Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 226–300

934 questions total · 13pages · All types, answers revealed

Page 3

Page 4 of 13

Page 5
226
Multi-Selectmedium

A cloud security engineer is reviewing an AWS IAM policy that includes the following statement: 'Effect: Allow, Action: iam:*, Resource: *'. Which two security concerns does this configuration create? (Choose TWO.)

Select 2 answers
A.Over-permissive IAM role
B.Exposed S3 bucket
C.Hardcoded credentials
D.SSRF vulnerability
E.Privilege escalation risk
AnswersA, E

Granting iam:* on Resource:* lets the principal create users, attach policies and modify roles across the whole account, far beyond any legitimate task. This violates least privilege, the specific concern the wildcard action and resource combination creates.

Why this answer

Option A (Over-permissive IAM role) is correct because Action: iam:* with Resource: * grants every IAM action on every IAM resource, far exceeding what any single role should hold and violating least privilege. Option E (Privilege escalation risk) is correct because iam:* includes actions like iam:CreatePolicyVersion, iam:AttachUserPolicy, iam:PutRolePolicy, and iam:PassRole, which let an identity grant itself or others broader permissions and effectively escalate to administrator. Option B is wrong because S3 bucket exposure depends on S3 bucket policies, ACLs, or Block Public Access settings, not an IAM statement.

Option C is wrong because hardcoded credentials are a code/secret-management issue, not something created by an IAM policy statement. Option D is wrong because SSRF is an application-layer vulnerability, not a property of an IAM policy.

227
MCQhard

A cloud architect is designing a solution that must ensure data isolation between tenants in a multi-tenant environment. The architect decides to use a virtual private cloud (VPC) per tenant. Which of the following is the PRIMARY security benefit of this approach?

A.It provides dedicated physical hardware for each tenant.
B.It automatically encrypts all data at rest for each tenant.
C.It guarantees compliance with data residency requirements.
D.It ensures that each tenant's network traffic is isolated from other tenants.
AnswerD

A VPC enables logical isolation of network traffic at the virtual network layer. Each tenant's resources are placed in separate subnets with their own routing and security group rules, preventing unauthorized access between tenants. This is a fundamental security control in multi-tenant cloud environments, as it reduces the risk of lateral movement and data leakage.

Why this answer

Using a VPC per tenant provides network-level isolation, which is critical in multi-tenant environments to prevent cross-tenant traffic and unauthorized access. Each VPC acts as a virtual network boundary, with its own IP range, subnets, route tables, and security groups. This logical separation helps enforce security policies and reduces the attack surface, making it the primary security benefit.

Exam trap

The trap here is conflating network isolation with other security controls like encryption or physical separation, and assuming that a VPC automatically provides those benefits.

228
MCQmedium

A company is performing a risk assessment of its cloud environment. They have identified a risk with a likelihood of 4 (on a scale of 1-5) and an impact of 3 (on a scale of 1-5). The company decides to implement controls that will reduce the likelihood to 2 and impact to 1. What is the residual risk score after controls?

A.12
B.4
C.2
D.3
AnswerC

Residual risk multiplies the reduced likelihood by the reduced impact: 2 × 1 = 2. Applying controls that lower likelihood to 2 and impact to 1 therefore yields a residual score of 2 on the same 1–5 scale.

Why this answer

The residual risk score is calculated by multiplying the reduced likelihood (2) by the reduced impact (1) after controls are applied, yielding a score of 2. This represents the risk that remains after implementing security controls, which is the correct interpretation of residual risk in a quantitative risk assessment. The original risk score of 12 (4×3) is the inherent risk, not the residual risk.

Exam trap

ISC2 often tests the distinction between inherent risk (before controls) and residual risk (after controls), and the trap here is that candidates mistakenly use the original likelihood or impact values in the multiplication instead of the reduced values after controls are applied.

How to eliminate wrong answers

Option A is wrong because 12 is the inherent risk score (4×3) before controls, not the residual risk after controls reduce likelihood to 2 and impact to 1. Option B is wrong because 4 would result from multiplying the original likelihood (4) by the reduced impact (1) or vice versa, which is a common miscalculation that ignores the dual reduction. Option D is wrong because 3 is the original impact value alone, not a product of the reduced likelihood and impact, and does not represent a risk score calculation.

229
MCQhard

A cloud application uses an IAM role with the policy "Action: s3:*" and "Resource: *". Which principle is violated?

A.Defense in depth
B.Fail secure
C.Separation of duties
D.Least privilege
AnswerD

Granting `s3:*` on `*` lets the role perform every S3 operation against every bucket, including deletion and policy changes. Least privilege requires permissions scoped to only the actions and resources the application genuinely needs, so this wildcard policy directly violates that constraint.

Why this answer

The policy grants full access to all S3 actions on all resources, violating the principle of least privilege. Wildcard permissions like s3:* and *:* are over-permissive.

230
Multi-Selecthard

Which THREE of the following are key considerations when designing a disaster recovery plan for a cloud-based application?

Select 3 answers
A.Performing manual failover testing only once a year.
B.Eliminating all security controls to speed up recovery.
C.Implementing cross-region replication for critical data.
D.Defining the Recovery Time Objective (RTO) for critical services.
E.Ensuring data consistency and integrity across replicated environments.
AnswersC, D, E

Cross-region replication ensures availability.

Why this answer

Cross-region replication ensures that critical data is asynchronously or synchronously copied to a geographically separate cloud region, providing resilience against regional outages. This design directly supports disaster recovery by enabling failover to a secondary site with minimal data loss, often leveraging cloud-native services like AWS S3 Cross-Region Replication or Azure Geo-Redundant Storage.

Exam trap

ISC2 often tests the misconception that disaster recovery planning can skip security controls or infrequent testing, but the exam emphasizes that DR must maintain security posture and be validated through regular, automated testing to meet compliance and operational requirements.

231
MCQmedium

A cloud service provider (CSP) experiences a security incident affecting customer data. The contract requires notification within 72 hours, but the CSP fails to notify. What is the most likely legal consequence for the CSP?

A.Breach of contract and potential regulatory fines
B.Automatic termination of all customer contracts
C.Criminal liability for the CSP's executives
D.No consequence if the incident was not serious
AnswerA

Failing the contractual 72-hour notification duty constitutes breach of contract, exposing the CSP to damages or penalties. Because the incident involves customer data, data-protection regulators may also impose fines independently. Both consequences flow directly from the missed notification obligation.

Why this answer

The most likely legal consequence is breach of contract and potential regulatory fines. The contract explicitly requires notification within 72 hours, so failure to notify constitutes a breach. Additionally, depending on the data and jurisdiction, regulations like GDPR or CCPA may impose fines for late notification of data breaches.

Exam trap

CCSP often tests the assumption that failure to notify only matters if the incident is serious, but contractual and regulatory obligations apply regardless of severity, and breach of contract is the primary consequence.

How to eliminate wrong answers

Option B is wrong because automatic termination of all contracts is not a standard legal consequence unless specified in the contract; it would typically require a material breach and notice. Option C is wrong because criminal liability for executives is rare and requires proving intent or gross negligence, not just failure to notify. Option D is wrong because even if the incident was not serious, the contractual obligation to notify within 72 hours was violated, leading to consequences.

232
MCQeasy

A financial services company is migrating sensitive customer data to the cloud. They require that encryption keys be generated and stored on-premises in their own hardware security module (HSM), with the cloud provider never having access to the plaintext keys. Which key management model should they implement?

A.Customer-managed encryption keys (CMEK)
B.Bring your own key (BYOK)
C.Cloud provider default encryption (SSE-S3)
D.Hold your own key (HYOK)
AnswerD

HYOK generates and retains keys in the customer's on-premises HSM, so plaintext keys never reach the provider; the cloud only ever handles ciphertext or wrapped keys. This satisfies the requirement that the provider cannot access plaintext keys.

Why this answer

Hold your own key (HYOK) is the only model where the customer generates and stores the key material in their own HSM on-premises, and the cloud provider never has access to the plaintext key. In HYOK, encryption and decryption typically occur on the customer side or through a proxy, so the cloud provider only ever handles ciphertext. This satisfies the requirement that the provider cannot access plaintext keys.

Exam trap

CCSP often tests the confusion between BYOK and HYOK — candidates assume that importing your own key (BYOK) means the provider never sees it, but only HYOK guarantees the provider has no access to plaintext key material.

How to eliminate wrong answers

Option A is wrong because CMEK means the customer manages the key lifecycle but the key material is still generated and stored within the cloud provider's KMS, so the provider has potential access. Option B is wrong because BYOK allows the customer to import their own key into the provider's KMS, but once imported the provider's infrastructure can access the plaintext key during cryptographic operations. Option C is wrong because SSE-S3 is provider-managed encryption where the cloud provider generates, stores, and manages the keys entirely — the customer has no control and the provider has full access.

233
Multi-Selectmedium

A cloud security team is evaluating DLP techniques to protect sensitive data in a cloud data warehouse. They want to replace sensitive values with realistic but fictitious data for non-production environments while preserving referential integrity. Which TWO de-identification techniques are suitable?

Select 2 answers
A.Pseudonymization
B.Bucketing
C.Masking
D.Tokenization
E.Date shifting
AnswersA, D

Pseudonymization swaps identifiers for consistent replacement values, so the same input always maps to the same output. That determinism preserves referential integrity across related tables while producing realistic fictitious data, exactly matching the non-production requirement without exposing genuine customer values.

Why this answer

Pseudonymization (A) is correct because it replaces sensitive values with consistent artificial identifiers, so the same input always maps to the same pseudonym, which preserves referential integrity across tables and joins in non-production environments. Tokenization (D) is also correct because it substitutes sensitive data with non-sensitive tokens stored in a secure token vault, and the deterministic token-to-value mapping maintains referential integrity while providing realistic fictitious values. Bucketing (B) only generalizes values into ranges and does not produce realistic fictitious replacements or preserve exact referential links.

Masking (C) typically obscures or redacts values, often irreversibly and without guaranteeing consistent cross-table substitution, so it does not reliably preserve referential integrity. Date shifting (E) only alters date values by a consistent offset and applies solely to date fields, not to general sensitive data replacement.

Exam trap

The trap is selecting masking because it is the most commonly mentioned de-identification technique — but masking does not preserve referential integrity, whereas pseudonymization and tokenization do through consistent mapping.

234
Multi-Selecteasy

A security architect is designing a cloud workload protection platform (CWPP) for a hybrid cloud environment. The architect needs to ensure that security policies are consistently applied across virtual machines running in both on-premises and public cloud environments. Which TWO components are essential for achieving this goal?

Select 2 answers
A.Software-defined perimeter (SDP) architecture
B.Virtual private cloud (VPC) network ACLs
C.Unified agent software installed on each VM
D.Centralized policy management console
E.Infrastructure as code templates
AnswersC, D

Unified agent software on each VM enforces policy at the workload itself, so identical rules apply whether the VM runs on-premises or in the public cloud. This satisfies the stem's consistency constraint across both environments, since host-level controls travel with the instance rather than depending on perimeter or cloud-specific tooling.

Why this answer

Option C (Unified agent software installed on each VM) is essential because a CWPP must have a consistent enforcement point on every workload regardless of location; the same agent binary running on on-premises VMs and public cloud instances provides uniform visibility, vulnerability assessment, and runtime protection across the hybrid estate. Option D (Centralized policy management console) is essential because it is the single control plane where policies are authored once and pushed to all agents, ensuring identical rules are applied in both environments rather than being configured separately per platform. Together, the agent provides distributed enforcement while the console provides centralized definition and orchestration, which is the core CWPP pattern for hybrid cloud.

Option A (SDP) is a network-centric zero-trust access model, not a workload protection mechanism, and does not itself apply host security policies. Option B (VPC network ACLs) are stateless subnet-level filters that exist only in the public cloud and cannot enforce policy on on-premises VMs. Option E (IaC templates) automate provisioning and configuration but do not deliver continuous runtime policy enforcement across existing VMs.

Exam trap

ISC2 often tests the distinction between network-level controls (SDP, VPC ACLs) and host-level controls (unified agents), leading candidates to mistakenly select network-centric options for workload protection that requires per-VM policy enforcement.

235
MCQmedium

A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that data is protected at rest but does not want to manage encryption keys themselves. They also need to prove to auditors that encryption is enabled. Which cloud provider feature should they use?

A.Transport Layer Security (TLS) for data in transit
B.Client-side encryption with customer-provided keys
C.Server-side encryption with provider-managed keys (SSE-S3 or equivalent)
D.Server-side encryption with customer-provided keys (SSE-C)
AnswerC

This option uses encryption at rest where the cloud provider manages the keys, eliminating the customer's key management burden. Auditors can verify that encryption is enabled via provider logs or configuration settings. It meets the requirement for data protection without customer-managed keys, and is a standard feature of object storage services.

Why this answer

Server-side encryption with provider-managed keys is correct because it automatically encrypts data at rest without requiring the customer to manage keys, and it can be audited through provider configurations. Client-side and SSE-C both involve customer key management, which the firm wants to avoid. TLS is irrelevant for data at rest.

Exam trap

The trap here is assuming that any encryption option satisfies the requirement, but the key management responsibility differentiates the choices.

236
Multi-Selecthard

A cloud architect is designing a defense-in-depth strategy for a containerized application. Which THREE practices should be implemented to secure the container supply chain?

Select 3 answers
A.Sign images using Cosign
B.Always use the 'latest' tag for base images
C.Run containers with root privileges by default
D.Use immutable image tags (e.g., commit hash)
E.Scan images for CVEs with Trivy
AnswersA, D, E

Cosign signing creates a verifiable cryptographic attestation binding each image digest to a trusted publisher identity. This satisfies the supply-chain integrity constraint by enabling admission controllers to reject unsigned or tampered images before deployment, ensuring only artefacts built through approved pipelines reach the container runtime.

Why this answer

Option A is correct because signing images with Cosign (part of the Sigstore project) creates verifiable cryptographic signatures that let Kubernetes admission controllers or CI/CD pipelines confirm an image's provenance and integrity before deployment, preventing tampered or unauthorized images from entering the supply chain. Option D is correct because immutable tags such as a Git commit hash or digest guarantee that the exact audited artifact is deployed and cannot be silently overwritten, unlike mutable tags that can be repointed to different content. Option E is correct because scanning images with Trivy detects known CVEs in OS packages and language dependencies, enabling vulnerabilities to be caught and remediated early in the build pipeline.

Option B is not appropriate because the 'latest' tag is mutable and non-deterministic, so builds become unreproducible and can pull in unvetted or vulnerable base images. Option C is not appropriate because running containers as root violates least privilege and dramatically increases the blast radius if a container is compromised; containers should run as a non-root user.

Exam trap

CCSP often tests the misconception that encryption or scanning alone secures the supply chain, when the exam expects you to recognize that signing (integrity), immutable tags (reproducibility), and CVE scanning (vulnerability) are three distinct, complementary controls.

237
MCQmedium

Which design principle is most directly aimed at avoiding vendor lock-in and ensuring that workloads can be moved between cloud providers with minimal effort?

A.Portability
B.Reversibility
C.Elasticity
D.Multitenancy isolation
AnswerA

Portability is the design principle that keeps workloads free of provider-specific dependencies, allowing migration between clouds with minimal rework. It directly addresses vendor lock-in by requiring portable formats, APIs and configurations, so the stem's movement requirement is met.

Why this answer

Portability is the design principle specifically concerned with avoiding vendor lock-in by ensuring workloads, data, and configurations can be moved between cloud providers with minimal rework. It drives the use of open standards, containerization, and abstraction layers so that an application is not tied to proprietary APIs or services. Reversibility is related but focuses on the ability to exit a provider and bring data back, whereas portability is about the ability to move and run elsewhere.

Exam trap

The trap here is confusing portability with reversibility — both relate to avoiding lock-in, but portability is about moving workloads to another provider, while reversibility is about exiting and recovering data from the current provider.

How to eliminate wrong answers

Option B is wrong because reversibility refers to the ability to terminate a cloud relationship and retrieve data, not the ability to run workloads on another provider with minimal effort. Option C is wrong because elasticity is the ability to automatically scale resources up and down based on demand — it has nothing to do with vendor lock-in. Option D is wrong because multitenancy isolation is about separating tenant data and workloads in a shared environment, not about moving workloads between providers.

238
MCQeasy

Which practice is essential for securing cloud application secrets such as database passwords and API tokens?

A.Store secrets in environment variables in the source code
B.Use a secrets management service like Vault or cloud secret manager
C.Encrypt secrets with a hardcoded key
D.Share secrets via encrypted email
AnswerB

A dedicated secrets manager stores credentials encrypted, issues short-lived dynamic secrets, and enforces audit and rotation, removing hardcoded passwords and tokens from source and configuration. This satisfies the stem's requirement for securing cloud application secrets against leakage and lateral movement.

Why this answer

A dedicated secrets management service such as HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault centralizes storage, enforces access control, supports automatic rotation, and audits secret access. This removes hardcoded credentials from code and configuration, which is the essential practice for securing cloud application secrets. These services also integrate with IAM and support dynamic, short-lived credentials.

Exam trap

CCSP often tests the misconception that encrypting secrets or using environment variables is sufficient, when the correct answer is always a dedicated secrets management service with rotation and access control.

How to eliminate wrong answers

Option A is wrong because storing secrets in environment variables within source code still embeds them in the repository, where they can be leaked via version control, logs, or CI artifacts. Option C is wrong because encrypting secrets with a hardcoded key simply moves the secret — the key itself becomes the unprotected secret, defeating the purpose. Option D is wrong because sharing secrets via encrypted email is an insecure, manual process that lacks rotation, auditing, and access control, and email encryption is often weak or misconfigured.

239
MCQhard

An organization uses a cloud key management service (KMS) to encrypt data at rest. The security policy requires that the encryption keys be rotated every 90 days. The operations team is concerned about the impact of key rotation on encrypted data. Which of the following statements is true regarding KMS key rotation?

A.Key rotation is not supported in cloud KMS
B.Data encrypted before rotation can still be decrypted using the previous key as long as it is available
C.The KMS automatically re-encrypts all data with the new key
D.Existing data encrypted with the previous key must be re-encrypted with the new key
AnswerB

Rotating a KMS key creates a new key version while retaining prior versions, so ciphertext stays bound to the version that encrypted it. Decryption therefore continues using that earlier version, provided it remains enabled. This satisfies the 90-day rotation policy without re-encrypting existing data or disrupting access.

Why this answer

Cloud KMS retains previous key versions after rotation, allowing decryption of data encrypted with older keys. The key rotation creates a new cryptographic key version, but the old version remains active for decryption until it is disabled or deleted. This ensures that data encrypted before rotation remains accessible without re-encryption.

Exam trap

ISC2 often tests the misconception that key rotation forces re-encryption of all existing data, but the correct understanding is that previous key versions remain available for decryption, making re-encryption optional unless the old key is deleted.

How to eliminate wrong answers

Option A is wrong because cloud KMS (e.g., AWS KMS, Azure Key Vault, GCP Cloud KMS) fully supports key rotation, both automatic and manual. Option C is wrong because KMS does not automatically re-encrypt existing data; re-encryption requires an explicit operation by the application or storage service. Option D is wrong because existing data encrypted with the previous key can still be decrypted using the retained previous key version, so re-encryption is not mandatory for access.

240
MCQmedium

A security operations team at a healthcare company running workloads on AWS needs to ensure that all API activity in their production account is recorded and retained for 12 months, with the ability to search for specific events during a forensic investigation. The compliance officer mandates that logs must be protected from deletion by any user, including administrators. Which AWS service and configuration should the team implement to meet these requirements?

A.Enable AWS CloudTrail with a multi-region trail, deliver logs to a CloudWatch Logs log group with a 12-month retention policy, and set up a subscription filter to S3.
B.Enable AWS Config to record configuration changes and deliver snapshots to an S3 bucket with a lifecycle policy to retain for 12 months.
C.Enable VPC Flow Logs to capture all traffic, store them in CloudWatch Logs with a 12-month retention policy, and restrict access using IAM policies.
D.Enable AWS CloudTrail with a multi-region trail, deliver logs to an S3 bucket with versioning and MFA delete enabled, and apply a bucket policy that denies deletion.
AnswerD

CloudTrail records API activity across regions. Delivering to an S3 bucket with versioning and MFA delete prevents accidental or malicious deletion. A bucket policy explicitly denying s3:DeleteObject for all principals, including administrators, enforces immutability. This combination meets retention and forensic search needs, as logs are stored durably and accessible via Athena or CloudTrail Lake.

Why this answer

CloudTrail is the AWS service that records API activity. To meet retention and immutability, logs should be stored in S3 with versioning and MFA delete, and a bucket policy that denies deletion for all principals. This ensures logs cannot be tampered with, even by administrators, and can be queried for forensic purposes.

Other services like AWS Config or VPC Flow Logs capture different data types and lack the required protection mechanisms.

Exam trap

The trap here is confusing AWS Config or VPC Flow Logs with CloudTrail for API activity logging, and assuming that IAM policies or lifecycle rules alone can prevent deletion by administrators.

241
MCQeasy

A data governance team is developing a classification scheme for cloud-stored data. They want to label data based on sensitivity, from least to most restrictive. Which of the following is a typical classification category for highly sensitive data that could cause severe damage if disclosed?

A.Internal
B.Confidential
C.Restricted
D.Public
AnswerC

Restricted denotes the highest sensitivity tier, applied where disclosure causes severe damage such as regulatory penalty or financial loss. Classification schemes typically escalate public, internal, confidential then restricted, so restricted correctly labels the most tightly controlled data in the governance taxonomy.

Why this answer

In common classification schemes, 'Restricted' is the highest level, used for data that requires strict access control and protection.

242
MCQhard

A healthcare organization runs a critical workload on Azure virtual machines. The security team wants to ensure that the VMs are protected against rootkit and kernel-level malware that could persist across reboots. They need a solution that can detect and alert on suspicious kernel driver loads and provide file integrity monitoring. Which Azure service should they implement?

A.Azure Defender for Servers
B.Azure Network Watcher
C.Azure Sentinel
D.Azure Security Center (standard tier)
AnswerA

Azure Defender for Servers (part of Microsoft Defender for Cloud) provides advanced threat protection for VMs, including file integrity monitoring, detection of suspicious kernel driver loads, and behavioral analytics. It can alert on rootkits and other kernel-level anomalies. This service is designed to meet the requirement for detecting and alerting on kernel-level malware and file integrity changes.

Why this answer

Azure Defender for Servers, a component of Microsoft Defender for Cloud, provides endpoint detection and response, file integrity monitoring, and kernel-level threat detection. It can identify suspicious kernel driver loads and rootkit behavior, alerting security teams. Other services like Network Watcher focus on network diagnostics, Sentinel is a SIEM, and the outdated Security Center standard tier is superseded by Defender for Servers.

Exam trap

The trap here is selecting Azure Sentinel or Network Watcher for endpoint-level kernel monitoring, when only Defender for Servers provides that host-based protection.

243
MCQmedium

A European retail company is migrating its customer analytics platform to a public cloud provider. The dataset contains personal data of EU residents, and the company wants to minimize the risk of regulatory enforcement action if the cloud provider suffers a breach. Which action BEST addresses the shared responsibility for compliance in this scenario?

A.Execute a data processing agreement with the provider and independently verify the technical and organizational measures applied to the personal data.
B.Encrypt the data at rest with provider-managed keys and consider the compliance obligation fully transferred to the cloud provider.
C.Rely on the cloud provider's ISO/IEC 27001 certification as full evidence of GDPR compliance for the workload.
D.Transfer all personal data to the provider's infrastructure and let the provider determine the lawful basis for processing.
AnswerA

Under GDPR, a controller engaging a processor must have a data processing agreement in place, and the controller remains accountable for demonstrating compliance. Independently verifying the provider's technical and organizational measures ensures the contractual commitments are actually implemented, which directly reduces enforcement risk if a breach occurs.

Why this answer

The customer remains the data controller and therefore accountable under GDPR, even when using a public cloud. A data processing agreement establishes the required contractual framework, and independent verification confirms that the provider's technical and organizational measures are effective. Together these actions address the shared responsibility model and reduce the risk of regulatory enforcement after a breach.

Exam trap

The trap here is assuming that a provider's security certification or encryption automatically transfers GDPR accountability to the cloud provider.

244
MCQmedium

A healthcare SaaS provider exposes REST APIs to partner clinics. The security team must ensure that the API cannot be abused by replaying captured requests. The API already uses TLS 1.3 and OAuth 2.0 bearer tokens with short lifetimes. Which additional control best mitigates replay attacks against the API?

A.Enable HTTP Strict Transport Security (HSTS) with a long max-age on the API domain.
B.Increase the OAuth 2.0 token lifetime to reduce the frequency of token refresh calls.
C.Enforce mutual TLS between partner clinics and the API gateway.
D.Require a unique nonce and timestamp in each request, validated server-side against a replay cache.
AnswerD

A server-validated nonce combined with a timestamp ensures each request is unique and only accepted once within a defined window. Even if an attacker captures a request, the nonce will already be consumed or the timestamp will be stale, so the server rejects the replay. This directly mitigates replay attacks at the application layer.

Why this answer

Replay attacks occur when a valid request is captured and resent. Defenses must make each request unique and single-use. A server-validated nonce plus timestamp achieves this by rejecting duplicates and expired requests.

Transport security such as TLS or mTLS does not stop replay of already-authenticated application requests, and longer token lifetimes worsen exposure. HSTS is browser-focused and irrelevant to server-to-server API replay.

Exam trap

The trap here is assuming that transport-layer protections like TLS or mTLS automatically prevent application-layer replay of valid requests.

245
MCQeasy

A startup runs a three-tier web application on cloud virtual machines. The database tier must accept connections only from the application tier and never from the internet. Which cloud network security control should the team implement to enforce this requirement with the least operational overhead?

A.A network ACL on the database subnet denying all inbound traffic
B.A host-based firewall rule on each database VM allowing the application tier's public IP address
C.A security group on the database instances allowing only the application tier's security group as source
D.A web application firewall inspecting SQL traffic bound for the database
AnswerC

Security groups can reference another security group as a source, so the database rule permits traffic only from instances that carry the application tier's group membership. As the application tier scales in or out, membership updates automatically, requiring no rule edits, which satisfies the requirement with minimal ongoing operational effort.

Why this answer

Referencing the application tier's security group as the source of the database rule creates a dynamic, identity-based allow that follows instances as they scale. Because membership is managed automatically, the team avoids editing CIDR ranges or host firewalls whenever the application tier changes, meeting the segmentation goal with the least ongoing effort.

Exam trap

The trap here is choosing a subnet-level deny or a public IP allow, which either blocks legitimate traffic or requires constant manual updates as the application tier scales.

246
MCQhard

An attacker exploits a cloud application to make HTTP requests to an internal metadata service and retrieve temporary credentials. Which control would be most effective in preventing this attack?

A.Using signed URLs for all requests
B.Web Application Firewall (WAF) rules
C.Network-level egress filtering to block 169.254.169.254
D.Input validation on URL parameters
AnswerC

SSRF to the instance metadata service requires the workload to reach the link-local address 169.254.169.254. Blocking that destination at the network egress layer prevents credential retrieval even if the application is exploited, satisfying the containment constraint.

Why this answer

The attack exploits the cloud metadata service at the link-local address 169.254.169.254 (RFC 3927). Network-level egress filtering blocks outbound traffic to this IP, preventing the attacker from reaching the metadata service even if the application is compromised. This is a fundamental defense-in-depth control for cloud workloads.

Exam trap

ISC2 often tests the distinction between inbound controls (WAF, input validation) and outbound controls (egress filtering) for SSRF attacks, and the trap here is that candidates assume a WAF or input validation can block internal requests when only network-layer egress rules can stop the outbound connection to the metadata service.

How to eliminate wrong answers

Option A is wrong because signed URLs control access to specific resources (e.g., S3 objects) but do not prevent the application from making arbitrary HTTP requests to internal IPs like the metadata service. Option B is wrong because a WAF inspects incoming HTTP traffic for common web attacks (e.g., SQLi, XSS) but does not block outbound requests from the application to internal IPs; the attacker's exploit is an outbound server-side request, not an inbound attack. Option D is wrong because input validation on URL parameters can mitigate injection attacks but does not prevent the application from making requests to 169.254.169.254 if the attacker controls the request target via other means (e.g., SSRF via redirects or protocol smuggling).

247
MCQhard

A company is deploying a new application that processes sensitive personal data. The cloud provider operates in a specific region that adheres to the EU General Data Protection Regulation (GDPR). The company requires that data never leave the region. Which combination of cloud architecture controls should be implemented?

A.Use a virtual private cloud (VPC) with a route table that only allows egress to the internet through a NAT gateway.
B.Use data sovereignty policies, restrict geographic deployment to the region, and disable cross-region replication.
C.Use encryption at rest and in transit with keys stored in a cloud HSM.
D.Use a cloud provider's CDN service to cache content within the region.
AnswerB

Data sovereignty policies, region-restricted deployment and disabled cross-region replication together guarantee that personal data is stored and processed only within the GDPR-compliant region. Disabling replication specifically prevents provider-initiated copies from leaving the geographic boundary, satisfying the residency constraint.

Why this answer

Data sovereignty policies explicitly enforce that data remains within a specific jurisdiction, restricting geographic deployment to the region ensures all cloud resources are provisioned only in that region, and disabling cross-region replication prevents any automated or manual data transfer to other regions. This combination directly addresses the GDPR requirement that data never leave the designated region, as it controls both resource placement and data movement at the infrastructure level.

Exam trap

ISC2 often tests the misconception that encryption alone ensures data residency, but encryption protects data confidentiality, not its geographic location, so candidates must recognize that data sovereignty requires explicit location-based controls rather than cryptographic measures.

How to eliminate wrong answers

Option A is wrong because a VPC with a NAT gateway only controls outbound internet traffic from private subnets; it does not prevent data from being stored or processed in other regions, nor does it enforce geographic boundaries for data residency. Option C is wrong because encryption at rest and in transit, even with keys in a cloud HSM, protects data confidentiality but does not control where data is stored or processed; data could still be replicated or moved to another region. Option D is wrong because a CDN caches content at edge locations, which are often distributed across multiple regions and countries, potentially causing data to leave the specified region and violating the data residency requirement.

248
MCQmedium

A cloud security engineer needs to protect a storage bucket from accidental deletion and ransomware attacks. Which two features should be enabled together for maximum protection?

A.IAM policies and MFA delete
B.Bucket versioning and object lock
C.Cross-region replication and lifecycle policies
D.Server access logging and bucket policies
AnswerB

Bucket versioning preserves every object revision, so overwritten or deleted data remains recoverable, while object lock enforces WORM retention that blocks deletion even by compromised credentials. Together they satisfy the accidental-deletion and ransomware protection requirement, since neither alone prevents malicious overwrite.

Why this answer

Versioning keeps multiple variants of an object, allowing recovery from accidental deletion or overwrite. Object lock (immutability) prevents objects from being deleted or overwritten for a specified retention period, protecting against ransomware. Combining both provides defense in depth.

249
MCQeasy

A cloud consumer uses an IaaS provider for storage of archived financial records. Regulatory requirements mandate that data at rest be encrypted using a key that is under the consumer's sole control. Which encryption approach should the consumer implement?

A.Use client-side encryption with keys stored in the consumer's on-premises HSM
B.Use a TLS tunnel to the storage service
C.Enable server-side encryption with keys managed by the cloud provider
D.Use server-side encryption with customer-provided keys (SSE-C)
AnswerA

Client-side encryption performed before upload, with keys held in the consumer's own on-premises HSM, ensures the IaaS provider never possesses or can access the key material, satisfying sole-control mandates. Provider-managed or customer-managed cloud keys still leave key custody within the provider's infrastructure.

Why this answer

Client-side encryption ensures the data is encrypted before it leaves the consumer's environment, and storing the keys in the consumer's on-premises HSM guarantees sole control over the encryption keys, meeting the regulatory requirement for data-at-rest encryption with keys under the consumer's sole control.

Exam trap

ISC2 often tests the distinction between 'customer-provided keys' (SSE-C) and 'client-side encryption' — candidates confuse SSE-C as giving sole control, but the key is still used by the provider's infrastructure, not solely under the consumer's control.

How to eliminate wrong answers

Option B is wrong because TLS protects data in transit, not data at rest; it does not encrypt the stored archived financial records. Option C is wrong because server-side encryption with provider-managed keys means the cloud provider controls the encryption keys, violating the requirement for sole consumer control. Option D is wrong because SSE-C allows the consumer to provide the encryption key, but the key is used by the cloud provider's server-side encryption process, and the provider may retain access to the key material or metadata, potentially compromising sole control.

250
MCQmedium

A company is using a cloud provider's key management service (KMS) with HSM-backed keys. They want to ensure that key material is automatically replaced periodically to limit the impact of a potential key compromise. Which KMS feature should they configure?

A.Key export
B.Key revocation
C.Key policies
D.Key rotation
AnswerD

Key rotation generates new cryptographic key material on a schedule, retiring the previous version while retaining it for decryption of existing ciphertext. This satisfies the requirement to limit exposure from compromise by shortening each key's useful lifespan.

Why this answer

Key rotation is the KMS feature that automatically replaces key material on a defined schedule, generating a new cryptographic key version while retaining old versions to decrypt previously encrypted data. This limits the blast radius of a compromise because ciphertext encrypted under the old key version remains protected by the new material going forward. Configuring rotation directly addresses the requirement to periodically replace key material.

Exam trap

The trap is confusing revocation with rotation — candidates pick revocation thinking it 'replaces' a compromised key, but revocation disables the key and breaks decryption, whereas rotation preserves old versions for decryption while issuing new material.

How to eliminate wrong answers

Option A is wrong because key export allows key material to leave the HSM boundary, which increases exposure risk rather than limiting the impact of compromise. Option B is wrong because revocation disables a key entirely, which would render existing ciphertext undecryptable and is a reactive response to suspected compromise, not a preventive periodic replacement. Option C is wrong because key policies define who can use or manage a key, not how often the underlying key material is replaced.

251
MCQmedium

A cloud architect is designing a VPC for a three-tier application. The web servers need to be accessible from the internet, while the application servers should only be reachable from the web servers, and the database servers should be isolated from all other traffic except the application servers. Which VPC design best meets these requirements?

A.Web servers in a public subnet, app and database servers in a single private subnet
B.All servers in a private subnet with a NAT gateway
C.All servers in a single public subnet with security groups
D.Web servers in a public subnet, app servers in a private subnet, databases in an isolated subnet with appropriate security groups
AnswerD

Placing web servers in a public subnet, app servers in a private subnet and databases in an isolated subnet, each governed by security groups, enforces the required traffic flow: internet to web only, web to app, and app to database.

Why this answer

A three-tier design requires three distinct network zones: a public subnet for internet-facing web servers, a private subnet for application servers reachable only from the web tier, and an isolated (private, no NAT/IGW route) subnet for databases reachable only from the app tier. Security groups enforce the tier-to-tier traffic rules (web SG allows 80/443 from internet; app SG allows app port from web SG; DB SG allows DB port from app SG). This layered segmentation is the canonical defense-in-depth VPC pattern.

Exam trap

CCSP often tests the misconception that a single private subnet with security groups is sufficient segmentation, when the exam expects recognition that each trust tier (web, app, DB) requires its own subnet and security group boundary.

How to eliminate wrong answers

Option A is wrong because placing app and database servers in the same private subnet collapses two trust tiers into one, so a compromised app server can directly reach the database without an additional security boundary. Option B is wrong because putting all servers in a private subnet with a NAT gateway removes the public entry point needed for internet-facing web servers and provides no tier separation. Option C is wrong because placing all servers in a single public subnet exposes the app and database tiers to the internet and eliminates network segmentation entirely, violating least privilege.

252
MCQeasy

A company requires that its cloud service provider offers a dedicated environment with no shared infrastructure. Which cloud deployment model should the company choose?

A.Public cloud
B.Hybrid cloud
C.Community cloud
D.Private cloud
AnswerD

A private cloud provides infrastructure dedicated solely to one organisation, with no shared compute, storage or network resources. Public, hybrid and community models all involve some shared infrastructure, so only the private deployment model satisfies the no-sharing constraint.

Why this answer

Private cloud is dedicated to a single organization, providing exclusive use of infrastructure. Public cloud is shared, community is shared by multiple organizations with common interests, and hybrid combines models.

253
MCQeasy

A cloud operations team is configuring a virtual private cloud (VPC) and needs to control both inbound and outbound traffic at the subnet level. The team wants to ensure that any traffic leaving the subnet is explicitly allowed, and that responses to inbound requests are automatically permitted. Which VPC component should the team configure?

A.Security groups, because they are stateful and evaluate all traffic at the instance level.
B.Network ACLs, because they are stateless and can enforce explicit allow/deny rules for both inbound and outbound traffic at the subnet boundary.
C.VPC flow logs, because they capture metadata about traffic and can be used to enforce outbound restrictions.
D.Route tables, because they determine which subnet traffic is directed to and can block unauthorized destinations.
AnswerB

Network ACLs are stateless and operate at the subnet level. They require explicit rules for both inbound and outbound traffic, and return traffic must be allowed by an outbound rule. This matches the requirement to control traffic at the subnet level with explicit outbound allowances. They are the correct component for subnet-level traffic filtering in a VPC.

Why this answer

Network ACLs are stateless and operate at the subnet level, requiring explicit rules for both inbound and outbound traffic. This makes them the correct choice for controlling traffic at the subnet boundary with explicit outbound allowances. Security groups are stateful and instance-level, route tables direct traffic without filtering, and flow logs only record metadata without enforcement.

Exam trap

The trap here is assuming that security groups can provide subnet-level control because they are stateful, when in fact they operate at the instance level and cannot enforce explicit outbound rules at the subnet boundary.

254
MCQhard

A company is deploying a containerized application on Kubernetes. The security team requires that containers run with the least privilege, and that any attempt to escalate privileges within a container is blocked. Which Kubernetes security context setting should be applied to the pod specification?

A.runAsNonRoot: true
B.capabilities: drop: ['ALL']
C.readOnlyRootFilesystem: true
D.allowPrivilegeEscalation: false
AnswerD

Setting allowPrivilegeEscalation to false prevents a container process from gaining more privileges than its parent, blocking mechanisms such as setuid binaries and file capabilities. This satisfies the stem's requirement that privilege escalation attempts within the container be blocked.

Why this answer

Setting `allowPrivilegeEscalation: false` in the pod's security context directly blocks any attempt by a container process to gain more privileges than its parent process, such as through setuid binaries or syscalls like `setuid()`. This satisfies the requirement to prevent privilege escalation within the container, aligning with the least privilege principle.

Exam trap

ISC2 often tests the distinction between preventing privilege escalation and other security controls like dropping capabilities or running as non-root, leading candidates to confuse capability removal with escalation prevention.

How to eliminate wrong answers

Option A is wrong because `runAsNonRoot: true` only ensures the container runs with a non-root user, but it does not block privilege escalation mechanisms (e.g., a non-root user could still execute a setuid binary to become root). Option B is wrong because dropping all capabilities (`capabilities: drop: ['ALL']`) removes kernel capabilities but does not prevent privilege escalation via other means like setuid binaries or file system capabilities. Option C is wrong because `readOnlyRootFilesystem: true` only makes the container's root filesystem read-only, which does not address privilege escalation at all.

255
MCQhard

A security architect is designing a multi-tenant SaaS application hosted on AWS. The application uses a shared Amazon RDS database with a tenant_id column to isolate data. The architect must ensure that tenants cannot access each other's data even if there is a vulnerability in the application layer. Which additional control should be implemented to enforce data isolation at the database level?

A.Use separate database schemas for each tenant.
B.Implement row-level security (RLS) policies in the database based on tenant_id.
C.Enable RDS encryption at rest using AWS KMS.
D.Configure security groups to restrict access to the RDS instance.
AnswerB

Row-level security (RLS) allows the database to enforce access control at the row level based on the tenant_id. Even if the application is compromised, the database will only return rows matching the tenant context set for the session. This provides a strong defense-in-depth control for multi-tenant isolation, assuming the application sets the tenant context correctly.

Why this answer

Row-level security (RLS) enforces data isolation at the database level by filtering rows based on the tenant context. Even if an attacker exploits the application, the database will only return rows for the current tenant, preventing cross-tenant data leakage. This defense-in-depth measure is critical for multi-tenant SaaS applications using a shared database, as it adds a layer of protection beyond application logic.

Exam trap

The trap here is assuming that encryption at rest or network controls like security groups can enforce tenant isolation, when they do not prevent queries from accessing other tenants' data.

256
MCQeasy

Which of the following is a primary benefit of using immutable tags for container images in a production registry?

A.Improved build performance
B.Automatic vulnerability scanning
C.Consistent and reproducible deployments
D.Reduced storage cost
AnswerC

Immutable tags map a fixed tag to one digest, so every deployment pulls byte-identical content. This eliminates drift between environments and gives the consistent, reproducible deployments the stem asks for, unlike mutable tags that can be overwritten silently.

Why this answer

Immutable tags prevent accidental overwriting of image tags, ensuring that the same tag always refers to the same image, which aids in traceability and rollback.

257
Multi-Selectmedium

A cloud customer is negotiating a contract with a new cloud provider. The customer wants to ensure they can maintain control over their data and verify the provider's security posture. Which TWO contractual provisions are most critical for these purposes? (Choose two.)

Select 2 answers
A.Data portability clause to export data in a usable format
B.Data ownership clause specifying customer retains all rights to data
C.Data deletion clause for removal upon contract termination
D.Service Level Agreement (SLA) for uptime and performance
E.Right to audit the cloud provider's security controls
AnswersB, E

A data ownership clause contractually confirms the customer retains all rights to their data, preserving control and preventing the provider from claiming or repurposing it. This directly satisfies the requirement to maintain control over data.

Why this answer

Option B is correct because a data ownership clause explicitly stating that the customer retains all rights to their data directly addresses the customer's goal of maintaining control over their data, removing ambiguity about who owns the information stored with the provider. Option E is correct because a right-to-audit provision lets the customer independently verify the provider's security posture through assessments, certifications, or on-site audits, which is exactly the verification capability the customer wants. Option A is not the best fit because data portability addresses avoiding lock-in and migrating data, not ownership control or security verification.

Option C is not selected because deletion on termination concerns data disposal, not ongoing control or security posture verification. Option D is not selected because an SLA for uptime and performance covers availability and service quality, not data control or security assurance.

Exam trap

ISC2 often tests the distinction between contractual clauses that provide legal ownership (data ownership) versus operational capabilities (data portability, deletion) versus performance guarantees (SLA), and candidates frequently confuse the right to audit with a general SLA or data portability clause.

258
Multi-Selecthard

A company is evaluating cloud providers for a critical workload and requires high availability, disaster recovery, and portability. Which THREE factors should the company prioritize in the provider evaluation?

Select 3 answers
A.Support for open APIs and industry standards
B.Availability of independent audit reports (e.g., SOC 2, ISO 27001)
C.Provider's customer support tiers
D.SLA guarantees for uptime and availability
E.Number of data center locations
AnswersA, B, D

Support for open APIs and industry standards directly satisfies the portability constraint by preventing vendor lock-in, letting the workload migrate between providers. Standardised interfaces also underpin resilient multi-provider architectures, so this factor addresses both the portability and high-availability requirements rather than only one.

Why this answer

Option A is correct because support for open APIs and industry standards directly enables portability, allowing the company to avoid vendor lock-in and migrate or integrate workloads across providers using well-defined interfaces. Option B is correct because independent audit reports such as SOC 2 and ISO 27001 provide verifiable assurance that the provider's security, availability, and operational controls meet recognized compliance frameworks, which is essential for a critical workload. Option D is correct because SLA guarantees for uptime and availability define the provider's contractual commitment to high availability and provide measurable remedies if service levels are missed, directly supporting the HA/DR requirement.

Option C is not a primary evaluation factor here because customer support tiers affect responsiveness and service experience but do not by themselves deliver high availability, disaster recovery, or portability. Option E is also not a primary factor because the number of data center locations alone does not guarantee HA/DR or portability; what matters is how those locations are architected, replicated, and exposed through standards and SLAs.

259
Multi-Selecthard

A cloud architect is designing a multi-tier application that will be deployed in a public cloud. The application must meet strict security and compliance requirements, including data isolation, network segmentation, and encryption of data at rest and in transit. The architect is considering using a virtual private cloud (VPC) and must ensure that the design aligns with the cloud shared responsibility model. Which TWO of the following are the cloud customer's responsibilities under the shared responsibility model? (Choose two.)

Select 2 answers
A.Ensuring the physical network infrastructure is redundant and fault-tolerant.
B.Managing the physical security of the data center where the application is hosted.
C.Encrypting application data at rest using customer-managed keys.
D.Configuring security groups and network ACLs to control traffic to and from the application instances.
E.Patching the hypervisor and underlying host operating system.
AnswersC, D

The customer is responsible for encrypting their data at rest, including choosing and managing encryption keys. While the cloud provider may offer encryption capabilities and key management services, the customer must configure and manage the encryption of their own data. This includes using customer-managed keys (CMKs) to maintain control over access to the data.

Why this answer

Under the shared responsibility model for IaaS, the customer is responsible for security in the cloud, which includes configuring network controls (security groups, network ACLs) and encrypting data at rest with customer-managed keys. The provider is responsible for security of the cloud, including physical security, hypervisor patching, and physical network redundancy. Therefore, the customer's responsibilities are configuring security groups and network ACLs, and encrypting application data at rest.

Exam trap

The trap here is confusing the provider's responsibility for physical security and hypervisor management with the customer's responsibility for securing their own data and network configurations. Many candidates incorrectly assume the provider handles all aspects of security, including data encryption.

260
MCQhard

A company is required to retain logs for 7 years per regulation. The cloud provider's default retention is 90 days. What is the most effective approach?

A.Disable log retention completely to avoid risk
B.Rely on the provider's default retention
C.Export logs to an external storage with a 7-year retention policy
D.Encrypt logs and store them in the same provider
AnswerC

Provider-native log retention caps at 90 days, so regulatory retention beyond that requires exporting logs to storage you control, where a lifecycle or retention policy enforces the full 7-year period independently of the provider's default.

Why this answer

The customer is responsible for compliance. Configuring log export to an external storage with 7-year retention ensures data is preserved. Relying on provider's default violates regulation, disabling retention breaks compliance, and encryption doesn't affect retention duration.

261
Multi-Selecteasy

Which TWO of the following are common best practices for securing cloud application APIs? (Choose two.)

Select 2 answers
A.Implement rate limiting
B.Validate and sanitize all input
C.Disable HTTPS to reduce latency
D.Return detailed error messages for debugging
E.Allow all origins with CORS
AnswersA, B

Rate limiting prevents DDoS and brute force.

Why this answer

Rate limiting is a critical best practice for securing cloud application APIs because it prevents abuse by limiting the number of requests a client can make within a specific time window. This mitigates brute-force attacks, denial-of-service (DoS) attacks, and resource exhaustion. By enforcing rate limits, the API maintains availability and protects backend services from being overwhelmed.

Exam trap

ISC2 often tests the misconception that disabling HTTPS improves performance for cloud APIs, but the correct priority is always encryption for data in transit, even at the cost of slight latency.

262
MCQmedium

A multinational corporation must ensure that customer data from the European Union is stored and processed only within EU regions to comply with GDPR. They are using a cloud provider with data centers globally. What is the primary mechanism to enforce this requirement?

A.Selecting cloud regions located within the EU for all services
B.Client-side encryption with keys stored in the EU
C.Using a VPN to route all traffic through an EU gateway
D.Configuring IAM policies to restrict access to EU-based administrators
AnswerA

Region selection is the foundational control: compute, storage and processing resources deployed only in EU regions keep data physically within the jurisdiction. It is the prerequisite mechanism on which replication restrictions and contractual safeguards then depend for GDPR residency.

Why this answer

The primary mechanism to enforce EU-only data residency is to select cloud regions physically located within the EU for all services that store or process the data, since data residency is fundamentally about where the data at rest and in processing resides. Region selection is a deployment-time architectural decision that determines the physical location of storage, compute, and backups. Other controls (encryption, VPN, IAM) complement but do not substitute for choosing EU regions.

Exam trap

CCSP often tests the misconception that encryption or access controls satisfy data residency, when the exam expects recognition that only physical region selection enforces where data is stored and processed.

How to eliminate wrong answers

Option B is wrong because client-side encryption with EU-stored keys protects confidentiality but does not prevent the ciphertext from being stored or processed outside the EU, so it fails the residency requirement. Option C is wrong because routing traffic through an EU VPN gateway only affects data in transit, not where data is stored or processed at rest. Option D is wrong because restricting IAM access to EU-based administrators controls who can access data, not where the data physically resides, so it does not enforce residency.

263
MCQeasy

A cloud architect is designing a data classification scheme for a SaaS application. Data must be classified based on sensitivity and regulatory requirements. Which of the following is the PRIMARY reason to classify data?

A.To reduce storage costs by identifying obsolete data
B.To comply with a specific data protection regulation
C.To improve data access speeds for high-priority data
D.To apply appropriate security controls based on data sensitivity
AnswerD

Classification exists to map data to sensitivity and regulatory categories so that proportionate security controls, such as encryption, access restrictions and retention rules, can be applied. Without classification, controls cannot be matched to the protection each dataset actually requires.

Why this answer

The primary reason to classify data in a cloud environment is to enable the application of appropriate security controls based on data sensitivity. Classification drives the selection of encryption standards, access control policies, and data loss prevention (DLP) rules, ensuring that sensitive data receives stronger protection while lower-sensitivity data is handled with less restrictive measures. Without classification, security controls would be applied uniformly, leading to either over-protection of trivial data or under-protection of critical data.

Exam trap

ISC2 often tests the misconception that compliance is the primary reason for classification, but the trap is that compliance is a downstream requirement—classification is the foundational step to identify which data is subject to which regulation, and the primary goal is always to apply appropriate security controls based on sensitivity.

How to eliminate wrong answers

Option A is wrong because reducing storage costs by identifying obsolete data is a secondary benefit of data lifecycle management, not the primary driver for classification; classification focuses on sensitivity and regulatory requirements, not storage optimization. Option B is wrong because while compliance with a specific data protection regulation (e.g., GDPR, HIPAA) is a common use case, it is not the primary reason—classification must occur first to determine which data falls under which regulation, and the core purpose is to map sensitivity to controls, not to comply with a single regulation. Option C is wrong because improving data access speeds for high-priority data is a performance optimization concern, typically addressed through caching, CDN, or storage tiering, not through data classification; classification does not inherently affect access latency.

264
Multi-Selecthard

A cloud security architect is designing a DevSecOps pipeline for a multi-cloud environment. Which THREE practices should be included to ensure security is integrated early? (Select THREE)

Select 3 answers
A.Scanning dependencies for known vulnerabilities in the CI pipeline
B.Scanning container images after they are deployed to production
C.Running DAST against the production environment
D.Running IaC security scanning on Terraform templates before deployment
E.Performing SAST scans in the IDE or during pull requests
AnswersA, D, E

Scanning dependencies in CI detects known vulnerabilities in third-party libraries before artefacts are built, shifting remediation left. This satisfies the multi-cloud DevSecOps requirement by catching supply-chain flaws early, when fixes are cheaper and before code reaches deployment.

Why this answer

Option A is correct because scanning dependencies for known vulnerabilities in the CI pipeline (e.g., with SCA tools like Dependabot, Snyk, or OWASP Dependency-Check) shifts detection of vulnerable third-party libraries to the earliest build stage, before artifacts are promoted. Option D is correct because IaC security scanning on Terraform templates (e.g., with Checkov, tfsec, or Terrascan) catches misconfigurations such as public S3 buckets or overly permissive security groups before any infrastructure is provisioned. Option E is correct because performing SAST scans in the IDE or during pull requests (e.g., with SonarQube, Semgrep, or CodeQL) gives developers immediate feedback on insecure code patterns at the point of authorship, which is the earliest possible integration point.

Option B does not belong because scanning container images only after production deployment is a reactive, post-deployment control rather than an early-shift-left practice. Option C does not belong because DAST against production is a late-stage, runtime test that exercises a live environment and cannot prevent defects from reaching production.

Exam trap

The CCSP exam often tests the concept of 'shift-left' by including late-stage security activities (like post-deployment scanning or production DAST) as distractors, tempting candidates who confuse 'security testing' with 'early integration'.

265
MCQhard

A cloud customer is subject to a regulatory audit and must provide evidence that the cloud provider's security controls are effective. The customer has no right to audit the provider directly but can rely on third-party attestations. Which report should the customer request to obtain an independent assessment of the provider's controls relevant to security, availability, and confidentiality?

A.Cloud Security Alliance STAR Level 1 self-assessment
B.SOC 1 Type II report
C.SOC 2 Type II report
D.ISO/IEC 27001 certificate
AnswerC

SOC 2 Type II reports provide an independent auditor's opinion on the effectiveness of controls over security, availability, processing integrity, confidentiality, and privacy. They cover a period of time, demonstrating sustained control operation. For a cloud customer needing evidence of security controls, this report is the most appropriate because it directly addresses the trust services criteria relevant to cloud services.

Why this answer

SOC 2 Type II is specifically designed to report on the effectiveness of controls related to security, availability, and confidentiality over a period. It is produced by an independent CPA firm and is widely accepted in regulatory audits. Other options either focus on financial controls, lack detailed period-based evidence, or are self-assessed, making SOC 2 Type II the correct choice.

Exam trap

The trap here is confusing a point-in-time certification like ISO 27001 with a period-based attestation like SOC 2 Type II.

266
Multi-Selecteasy

A cloud security engineer needs to ensure that logs from multiple AWS accounts are centrally stored in a security account for analysis. Which TWO services can be used to aggregate logs across accounts? (Choose two.)

Select 2 answers
A.Amazon CloudWatch Logs with cross-account subscription filters
B.AWS Config
C.AWS Security Hub
D.Amazon S3 with cross-account bucket policies
E.Amazon GuardDuty
AnswersA, D

CloudWatch Logs cross-account subscription filters stream log events in near real time from source accounts to a Kinesis Data Streams or Lambda destination in the security account, satisfying the centralised aggregation requirement without polling. This native mechanism avoids duplicating log groups per account, unlike resource-policy-based sharing.

Why this answer

Option A is correct because CloudWatch Logs supports cross-account subscription filters, which allow a destination account (the security account) to receive real-time log events from source accounts via a destination Logs resource policy and a subscription filter, enabling centralized log aggregation. Option D is correct because Amazon S3 with cross-account bucket policies lets multiple accounts write their logs (e.g., via PutObject permissions in the bucket policy) into a single central bucket owned by the security account, which is a common pattern for centralized log storage and analysis. Option B (AWS Config) is a configuration compliance and resource inventory service, not a cross-account log aggregation mechanism.

Option C (AWS Security Hub) aggregates security findings and compliance checks across accounts, not raw logs. Option E (Amazon GuardDuty) is a threat detection service that generates findings, not a general log aggregation service.

Exam trap

A common trap is mixing up services that aggregate raw logs (CloudWatch Logs, S3) with those that aggregate security findings or metadata (Security Hub, GuardDuty). Candidates may incorrectly select Security Hub or GuardDuty for log aggregation.

267
Multi-Selectmedium

An organization is implementing a data loss prevention (DLP) solution to protect sensitive data in cloud storage. Which TWO of the following are capabilities of a cloud DLP service? (Select TWO.)

Select 2 answers
A.Automatic encryption key rotation
B.Enforcing multi-factor authentication
C.De-identification transforms such as masking and tokenization
D.Inspection of data for sensitive information types
E.Automated backup of sensitive data
AnswersC, D

De-identification transforms such as masking and tokenisation irreversibly or reversibly obscure sensitive fields, a core DLP capability for protecting data at rest in cloud storage. They reduce exposure of regulated data while preserving usability for analytics or testing.

Why this answer

Option C is correct because cloud DLP services (such as Google Cloud DLP/Sensitive Data Protection) provide de-identification transforms including masking, tokenization, and format-preserving encryption to obfuscate sensitive values while preserving usability. Option D is correct because the core function of a cloud DLP service is inspecting data at rest or in transit to detect sensitive information types (SITs) such as credit card numbers, SSNs, and API keys using built-in or custom infoType detectors. Option A is not a DLP capability; encryption key rotation is handled by a key management service (KMS) such as Cloud KMS.

Option B is not a DLP capability; MFA enforcement is an identity and access management function (e.g., IAM, MFA policies). Option E is not a DLP capability; automated backups are provided by storage or backup services, not by DLP inspection tooling.

Exam trap

CCSP often tests whether candidates can distinguish DLP capabilities from adjacent security functions — the trap is selecting encryption key rotation or MFA enforcement as DLP features when DLP is specifically about data inspection and de-identification.

268
MCQmedium

A media production company wants to use a public cloud for rendering video but must retain full control over the guest OS, patching, and runtime configuration. The company does not want to manage physical hardware or hypervisors. Which cloud service model BEST meets these requirements?

A.Function as a Service (FaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Software as a Service (SaaS)
AnswerC

IaaS provides virtualized compute, storage, and networking while the provider manages the physical hosts and hypervisor. The customer retains control of the guest operating system, middleware, and applications, which aligns with the need to control patching and runtime configuration. It also avoids hardware and hypervisor management, exactly matching the stated requirements.

Why this answer

IaaS is the only model that gives the customer control over the guest operating system and runtime while the provider manages the physical infrastructure and hypervisor. PaaS, SaaS, and FaaS abstract away the OS layer, removing the control the media company needs. The scenario explicitly requires retaining patching and runtime configuration, which maps directly to IaaS responsibilities.

Exam trap

The trap here is assuming that any cloud model removing hardware management also permits guest OS control, when only IaaS preserves that layer for the customer.

269
MCQmedium

A cloud customer's legal team is reviewing a provider's contract and finds a clause requiring the customer to resolve all disputes through binding arbitration in the provider's home country. The customer operates in several jurisdictions and wants to preserve its options. Which contract provision should the customer negotiate to best address this concern?

A.A choice-of-law and choice-of-forum clause naming a neutral jurisdiction
B.A right to audit the provider's security controls annually
C.A service-level agreement with credits for availability shortfalls
D.A data residency clause requiring storage only in the customer's home country
AnswerA

A choice-of-law and choice-of-forum clause determines which jurisdiction's law applies and where disputes are heard. Naming a neutral jurisdiction, or at least one acceptable to both parties, counteracts a mandatory arbitration clause tied to the provider's home country. This directly addresses the customer's desire to preserve legal options across multiple operating jurisdictions.

Why this answer

A choice-of-law and choice-of-forum clause determines the governing law and the venue for disputes, directly countering a one-sided mandatory arbitration provision. Naming a neutral jurisdiction protects the customer's ability to pursue remedies across multiple operating regions. Audit rights, SLAs, and data residency provisions serve different purposes and do not affect where disputes are heard.

Exam trap

The trap here is confusing a data residency requirement, which limits where data is stored, with a forum selection clause, which determines where legal disputes are adjudicated.

270
MCQmedium

An API allows users to access their own profile data by providing a user ID. However, an attacker can change the user ID parameter to access another user's data. Which OWASP API Security vulnerability is this?

A.Excessive Data Exposure
B.Mass Assignment
C.Broken User Authentication
D.Broken Object Level Authorization
AnswerD

Broken Object Level Authorization occurs when the API validates the user's identity but not their entitlement to the requested object. Changing the user ID parameter lets the attacker access another user's profile because no per-object ownership check is enforced server-side.

Why this answer

Broken Object Level Authorization (BOLA), listed as API1:2023 in the OWASP API Security Top 10, occurs when an API fails to verify that the authenticated user is authorized to access the specific object referenced by an identifier. Changing the user ID to retrieve another user's profile is the textbook BOLA example. The fix is to enforce object-level authorization checks on every request, not just authentication.

Exam trap

CCSP often tests the distinction between BOLA (object-level, horizontal access to another user's data) and Broken User Authentication or Excessive Data Exposure, so candidates must focus on the identifier-manipulation detail.

How to eliminate wrong answers

Option A is wrong because Excessive Data Exposure refers to APIs returning more data than the client needs (e.g., full user objects with sensitive fields), not to manipulating identifiers to access other users' records. Option B is wrong because Mass Assignment occurs when an API binds client-supplied input directly to internal object properties, allowing attackers to modify fields they shouldn't (e.g., setting isAdmin=true). Option C is wrong because Broken User Authentication concerns weaknesses in authentication mechanisms (tokens, credentials, session handling), whereas here the user is authenticated but improperly authorized.

271
MCQeasy

A DevOps team wants to prevent insecure code from being deployed to production. Which gate should be implemented in the CI/CD pipeline?

A.Automated security scanning with failure conditions
B.Run penetration testing after release
C.Dependency scanning only on weekly basis
D.Manual code review after deployment
AnswerA

Automated security scanning with failure conditions blocks the pipeline when vulnerabilities are detected, directly preventing insecure code from reaching production. This satisfies the stem's deployment-prevention constraint by enforcing a hard gate rather than advisory reporting, ensuring builds fail before artefacts are promoted.

Why this answer

Automated security scanning with failure conditions (option A) is the correct gate because it enforces security checks directly within the CI/CD pipeline, preventing any code that fails static application security testing (SAST) or software composition analysis (SCA) from progressing to production. This shift-left approach ensures that vulnerabilities are caught before deployment, aligning with DevSecOps principles and reducing risk.

Exam trap

ISC2 often tests the misconception that any security activity after deployment (like penetration testing or manual review) can serve as a preventive gate, when in fact only automated checks with failure conditions integrated into the pipeline can block insecure code before it reaches production.

How to eliminate wrong answers

Option B is wrong because running penetration testing after release does not prevent insecure code from being deployed; it only identifies vulnerabilities post-deployment, which violates the principle of shifting security left. Option C is wrong because dependency scanning only on a weekly basis introduces a significant delay, allowing vulnerable dependencies to be deployed before they are detected, whereas real-time scanning in the pipeline is needed. Option D is wrong because manual code review after deployment cannot block insecure code from reaching production; it is a reactive measure that does not serve as a pipeline gate.

272
MCQmedium

Refer to the exhibit. A security engineer attaches this bucket policy to a cloud storage bucket. What does this policy accomplish?

A.It allows only requests from a specific virtual network endpoint.
B.It denies all requests to the bucket that are not using HTTPS.
C.It denies requests from IP addresses outside a specific range.
D.It denies all requests to the bucket.
AnswerB

The policy's `aws:SecureTransport` condition evaluates to false for plain HTTP requests, triggering an explicit Deny. This enforces encryption in transit for every request to the bucket, satisfying the stem's requirement that unencrypted access be blocked regardless of principal or action.

Why this answer

The bucket policy uses a condition that checks for HTTPS usage (secure transport) and an explicit Deny effect. This denies any request that does not use HTTPS (i.e., plain HTTP), ensuring all traffic to the bucket is encrypted in transit.

Exam trap

The trap is that candidates may confuse the HTTPS condition with IP-based or virtual network endpoint conditions, or mistakenly think the policy denies all requests because of the Deny effect, without reading the condition that limits the denial to non-HTTPS traffic.

How to eliminate wrong answers

Option A is wrong because the policy does not reference `aws:SourceVpce` or any VPC endpoint condition; it only checks `aws:SecureTransport`. Option C is wrong because the policy does not use `aws:SourceIp` or any IP address condition; it only checks the transport protocol. Option D is wrong because the policy does not deny all requests; it only denies requests where `aws:SecureTransport` is `false`, so HTTPS requests are still allowed.

273
MCQeasy

Which of the following is a key requirement for data portability under the General Data Protection Regulation (GDPR)?

A.Data must be transferred directly to the data subject's own device.
B.Data must be provided in a structured, commonly used, and machine-readable format.
C.Data portability applies only to pseudonymized data.
D.Data must be deleted within 30 days of a portability request.
AnswerB

GDPR Article 20 requires portability in a structured, commonly used and machine-readable format, enabling the data subject to transmit data to another controller without hindrance. This format requirement is the specific technical condition the regulation imposes.

Why this answer

GDPR Article 20 requires that when data portability applies, the controller must provide the personal data 'in a structured, commonly used and machine-readable format.' This ensures the data can be transmitted to another controller without hindrance, typically using formats such as JSON, XML, or CSV. The right applies to data processed by automated means based on consent or contract.

Exam trap

The trap here is confusing data portability with the right of access or erasure, leading candidates to pick deletion timelines or device-transfer requirements that GDPR does not mandate.

How to eliminate wrong answers

Option A is wrong because GDPR does not require direct transfer to the data subject's own device; the data subject may receive the data or have it transmitted directly to another controller. Option C is wrong because portability applies to personal data provided by the data subject, not only pseudonymized data; pseudonymized data may still be within scope if it relates to an identifiable person. Option D is wrong because GDPR does not impose a 30-day deletion requirement tied to portability requests; deletion timelines are governed by other principles such as storage limitation and the right to erasure.

274
MCQeasy

In a cloud VPC, what is the difference between security groups and network ACLs (NACLs)?

A.Security groups are stateful and support allow rules only; NACLs are stateless and support allow and deny rules
B.Security groups support allow and deny rules; NACLs support only allow
C.Security groups are stateless and NACLs are stateful
D.Security groups and NACLs are both stateless
AnswerA

Security groups operate at the instance level, are stateful, and permit allow rules only. NACLs operate at the subnet level, are stateless, and support both allow and deny rules, so return traffic must be explicitly permitted in each direction.

Why this answer

Security groups are stateful—return traffic for an allowed inbound connection is automatically permitted—and they support only allow rules, with an implicit deny for anything not explicitly allowed. NACLs are stateless—each direction must be explicitly allowed, including ephemeral return ports—and they support both allow and deny rules, evaluated in numbered order. This stateful/stateless and allow-only/allow-deny distinction is the core difference.

Exam trap

CCSP often tests the stateful/stateless and allow-only/allow-deny distinction, and candidates frequently reverse the two (e.g., thinking SGs support deny or that NACLs are stateful), which is exactly the trap this question sets.

How to eliminate wrong answers

Option B is wrong because it reverses the rule types: security groups do not support deny rules (only allow), and NACLs do support deny rules in addition to allow. Option C is wrong because it reverses the statefulness: security groups are stateful, and NACLs are stateless. Option D is wrong because it incorrectly states both are stateless; security groups are stateful, which is why return traffic is automatically allowed.

275
MCQhard

During a security audit, a cloud security architect discovers that a cloud storage bucket is configured with a bucket policy that allows read access to objects from any principal. What is the most likely risk?

A.Denial of service from excessive requests
B.Potential for data exfiltration by unauthorized users
C.Insufficient logging of access
D.Increased cost due to excessive write operations
AnswerB

A bucket policy granting read access to any principal removes authentication entirely, letting anyone retrieve stored objects. This directly enables data exfiltration by unauthorised users, satisfying the stem's constraint of an unrestricted principal. Unlike identity-based controls, resource policies apply regardless of Microsoft Entra ID membership, so anonymous or external actors can enumerate and download data.

Why this answer

A bucket policy allowing read access to objects from any principal means anyone on the internet can list and download objects, leading to potential data exfiltration. This is a classic cloud storage misconfiguration where sensitive data becomes publicly accessible without authentication. The primary risk is unauthorized disclosure of data, not performance or cost issues.

Exam trap

The trap is that candidates may focus on secondary effects like cost or logging, but the core risk of a public-read bucket policy is unauthorized data access and exfiltration.

How to eliminate wrong answers

Option A is wrong because while public access could theoretically increase request volume, the policy grants read access — not a mechanism for denial of service, which would require overwhelming the bucket with requests beyond its capacity. Option C is wrong because insufficient logging is a separate configuration concern (CloudTrail data events, S3 server access logging) and is not caused by the bucket policy itself. Option D is wrong because the policy allows read access, not write access, so it would not increase costs from write operations — though egress costs from data downloads could rise, that is a secondary effect, not the primary risk.

276
Multi-Selecteasy

A company is deploying a cloud application that processes customers' personal data. They need to ensure data in transit is protected. Which THREE of the following are appropriate controls for data in transit? (Select THREE.)

Select 3 answers
A.Establishing a VPN for hybrid connectivity
B.Setting data classification labels on the data
C.Enforcing HTTPS for web application access
D.Encrypting data at rest using AES-256
E.Using TLS 1.2 for all API communications
AnswersA, C, E

A VPN encrypts traffic traversing untrusted networks between on-premises infrastructure and the cloud provider, using protocols such as IPsec. This protects data in transit for hybrid connectivity, satisfying the stem's requirement to safeguard personal data moving between environments.

Why this answer

Option A is correct because a VPN (e.g., IPsec or TLS-based tunnel) encrypts traffic between on-premises networks and the cloud, protecting data in transit across hybrid connections. Option C is correct because enforcing HTTPS ensures web application traffic is encrypted with TLS, preventing eavesdropping or tampering over the network. Option E is correct because using TLS 1.2 for API communications encrypts data in transit between clients and services, providing confidentiality and integrity.

Option B is not correct because data classification labels identify sensitivity and guide handling but do not themselves encrypt or protect data in transit. Option D is not correct because AES-256 encryption at rest protects stored data, not data moving across a network.

Exam trap

The trap is mixing data-at-rest controls (AES-256) and governance controls (classification labels) with in-transit encryption; the exam tests whether you can distinguish the three data states.

277
MCQmedium

An API endpoint returns user profile details including email, phone, and address. The response includes fields that are not needed for the client application. Which OWASP API Security risk does this represent?

A.Mass Assignment
B.Broken Object Level Authorization
C.Excessive Data Exposure
D.Lack of Rate Limiting
AnswerC

The endpoint returns more fields than the client needs, so sensitive attributes like phone and address leak in the response body. Excessive Data Exposure describes relying on the client to filter data, rather than the API returning only the minimum necessary fields.

Why this answer

Excessive Data Exposure occurs when an API returns more data than the client needs, often relying on the client to filter sensitive fields. In this case, the API returns email, phone, and address even though the client application does not require them, exposing sensitive user information. This is a top OWASP API Security risk because it can lead to privacy breaches and data leakage.

Exam trap

CCSP often tests the confusion between Excessive Data Exposure and Mass Assignment, where candidates might think returning extra data is Mass Assignment, but Mass Assignment is about accepting extra data from the client, not returning it.

How to eliminate wrong answers

Option A is wrong because Mass Assignment refers to binding client-provided data to internal objects without proper filtering, allowing attackers to modify fields they shouldn't, not about returning excessive data. Option B is wrong because Broken Object Level Authorization (BOLA) involves accessing objects by manipulating identifiers (e.g., user IDs) without proper authorization checks, not about excessive data in responses. Option D is wrong because Lack of Rate Limiting concerns the absence of controls to prevent abuse via high request volumes, not about the amount of data returned in a single response.

278
MCQhard

A multinational corporation uses a hybrid cloud model with on-premises data centers and the AWS cloud. They have implemented a Cloud Access Security Broker (CASB) to enforce security policies. Recently, the security team noticed that users are accessing cloud applications from unusual geographic locations and downloading large volumes of data. The CASB logs show that the users authenticated using single sign-on (SSO) with valid credentials. The company has not enabled multi-factor authentication (MFA) for all users due to a previous pushback from the user community. The security team suspects a credential theft incident. What is the BEST course of action to mitigate the risk and respond to the potential incident?

A.Revoke the suspicious sessions and require all users to re-authenticate with MFA before granting access to cloud applications.
B.Ask the affected users to change their passwords and monitor their accounts for further suspicious activity.
C.Lock all user accounts and require the IT team to manually verify each user's identity before unlocking.
D.Disable SSO immediately and require users to authenticate directly with the cloud applications.
AnswerA

Revoking the active sessions terminates the attackers' authenticated access, and enforcing MFA on re-authentication blocks reuse of the stolen credentials, since SSO alone validated the anomalous logins. This directly addresses the credential theft vector the CASB logs revealed.

Why this answer

The best course of action is to immediately revoke the suspicious sessions and enforce MFA for all users before granting further access. This contains the potential breach by invalidating stolen credentials and adds a strong authentication factor to prevent unauthorized access. Since the CASB logs show valid SSO credentials, simply changing passwords may not be sufficient if the attacker has session tokens.

Exam trap

CCSP often tests the confusion between password reset and session revocation, leading candidates to choose password changes as sufficient when active sessions remain valid.

How to eliminate wrong answers

Option B is wrong because changing passwords alone does not invalidate active sessions or prevent session hijacking, and it lacks the immediate MFA enforcement needed to block further unauthorized access. Option C is wrong because locking all accounts is overly disruptive and does not address the root cause; it also doesn't require MFA for future access. Option D is wrong because disabling SSO entirely is a drastic measure that disrupts all users and doesn't directly mitigate the compromised credentials; it also doesn't enforce MFA.

279
MCQmedium

A financial services company is adopting a cloud-native microservices architecture. They want to ensure that only authorized services can communicate with each other, and that all inter-service communication is encrypted. Which of the following is the BEST approach?

A.Use network security groups to restrict traffic between service subnets
B.Implement a service mesh with mutual TLS (mTLS) and fine-grained access policies
C.Connect services using VPC peering and enable encryption in transit
D.Deploy an API gateway and route all internal traffic through it
AnswerB

A service mesh with mutual TLS authenticates both ends of every connection and encrypts traffic in transit, while fine-grained access policies enforce which services may call which. This satisfies the requirement for authorised, encrypted inter-service communication across the microservices architecture.

Why this answer

A service mesh with mutual TLS (mTLS) provides both encryption and identity-based authorization for inter-service communication. mTLS ensures that each service presents a valid certificate, proving its identity, and the mesh's control plane enforces fine-grained access policies (e.g., which services can call which endpoints). This directly meets the requirement for authorized, encrypted communication in a cloud-native microservices architecture.

Exam trap

A common misconception is that network-layer controls (like NSGs or VPC peering) are sufficient for service-to-service security, but the CCSP emphasizes that cloud-native architectures require identity-based authentication and encryption at the application or transport layer, which only a service mesh with mTLS provides.

How to eliminate wrong answers

Option A is wrong because network security groups (NSGs) operate at the network layer (IP/port) and cannot authenticate service identities or provide encryption; they only filter traffic based on source/destination IPs and ports, which is insufficient for service-level authorization in a dynamic microservices environment. Option C is wrong because VPC peering connects entire virtual networks and does not inherently enforce service-level authorization or mutual authentication; while encryption in transit can be enabled (e.g., IPsec), it lacks the fine-grained, identity-based access control that mTLS provides. Option D is wrong because an API gateway is designed for external traffic management and routing, not for internal service-to-service communication; routing all internal traffic through a single gateway creates a bottleneck, adds latency, and does not provide per-service mutual authentication or encryption at the transport layer.

280
MCQmedium

A company is using AWS CloudTrail to log API calls. A security analyst needs to be alerted when an IAM user creates a new access key for another user. Which CloudTrail event should be monitored?

A.CreateAccessKey
B.DeleteAccessKey
C.CreateUser
D.UpdateAccessKey
AnswerA

CreateAccessKey is the CloudTrail management event logged when an IAM user generates a new access key, including for another user. Monitoring this event name detects the exact activity described, since CloudTrail records the API call with its parameters and identity.

Why this answer

The correct event to monitor is 'CreateAccessKey' because this is the CloudTrail event name generated when an IAM user creates a new access key for another user. AWS CloudTrail logs all IAM API calls, and the event name directly corresponds to the API action invoked (CreateAccessKey). Monitoring this event allows the security analyst to detect unauthorized creation of access keys, which is a common privilege escalation or persistence technique.

Exam trap

ISC2 often tests the distinction between API actions that create versus modify versus delete resources, and the trap here is confusing 'CreateAccessKey' with 'UpdateAccessKey' because both involve access keys, but only 'CreateAccessKey' generates a new credential.

How to eliminate wrong answers

Option B (DeleteAccessKey) is wrong because it logs the deletion of an access key, not its creation, and would not alert on the described activity. Option C (CreateUser) is wrong because it logs the creation of a new IAM user, not the creation of an access key for an existing user. Option D (UpdateAccessKey) is wrong because it logs changes to an existing access key's status (e.g., Active/Inactive), not the creation of a new key.

281
MCQmedium

A company is migrating healthcare data to the cloud and must comply with HIPAA. They need to sign a Business Associate Agreement (BAA) with the CSP. What key element must be included in the BAA?

A.Data encryption requirements for data at rest and in transit
B.Audit log retention period for access to PHI
C.Breach notification timeframe to the covered entity
D.Permitted uses and disclosures of protected health information (PHI)
AnswerD

A BAA must specify the permitted uses and disclosures of protected health information, defining exactly how the CSP may handle PHI on the covered entity's behalf. This satisfies HIPAA's requirement that the agreement establish permissible processing boundaries before any healthcare data is migrated to the cloud.

Why this answer

Under HIPAA, the BAA must specify the permitted uses and disclosures of protected health information (PHI) by the business associate. This is the core contractual element that defines the scope of the CSP's handling of PHI and ensures the CSP only uses or discloses PHI as permitted by the covered entity and HIPAA. Without this, the BAA does not satisfy the HIPAA Privacy Rule requirements for business associate contracts.

Exam trap

CCSP often tests the confusion between the required BAA elements (permitted uses and disclosures) and related security details (encryption, audit retention, breach notification), so candidates pick a control instead of the contractual core element.

How to eliminate wrong answers

Option A is wrong because encryption requirements, while important, are implementation details that may be addressed in the BAA but are not the key required element defining the business associate's obligations. Option B is wrong because audit log retention is a security control detail, not the core BAA element required by HIPAA. Option C is wrong because breach notification timeframe is a required BAA provision under the HITECH Act, but the question asks for the key element defining the CSP's handling of PHI, which is permitted uses and disclosures.

282
MCQeasy

A cloud operations team has a process for making changes to production environments. Which change management practice is MOST important for reducing the risk of service disruption?

A.Allowing all changes to be made immediately with no approval process.
B.Testing all changes in a staging environment before production deployment.
C.Notifying the security team after the change is completed.
D.Ensuring a rollback plan is documented after the change is made.
AnswerB

Staging replicates production configuration, so functional, integration and regression faults surface before users are affected. This directly reduces the risk of service disruption named in the stem, because faulty changes are caught and remediated in a non-production environment rather than during a live deployment.

Why this answer

Testing all changes in a staging environment before production deployment is the most important practice because it validates the change's behavior, performance, and compatibility in an isolated replica of production. This directly reduces the risk of service disruption by catching configuration errors, resource conflicts, or software defects that could cause outages. Without staging validation, even well-intentioned changes can introduce silent failures or cascading issues.

Exam trap

ISC2 often tests the misconception that a documented rollback plan is sufficient to reduce risk, but the trap is that a rollback plan is reactive and cannot prevent the initial disruption, whereas staging testing proactively prevents the disruption from occurring in the first place.

How to eliminate wrong answers

Option A is wrong because allowing all changes to be made immediately with no approval process bypasses change advisory board (CAB) review and automated gating, leading to unvalidated modifications that frequently cause production incidents. Option C is wrong because notifying the security team after the change is completed provides no opportunity for pre-deployment security review or compensating controls, leaving vulnerabilities exploitable during the change window. Option D is wrong because ensuring a rollback plan is documented after the change is made defeats its purpose; a rollback plan must be prepared and tested before the change to be effective, as post-change documentation cannot reverse an ongoing disruption.

283
MCQeasy

In the shared responsibility model for public cloud, which of the following is typically the responsibility of the cloud customer when using IaaS?

A.Network firewall configuration at the hypervisor level
B.Physical security of data centers
C.Patch management of the guest operating system
D.Storage device maintenance
AnswerC

In IaaS the provider secures the physical hosts, network, and hypervisor, while the customer retains control of everything from the guest operating system upward. Patching that guest OS, including its installed software and security updates, therefore falls to the customer.

Why this answer

In the IaaS shared responsibility model, the cloud provider secures the physical infrastructure, hypervisor, and network fabric, while the customer is responsible for everything from the guest OS upward — including OS patching, middleware, runtime, applications, and data. Patch management of the guest operating system (C) is therefore squarely the customer's duty. This is a defining characteristic of IaaS versus PaaS or SaaS, where the provider assumes more of the stack.

Exam trap

CCSP often tests the boundary between provider and customer responsibilities; the trap is assuming the provider patches everything, when in IaaS the guest OS is explicitly the customer's job.

How to eliminate wrong answers

Option A is wrong because hypervisor-level network firewall configuration is part of the provider's virtualization and network infrastructure layer, not the customer's responsibility in IaaS. Option B is wrong because physical security of data centers is always the cloud provider's responsibility under every service model. Option D is wrong because storage device maintenance (hardware, firmware, disk replacement) is handled by the provider as part of the physical infrastructure layer.

284
MCQhard

A financial services company deploys a containerized application on Amazon ECS with Fargate. The application needs to access an encrypted RDS database. The security policy mandates that database credentials must never be stored in the application code or configuration files and must be rotated automatically every 90 days. Which solution should the DevOps team implement to satisfy these requirements?

A.Store credentials in AWS Secrets Manager, grant ECS task role access, and enable automatic rotation
B.Encrypt credentials with AWS KMS and pass them as environment variables during task definition
C.Store credentials in AWS Systems Manager Parameter Store (SecureString) and retrieve them at container startup
D.Use a secrets vault like Hashicorp Vault deployed on EC2 and mount secrets via sidecar container
AnswerA

Secrets Manager holds credentials outside code and configuration, the ECS task role grants access without static keys, and native rotation satisfies the 90-day mandate automatically. This meets both stated constraints: no embedded credentials and scheduled rotation.

Why this answer

AWS Secrets Manager is the correct choice because it is designed to securely store, retrieve, and automatically rotate database credentials on a schedule (e.g., every 90 days) without storing them in code or configuration. By granting the ECS task role (via IAM) permission to access the secret, the Fargate task can retrieve the credentials at runtime using the AWS SDK or CLI, ensuring they are never hardcoded. This satisfies both the no-storage-in-code and automatic rotation requirements mandated by the security policy.

Exam trap

ISC2 often tests the distinction between AWS Secrets Manager and Systems Manager Parameter Store, where candidates mistakenly choose Parameter Store because it is cheaper, but they overlook that Secrets Manager provides native automatic rotation for RDS credentials, which is explicitly required by the policy.

How to eliminate wrong answers

Option B is wrong because passing encrypted credentials as environment variables in the task definition still embeds them in the container's environment, which violates the policy of never storing credentials in code or configuration files, and it does not provide automatic rotation. Option C is wrong because AWS Systems Manager Parameter Store (SecureString) can store encrypted secrets but does not natively support automatic rotation of RDS database credentials; it requires custom Lambda functions or additional services to implement rotation, making it less suitable for the 90-day rotation requirement. Option D is wrong because deploying Hashicorp Vault on EC2 adds operational overhead, requires managing the EC2 instances and Vault cluster, and does not integrate natively with ECS Fargate's task role for seamless credential retrieval; it also does not automatically rotate RDS credentials without additional configuration.

285
MCQhard

A cloud customer is negotiating a contract and wants to ensure they have the right to verify the cloud provider's security controls. Which contractual provision is most important?

A.Data portability clause
B.Data deletion clause
C.Right to audit clause
D.Service Level Agreement (SLA) for uptime
AnswerC

A right to audit clause contractually grants the customer the ability to verify the provider's security controls, whether directly or via an independent assessor. This directly satisfies the stated requirement to secure verification rights during contract negotiation.

Why this answer

The right to audit clause is a contractual provision that grants the cloud customer the ability to verify the provider's security controls, either through direct audits or by accepting third-party audit reports. It is essential for ensuring compliance and trust in the cloud provider's security posture.

Exam trap

The trap is confusing the right to audit with other contractual clauses like SLAs or data portability; candidates may pick SLA because it sounds like it ensures performance, but it does not cover security verification.

How to eliminate wrong answers

Option A is wrong because data portability clauses address the ability to move data, not verify security controls. Option B is wrong because data deletion clauses specify how data is destroyed at contract termination, not security verification. Option D is wrong because an SLA for uptime guarantees availability, not security control effectiveness.

286
MCQmedium

A cloud operations team manages 200 Amazon EC2 instances spread across three AWS accounts. They must continuously assess the instances for missing OS patches and misconfigured software, and they want findings aggregated in a single console with severity ratings and remediation runbooks. Which AWS service should the team deploy to meet these requirements?

A.AWS Trusted Advisor
B.AWS Config
C.Amazon GuardDuty
D.Amazon Inspector
AnswerD

Amazon Inspector continuously scans EC2 instances using the Systems Manager agent to detect software vulnerabilities and unintended network exposure, then assigns severity ratings and aggregates findings centrally across accounts via AWS Organizations and delegated administrator. This directly matches the requirement for ongoing OS patch and misconfiguration assessment with consolidated findings and remediation guidance.

Why this answer

Continuous detection of missing OS patches and software misconfigurations inside EC2 instances requires a vulnerability management service with host-level visibility. Amazon Inspector uses the SSM agent to inventory packages and network reachability, assigns severity, and supports multi-account aggregation through a delegated administrator, so findings from all three accounts appear in one console with remediation runbooks.

Exam trap

The trap here is assuming configuration-compliance services such as AWS Config or Trusted Advisor can see inside the guest operating system, when only a host-based vulnerability scanner like Amazon Inspector inventories installed packages and patches.

287
MCQeasy

A team is adopting DevSecOps. Which practice best integrates security into the development lifecycle?

A.Security awareness training
B.Annual penetration testing
C.Automated security testing in CI/CD pipeline
D.Manual code review before release
AnswerC

Embedding automated security testing into the CI/CD pipeline shifts detection left, so vulnerabilities and misconfigurations are caught at build time rather than after deployment. This continuous, tool-driven gate is what actually integrates security into the development lifecycle, satisfying the DevSecOps adoption requirement in the stem.

Why this answer

Automated security testing in the CI/CD pipeline (Option C) is the correct practice because it embeds security checks—such as static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA)—directly into the build and deployment process. This ensures that vulnerabilities are detected and remediated early, aligning with the DevSecOps principle of 'shifting left' and enabling continuous security validation without slowing down development velocity.

Exam trap

ISC2 often tests the misconception that manual or periodic security activities (like annual pen tests or pre-release code reviews) are sufficient for DevSecOps, when the core requirement is continuous, automated security integration within the CI/CD pipeline itself.

How to eliminate wrong answers

Option A is wrong because security awareness training, while important for culture, is a people-focused activity that does not integrate automated, code-level security checks into the development lifecycle; it lacks the technical enforcement needed for continuous security in CI/CD. Option B is wrong because annual penetration testing is a point-in-time, manual assessment that occurs long after code is deployed, failing to provide the continuous, automated feedback required in a DevSecOps pipeline to catch vulnerabilities during development. Option D is wrong because manual code review before release is a gate-based, human-dependent process that introduces delays and inconsistency, and it does not scale or integrate with automated CI/CD workflows, whereas DevSecOps demands automated, frequent security validation.

288
MCQeasy

Which cloud-specific vulnerability involves an attacker making a server-side request to the cloud metadata endpoint (e.g., 169.254.169.254) to retrieve temporary credentials?

A.Server-Side Request Forgery (SSRF)
B.Cross-Site Scripting (XSS)
C.Broken Object Level Authorization (BOLA)
D.SQL Injection
AnswerA

SSRF lets an attacker induce the server to request the link-local metadata endpoint 169.254.169.254, which returns instance-role temporary credentials. This cloud-specific vulnerability satisfies the stem precisely: the metadata service is reachable only from the instance, so the server becomes the credential-theft proxy.

Why this answer

Server-Side Request Forgery (SSRF) is a vulnerability where an attacker can manipulate a server to make HTTP requests to arbitrary destinations, including the cloud metadata endpoint at 169.254.169.254. By exploiting SSRF, an attacker can retrieve temporary credentials associated with the instance's IAM role, leading to cloud account compromise. This is a cloud-specific risk because the metadata endpoint is unique to cloud environments and is a common target for SSRF attacks.

Exam trap

CCSP often tests the misconception that SSRF is only about accessing internal web servers, but in cloud environments, the metadata endpoint is the most critical target because it can yield credentials.

How to eliminate wrong answers

Option B is wrong because Cross-Site Scripting (XSS) is a client-side vulnerability that executes scripts in a victim's browser, not a server-side request to a metadata endpoint. Option C is wrong because Broken Object Level Authorization (BOLA) involves accessing objects by manipulating identifiers without proper authorization checks, not making server-side requests to internal endpoints. Option D is wrong because SQL Injection targets database queries, not HTTP requests to metadata services.

289
MCQeasy

Which hypervisor technology is used to provide direct device access to a VM, improving performance and isolation for I/O operations?

A.IOMMU
B.CPU pinning
C.Virtual switches
D.Memory ballooning
AnswerA

IOMMU (Input-Output Memory Management Unit) maps device DMA requests to guest physical addresses, letting a VM access hardware directly while confining each device to its assigned memory region. This delivers near-native I/O performance and enforces isolation between guests, satisfying the stem's requirement for direct device access.

Why this answer

IOMMU (Input-Output Memory Management Unit) provides direct device access to a VM by translating device DMA addresses through the hypervisor's memory mapping, enabling safe passthrough of physical devices. This improves I/O performance and maintains isolation by preventing devices from accessing memory outside their assigned VM. It is the hardware feature that underpins secure device assignment.

Exam trap

The trap is confusing CPU or memory optimization features with I/O isolation — candidates must recognize IOMMU as the hardware mechanism specifically enabling safe direct device access.

How to eliminate wrong answers

Option B is wrong because CPU pinning binds vCPUs to physical cores to reduce scheduling overhead; it does not provide direct device access or I/O isolation. Option C is wrong because virtual switches handle network traffic between VMs and external networks, not direct device passthrough for I/O. Option D is wrong because memory ballooning reclaims unused guest memory to optimize host memory usage and has no role in device access or I/O isolation.

290
Multi-Selectmedium

Which TWO of the following are best practices for monitoring a cloud environment to detect security incidents?

Select 2 answers
A.Centralize logs from all cloud services into a single analytics platform.
B.Set up automated alerts based on defined thresholds for key security metrics.
C.Enable all available log sources to ensure complete visibility.
D.Monitor only network flow logs to reduce data volume.
E.Conduct manual log reviews on a weekly basis to identify anomalies.
AnswersA, B

Centralization allows correlation across services for better detection.

Why this answer

Centralizing logs from all cloud services into a single analytics platform (e.g., SIEM like Splunk or AWS Security Hub) enables correlation across disparate data sources, which is essential for detecting multi-vector attacks. This practice aligns with the NIST SP 800-92 log management guidelines and the CCSP domain of Cloud Security Operations, as it provides a unified view for threat detection and incident response.

Exam trap

ISC2 often tests the misconception that 'more logs are always better' (Option C) or that manual reviews are sufficient, when in reality, automated correlation and threshold-based alerting are required for effective incident detection in cloud environments.

291
Multi-Selectmedium

Which TWO of the following are considered best practices for securing containerized applications in a cloud environment?

Select 2 answers
A.Run containers with a non-root user.
B.Enable SSH inside the container for remote administration.
C.Use the 'latest' tag for base images to get the newest features.
D.Include debugging tools inside the container for troubleshooting.
E.Use a read-only filesystem for the container.
AnswersA, E

Running containers as a non-root user removes the default root privileges inside the container namespace, so a compromised process cannot escalate to host-level actions or write to protected paths. This directly reduces the blast radius of container breakout, satisfying the best-practice requirement for securing containerised cloud workloads.

Why this answer

Option A is correct because running containers with a non-root user (via the USER directive in the Dockerfile or runAsNonRoot/runAsUser in a Kubernetes securityContext) enforces least privilege, so a container breakout or compromised process cannot gain root-level access to the host or mounted resources. Option E is correct because mounting the container's root filesystem as read-only (docker run --read-only or readOnlyRootFilesystem: true in Kubernetes) prevents attackers from modifying binaries, writing malware, or persisting changes, and any needed writable paths can be explicitly mounted as tmpfs or volumes. Option B is not a best practice: enabling SSH inside a container increases the attack surface, bloats the image, and contradicts the immutable, single-process container model; administration should use docker exec, kubectl exec, or orchestration APIs instead.

Option C is wrong because the 'latest' tag is mutable and non-deterministic, breaking reproducibility and potentially pulling in unvetted or vulnerable base images; images should be pinned to specific immutable digests or version tags. Option D is also wrong because bundling debugging tools enlarges the attack surface and image size; troubleshooting should be done with ephemeral debug containers or sidecars rather than shipping tools in production images.

Exam trap

ISC2 often tests the misconception that SSH or debugging tools are necessary for container management, when in fact they violate the immutable and ephemeral principles of container security; the trap is that candidates confuse traditional server administration with cloud-native container operations.

292
MCQmedium

A company uses a Cloud Access Security Broker (CASB) to enforce security policies on SaaS applications. They want to ensure that data uploaded to a file-sharing service does not contain Social Security numbers (SSNs). Which CASB capability is most effective?

A.Contextual access control
B.Inline DLP scanning
C.API-based data discovery
D.Encryption of data in transit
AnswerB

Inline DLP scanning inspects data in transit as it moves to the SaaS service, blocking or alerting on uploads containing Social Security numbers before they leave the organisation's control. This satisfies the stem's requirement to prevent SSNs reaching the file-sharing service.

Why this answer

Inline DLP scanning is the most effective CASB capability for preventing data containing Social Security numbers from being uploaded to a file-sharing service because it inspects the content of files in real time as they are being uploaded. The CASB acts as a proxy, intercepting the HTTP/HTTPS traffic, parsing the file payload, and applying pattern-matching algorithms (e.g., regex for SSN format) to block the upload before it reaches the SaaS application. This proactive, real-time enforcement is essential for data loss prevention (DLP) at the point of upload.

Exam trap

The trap here is that candidates often confuse API-based data discovery (which is excellent for identifying sensitive data at rest) with inline DLP scanning (which is required for real-time prevention), leading them to choose Option C even though it cannot block the upload in progress.

How to eliminate wrong answers

Option A is wrong because contextual access control focuses on who, when, and from where access is attempted (e.g., location, device posture), not on inspecting the content of uploaded files for sensitive data like SSNs. Option C is wrong because API-based data discovery scans data already stored in the SaaS application via its API, which is reactive and cannot prevent the initial upload of SSNs; it can only detect them after the fact. Option D is wrong because encryption of data in transit (e.g., TLS 1.2/1.3) protects data from eavesdropping during transmission but does not inspect or block the content of the data being uploaded.

293
MCQeasy

A retail company is migrating its monolithic e-commerce application to containers on a managed Kubernetes service. The security architect wants to ensure that if a container is compromised, the attacker cannot use the container's credentials to access the underlying node's filesystem or other pods' volumes. Which Kubernetes feature should be configured to meet this requirement?

A.Role-Based Access Control (RBAC) to limit service account permissions
B.NetworkPolicy to restrict pod-to-pod traffic
C.Pod Security Admission with the restricted profile
D.Runtime sandboxing with gVisor or Kata Containers
AnswerD

Runtime sandboxing such as gVisor or Kata Containers provides a stronger isolation boundary between the container and the host kernel or node. gVisor intercepts syscalls in user space, while Kata runs containers in lightweight VMs. Both reduce the ability of a compromised container to access the node filesystem or other pods' volumes, directly meeting the isolation requirement.

Why this answer

The requirement is strong runtime isolation so a compromised container cannot reach the node or other pods' data. Runtime sandboxing with gVisor or Kata Containers creates a boundary beyond standard Linux namespaces and cgroups. Pod Security Admission, NetworkPolicy, and RBAC are valuable but address configuration hardening, network traffic, and API authorization respectively, not filesystem and volume isolation from the host.

Exam trap

The trap here is confusing network or API authorization controls with runtime isolation of the container from the host and other workloads.

294
MCQmedium

A healthcare organization stores protected health information (PHI) in a cloud environment. Under HIPAA, what must the organization obtain from the cloud provider before processing PHI?

A.A Data Processing Agreement (DPA) under GDPR
B.A Business Associate Agreement (BAA)
C.A Service Organization Control (SOC) 2 report
D.An ISO 27001 certification
AnswerB

A BAA is mandatory under HIPAA before a covered entity may disclose PHI to a cloud provider, which acts as a business associate. It contractually binds the provider to safeguard PHI, satisfying the stem's requirement to obtain an agreement prior to processing.

Why this answer

Under HIPAA, a covered entity must obtain a Business Associate Agreement (BAA) from any cloud provider that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. The BAA establishes the permitted uses and disclosures of PHI and requires the business associate to implement safeguards.

Exam trap

The trap is confusing GDPR's DPA with HIPAA's BAA; candidates may think any data processing agreement suffices, but HIPAA specifically requires a BAA for PHI.

How to eliminate wrong answers

Option A is wrong because a DPA under GDPR is for EU personal data, not HIPAA PHI; while a DPA may be needed for GDPR compliance, it does not satisfy HIPAA. Option C is wrong because a SOC 2 report is an audit report that provides assurance but is not a contractual requirement under HIPAA. Option D is wrong because ISO 27001 certification is a voluntary security standard, not a HIPAA requirement.

295
MCQeasy

Which of the following is a key practice for secure management of cloud credentials in application code?

A.Hardcode credentials in environment variables
B.Use IAM roles or managed identities
C.Store credentials in source code comments
D.Encrypt credentials with a static key in the codebase
AnswerB

IAM roles and managed identities issue short-lived, automatically rotated credentials to workloads, eliminating hard-coded secrets in application code. This satisfies secure credential management by removing static keys that could be leaked, committed to repositories, or exfiltrated.

Why this answer

Using IAM roles or managed identities eliminates the need to embed long-term credentials in application code. This approach relies on temporary, automatically rotated credentials obtained via the cloud provider's metadata service (e.g., AWS IMDSv2, Azure Instance Metadata Service), which significantly reduces the risk of credential leakage and simplifies credential management.

Exam trap

A common misconception is that environment variables are a secure alternative to hardcoding, but they are still plaintext and can be exposed through process listings, container orchestration tools, or misconfigured logging.

How to eliminate wrong answers

Option A is wrong because hardcoding credentials in environment variables still exposes them in plaintext within the environment, and they can be leaked through logs, debugging output, or container image layers. Option C is wrong because storing credentials in source code comments is a severe security risk, as comments are often included in version control and can be read by anyone with repository access. Option D is wrong because encrypting credentials with a static key in the codebase is fundamentally flawed; the static key itself must be stored somewhere, creating a circular security problem where the key is as vulnerable as the credentials it protects.

296
MCQeasy

A cloud security engineer needs to review who created or modified IAM policies in an Azure subscription over the past 90 days, and must retain that evidence for compliance. Which Azure-native capability should be used to collect and store these records?

A.Microsoft Defender for Cloud secure score
B.Azure Activity Log with a diagnostic setting to a Log Analytics workspace
C.Azure Policy compliance reports
D.Azure Monitor metrics
AnswerB

The Azure Activity Log records subscription-level control-plane operations including role assignment and policy changes, with the caller identity and timestamp. Routing it through a diagnostic setting to a Log Analytics workspace enables long-term retention and querying, satisfying the 90-day review and compliance retention needs.

Why this answer

The Azure Activity Log is the subscription's control-plane audit record and captures write operations such as role assignment and policy edits along with the calling identity. Exporting it via a diagnostic setting to a Log Analytics workspace provides queryable, retainable evidence, which is exactly what is needed to review IAM changes over 90 days.

Exam trap

The trap here is assuming that posture or compliance tooling like secure score or Azure Policy provides an audit trail of who made a change.

297
MCQmedium

An organization wants to protect its cloud storage data from ransomware attacks that might encrypt or delete objects. The security team decides to enable a feature that maintains previous versions of objects when changes are made. Which feature is being described?

A.Object versioning
B.Access control lists
C.Cross-region replication
D.Bucket locking
AnswerA

Object versioning retains prior copies of each object whenever it is overwritten or deleted, so ransomware encryption or deletion produces a new version while the original remains recoverable. This directly satisfies the requirement to maintain previous versions of objects, enabling restoration without paying a ransom.

Why this answer

Object versioning is the feature that retains previous versions of objects when they are overwritten or deleted, allowing recovery from accidental or malicious changes such as ransomware encryption. When versioning is enabled, each PUT creates a new version, and the previous version remains accessible, so encrypted or deleted objects can be restored.

Exam trap

CCSP often tests the difference between versioning (retains history) and object lock (prevents deletion) — candidates may pick bucket locking thinking it maintains versions, but it actually enforces immutability without keeping older versions.

How to eliminate wrong answers

Option B is wrong because ACLs control access permissions on buckets and objects, not version retention — they do not protect against data modification or deletion. Option C is wrong because cross-region replication copies objects to another region for durability and compliance, but it does not maintain previous versions unless versioning is also enabled, and it does not by itself protect against ransomware overwriting the source. Option D is wrong because bucket locking (S3 Object Lock) prevents object deletion or overwriting for a specified retention period, but it does not maintain previous versions — it enforces immutability, which is a different mechanism.

298
MCQmedium

An organization uses infrastructure as code (IaC) to deploy cloud resources. The security team wants to prevent misconfigurations such as open security groups from being deployed. Which two practices should be integrated into the IaC pipeline? (Select TWO)

A.Limit access to the cloud management console
B.Perform manual code reviews for every change
C.Segment the network using security groups
D.Implement policy-as-code to enforce security rules
E.Use automated security scanning tools for IaC templates
AnswerD, E

Policy-as-code encodes security rules, such as prohibiting open security groups, as machine-enforceable policies evaluated during the pipeline. This blocks non-compliant templates before deployment, satisfying the requirement to prevent misconfigurations rather than detect them after resources are provisioned.

Why this answer

Policy-as-code (D) allows security rules to be defined in a machine-readable format (e.g., using Open Policy Agent or HashiCorp Sentinel) and automatically evaluated during the IaC pipeline, preventing non-compliant configurations from being deployed. Automated security scanning tools (E) analyze IaC templates (e.g., Terraform, CloudFormation) for known misconfigurations, such as overly permissive security group rules, before they reach production. Together, these practices enforce security guardrails early in the development lifecycle.

Exam trap

ISC2 often tests the distinction between operational controls (like manual reviews or console access) and automated pipeline controls (like policy-as-code and scanning), expecting candidates to recognize that only automated, integrated checks can prevent misconfigurations at the code level before deployment.

How to eliminate wrong answers

Option A is wrong because limiting access to the cloud management console is an administrative control that does not prevent misconfigurations in IaC templates; it only restricts who can manually make changes after deployment. Option B is wrong because manual code reviews are slow, error-prone, and cannot scale to catch all misconfigurations, especially in large IaC codebases; automated checks are required for consistent enforcement. Option C is wrong because segmenting the network using security groups is a network architecture practice, not a pipeline integration; it does not prevent misconfigurations in the IaC templates themselves.

299
MCQhard

An attacker publishes a malicious package to a public registry using the same name as an internal package used by a cloud application. This is known as:

A.Cross-site scripting (XSS)
B.Man-in-the-middle attack
C.Dependency confusion attack
D.Supply chain poisoning
AnswerC

Dependency confusion exploits package managers that check public registries before private ones, letting an attacker register a higher-versioned public package matching an internal name. The build resolves the malicious public package, executing attacker code within the pipeline.

Why this answer

Dependency confusion attacks exploit package managers that prioritize public registries over private ones, allowing malicious packages to be installed.

300
Multi-Selectmedium

A cloud service provider wants to demonstrate compliance with ISO/IEC 27017 for cloud services. Which TWO controls are specific additions that this standard introduces beyond ISO/IEC 27002? (Choose two.)

Select 2 answers
A.A mandate that all cloud personnel hold a Certified Cloud Security Professional (CCSP) certification.
B.A requirement to publish real-time security incident dashboards to all customers.
C.Guidance on shared roles and responsibilities between cloud service customers and cloud service providers.
D.Requirements for the removal or return of cloud service customer assets upon contract termination.
E.Mandatory encryption of all data at rest using AES-256 or an equivalent algorithm.
AnswersC, D

ISO/IEC 27017 explicitly addresses the division of security responsibilities between cloud service customers and providers. This guidance clarifies who handles which controls in the shared responsibility model, reducing ambiguity. It is one of the cloud-specific additions not found in the base ISO/IEC 27002 control set.

Why this answer

ISO/IEC 27017 extends ISO/IEC 27002 with cloud-specific implementation guidance, notably clarifying shared roles and responsibilities between customers and providers, and addressing the return or removal of customer assets at service termination. These additions target the unique risks of cloud arrangements rather than imposing technology mandates or certification requirements.

Exam trap

The trap here is assuming ISO/IEC 27017 mandates specific technologies or certifications, when it actually adds cloud-specific guidance and controls.

Page 3

Page 4 of 13

Page 5