnswerA

A Right to Audit clause directly grants the customer contractual authority to examine the provider's security controls and certifications, satisfying the requirement for periodic assessment of the provider's operations. Without this clause, the customer relies solely on the provider's self-reported attestations, losing independent verification rights.

Why this answer

A Right to Audit clause explicitly grants the customer the contractual right to assess the cloud provider's security controls, certifications, and compliance through audits or inspections. This directly addresses the requirement to periodically assess the provider's operations. Other clauses address different concerns such as data portability, performance, or data deletion, but not security assessment.

Exam trap

CCSP often tests confusion between Right to Audit and other contractual clauses like SLA or data portability, but the key is that only Right to Audit directly enables security assessment.

How to eliminate wrong answers

Option B is wrong because data portability focuses on the ability to export data, not on assessing security controls. Option C is wrong because an SLA with uptime guarantees addresses availability, not security assessment. Option D is wrong because a data deletion clause specifies how data is removed after contract termination, not ongoing security evaluation.

183
MCQhard

A security engineer is reviewing a Terraform configuration and wants to prevent deployment of an S3 bucket with public read access. Which IaC scanning tool is best suited for this task?

A.Checkov
B.GitGuardian
C.Snyk
D.Dependabot
AnswerA

Checkov is a static analysis tool that parses Terraform plans and flags misconfigured resources, including S3 buckets permitting public read access. This satisfies the stem's requirement to block deployment of publicly readable buckets before apply, unlike runtime or cloud-native posture tools.

Why this answer

Checkov is a static analysis tool purpose-built for scanning Infrastructure-as-Code (Terraform, CloudFormation, Kubernetes) against security and compliance policies. It has built-in policies that flag S3 buckets with public ACLs or policies, making it the right fit for preventing public-read S3 deployments.

Exam trap

The trap is confusing secrets scanning (GitGuardian) or dependency scanning (Snyk, Dependabot) with IaC misconfiguration scanning — only Checkov is designed to evaluate Terraform resource attributes like S3 ACLs.

How to eliminate wrong answers

Option B is wrong because GitGuardian is a secrets-detection tool that scans repositories for leaked credentials, not IaC misconfigurations. Option C is wrong because Snyk focuses on open-source dependency vulnerabilities and container scanning, not Terraform policy enforcement. Option D is wrong because Dependabot automates dependency updates and vulnerability alerts for package manifests, not IaC security scanning.

184
MCQeasy

A healthcare company stores patient records in a cloud storage bucket. They need to encrypt the data at rest using encryption keys that they manage themselves, but they want to generate the keys within the cloud provider's key management service. Which encryption option should they choose?

A.Client-side encryption
B.Server-side encryption with Amazon S3-managed keys (SSE-S3)
C.Customer-Managed Encryption Keys (CMEK)
D.Customer-Supplied Encryption Keys (CSEK)
AnswerC

CMEK lets the provider's KMS generate and hold the key material while the customer retains control over key lifecycle and permissions, satisfying the requirement for self-managed keys generated inside the cloud KMS rather than imported or provider-owned.

Why this answer

Customer-Managed Encryption Keys (CMEK) means the cloud provider's KMS generates and stores the key material, but the customer controls the key's lifecycle — rotation, disabling, and deletion — and the key is used by the provider's service to encrypt data at rest. This matches the requirement of keys managed by the customer but generated within the provider's KMS.

Exam trap

The trap is conflating 'customer-managed' with 'customer-supplied' or 'client-side' — candidates must distinguish who generates the key (provider KMS vs. customer) from who controls its lifecycle (customer vs. provider).

How to eliminate wrong answers

Option A is wrong because client-side encryption means the customer encrypts data before uploading, managing keys entirely outside the provider's KMS — the opposite of generating keys in the provider's KMS. Option B is wrong because SSE-S3 uses keys fully managed by AWS (or the provider), giving the customer no control over key lifecycle or rotation. Option D is wrong because Customer-Supplied Encryption Keys (CSEK) require the customer to generate and supply the raw key material with each request; the provider never stores or generates it, so it fails the 'generate within the provider's KMS' requirement.

185
Multi-Selecthard

A cloud architect is implementing data loss prevention (DLP) for a data lake containing PII. They want to automatically detect and transform sensitive data like Social Security numbers and medical record numbers. Which THREE actions should they take? (Choose three.)

Select 3 answers
A.Apply de-identification transforms such as masking or tokenization
B.Enable bucket versioning
C.Use cloud DLP API to scan for sensitive data types
D.Configure automated classification labels based on DLP findings
E.Set up cross-region replication for durability
AnswersA, C, D

Masking and tokenisation replace or substitute sensitive values so the data lake retains analytical utility while Social Security and medical record numbers are no longer exposed. This directly satisfies the stem's requirement to transform detected sensitive data, complementing scanning and classification rather than duplicating them.

Why this answer

Option C is correct because the cloud DLP API (e.g., Google Cloud DLP / Sensitive Data Protection) is the service that inspects data lake content and identifies predefined infoTypes such as US_SOCIAL_SECURITY_NUMBER and medical record numbers, which is the required detection step. Option A is correct because de-identification transforms like masking, tokenization, or format-preserving encryption are exactly the mechanisms DLP provides to irreversibly or reversibly transform the detected PII before it is stored or shared. Option D is correct because automated classification labels derived from DLP findings let the architect tag and govern the data lake objects by sensitivity level, enabling downstream policy enforcement and audit.

Option B is not correct because bucket versioning only preserves object versions for recovery and does not detect or transform PII. Option E is not correct because cross-region replication addresses durability and availability, not data loss prevention or sensitive-data transformation.

Exam trap

The trap is that versioning and replication are common 'best practice' options that sound security-relevant, but they address durability and availability — not detection, classification, or transformation of sensitive data.

186
Multi-Selecthard

A cloud security architect is drafting design requirements for storing regulated data in a public cloud IaaS environment. The requirements must address the risks introduced by resource pooling and multi-tenancy. Which TWO of the following design controls directly mitigate multi-tenancy risks in this environment? (Choose two.)

Select 2 answers
A.Require strong workload isolation using virtual networks, security groups, and separate tenant identities
B.Rely on the provider's published service-level agreement to guarantee that tenants never share a physical host
C.Disable all provider-side logging so that telemetry from one tenant cannot be aggregated with another tenant's records
D.Enforce cryptographic isolation of data at rest with tenant-managed keys held outside the provider's control
E.Move the regulated data into the provider's object storage with default provider-managed encryption only
AnswersA, D

Logical segmentation through virtual private networks, security groups, and distinct identity domains keeps one tenant's workloads from reaching another's even when they share physical infrastructure. These controls constrain east-west traffic and administrative reachability, which are the primary paths exploited when isolation is weak. They are standard, effective mitigations for the risks introduced by pooled multi-tenant compute and network resources.

Why this answer

Resource pooling means physical infrastructure is shared, so mitigations must either make the data unreadable to anyone outside the tenant or make the logical boundaries between tenants enforceable and auditable. Externally held encryption keys protect confidentiality even if a boundary fails, and virtual network segmentation with distinct identities constrains reachability. Contractual guarantees, disabled logging, and default provider-managed encryption do not change the underlying sharing risk.

Exam trap

The trap here is accepting a provider guarantee or default encryption as sufficient isolation, when multi-tenancy risk must be mitigated by controls the tenant actually enforces.

187
MCQeasy

A US-based retail company stores customer personal data in a cloud provider's data center located in Germany. The company is subject to GDPR because it offers goods to EU residents. Which legal mechanism most directly establishes that the controller and the cloud provider may lawfully transfer personal data from the EU to the provider's US-based support team?

A.Standard Contractual Clauses (SCCs) executed between the controller and the cloud provider
B.A data processing agreement (DPA) alone, without any additional transfer safeguard
C.A Binding Corporate Rules (BCR) approval granted to the cloud provider by its lead supervisory authority
D.The provider's ISO/IEC 27001 certification covering its German data center
AnswerA

SCCs are pre-approved contractual terms adopted by the European Commission that provide an Article 46 transfer safeguard when personal data leaves the EEA. Because the provider's US support staff can access EU personal data, the controller needs a valid transfer tool, and SCCs are the most common and directly applicable mechanism for controller-to-processor transfers in a cloud engagement.

Why this answer

When EU personal data is accessible from a third country such as the United States, the controller needs a valid Chapter V transfer mechanism. Standard Contractual Clauses are pre-approved by the European Commission and are the most direct, widely used tool for controller-to-processor cloud transfers. A DPA governs processing but does not authorize the transfer, and security certifications or corporate-group rules do not fill that gap.

Exam trap

The trap here is assuming that a data processing agreement or a security certification alone satisfies GDPR cross-border transfer requirements, when an Article 46 mechanism such as SCCs is also needed.

188
Multi-Selectmedium

A cloud customer is assessing a provider's compliance with the Cloud Security Alliance (CSA) STAR program. Which TWO artifacts are part of the STAR program? (Choose two.)

Select 2 answers
A.ISO/IEC 27017 certificate
B.Cloud Controls Matrix (CCM)
C.GDPR compliance statement
D.SOC 2 Type II report
E.Consensus Assessments Initiative Questionnaire (CAIQ)
AnswersB, E

The CCM is a cybersecurity control framework specifically for cloud computing, developed by the CSA. It is a foundational component of the STAR program, providing the controls against which providers are assessed. The CCM helps customers understand necessary controls and is integral to STAR.

Why this answer

The CSA STAR program includes the Cloud Controls Matrix (CCM) as the control framework and the Consensus Assessments Initiative Questionnaire (CAIQ) as the assessment tool. These artifacts enable cloud providers to document their security controls and customers to evaluate them. Other reports like SOC 2 or ISO certifications are separate and not unique to STAR, though they may be used in conjunction.

Exam trap

The trap here is assuming that any security certification or report is part of the STAR program, when STAR specifically offers the CCM and CAIQ as its own tools.

189
MCQmedium

A cloud security architect is evaluating a CSP for a financial services client. Which of the following audit reports would provide the most comprehensive assurance regarding the CSP's controls over security, availability, processing integrity, confidentiality, and privacy?

A.PCI DSS Attestation of Compliance
B.SOC 2 Type II
C.SOC 1 Type II
D.ISO 27001 certification
AnswerB

SOC 2 Type II reports on the design and operating effectiveness of controls across security, availability, processing integrity, confidentiality and privacy over an audit period. This matches the stem's five trust services criteria, unlike point-in-time reports.

Why this answer

SOC 2 Type II is specifically designed to provide assurance over security, availability, processing integrity, confidentiality, and privacy (the Trust Services Criteria). It includes an independent auditor's opinion on the effectiveness of controls over a period. This makes it the most comprehensive for the listed areas.

Exam trap

CCSP often tests the distinction between SOC 2 and ISO 27001; candidates might think ISO 27001 certification covers all five trust principles, but SOC 2 Type II is specifically designed for that comprehensive assurance.

How to eliminate wrong answers

Option A is wrong because PCI DSS AoC focuses only on payment card data security, not the broader trust principles. Option C is wrong because SOC 1 Type II is for financial reporting controls (ICFR), not security, availability, etc. Option D is wrong because ISO 27001 certification covers information security management, but it does not specifically address availability, processing integrity, confidentiality, and privacy in the same comprehensive audit report as SOC 2.

190
MCQmedium

A healthcare organization stores patient records in a cloud database. They need to ensure that database administrators cannot view sensitive columns like SSN and diagnosis. Which data masking technique should be applied?

A.Dynamic data masking
B.Static data masking
C.Encryption at rest
D.Tokenization
AnswerA

Dynamic data masking applies masking at query time, so administrators querying the database see redacted SSN and diagnosis values while privileged roles retain full data. This satisfies the constraint that DBAs must not view sensitive columns, unlike static masking, which would alter stored data permanently.

Why this answer

Dynamic data masking (DDM) is the correct choice because it allows the healthcare organization to mask sensitive columns (e.g., SSN, diagnosis) in real-time at the database query layer, based on user permissions. DDM does not alter the underlying stored data; it transforms the result set on-the-fly for unauthorized users (like DBAs), ensuring they see masked values while authorized personnel see the actual data. This meets the requirement of preventing database administrators from viewing sensitive columns without changing the data at rest.

Exam trap

ISC2 often tests the distinction between masking at query time (dynamic) versus masking at rest (static), and candidates mistakenly choose static masking because they think it 'permanently' protects data, but the key requirement is that DBAs cannot view sensitive columns in the live production database, which only dynamic masking addresses without altering the original data.

How to eliminate wrong answers

Option B (Static data masking) is wrong because it creates a separate, permanently masked copy of the database, which does not prevent DBAs from accessing the original unmasked data in the production database. Option C (Encryption at rest) is wrong because it protects data on disk but does not control visibility at query time; DBAs with database access can still decrypt and view the data when querying. Option D (Tokenization) is wrong because it replaces sensitive data with tokens and stores the mapping in a separate vault, which is overkill for this use case and does not provide real-time, role-based masking within the database itself.

191
MCQeasy

A security engineer needs to provide temporary access to a specific object in a cloud storage bucket for a third-party auditor, without granting them any other permissions. The access should expire automatically after 24 hours. Which method should the engineer use?

A.Generate a time-limited signed URL for the object with a 24-hour expiration.
B.Configure a bucket access policy that allows access from the auditor's IP address.
C.Assign the auditor a cloud role with read-only access to the bucket.
D.Generate a long-term access key pair for the auditor and attach a user policy.
AnswerA

A signed URL embeds a cryptographic signature and expiry timestamp, granting temporary read access to that single object. The 24-hour expiration satisfies the automatic revocation requirement without granting the auditor broader bucket permissions or requiring an account.

Why this answer

A time-limited signed URL is generated using the object owner's credentials and embeds an expiration (e.g., 24 hours) directly in the URL. The third-party auditor can retrieve only that specific object until expiry, with no cloud identity, no IAM user, and no broader permissions. This satisfies least privilege, automatic expiry, and zero credential distribution.

Exam trap

The trap is assuming that IAM roles or bucket policies can provide automatic time-limited, per-object access — they cannot; only signed URLs (or similar presigned mechanisms) combine per-object granularity with built-in expiration and no credential requirement.

How to eliminate wrong answers

Option B is wrong because a bucket access policy tied to an IP address still requires the auditor to authenticate with cloud credentials and grants access to the bucket, not just one object, and does not auto-expire. Option C is wrong because assigning a cloud role requires creating an identity for the auditor, grants read access to the entire bucket (or more), and the role persists until explicitly removed — no automatic 24-hour expiry. Option D is wrong because long-term access keys are a persistent credential, violate least privilege, and do not expire automatically, creating a serious security risk.

192
MCQmedium

A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that if an attacker gains access to the bucket, the data cannot be read. They also want to prevent the cloud provider from accessing the plaintext. Which approach best meets these requirements?

A.Use bucket policies to restrict access to only authorized IAM roles.
B.Enable server-side encryption with provider-managed keys (SSE-S3).
C.Enable server-side encryption with customer-provided keys (SSE-C).
D.Use client-side encryption with customer-managed keys stored on-premises.
AnswerD

Client-side encryption encrypts data before it leaves the customer's environment, and keys are stored on-premises, outside the provider's control. Thus, the cloud provider only stores ciphertext and cannot decrypt without the customer's keys. If an attacker gains access to the bucket, they obtain only encrypted data, satisfying both requirements.

Why this answer

Client-side encryption with customer-managed keys ensures data is encrypted before reaching the cloud and keys never leave the customer's control. This prevents the cloud provider from accessing plaintext and protects data even if the storage bucket is compromised. Server-side options leave key management or plaintext handling with the provider, failing the requirement.

Exam trap

The trap here is assuming that server-side encryption with customer-provided keys (SSE-C) prevents the provider from accessing plaintext, when in fact the provider handles the key during encryption and decryption operations.

193
Multi-Selectmedium

Which TWO of the following are effective methods for preventing hardcoded credentials from being committed to a cloud application's source code repository? (Select TWO)

Select 2 answers
A.Implementing pre-commit hooks with secret scanning
B.Disabling SSH keys for developers
C.Enforcing code reviews by senior developers
D.Encrypting the entire repository
E.Using environment variables instead of hardcoding
AnswersA, E

Pre-commit hooks run secret scanning locally before a commit is finalised, blocking credentials from ever entering repository history. This directly satisfies the stem's prevention requirement, unlike detection tools that only flag secrets after they have already been committed.

Why this answer

Option A is correct because pre-commit hooks with secret scanning tools (e.g., git-secrets, gitleaks, detect-secrets) run locally before code is committed, detecting and blocking secrets such as API keys, passwords, and tokens before they ever enter the repository history. Option E is correct because storing credentials in environment variables (or a secrets manager) keeps sensitive values out of source files entirely, so nothing hardcoded can be committed. Option B is wrong because disabling SSH keys addresses developer authentication to Git, not the presence of hardcoded credentials in code.

Option C is wrong because code reviews are a detective, manual control that may catch secrets but does not reliably prevent them from being committed. Option D is wrong because encrypting the repository at rest does not stop plaintext credentials from being committed and later exposed once decrypted or cloned.

Exam trap

ISC2 CCSP often tests the distinction between preventive controls (pre-commit hooks, environment variables) and detective/reactive controls (code reviews, encryption) to see if candidates understand that only proactive measures can stop secrets from entering the repository in the first place.

194
MCQeasy

A cloud security engineer is troubleshooting a failure in automated backups for a production database. The backup job runs nightly but has failed for the past three nights. The logs show permission denied errors when the backup service attempts to write to the storage bucket. Which action should the engineer take first?

A.Open a support ticket with the cloud provider for incident response.
B.Check the IAM roles and bucket ACLs assigned to the service account.
C.Restart the backup service and retry the job.
D.Rotate the service account keys used for authentication.
AnswerB

Permission denied errors when writing to the bucket point to identity or resource-policy authorisation, so verifying the service account's IAM roles and bucket ACLs satisfies the stem's access-failure constraint before any retry or code change.

Why this answer

The permission denied errors indicate that the service account used by the backup job lacks the necessary permissions to write to the storage bucket. Checking the IAM roles and bucket ACLs is the first logical step to identify and resolve the misconfiguration, as it directly addresses the root cause without introducing unnecessary changes or escalations.

Exam trap

ISC2 often tests the distinction between authentication (who you are) and authorization (what you can do), leading candidates to mistakenly rotate keys or restart services instead of checking permissions.

How to eliminate wrong answers

Option A is wrong because opening a support ticket is premature; the engineer should first investigate and resolve the permission issue internally, as it is likely a configuration problem rather than a provider-side incident. Option C is wrong because restarting the backup service and retrying the job will not fix the underlying permission denial; the same error will recur until the IAM or ACL configuration is corrected. Option D is wrong because rotating service account keys addresses authentication (who you are), not authorization (what you are allowed to do); the error is about permission to write, not about invalid credentials.

195
Multi-Selecteasy

A company is planning to implement data classification for its cloud environment. Which TWO components are essential for an effective data classification scheme? (Select TWO.)

Select 2 answers
A.Encryption at rest for all classified data
B.A process to tag resources with the appropriate classification labels
C.Access control policies based on classification
D.Automated DLP scanning to enforce classification
E.A classification scheme with defined labels (e.g., public, internal, confidential, restricted)
AnswersB, E

Tagging resources with classification labels is the operational mechanism that actually applies the scheme to data at scale. Without an enforced tagging process, labels remain theoretical and cannot drive protection, access, or retention controls, so the classification scheme is never realised across the cloud estate.

Why this answer

Option B is correct because an effective data classification scheme requires a repeatable process to tag resources with the appropriate classification labels, so that the assigned sensitivity level is actually recorded and travels with the data or resource for later policy enforcement. Option E is correct because classification cannot function without a defined taxonomy of labels, such as public, internal, confidential, and restricted, which establishes the categories and criteria that everything else maps to. Together, the label scheme (E) and the tagging process (B) form the foundational components of classification.

Option A is not essential to the classification scheme itself; encryption at rest is a protective control that may be applied based on classification, not a component required to classify data. Option C is also a downstream control, since access policies consume classification labels rather than define the scheme. Option D is likewise an enforcement mechanism, and automated DLP scanning depends on classification being established first rather than being essential to creating it.

Exam trap

CCSP often tests the difference between the classification scheme itself and the controls that enforce it, causing candidates to select encryption or DLP as 'essential components' when they are actually downstream controls.

196
MCQeasy

A security analyst is reviewing application logs and notices that a large number of requests from a single IP address are attempting to access a REST API endpoint with invalid session tokens. Which cloud-based mitigation is MOST effective at blocking such automated attacks?

A.Rotate API keys more frequently
B.Implement cross-origin resource sharing (CORS) policies
C.Configure a web application firewall (WAF) with rate limiting and IP blacklisting
D.Require encryption of session tokens
AnswerC

A WAF inspects HTTP traffic and applies rate limiting plus IP blacklisting, throttling or dropping the abusive source before requests reach the API. This blocks automated token-guessing floods more effectively than host-level or identity controls.

Why this answer

A Web Application Firewall (WAF) with rate limiting and IP blacklisting directly addresses the described attack: a single IP flooding a REST API with invalid session tokens. Rate limiting throttles the number of requests from that IP, while IP blacklisting blocks it entirely, preventing automated brute-force or credential-stuffing attempts at the cloud edge before they reach the application.

Exam trap

The trap here is that candidates may confuse session token management (e.g., rotation, encryption) with the need for a perimeter defense that controls request volume and source, leading them to pick options that address token validity rather than the automated, high-volume nature of the attack.

How to eliminate wrong answers

Option A is wrong because rotating API keys more frequently does not mitigate automated attacks using invalid session tokens; API keys are typically used for service-to-service authentication, not for user session validation, and rotation does not stop a flood of requests from a single IP. Option B is wrong because CORS policies control which origins (domains) can make cross-origin requests from a browser, but they do not block automated scripts or tools (e.g., cURL, Postman) that ignore CORS headers, nor do they rate-limit or blacklist IPs. Option D is wrong because requiring encryption of session tokens (e.g., via TLS) protects token confidentiality in transit but does not prevent an attacker from sending many requests with invalid tokens; encryption does not address the volume or source of the attack.

197
Multi-Selecthard

An organization is migrating critical workloads to the cloud and must ensure data confidentiality. Which THREE of the following practices help protect data in transit? (Choose three.)

Select 3 answers
A.Implementing IPsec VPNs
B.Using HTTPS for web applications
C.Applying access control policies
D.Enabling encryption for stored data
E.Using SSL/TLS for application traffic
AnswersA, B, E

IPsec VPNs encrypt packets at the network layer, protecting data as it traverses untrusted networks between sites or to the cloud. This directly satisfies the confidentiality-in-transit constraint by preventing interception or eavesdropping on traffic flows, independent of application-level controls.

Why this answer

Option A (Implementing IPsec VPNs) is correct because IPsec operates at the network layer to encrypt and authenticate IP packets between endpoints, protecting data as it travels across untrusted networks such as the internet. Option B (Using HTTPS for web applications) is correct because HTTPS wraps HTTP in TLS, encrypting the session between browser and server and preventing eavesdropping or tampering in transit. Option E (Using SSL/TLS for application traffic) is correct because TLS (and its predecessor SSL) provides cryptographic confidentiality and integrity for application-layer protocols, directly securing data in transit.

Option C (Applying access control policies) is not a transit-encryption mechanism; it governs who may access resources and does not itself protect data confidentiality while it moves across a network. Option D (Enabling encryption for stored data) addresses data at rest, not data in transit, so it does not satisfy the scenario's requirement.

Exam trap

ISC2 often tests the distinction between data-in-transit controls (like IPsec, TLS, HTTPS) and data-at-rest controls (like storage encryption) or policy-based controls (like access control policies), leading candidates to mistakenly select options that protect data at rest or manage permissions instead of securing data during transmission.

198
MCQmedium

Refer to the exhibit. A security analyst sees this alert. According to the shared responsibility model, who is primarily responsible for ensuring that the IAM policy correctly restricts access?

A.The third-party auditor
B.The customer
C.Both equally
D.The cloud provider
AnswerB

Under the shared responsibility model, the cloud provider secures the infrastructure, while the customer owns identity and access management configuration. The customer defines and maintains IAM policies, so ensuring a policy correctly restricts access remains the customer's responsibility, not the provider's.

Why this answer

Under the cloud shared responsibility model, the customer is always responsible for the security 'in' the cloud — including identity and access management (IAM) policies, user permissions, and access controls. The cloud provider secures the infrastructure 'of' the cloud, but configuring IAM policies to correctly restrict access is squarely a customer responsibility.

Exam trap

CCSP often tests whether candidates incorrectly assume the cloud provider shares responsibility for customer-defined IAM policies, when in fact IAM configuration is exclusively a customer responsibility.

How to eliminate wrong answers

Option A is wrong because a third-party auditor provides independent assessment and attestation, not operational responsibility for IAM configuration. Option C is wrong because responsibility is not shared equally for IAM policy correctness; the customer owns identity and access management entirely. Option D is wrong because the cloud provider manages the underlying infrastructure and the IAM service's availability, but not the customer's specific policy definitions and permission assignments.

199
MCQeasy

A company is migrating its on-premises database to a cloud-based managed database service. The security policy requires that data at rest be encrypted and that the company retain control over key rotation. Which cloud service should they use to meet these requirements?

A.Cloud HSM or Key Management Service (KMS) with customer-managed keys.
B.Transparent Data Encryption (TDE) with keys stored in the database.
C.Cloud provider's default encryption with provider-managed keys.
D.Client-side encryption with keys stored in a local file server.
AnswerA

Using a cloud HSM or KMS with customer-managed keys allows the company to create, rotate, and disable keys according to its own policies. The cloud provider manages the hardware but cannot access key material. This meets both encryption at rest and customer control over rotation.

Why this answer

A cloud HSM or KMS with customer-managed keys gives the company control over key lifecycle, including rotation, while still encrypting data at rest. Provider-managed keys, client-side encryption with local key storage, and TDE with in-database keys either cede rotation control or introduce operational risks that fail the policy requirement.

Exam trap

The trap here is confusing encryption at rest with key control; default provider encryption encrypts data but does not give the customer control over rotation.

200
Multi-Selectmedium

A cloud security manager is evaluating the security responsibilities of the cloud provider and the cloud consumer under the shared responsibility model for a PaaS deployment. Which TWO of the following are typically the responsibility of the cloud consumer? (Choose two.)

Select 2 answers
A.Managing the physical security of data centers
B.Securing the hypervisor and virtualization layer
C.Patching the underlying operating system and runtime
D.Managing user identities and access within the application
E.Configuring application-level security controls
AnswersD, E

The consumer is responsible for managing user identities and access within their application, including creating user accounts, assigning roles, and enforcing least privilege. While the provider may offer identity services, the consumer must configure and manage them for their specific application. This is a key consumer responsibility in PaaS.

Why this answer

In a PaaS model, the cloud provider manages the underlying infrastructure, including servers, operating systems, and runtime environments, while the consumer is responsible for the security of their applications and data. This includes configuring application-level security controls and managing user identities and access within the application. These two areas fall under the consumer's control and are critical for protecting the application from threats.

Exam trap

The trap here is assuming that because the provider manages the platform, the consumer has no security responsibilities, or confusing infrastructure-level responsibilities with application-level ones.

201
MCQhard

During a forensic investigation of a suspected data exfiltration incident in AWS, a security team needs to analyze network traffic to identify the destination IP addresses and volume of data transferred. Which data source is most appropriate for this analysis?

A.VPC Flow Logs
B.AWS Config configuration history
C.AWS CloudTrail management events
D.Amazon S3 access logs
AnswerA

VPC Flow Logs capture IP-level metadata for traffic traversing elastic network interfaces, including source and destination addresses, ports, protocol and bytes transferred. This directly satisfies the requirement to identify exfiltration destinations and quantify transferred volume, which CloudTrail management events cannot provide.

Why this answer

VPC Flow Logs capture metadata about IP traffic flowing to and from network interfaces in a VPC, including source/destination IP addresses, ports, protocols, and the number of bytes transferred. This makes them the ideal data source for identifying the destination IP addresses and volume of data exfiltrated, as they provide per-flow byte counts and packet-level details without requiring packet capture.

Exam trap

ISC2 CCSP often tests the distinction between logs that capture API-level activity (CloudTrail) versus network-level metadata (Flow Logs), and candidates mistakenly choose CloudTrail because they think 'management events' includes network traffic, but it only records control plane operations, not data plane flows.

How to eliminate wrong answers

Option B (AWS Config configuration history) is wrong because it records resource configuration changes (e.g., security group rules, instance types) over time, not network traffic or data transfer volumes. Option C (AWS CloudTrail management events) is wrong because it logs API calls that modify AWS resources (e.g., CreateInstance, AuthorizeSecurityGroupIngress), not the actual network packets or byte counts flowing through the VPC. Option D (Amazon S3 access logs) is wrong because they only log requests made to S3 buckets (e.g., GET, PUT, DELETE operations) and do not capture general VPC network traffic or destination IP addresses for exfiltration outside of S3 interactions.

202
Multi-Selectmedium

An enterprise is evaluating whether to move a legacy customer relationship management system to a cloud provider. The security architect must assess the provider's ability to meet the enterprise's control requirements before signing. Which TWO artifacts or activities BEST provide direct evidence of the provider's security control environment? (Choose two.)

Select 2 answers
A.A current independent third-party audit report covering the relevant trust services criteria
B.The provider's public marketing brochure describing its security posture
C.A customer reference call with another organization of similar size in the same industry
D.A completed security questionnaire returned by the provider, with supporting documentation reviewed in a follow-up session
E.The provider's standard terms of service and acceptable use policy
AnswersA, D

An independent audit report, such as a SOC 2 report, is produced by a qualified auditor and describes the design and operating effectiveness of controls against defined criteria over a specific period. It gives the architect evidence that controls exist and were tested, along with any exceptions noted. This is direct, verifiable evidence rather than a self-declaration, making it one of the strongest artifacts for pre-contract assessment.

Why this answer

Direct evidence comes from independent testing and from a structured, documented assessment conducted by the enterprise itself. An independent third-party audit report covers defined criteria over a stated period and discloses exceptions, while a framework-mapped questionnaire reviewed with the provider turns vague assurances into specific, verifiable answers. Marketing brochures, terms of service, and reference calls may inform the decision, but they do not establish that the provider's controls are designed and operating effectively.

Exam trap

The trap here is accepting provider-authored assurances or peer anecdotes as control evidence instead of independently tested reports and documented assessment results.

203
MCQhard

A software company develops a mobile application that communicates with a cloud backend using REST APIs. The application uses OAuth 2.0 with the authorization code grant and PKCE for authentication. After a security audit, the team identifies that the backend API accepts both a client secret (from the authorization code grant) and a PKCE code verifier. The security team wants to remove unnecessary attack surface. Which change should be made?

A.Switch to the implicit grant (response_type=token) to avoid client secrets
B.Keep both mechanisms but use short-lived tokens to reduce risk
C.Remove the client_secret parameter from the token endpoint and rely solely on PKCE
D.Require a stronger client secret (e.g., 256-bit) and store it in the app's encrypted storage
AnswerC

PKCE binds the authorization code to the client via a dynamically generated code verifier, so a public mobile client cannot protect a static secret. Removing client_secret eliminates a credential that could be extracted from the app bundle, satisfying the goal of reducing unnecessary attack surface.

Why this answer

PKCE (Proof Key for Code Exchange, RFC 7636) was specifically designed to secure the authorization code grant for public clients like mobile apps, where a client secret cannot be reliably kept confidential. By removing the client_secret parameter and relying solely on PKCE, the team eliminates an unnecessary attack surface—since the secret is effectively a static credential that can be extracted from the app binary—while maintaining strong protection against authorization code interception attacks. The backend should enforce PKCE verification using the code_challenge and code_verifier, making the client_secret redundant for public clients.

Exam trap

ISC2 often tests the misconception that removing the client_secret weakens security, when in fact for public clients (mobile apps, SPAs) PKCE makes the secret unnecessary and its removal reduces attack surface; candidates may incorrectly think keeping the secret adds a layer of defense, but it actually introduces a static credential that can be stolen.

How to eliminate wrong answers

Option A is wrong because switching to the implicit grant (response_type=token) would actually increase attack surface by exposing the access token directly in the URL fragment, making it vulnerable to leakage via browser history, referrer headers, and other side channels; it also removes the authorization code exchange step that PKCE protects. Option B is wrong because keeping both mechanisms does not reduce attack surface—it leaves the client_secret as an exploitable static credential that can be extracted from the app, and short-lived tokens do not mitigate the risk of secret theft or replay of the secret at the token endpoint. Option D is wrong because requiring a stronger client secret and storing it in encrypted storage still leaves the secret extractable from the mobile device at runtime (via memory dumps or reverse engineering), and encrypted storage keys are also accessible on the device; the fundamental issue is that public clients cannot securely hold secrets, so any reliance on a client_secret is a design flaw.

204
MCQhard

A financial services company uses Azure and must ensure that all administrative actions in their Azure subscription are logged and that logs are stored in an immutable storage account for 7 years. They also need to be able to alert on specific critical operations, such as deletion of a resource group. Which combination of Azure services should they implement?

A.Azure Monitor activity log, Azure Event Hubs, and Azure Stream Analytics.
B.Azure Security Center (now Microsoft Defender for Cloud), Azure SQL Database auditing, and Azure Logic Apps.
C.Azure Monitor activity log, Azure Storage with immutable blob storage, and Azure Monitor alerts.
D.Azure Log Analytics workspace, Azure Monitor alerts, and Azure Automation runbooks.
AnswerC

The Azure Monitor activity log captures subscription-level control plane operations, including resource group deletions. Exporting to a storage account with immutable blob storage (using time-based retention policies) ensures logs cannot be altered or deleted for the specified period. Azure Monitor alerts can trigger on specific events from the activity log, such as Delete Resource Group, providing real-time notification.

Why this answer

The Azure Monitor activity log is the source for subscription-level administrative events. To achieve immutability, logs must be exported to a storage account configured with immutable blob storage policies. Azure Monitor alerts can be set up to trigger on specific operations like resource group deletion.

This trio meets logging, retention, and alerting requirements.

Exam trap

The trap here is assuming that Log Analytics or Event Hubs provide immutable long-term storage, when they are designed for analysis and transient processing, not compliance-grade retention.

205
Multi-Selecthard

Which THREE statements about tokenization compared to encryption are correct?

Select 3 answers
A.Encryption is always more secure than tokenization.
B.Tokenization is typically used for payment card data.
C.Tokenization preserves data format and length.
D.Tokenization is reversible if the mapping is maintained.
E.Tokenization requires a secure token vault.
AnswersB, D, E

Tokenization is widely used for PCI DSS compliance.

Why this answer

Tokenization is commonly used for payment card data (e.g., PCI DSS compliance) because it replaces sensitive PANs with non-sensitive tokens that have no exploitable value outside the tokenization system. This allows organizations to reduce their compliance scope by not storing actual card numbers, while encryption still leaves ciphertext that could be decrypted if keys are compromised.

Exam trap

ISC2 often tests the misconception that tokenization always preserves format and length, but in reality, format preservation is an optional feature, not a core requirement, and many tokenization systems produce tokens of different lengths or formats.

206
MCQeasy

Under GDPR, what is the maximum time allowed for a data controller to notify the supervisory authority of a personal data breach?

A.7 days
B.24 hours
C.72 hours
D.48 hours
AnswerC

GDPR Article 33 requires controllers to notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in risk to individuals' rights and freedoms.

Why this answer

GDPR Article 33 requires notification within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to rights and freedoms.

207
Multi-Selectmedium

A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The legal team must ensure the policy addresses key contractual and regulatory considerations. Which TWO elements should the policy include? (Choose two.)

Select 2 answers
A.A provision allowing the provider to retain customer data indefinitely for its own business purposes
B.A right for the provider to retain data beyond the agreed retention period if it is technically difficult to delete
C.A process for the customer to request early deletion of specific data during the contract term and for the provider to confirm deletion
D.A clause stating that the provider may use customer data for marketing purposes after anonymization without customer consent
E.A requirement that the provider delete all customer data within a specified period after contract termination, including from backups, and provide a certificate of destruction
AnswersC, E

Customers often need to delete specific data before contract end, such as when a data subject exercises the right to erasure or when data is no longer needed. A defined process with confirmation ensures the provider acts on these requests and provides auditability. This supports compliance with GDPR and other privacy laws that require timely deletion. It also helps manage storage costs and reduce risk.

Why this answer

A robust data retention and deletion policy must include a contractual commitment for the provider to delete all customer data, including backups, after termination and to certify destruction. It should also define a process for early deletion during the contract term. These elements ensure the customer can meet regulatory retention limits and respond to data subject requests.

Exam trap

The trap here is focusing only on deletion at contract end and forgetting the need for a process to delete specific data during the contract, or accepting provider-friendly clauses that allow indefinite retention for business purposes.

208
Multi-Selecthard

A cloud-native application team is adopting a secrets management service to eliminate hardcoded credentials in source code and configuration files. Which two practices best align with secure secrets management in the cloud? (Choose two.)

Select 2 answers
A.Commit encrypted secrets to the source repository so they are version-controlled alongside application code.
B.Store secrets in environment variables injected at container start to keep them out of the image.
C.Enable automatic rotation of secrets on a defined schedule and update dependent applications through the secrets manager.
D.Grant the application a workload identity so it retrieves secrets dynamically at runtime from the secrets manager.
E.Embed secrets in the container image and rely on image scanning to detect accidental exposure.
AnswersC, D

Automatic rotation limits the useful lifetime of a compromised secret and reduces the window of exposure. When rotation is coupled with dynamic retrieval from the secrets manager, applications pick up new values without redeployment, maintaining availability while improving security.

Why this answer

Secure secrets management favours dynamic, identity-based retrieval and routine rotation over static storage. Workload identity removes static credentials, and automatic rotation limits exposure windows; environment variables, encrypted secrets in repositories, and embedded secrets all retain long-lived or broadly accessible copies.

Exam trap

The trap here is believing that storing secrets in environment variables or encrypted in source control is equivalent to using a secrets manager with workload identity and rotation.

209
MCQeasy

A company is migrating its on-premises database to a cloud-based database-as-a-service (DBaaS) offering. The security team wants to ensure that the data remains encrypted at rest and that they retain control over the encryption keys. Which cloud data security concept should they implement?

A.SSL/TLS encryption for data in transit between the application and the database.
B.Database auditing and logging to monitor access to sensitive data.
C.Bring Your Own Key (BYOK) integrated with the cloud provider's key management service.
D.Transparent Data Encryption (TDE) with keys managed by the cloud provider.
AnswerC

BYOK allows the company to generate and manage its own encryption keys while using the cloud provider's key management service for storage and lifecycle operations. This gives the company control over the keys and satisfies the requirement for encryption at rest with customer-controlled keys.

Why this answer

BYOK enables the company to generate and control its own encryption keys while leveraging the cloud provider's KMS for key storage and operations. This meets the need for encryption at rest with customer-controlled keys, unlike provider-managed TDE or transit encryption.

Exam trap

The trap here is equating encryption at rest with customer key control; provider-managed TDE encrypts data but does not give the customer key ownership.

210
Multi-Selecteasy

Which TWO of the following are key components of an Information Security Management System (ISMS) as defined by ISO 27001?

Select 2 answers
A.Business continuity plan.
B.Continuous improvement process.
C.Annual penetration testing.
D.Encryption of all data at rest.
E.Risk assessment and treatment.
AnswersB, E

ISMS requires ongoing improvement based on monitoring.

Why this answer

The ISO 27001 standard defines an ISMS as a systematic approach to managing sensitive information, and it explicitly requires a continuous improvement process (Clause 10.1) to ensure the ISMS remains effective over time. This is a core component, not an optional add-on, and is implemented through the Plan-Do-Check-Act (PDCA) cycle.

Exam trap

ISC2 often tests the distinction between mandatory ISMS components (like risk assessment and continuous improvement) and optional security controls (like encryption or penetration testing), leading candidates to mistakenly select specific technical controls as core ISMS elements.

211
MCQhard

A financial services company runs a regulated workload on a public cloud. The security team must ensure that all data at rest in the cloud provider's block storage service is encrypted with keys that the company controls and can revoke immediately. The company also needs to prove to auditors that the cloud provider cannot access the plaintext data. Which approach BEST meets these requirements?

A.Use provider-managed encryption keys with automatic rotation enabled, and rely on the provider's attestation reports for audit evidence.
B.Use a cloud provider's key management service to generate a customer-managed key (CMK) and enable automatic rotation, while the provider manages the underlying HSM.
C.Implement client-side encryption before writing data to block storage, using a customer-managed key stored in an external key management system.
D.Enable server-side encryption with customer-provided keys (SSE-C), where the company supplies the key with each API request but the provider stores the encrypted data.
AnswerC

Client-side encryption ensures data is encrypted before it reaches the cloud provider, so the provider never sees plaintext. Storing the key in an external KMS that the company controls allows immediate revocation and provides audit evidence that the provider cannot access the key. This directly satisfies all stated requirements: customer control, immediate revocation, and provable provider inaccessibility.

Why this answer

Client-side encryption with an externally managed key ensures the cloud provider never receives plaintext and cannot access the key. The company retains full control and can revoke the key instantly, and auditors can verify that the provider has no path to the plaintext. Other options either leave key control with the provider or do not provide provable inaccessibility, failing the regulatory requirements.

Exam trap

The trap here is confusing customer-managed keys in the provider's KMS with true customer-controlled keys, when only client-side encryption with external key storage guarantees the provider cannot access plaintext.

212
MCQeasy

An enterprise uses a cloud access security broker (CASB) to protect data in cloud applications. They want to prevent users from uploading files containing credit card numbers to a cloud storage service. Which CASB feature should be configured?

A.Encryption in transit settings
B.User activity monitoring
C.Single sign-on (SSO) integration
D.Data loss prevention (DLP) policies
AnswerD

Data loss prevention policies inspect content in transit to cloud services and block uploads matching credit card number patterns. This satisfies the requirement to prevent sensitive data exfiltration to cloud storage, which generic access controls or encryption cannot achieve.

Why this answer

Data loss prevention (DLP) policies are the correct CASB feature because they allow the enterprise to define content inspection rules that scan files for sensitive data patterns, such as credit card numbers (matching Luhn algorithm or regex patterns like those in PCI DSS). When a match is detected, the CASB can block the upload, quarantine the file, or trigger an alert, directly preventing data exfiltration to the cloud storage service.

Exam trap

The trap here is that candidates confuse user activity monitoring (which logs behavior) with DLP (which enforces content-based policies), or they assume encryption alone can prevent data leakage, not realizing encryption protects data in transit but does not inspect or block the data itself.

How to eliminate wrong answers

Option A is wrong because encryption in transit (e.g., TLS 1.2/1.3) protects data during transmission between the user and the cloud service, but it does not inspect or block the content of files being uploaded; it only ensures confidentiality over the network. Option B is wrong because user activity monitoring tracks and logs user actions (e.g., login times, file access) for auditing and anomaly detection, but it lacks the content-aware inspection engine needed to identify and block specific data patterns like credit card numbers. Option C is wrong because single sign-on (SSO) integration (e.g., SAML 2.0 or OIDC) manages authentication and access control, but it does not perform deep packet inspection or content analysis on uploaded files to prevent sensitive data leakage.

213
MCQhard

A healthcare organization stores patient data in a cloud database. Regulatory requirements mandate that data must be encrypted at rest using FIPS 140-2 validated cryptographic modules. The organization wants to use the cloud provider's managed encryption service. Which aspect should they verify to ensure compliance?

A.That the database uses AES-256 encryption.
B.That the cloud provider's encryption service uses FIPS 140-2 validated hardware security modules (HSMs) for key storage.
C.That the cloud provider is certified under ISO/IEC 27001.
D.That the encryption service's cryptographic module has a current FIPS 140-2 validation certificate.
AnswerD

FIPS 140-2 validation is specific to the cryptographic module. The organization must ensure that the module used for encryption has a valid certificate from a NIST-accredited lab. This directly confirms that the encryption meets the regulatory requirement. The certificate should cover the exact module version and configuration used.

Why this answer

FIPS 140-2 validation is a requirement for cryptographic modules used by federal agencies and often mandated by regulations like HIPAA. To comply, the organization must confirm that the specific cryptographic module used by the cloud service has a valid FIPS 140-2 certificate. This ensures the module meets stringent security standards for design and implementation.

Exam trap

The trap here is confusing algorithm strength (AES-256) or general security certifications (ISO 27001) with FIPS 140-2 validation of the cryptographic module itself.

214
MCQeasy

Under GDPR, what is the role of a cloud provider that processes personal data solely on behalf of a customer?

A.Data controller
B.Supervisory authority
C.Data subject
D.Data processor
AnswerD

A processor handles personal data only on documented instructions from the controller, which is precisely the cloud provider's position here. The controller determines purposes and means; the processor bears no such determination, matching the stem's solely-on-behalf wording.

Why this answer

Under GDPR, a data processor is an entity that processes personal data on behalf of a data controller. The cloud provider, in this scenario, acts as a processor because it processes data solely on behalf of the customer (the controller). The processor must follow the controller's instructions and comply with GDPR obligations.

Exam trap

CCSP often tests confusion between controller and processor roles, but the key is that a cloud provider processing data solely on behalf of a customer is a processor, not a controller.

How to eliminate wrong answers

Option A is wrong because the data controller determines the purposes and means of processing; here, the customer is the controller. Option B is wrong because a supervisory authority is a regulatory body, not a role in the processing relationship. Option C is wrong because a data subject is the individual whose data is processed, not the cloud provider.

215
MCQhard

A healthcare organization is designing a cloud solution to store and process electronic protected health information (ePHI). The organization must comply with HIPAA and wants to ensure that the cloud service provider (CSP) meets the necessary security and privacy requirements. The organization is evaluating a CSP that offers a Business Associate Agreement (BAA). Which of the following is the MOST critical factor to verify before signing the BAA?

A.The CSP's BAA includes a clause allowing the CSP to use ePHI for its own purposes.
B.The CSP's data center locations are within the United States.
C.The CSP has implemented appropriate administrative, physical, and technical safeguards to protect ePHI.
D.The CSP offers a 99.999% uptime service level agreement (SLA).
AnswerC

Under HIPAA, a covered entity must ensure that its business associates, including CSPs, implement appropriate safeguards to protect ePHI. The BAA itself is a contractual requirement, but the most critical factor is verifying that the CSP actually has the necessary administrative, physical, and technical safeguards in place. This includes access controls, encryption, audit controls, and integrity controls, which are essential to comply with the HIPAA Security Rule.

Why this answer

The HIPAA Security Rule requires covered entities and their business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI. Before signing a BAA, the healthcare organization must verify that the CSP has these safeguards in place. While data residency, contractual clauses, and SLAs are relevant, they do not replace the need for comprehensive security controls.

Exam trap

The trap here is focusing on the BAA as a document rather than on the underlying security controls. A BAA is necessary but not sufficient; the CSP must actually implement the required safeguards, and the organization must verify this through audits or certifications.

216
MCQmedium

A healthcare company runs a containerized patient portal on a managed Kubernetes service. Security policy requires that every container image be cryptographically verified as coming from the company's internal build pipeline before any pod is admitted to the cluster. The images are stored in a private OCI registry, and each build produces a signature using a private key held in a cloud key management service. Which mechanism should be implemented to enforce this policy at admission time?

A.Enable image vulnerability scanning in the registry and configure the cluster to pull only images with a CVSS score below a defined threshold.
B.Use a mutating admission webhook to inject an init container that runs a checksum comparison of the image layers against a manifest stored in the registry.
C.Configure an admission controller that validates image signatures against a trusted public key and rejects pods whose images are unsigned or signed by an untrusted key.
D.Apply a network policy that restricts pod egress to only the private registry, preventing images from being pulled from any other source.
AnswerC

Admission controllers that verify cryptographic signatures on container images can block any pod whose image lacks a valid signature from the trusted public key. This directly enforces the policy before the pod is scheduled, ensuring only images from the internal pipeline are admitted. It works with the existing KMS-held private key because the corresponding public key is what the controller checks.

Why this answer

Enforcing image provenance requires cryptographic verification at admission time, not merely scanning or network controls. An admission controller that checks signatures against a trusted public key ensures that only images signed by the internal pipeline's private key are admitted. This directly ties the cluster's admission decision to the build pipeline's signing authority, satisfying the policy while leveraging the existing KMS key infrastructure.

Exam trap

The trap here is assuming that vulnerability scanning or registry access controls prove image origin, when only cryptographic signature verification establishes provenance.

217
MCQhard

A government agency is evaluating a cloud deployment model where several agencies with similar missions and compliance obligations will jointly use a cloud environment governed by a shared policy framework. Each agency will retain independent control over its own data and security configurations. Which cloud deployment model does this describe?

A.Hybrid cloud
B.Community cloud
C.Private cloud
D.Public cloud
AnswerB

A community cloud is provisioned for exclusive use by a specific community of consumers from organizations that share common concerns such as mission, security requirements, policy, and compliance considerations. The scenario explicitly describes multiple agencies with similar missions and obligations jointly using a governed environment while retaining control over their own data, which is the textbook community cloud arrangement.

Why this answer

The community cloud model is defined by exclusive use among a group of organizations sharing common mission, security, policy, and compliance interests. Because several agencies jointly consume the environment under a shared governance framework while each controls its own data, this matches the community cloud definition precisely rather than single-tenant private, open public, or cross-model hybrid arrangements.

Exam trap

The trap here is confusing a community cloud with a private cloud simply because access is restricted, when the distinguishing factor is that multiple independent organizations share the environment under common governance.

218
MCQmedium

A media production company stores and edits large video files on-premises. During peak project periods, editors need to temporarily consume extra compute and storage, but the company wants to keep its existing private cloud and avoid rebuilding workflows. The company wants a solution that lets the private cloud seamlessly use public cloud resources for these bursts without changing how editors access the files. Which cloud deployment model BEST meets this requirement?

A.Hybrid cloud
B.Private cloud
C.Public cloud
D.Community cloud
AnswerA

A hybrid cloud combines a private cloud with public cloud services and enables workloads to move or burst between them. Here, the private cloud can remain the primary editing environment while public cloud resources absorb peak compute and storage demands, which matches the requirement to keep existing workflows and avoid a full migration.

Why this answer

A hybrid cloud is designed to integrate a private cloud with public cloud services so workloads can move or burst between them. Because the company wants to retain its private editing workflows while temporarily using public resources during peaks, the hybrid model provides the required elasticity without forcing a full migration or redesign.

Exam trap

The trap here is assuming that any use of public cloud capacity automatically makes the deployment a public cloud, when the defining factor is the integrated combination of private and public environments.

219
MCQhard

A company deploys microservices in Kubernetes. Each service communicates via gRPC with mutual TLS. A security assessment reveals that some services use self-signed certificates. What is the primary risk?

A.Inability to revoke certificates
B.Exposure of private keys in the container image
C.Increased latency due to certificate validation
D.Man-in-the-middle (MITM) attacks between services
AnswerD

Self-signed certificates lack a trusted certificate authority, so services cannot reliably verify each other's identity during the mutual TLS handshake. An attacker positioned between pods could present their own self-signed certificate and impersonate a legitimate service, intercepting gRPC traffic. This directly enables man-in-the-middle attacks, satisfying the scenario's mutual authentication requirement.

Why this answer

The primary risk of using self-signed certificates in a gRPC mutual TLS environment is that there is no trusted Certificate Authority (CA) to verify the identity of the communicating services. Without proper CA-signed certificates, an attacker can easily perform a man-in-the-middle (MITM) attack by presenting a forged self-signed certificate, intercepting and modifying gRPC traffic between microservices.

Exam trap

ISC2 often tests the misconception that self-signed certificates are only a problem for revocation or key exposure, when the core issue is the lack of trusted identity verification enabling MITM attacks.

How to eliminate wrong answers

Option A is wrong because self-signed certificates can still be revoked using mechanisms like CRLs or OCSP, though it is more cumbersome; the inability to revoke is not the primary risk. Option B is wrong because private keys are not inherently exposed in the container image; exposure is a separate misconfiguration issue, not a direct consequence of using self-signed certificates. Option C is wrong because certificate validation does not introduce significant latency; the overhead of TLS handshake is negligible compared to the security benefits, and self-signed certificates do not inherently increase validation time.

220
MCQeasy

A development team is building a web application that stores user passwords. The security architect recommends using a password hashing algorithm with a tunable work factor and a per-user random salt. Which approach best meets this recommendation?

A.Hash each password with SHA-256 and store the resulting digest alongside a random salt generated per user.
B.Encrypt each password with AES-256 using a key stored in a hardware security module and store the ciphertext.
C.Apply HMAC-SHA-256 to each password using a global application secret as the key and store the resulting tag.
D.Use a memory-hard password hashing function such as Argon2id with a calibrated cost parameter and a unique salt per user.
AnswerD

Argon2id is purpose-built for password storage, combining a tunable cost parameter with per-user salting to make offline guessing expensive and rainbow tables useless. The memory-hard design blunts GPU and ASIC attacks. This directly satisfies the architect's requirement for a tunable work factor and a per-user random salt while remaining a one-way function suitable for verification.

Why this answer

Storing passwords securely requires a one-way function designed for the purpose, with a per-user salt and an adjustable cost that can be raised as hardware improves. Argon2id provides memory hardness and a calibrated cost parameter, satisfying both parts of the architect's recommendation. Fast hashes, reversible encryption, and keyed hashes with a shared secret each fail to make large-scale offline guessing economically impractical.

Exam trap

The trap here is assuming that any salted hash is adequate, when the work factor and memory hardness are what actually determine resistance to offline cracking.

221
MCQeasy

A developer is tasked with securely storing a session token in a browser-based web application. Which storage mechanism is most secure?

A.HTTP-only cookies with Secure and SameSite flags
B.sessionStorage
C.URL query parameters
D.localStorage
AnswerA

HTTP-only cookies are inaccessible to JavaScript, so cross-site scripting cannot read the token, while Secure restricts transmission to HTTPS and SameSite blocks cross-site request forgery. This satisfies secure browser storage, unlike localStorage, which script can freely exfiltrate.

Why this answer

HTTP-only cookies with Secure and SameSite flags are the most secure storage mechanism for session tokens because they prevent client-side script access (mitigating XSS-based token theft), ensure transmission only over HTTPS (mitigating network eavesdropping), and restrict cross-origin request inclusion (mitigating CSRF). This combination aligns with OWASP best practices for session management, as the token is never exposed to JavaScript or sent over unencrypted channels.

Exam trap

ISC2 often tests the misconception that localStorage or sessionStorage is secure because they are 'client-side only,' but the trap is that both are fully accessible via JavaScript and thus vulnerable to XSS, whereas HTTP-only cookies are the only option that prevents script-level access.

How to eliminate wrong answers

Option B is wrong because sessionStorage is accessible via JavaScript, making it vulnerable to XSS attacks where an attacker can read the token directly. Option C is wrong because URL query parameters are logged in server logs, browser history, and referrer headers, exposing the session token to interception and persistent storage. Option D is wrong because localStorage persists data indefinitely and is fully accessible via JavaScript, offering no protection against XSS or CSRF, and lacks built-in expiration or secure transmission controls.

222
Multi-Selectmedium

An organization is adopting a hybrid cloud strategy. Which THREE considerations are vital for maintaining consistent security across environments? (Select THREE.)

Select 3 answers
A.Dedicated security team for each environment
B.Unified identity and access management (IAM)
C.Consistent network segmentation and firewall rules
D.Harmonized data encryption and key management
E.Different encryption standards for public and private clouds
AnswersB, C, D

A single identity plane spanning on-premises and cloud lets one directory govern authentication and authorisation everywhere. Microsoft Entra ID provides this, satisfying the hybrid requirement for consistent access control rather than duplicated, divergent credential stores.

Why this answer

Unified IAM (B) is vital because a hybrid cloud requires a single, consistent authentication and authorization model—using standards like SAML, OAuth 2.0, or OIDC and centralized directory services—so that identities and permissions behave identically across on-premises and cloud environments rather than fragmenting into separate trust domains. Consistent network segmentation and firewall rules (C) are essential because traffic flows between private and public environments must be governed by the same security zones, ACLs, and microsegmentation policies; otherwise lateral movement and misconfigured cross-cloud connectivity create exploitable gaps. Harmonized data encryption and key management (D) is critical because data moving between or stored across environments must use compatible algorithms and centrally governed keys (e.g., via a KMS or HSM with consistent rotation and access policies) to avoid weak links and unmanageable key sprawl.

Option A is not required—separate security teams per environment actually undermine consistency by creating divergent policies and fragmented accountability, whereas a unified governance model with shared standards is preferred. Option E is incorrect because using different encryption standards for public versus private clouds introduces interoperability, compliance, and key-management problems; encryption should be harmonized, not differentiated by environment.

Exam trap

CCSP often tests the misconception that hybrid cloud security is best achieved by giving each environment its own dedicated team and tailored controls, when the exam's correct answer always favors unified, consistent controls across environments.

223
MCQmedium

Which cloud design principle ensures that resources can be dynamically adjusted to meet changing demand, often using auto-scaling groups?

A.Elasticity
B.Resource pooling
C.Resiliency
D.Measured service
AnswerA

Elasticity directly satisfies the changing-demand constraint by automatically provisioning and deprovisioning resources through auto-scaling groups, matching capacity to real-time workload. Unlike scalability, which addresses growth in fixed increments, elasticity handles fluctuating demand dynamically, including scale-in, making it the precise principle described in the stem.

Why this answer

Elasticity is the cloud design principle that allows resources to be automatically and dynamically scaled up or down to match changing demand, typically implemented via auto-scaling groups, horizontal pod autoscalers, or serverless concurrency. It is what lets a workload add capacity during peak load and release it during idle periods, optimizing both performance and cost. Auto-scaling groups are the canonical implementation of elasticity on IaaS platforms.

Exam trap

The trap here is conflating elasticity with scalability or resiliency; candidates pick 'resiliency' because auto-scaling 'sounds like' high availability, but the question's keyword is dynamic adjustment to demand.

How to eliminate wrong answers

Option B is wrong because resource pooling refers to the multi-tenant model where a provider serves many consumers from shared physical resources (compute, storage, network), not to dynamic scaling. Option C is wrong because resiliency is the ability to withstand and recover from failures (redundancy, failover, multi-AZ), which is about availability, not demand-driven scaling. Option D is wrong because measured service (metering) is the pay-per-use billing model that tracks consumption, not the mechanism that adjusts capacity.

224
MCQeasy

Which of the following is a cloud-specific vulnerability that can lead to exposure of IAM credentials through the metadata service?

A.SQL injection
B.SSRF to metadata endpoint
C.Insecure deserialization
D.Cross-site scripting (XSS)
AnswerB

Server-side request forgery tricks an application into requesting the cloud instance metadata endpoint, which returns temporary IAM credentials to any process that reaches it. This satisfies the stem's cloud-specific requirement: the metadata service is unique to cloud platforms, and SSRF is the documented vector for credential exposure.

Why this answer

Server-Side Request Forgery (SSRF) that targets the cloud metadata endpoint (e.g., http://169.254.169.254) can retrieve IAM credentials. This is a cloud-specific issue.

225
Multi-Selecthard

Which THREE of the following are effective controls to secure a RESTful API in the cloud?

Select 3 answers
A.Enabling CORS (Cross-Origin Resource Sharing) for all domains
B.Using HTTP basic authentication over plain HTTP
C.Implementing rate limiting and throttling
D.Enforcing strong authentication and authorization mechanisms
E.Validating and sanitizing all inputs to avoid injection attacks
AnswersC, D, E

Rate limiting and throttling cap request volume per client or key, mitigating brute-force, credential-stuffing and denial-of-service abuse against REST endpoints. This directly satisfies the stem's requirement for an effective control protecting cloud-hosted APIs from volumetric and enumeration attacks.

Why this answer

Option C is correct because rate limiting and throttling cap the number of requests a client can make in a given time window, mitigating brute-force, credential-stuffing, and denial-of-service abuse against API endpoints. Option D is correct because strong authentication (e.g., OAuth 2.0 tokens, mutual TLS) and authorization (e.g., scopes, RBAC, least privilege) ensure only verified, permitted identities can invoke API operations. Option E is correct because validating and sanitizing all inputs defends against injection flaws such as SQL injection, NoSQL injection, and command injection that arise from untrusted API parameters.

Option A is not appropriate because enabling CORS for all domains (wildcard Access-Control-Allow-Origin) exposes the API to cross-origin abuse rather than restricting access to trusted origins. Option B is not appropriate because HTTP Basic authentication over plain HTTP transmits base64-encoded credentials in cleartext, which can be intercepted; it should only be used over TLS.

Exam trap

ISC2 often tests the misconception that CORS is a security control that should be broadly enabled, when in fact it is a relaxation of the same-origin policy and must be tightly scoped to prevent cross-origin attacks.

Page 2

Page 3 of 13

Page 4