Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 301–375

934 questions total · 13pages · All types, answers revealed

Page 4

Page 5 of 13

Page 6
301
MCQhard

A cloud application uses a managed API gateway to expose REST APIs. The security team wants to ensure that clients cannot bypass the gateway and call backend services directly. The backend services run on private subnets and are fronted by an internal load balancer. Which control should be implemented to enforce this requirement?

A.Enable TLS mutual authentication between the API gateway and backend services
B.Use API keys validated at the API gateway only
C.Configure the backend services to accept traffic only from the API gateway's security group or service account
D.Deploy a web application firewall (WAF) on the backend services
AnswerC

Restricting backend ingress to the API gateway's identity ensures that only the gateway can forward requests. This can be done with security groups, network ACLs, or IAM-based authentication depending on the cloud provider. It directly prevents clients from bypassing the gateway, because direct calls from other sources are denied at the network or identity layer.

Why this answer

The only way to prevent clients from bypassing the API gateway is to restrict backend ingress to the gateway's identity. This can be enforced through security groups, network policies, or IAM roles. mTLS, WAFs, and gateway-only API key validation add security but do not block direct network access, so they cannot guarantee that all traffic flows through the gateway.

Exam trap

The trap here is assuming that mTLS or API keys at the gateway prevent bypass, when network-level or identity-level restrictions on the backend are required.

302
MCQeasy

A cloud security administrator is configuring access to a cloud storage bucket that contains regulated data. The administrator needs to ensure that data is encrypted at rest using keys that are automatically rotated every 90 days. Which cloud service feature should the administrator use?

A.Client-side encryption with a locally stored key.
B.Server-side encryption with customer-provided keys (SSE-C).
C.Server-side encryption with customer-managed keys in a cloud KMS.
D.Server-side encryption with provider-managed keys (SSE-S3 or equivalent).
AnswerC

Customer-managed keys in a cloud KMS allow the administrator to configure automatic rotation with a custom schedule, such as every 90 days. This meets the requirement for controlled rotation. The administrator retains control over the key lifecycle while benefiting from server-side encryption.

Why this answer

Customer-managed keys in a cloud KMS enable automatic rotation with a configurable schedule, satisfying the 90-day requirement. Provider-managed keys rotate automatically but without customer control over the interval. Client-side and customer-provided keys require manual rotation.

Thus, the KMS option is the correct choice.

Exam trap

The trap here is assuming that provider-managed keys allow custom rotation schedules, when in fact the rotation interval is controlled by the provider and not configurable.

303
MCQeasy

A cloud administrator notices that a storage bucket containing sensitive data is publicly accessible. What is the most likely misconfiguration?

A.The bucket has logging disabled.
B.The bucket's ACLs are too permissive.
C.The bucket is using server-side encryption.
D.The bucket is versioned.
AnswerB

Bucket ACLs grant permissions directly to individual grantees, so an overly permissive ACL exposes objects to AllUsers or AuthenticatedUsers regardless of bucket policy. This directly explains the public accessibility observed, making the ACL the likely misconfiguration.

Why this answer

The most likely misconfiguration is that the bucket's ACLs are too permissive, granting public read or write access to the storage bucket. In cloud platforms like AWS S3 or Azure Blob Storage, bucket ACLs or bucket policies can be set to allow public access, which directly exposes sensitive data. Disabling logging, using server-side encryption, or enabling versioning do not inherently make a bucket publicly accessible.

Exam trap

ISC2 often tests the misconception that security features like encryption or logging directly prevent unauthorized access, when in fact access control misconfigurations (like permissive ACLs) are the root cause of public exposure.

How to eliminate wrong answers

Option A is wrong because disabling logging only affects audit trails and does not control access permissions; a bucket can be publicly accessible even with logging enabled. Option C is wrong because server-side encryption protects data at rest but does not affect access control; a publicly accessible bucket with encryption still exposes data to anyone who can read it. Option D is wrong because versioning creates multiple object versions but does not change the bucket's access policy; a publicly accessible bucket remains public regardless of versioning status.

304
MCQhard

During a cloud incident response, a security team needs to collect memory from a compromised EC2 instance for forensic analysis. Which method is most appropriate for acquiring a memory dump?

A.Analyze CloudTrail logs for the instance's API calls.
B.Take a snapshot of the EBS volumes attached to the instance.
C.Review VPC Flow Logs for network traffic.
D.Use AWS Systems Manager to run a memory acquisition script on the instance.
AnswerD

AWS Systems Manager Run Command executes a memory acquisition script directly on the running EC2 instance, preserving volatile memory contents. This avoids rebooting or stopping the instance, which would destroy the RAM evidence needed for forensic analysis.

Why this answer

Memory acquisition on a running EC2 instance requires executing a tool on the instance itself, and AWS Systems Manager (SSM) Run Command allows the security team to run a memory acquisition script remotely without SSH access or opening inbound ports. This preserves the volatile memory contents while maintaining an auditable, IAM-controlled execution path. It is the most appropriate method for capturing RAM from a live instance.

Exam trap

CCSP often tests cloud forensic order of volatility, and candidates may pick EBS snapshots or logs because they are familiar AWS artifacts — the trap is forgetting that memory is volatile and cannot be captured from disk or API logs.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs record API activity, not the contents of instance memory, and cannot reconstruct process memory or encryption keys. Option B is wrong because an EBS snapshot captures disk state, not volatile memory, and would miss in-memory malware, credentials, and network connections. Option C is wrong because VPC Flow Logs capture metadata about network flows (IPs, ports, bytes), not memory contents or process-level artifacts.

305
MCQeasy

Which of the following is a primary purpose of a SOAR (Security Orchestration, Automation and Response) platform in cloud security operations?

A.To automate response to security incidents by executing predefined playbooks.
B.To provide a centralized dashboard for cloud cost management.
C.To scan container images for vulnerabilities.
D.To enforce identity and access management policies.
AnswerA

SOAR platforms integrate security tools and execute predefined playbooks automatically, triggering containment, enrichment and notification actions when alerts fire. This orchestration and automation directly satisfies the stem's requirement to accelerate incident response beyond manual analyst triage.

Why this answer

SOAR platforms are designed to orchestrate security tools, automate repetitive response tasks, and execute predefined playbooks that coordinate actions across multiple systems during an incident. This reduces mean time to respond (MTTR) and enables consistent, repeatable incident handling. The primary purpose is automation of incident response workflows, not cost management, vulnerability scanning, or IAM enforcement.

Exam trap

CCSP often tests whether candidates confuse SOAR with other security tools — the trap is picking a tool that performs a specific function (scanning, IAM) rather than the orchestration and automation of response workflows.

How to eliminate wrong answers

Option B is wrong because cloud cost management is handled by FinOps tools or cloud provider cost explorers, not SOAR platforms — SOAR focuses on security operations, not financial operations. Option C is wrong because scanning container images for vulnerabilities is a function of vulnerability scanners (e.g., Trivy, Clair, Anchore) or CSPM tools, not SOAR — SOAR may consume scanner findings but does not perform the scanning itself. Option D is wrong because enforcing IAM policies is the role of identity providers and IAM systems (e.g., Okta, Azure AD, AWS IAM), not SOAR — SOAR may integrate with IAM for response actions like disabling a user, but it does not enforce policies.

306
MCQhard

A cloud security architect is designing a CI/CD pipeline for a containerized application. The requirement is that container images be cryptographically signed by the build system and that only images with valid signatures be admitted to the production Kubernetes cluster. Which combination of controls best achieves this?

A.Store images in a private registry and restrict registry access using IAM policies.
B.Scan images for vulnerabilities during the build and block the pipeline if critical findings are detected.
C.Sign images with a key managed by the build system and enforce signature verification with an admission controller that rejects unsigned images.
D.Enable image layer caching in the build system to speed up builds and reduce exposure to tampering.
AnswerC

Cryptographic signing by the build system establishes provenance, and an admission controller that verifies signatures before allowing pod creation enforces the policy at deploy time. Together they ensure only trusted images run in production, satisfying both the signing and admission requirements.

Why this answer

Meeting the requirement needs two complementary controls: cryptographic signing at build time to prove provenance, and admission-time verification to reject unsigned or tampered images. Scanning, registry access controls, and caching address different concerns and cannot enforce signature validity when pods are scheduled.

Exam trap

The trap here is treating vulnerability scanning or private registry access as equivalent to image signing and admission verification, when none of those establishes or checks cryptographic provenance.

307
Multi-Selectmedium

A company is adopting a hybrid cloud strategy. Which TWO security considerations are most critical for maintaining a consistent security posture across environments? (Choose two.)

Select 2 answers
A.Establishing consistent network security policies (e.g., firewall rules)
B.Relying solely on perimeter security
C.Deploying separate security teams for each environment
D.Implementing identity federation for single sign-on
E.Using different encryption keys for each environment
AnswersA, D

Hybrid cloud spans on-premises and provider networks, so inconsistent firewall rules create gaps between environments. Uniform network security policies enforce one traffic-filtering baseline across both sides, directly satisfying the stem's demand for a consistent security posture.

Why this answer

Option A is correct because consistent network security policies such as firewall rules, security groups, and ACLs ensure that traffic controls are enforced uniformly across on-premises and cloud environments, preventing gaps that attackers could exploit when workloads span both. Option D is correct because identity federation for single sign-on (e.g., SAML 2.0 or OIDC with a central IdP like Entra ID or Okta) provides a unified authentication and authorization model, so users and services have consistent identities and access rights regardless of environment. Option B is incorrect because relying solely on perimeter security fails in hybrid cloud, where assets sit outside a single network boundary and zero-trust, defense-in-depth controls are required.

Option C is incorrect because separate security teams per environment create inconsistent policies, duplicated effort, and coordination gaps rather than a unified posture. Option E is incorrect because using different encryption keys per environment is not inherently a consistency requirement; key management should follow a unified governance model (e.g., centralized KMS/HSM with proper key rotation and separation), not simply differ by environment.

Exam trap

CCSP often tests the misconception that perimeter security or environment-specific teams/keys provide consistency, when in fact hybrid cloud consistency hinges on unified policy and federated identity.

308
MCQhard

A cloud customer is subject to the EU General Data Protection Regulation (GDPR) and uses a cloud provider that subcontracts data processing to a third party without notification. Which GDPR requirement is violated?

A.Data protection by design
B.Data breach notification
C.Sub-processor authorization
D.Right to erasure
AnswerC

GDPR Article 28 requires the controller to authorise sub-processors and be notified of intended changes, so a provider engaging a third party without notification breaches the sub-processor authorisation requirement, regardless of security or breach-notification controls.

Why this answer

GDPR requires that data controllers obtain prior authorization before a processor engages a sub-processor. The customer (controller) was not notified, violating the requirement for sub-processor authorization. Other rights like erasure are unrelated to this scenario.

309
MCQmedium

A company needs to ensure that its cloud-stored data is retained only for a specific period due to legal requirements. Which process should be automated?

A.Data lifecycle management
B.Data classification
C.Data encryption
D.Data backup
AnswerA

Data lifecycle management automates retention by applying policies that expire or delete objects once the legal retention period ends. This directly enforces the specified retention duration, unlike backup, classification or encryption, which address availability, sensitivity and confidentiality rather than time-bound disposal.

Why this answer

Data lifecycle management (DLM) focuses on managing data throughout its lifecycle, including retention and deletion. Data classification categorizes data, encryption protects it, and backup creates copies, but none directly automate retention periods.

310
MCQmedium

A media company runs a video-transcoding workload on a public cloud IaaS platform. The workload is stateless, tolerant of interruption, and must complete within a 6-hour window at the lowest possible compute cost. The company's architects propose using a cloud service that provisions spare capacity at a significant discount but can reclaim it with a two-minute notice. Which cloud deployment and service model does this describe?

A.Reserved instances within a community cloud
B.Dedicated hosts within a private cloud
C.Spot instances within a public cloud
D.On-demand instances within a hybrid cloud
AnswerC

Spot instances (also called spot VMs or preemptible VMs) let a consumer bid on a provider's unused capacity at steep discounts, and the provider can reclaim that capacity with short notice, often around two minutes. Stateless, interruption-tolerant batch work such as video transcoding is the canonical fit, and the reclaimed capacity directly explains the lowest-cost requirement in this scenario.

Why this answer

The workload is stateless, tolerant of interruption, and cost-sensitive, which maps precisely to spare-capacity compute sold at a discount with short-notice reclamation. Committed-term reservations, physically isolated hosts, and full-price on-demand capacity all fail at least one stated constraint, either cost, availability guarantees, or the eviction behavior the architects are designing around.

Exam trap

The trap here is assuming any discounted compute purchase is equivalent, when only spare-capacity instances carry the provider-initiated reclamation with short notice that this workload is built to tolerate.

311
Multi-Selecthard

A global enterprise is designing a cloud storage architecture with cross-region replication for disaster recovery. They must ensure that data replicated to a secondary region is encrypted with keys managed by the customer, and that those keys are stored in the secondary region's key management service (KMS). Which THREE capabilities must be enabled?

Select 3 answers
A.Default encryption with provider keys
B.Client-side encryption before upload
C.Permission for the replication service to use the secondary region's key
D.Cross-region replication
E.Customer-managed encryption keys in the secondary region
AnswersC, D, E

Replication must be granted explicit permission to encrypt with the customer-managed key held in the secondary region's KMS; without that authorisation, cross-region writes fail because the destination key cannot be used. This satisfies the stem's constraint that replicated data be encrypted under customer-managed keys stored in the secondary region.

Why this answer

Option D (Cross-region replication) is required because the scenario explicitly demands that data be replicated to a secondary region for disaster recovery, which is the core mechanism that copies objects across regions. Option E (Customer-managed encryption keys in the secondary region) is correct because the requirement states the replicated data must be encrypted with customer-managed keys that reside in the secondary region's KMS, satisfying the customer-controlled key mandate. Option C (Permission for the replication service to use the secondary region's key) is correct because the replication service must be authorized to encrypt the replicated objects with that secondary-region customer-managed key; without the appropriate KMS key policy/grant, replication would fail to apply the required encryption.

Option A (Default encryption with provider keys) does not belong because provider-managed keys do not meet the customer-managed key requirement. Option B (Client-side encryption before upload) does not belong because client-side encryption is performed before the data reaches the storage service and would not use the secondary region's KMS-managed customer keys as specified.

Exam trap

The trap is selecting default encryption or client-side encryption as sufficient; candidates must recognize that customer-managed keys in the secondary region require explicit permissions and cross-region replication configuration, not just any encryption method.

312
MCQmedium

A cloud security team is implementing data loss prevention (DLP) for sensitive data in a cloud data warehouse. They need to detect and classify Social Security numbers (SSNs) stored in tables. Which cloud service capability is most appropriate for this task?

A.Object storage bucket policies
B.Cloud DLP API
C.Key management service
D.Identity and access management (IAM)
AnswerB

Cloud DLP API inspects and classifies data at rest, using built-in infoType detectors to identify SSN patterns within warehouse tables, satisfying the requirement to detect and classify stored sensitive data. Unlike encryption or access controls, it performs content-level discovery, matching the stem's classification constraint directly.

Why this answer

Cloud DLP API is purpose-built to discover, classify, and de-identify sensitive data such as SSNs, credit card numbers, and PHI across storage and data warehouses using built-in and custom infoType detectors. It can scan BigQuery tables, Cloud Storage, and Datastore directly, making it the correct tool for detecting and classifying SSNs in a cloud data warehouse. The other options are access-control or key-management services that do not perform content inspection.

Exam trap

CCSP often tests whether candidates confuse access control with data classification — the trap is picking IAM or bucket policies because they sound like 'security controls,' when the question specifically asks about detecting and classifying sensitive content.

How to eliminate wrong answers

Option A is wrong because object storage bucket policies are IAM-style access controls that govern who can read/write objects — they do not inspect content or classify data types like SSNs. Option C is wrong because a key management service handles cryptographic key lifecycle (generation, rotation, destruction) and has no data-classification capability. Option D is wrong because IAM controls authentication and authorization (who can do what) and does not scan or classify data content.

313
Multi-Selecthard

A cloud customer is assessing the risk of using a cloud provider. Which THREE factors are most important in evaluating the inherent risk of migrating data and applications to the cloud?

Select 3 answers
A.Data leaving the customer's direct control and being stored on shared infrastructure
B.Dependence on the provider's security controls and the risk of a provider-side breach affecting multiple tenants
C.The provider's compliance certifications (e.g., ISO 27001, SOC 2)
D.The shared responsibility model and potential for misconfiguration by the customer
E.The provider's physical security controls at data centers
AnswersA, B, D

Data leaving direct control removes the customer's ability to enforce physical and logical safeguards, while shared infrastructure introduces multi-tenancy risks such as side-channel exposure and noisy-neighbour contention. These are inherent to cloud migration, satisfying the stem's focus on risks arising from the provider's model rather than contractual or operational controls.

Why this answer

Option A is correct because migrating to the cloud inherently means data leaves the customer's direct physical and logical control and resides on multi-tenant shared infrastructure, which is a fundamental source of inherent risk regardless of any controls the provider implements. Option B is correct because the customer becomes dependent on the provider's security controls, and a provider-side breach or compromise can affect multiple tenants simultaneously, creating concentration and supply-chain risk that the customer cannot fully mitigate alone. Option D is correct because the shared responsibility model defines which security duties remain with the customer, and customer-side misconfiguration (for example, an exposed S3 bucket or overly permissive IAM role) is a leading cause of cloud incidents, making it a core inherent risk factor.

Option C is not selected because compliance certifications are assurance artifacts that help evaluate the provider's control environment rather than inherent risk factors of the migration itself. Option E is not selected because the provider's physical data center security is a control the provider manages and is largely inherited by the customer, so it is not one of the most important inherent risk factors in this assessment.

Exam trap

The trap is selecting provider certifications or physical security as 'inherent risk' factors; candidates must distinguish inherent risks (introduced by the cloud model) from mitigating controls or assurances that reduce risk.

314
MCQmedium

A cloud architect is documenting the essential characteristics that distinguish a cloud service from traditional hosting for an internal design review. The architect must list the characteristics defined in the widely used cloud reference architecture. Which of the following is one of those essential characteristics?

A.Guaranteed data residency in a single jurisdiction
B.Perpetual license ownership of the provider's software
C.Rapid elasticity and measured service
D.Mandatory single-tenancy of every physical host
AnswerC

Rapid elasticity describes capabilities that appear unlimited and can be scaled out and back in quickly, while measured service means resource usage is monitored, controlled, and reported transparently to both provider and consumer. Both appear in the standard set of essential cloud characteristics. They distinguish cloud from fixed hosting because capacity flexes with demand and consumption is metered for billing and governance.

Why this answer

The essential characteristics describe on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service. Rapid elasticity and measured service together capture how capacity flexes with demand and how consumption is metered and reported, which are definitional traits. Residency guarantees, single-tenancy mandates, and perpetual licensing are commercial or deployment choices, not defining cloud characteristics.

Exam trap

The trap here is mixing commercial terms such as residency guarantees or perpetual licensing into the architectural definition of what makes a service cloud.

315
MCQhard

A company uses a cloud-based SIEM to aggregate logs from multiple sources. Recently, the SIEM stopped receiving logs from a critical application server. The server is running and the application is functioning normally. The security team has verified that the log forwarder service is running on the server and the network path to the SIEM is open. Which additional step should the team take to diagnose the issue?

A.Check the server's CPU and memory utilization.
B.Review the firewall rules between the server and the SIEM.
C.Restart the SIEM collector service.
D.Inspect the log forwarder's configuration and recent log files for errors.
AnswerD

With the service running and network path verified, the remaining likely cause is a misconfigured or failing forwarder. Inspecting its configuration and recent log files reveals errors such as changed credentials, wrong destination, or buffer failures.

Why this answer

The most likely cause of logs not being received by the SIEM, when the server is running and the network path is open, is a misconfiguration or error within the log forwarder itself. Inspecting the forwarder's configuration (e.g., destination IP, port, protocol) and its local log files (e.g., syslog, Windows Event Forwarding logs) can reveal authentication failures, queue overflows, or parsing errors that prevent log transmission. This step directly addresses the log generation and forwarding pipeline, which is the remaining point of failure after verifying network connectivity and service status.

Exam trap

ISC2 often tests the misconception that network-level checks (firewall, connectivity) are sufficient, when the real issue is often an application-layer misconfiguration within the log forwarder itself, which candidates overlook because they assume a 'running' service is correctly configured.

How to eliminate wrong answers

Option A is wrong because CPU and memory utilization on the application server would not prevent a properly configured and running log forwarder from sending logs; high resource usage might cause delays but not a complete cessation of log forwarding, and the server is functioning normally. Option B is wrong because the security team has already verified that the network path to the SIEM is open, which implicitly includes firewall rules; reviewing them again would be redundant and not address the log forwarder's internal state. Option C is wrong because restarting the SIEM collector service on the cloud-based SIEM side would not fix a problem originating from the log forwarder's configuration or errors; the collector is receiving logs from other sources, indicating it is operational.

316
Multi-Selecteasy

Which TWO best practices help secure a cloud application's runtime environment?

Select 2 answers
A.Use immutable infrastructure
B.Implement host-based intrusion detection
C.Run applications with least privilege
D.Enable automatic patching of dependencies
E.Use container orchestration platform
AnswersA, C

Immutable infrastructure replaces running instances rather than patching them in place, so configuration drift and persistent compromise are eliminated on each deployment. This satisfies the runtime security requirement by ensuring every instance starts from a known, verified image.

Why this answer

Option A (Use immutable infrastructure) is correct because replacing rather than modifying running instances eliminates configuration drift and prevents attackers from persisting changes on a compromised host, since any tampering is discarded when the instance is rebuilt from a known-good image. Option C (Run applications with least privilege) is correct because granting each process, service account, and container only the minimum permissions it needs limits the blast radius of a compromise and blocks privilege-escalation paths within the runtime environment. Option B (host-based intrusion detection) is a detective control that can complement runtime security but does not itself harden or secure the environment, and it is often impractical in ephemeral cloud workloads.

Option D (automatic patching of dependencies) addresses vulnerability management in the build/supply chain rather than securing the runtime environment itself, and blind auto-patching can introduce instability. Option E (container orchestration platform) is a deployment technology, not a security best practice, and using it without proper configuration can actually widen the attack surface.

Exam trap

ISC2 often tests the distinction between security controls that are preventive (like immutable infrastructure and least privilege) versus detective or reactive controls (like HIDS), leading candidates to mistakenly select host-based intrusion detection as a runtime security best practice.

317
MCQhard

A cloud application uses a service mesh for inter-service communication. The security team wants to enforce mutual TLS (mTLS) between all services and ensure that service identities are verified. What is the most effective way to achieve this?

A.Set up Kerberos authentication between services
B.Configure a VPN between all service subnets
C.Implement IPsec in the network layer
D.Use the service mesh's built-in mTLS and certificate management
AnswerD

The service mesh's built-in mTLS issues and rotates workload certificates, authenticating service identities via SPIFFE-style identities without application code changes. This satisfies the stem's requirement to enforce mutual TLS and verify service identities across all inter-service communication automatically.

Why this answer

The service mesh's built-in mTLS and certificate management is the most effective approach because it provides automatic, transparent mutual TLS encryption and identity verification at the application layer, using X.509 certificates issued by the mesh's certificate authority (e.g., Istio's Citadel or Linkerd's identity controller). This ensures that every inter-service communication is authenticated and encrypted without requiring changes to application code, and it integrates directly with the service mesh's identity model (e.g., Kubernetes service accounts).

Exam trap

ISC2 often tests the misconception that network-layer encryption (IPsec or VPN) is sufficient for service-to-service authentication, but the key requirement here is per-service identity verification at the application layer, which only a service mesh's mTLS with certificate management can provide.

How to eliminate wrong answers

Option A is wrong because Kerberos is a network authentication protocol that requires a centralized Key Distribution Center (KDC) and is not designed for per-request mTLS in a service mesh; it adds complexity and does not provide transport-layer encryption natively. Option B is wrong because a VPN encrypts traffic at the network layer between subnets but does not provide per-service identity verification or mutual authentication at the application layer, and it cannot enforce mTLS between individual services within the same subnet. Option C is wrong because IPsec operates at the network layer (Layer 3) and can encrypt traffic between hosts or subnets, but it lacks the granularity to verify individual service identities and does not integrate with service mesh certificate management for dynamic, short-lived certificates.

318
MCQeasy

A healthcare organization is migrating patient data to a public cloud. Which legal framework most directly governs the protection of this data?

A.Health Insurance Portability and Accountability Act (HIPAA)
B.Payment Card Industry Data Security Standard (PCI DSS)
C.Sarbanes-Oxley Act (SOX)
D.General Data Protection Regulation (GDPR)
AnswerA

HIPAA directly regulates protected health information held by covered entities and their business associates, imposing privacy, security and breach-notification duties. It therefore governs this patient-data migration, unlike broader frameworks such as GDPR or PCI DSS that address different data categories.

Why this answer

HIPAA applies to protected health information (PHI) in the US, making it the most directly relevant legal framework for healthcare data. GDPR is broader but less specific to US healthcare, and PCI DSS is for payment card data.

319
MCQmedium

A cloud security team is implementing data loss prevention for a data lake that stores customer support logs. They need to redact credit card numbers from the logs before they are used for analytics. Which DLP de-identification technique should be applied?

A.Date shifting
B.Bucketing
C.Masking
D.Tokenization
AnswerC

Masking replaces detected credit card values with a placeholder character, such as a hash or asterisk, so the sensitive digits are irreversibly removed from the log records while the surrounding analytics fields remain intact and queryable.

Why this answer

Masking is the correct DLP de-identification technique because it replaces sensitive values like credit card numbers with obfuscated characters (e.g., ****-****-****-1234) while preserving the format and length of the original data. This allows the support logs to remain usable for analytics and pattern matching without exposing the actual PAN data. Masking is irreversible or partially reversible depending on configuration, making it ideal for redaction before analytics processing.

Exam trap

CCSP often tests the distinction between reversible pseudonymization (tokenization) and irreversible anonymization (masking) — candidates incorrectly choose tokenization because it sounds more 'secure,' but the question specifically asks for redaction of the number itself.

How to eliminate wrong answers

Option A is wrong because date shifting only alters date/timestamp values by a consistent offset to preserve temporal relationships for analytics, and does nothing to redact credit card numbers. Option B is wrong because bucketing groups values into ranges (e.g., age brackets) to generalize data, which would destroy the credit card number format and is not a redaction technique. Option D is wrong because tokenization replaces sensitive data with a surrogate token that maps back to the original value via a token vault — it preserves referential integrity but does not redact the number from view, and the token itself may still be considered sensitive.

320
Multi-Selecteasy

Which TWO of the following are best practices for cloud key management?

Select 2 answers
A.Use separate keys for different tenants or applications.
B.Hard-code encryption keys in application source code for simplicity.
C.Store keys in the same geographic region as the data for low latency.
D.Rotate encryption keys on a regular schedule.
E.Use a single master key for all encryption operations.
AnswersA, D

Correct. Isolation reduces impact of a key compromise.

Why this answer

Option A is correct because using separate keys for different tenants or applications enforces cryptographic isolation, so a compromise or misuse of one key cannot decrypt another tenant's or application's data and it keeps blast radius and access policies scoped per workload. Option D is correct because regularly rotating encryption keys limits the amount of data protected by any single key version, reduces the impact of an undetected key compromise, and is a standard requirement in frameworks such as NIST SP 800-57 and PCI DSS; cloud KMS services like AWS KMS, Azure Key Vault, and Google Cloud KMS support automatic rotation. Option B is wrong because hard-coding keys in source code exposes them to anyone with repository access and prevents secure rotation, violating the principle of keeping keys out of application code.

Option C is wrong because key storage should be chosen based on security, compliance, and data-residency requirements, not merely latency; keys can be used cross-region through KMS endpoints, and co-locating keys with data is not itself a best practice. Option E is wrong because a single master key for all encryption operations creates a single point of failure and maximizes the impact of compromise, contradicting the key-separation and least-privilege principles.

Exam trap

CCSP often tests the misconception that a single master key simplifies management and is acceptable, when in fact key separation and rotation are non-negotiable best practices for limiting blast radius and meeting compliance.

321
MCQhard

A financial services company stores regulated data in a cloud object storage bucket and uses a cloud key management service (KMS) with customer-managed keys. An auditor asks how the company ensures that data remains protected if a malicious insider with KMS administrator rights attempts to export key material. Which KMS capability should the security team describe?

A.The KMS uses hardware security modules that are validated to FIPS 140-2 or FIPS 140-3 and are configured to prevent key material from being exported in plaintext.
B.The KMS automatically rotates customer-managed keys every 90 days, which limits the usefulness of any exported key material.
C.The KMS logs all key usage to an immutable audit trail, so any export attempt by an insider would be detected after the fact.
D.The KMS enforces multi-factor authentication for all administrative actions, which prevents an insider from exporting key material.
AnswerA

HSM-backed KMS implementations are designed so that key material never leaves the HSM in plaintext, even for administrators. FIPS validation provides assurance that the cryptographic module enforces this boundary. This directly answers the auditor's concern about an insider exporting keys, because administrative rights do not translate into the ability to extract raw key bytes.

Why this answer

HSM-backed KMS with FIPS validation is the correct capability because these modules are designed to keep key material inside the hardware boundary and prevent plaintext export, even by administrators. MFA, audit logging, and rotation are useful controls but do not stop an insider from extracting usable key material through legitimate administrative interfaces.

Exam trap

The trap here is confusing detective or access controls such as logging and MFA with the preventive guarantee that key material cannot be exported from a validated HSM.

322
MCQhard

Refer to the exhibit. A security analyst reviews this CloudTrail log entry. What is the most immediate concern?

A.A user named john.doe is not authorized to modify security groups.
B.An EC2 instance was launched without approval.
C.A security group rule was added that allows unrestricted SSH access.
D.The user john.doe failed to authenticate.
AnswerC

The log records an AuthorizeSecurityGroupIngress action opening port 22 to 0.0.0.0/0, exposing SSH on the instance to the entire internet. That unrestricted inbound rule is the immediate risk, enabling brute-force or exploitation attempts from any source.

Why this answer

The CloudTrail log entry shows an AuthorizeSecurityGroupIngress API call that added a rule allowing SSH (port 22) from source 0.0.0.0/0, which grants unrestricted internet access. This is a critical security misconfiguration that exposes the EC2 instance to potential brute-force attacks or unauthorized access, making it the most immediate concern.

Exam trap

ISC2 often tests the distinction between an authorization failure (IAM policy deny) and a successful but dangerous action; the trap here is that candidates see the user name and assume a permission error, but the log shows the action succeeded, making the unrestricted SSH rule the real risk.

How to eliminate wrong answers

Option A is wrong because the log entry shows the API call was successful ("eventType": "AwsApiCall", no error code), indicating john.doe was authorized to modify security groups at the time of the event. Option B is wrong because the log entry records an AuthorizeSecurityGroupIngress action, not a RunInstances action; no EC2 instance was launched in this event. Option D is wrong because the log entry shows a successful API call with "userIdentity" details and no authentication failure (no "errorCode" or "errorMessage" fields indicating a failure), so john.doe authenticated successfully.

323
Multi-Selectmedium

A cloud security architect is implementing a CI/CD pipeline for a containerized application on AWS. Which TWO practices should be integrated to enforce container image security?

Select 2 answers
A.Implement runtime application self-protection (RASP)
B.Scan container images for vulnerabilities before push to registry
C.Use a cloud WAF to protect the containerized application
D.Sign container images to ensure integrity
E.Run SAST on the application source code
AnswersB, D

Scanning images before pushing to the registry blocks vulnerable artefacts from ever entering the pipeline, satisfying the shift-left constraint. Vulnerabilities are detected at build time, so compromised layers never reach Amazon ECR or production. This pre-push gate enforces image security earlier than post-registry scanning, which only detects flaws after distribution.

Why this answer

Option B is correct because scanning container images for vulnerabilities before pushing them to the registry (e.g., using Amazon ECR image scanning, Clair, or Trivy) catches known CVEs in OS packages and application dependencies at build time, preventing vulnerable images from ever entering the pipeline. Option D is correct because signing container images (e.g., with Docker Content Trust/Notary or Sigstore Cosign) and verifying signatures at deploy time ensures image integrity and provenance, blocking tampered or unauthorized images from running. Option A is not appropriate here because RASP protects a running application from attacks at runtime and does not secure the image build/supply chain.

Option C is not appropriate because a cloud WAF filters HTTP/S traffic to the application and does not inspect or validate container images. Option E is not appropriate because SAST analyzes source code for flaws, not the built container image and its layers.

Exam trap

ISC2 often tests the distinction between pipeline-time security controls (like scanning and signing) and runtime or perimeter controls (like RASP and WAF), leading candidates to mistakenly select runtime defenses for a CI/CD enforcement question.

324
MCQhard

A cloud customer is evaluating a provider's service level agreement (SLA) that guarantees 99.99% availability. What is the maximum allowable downtime per year (in minutes) before the SLA is violated?

A.8.76 hours
B.52.56 minutes
C.5.26 minutes
D.87.6 hours
AnswerB

A 99.99% availability guarantee permits 0.01% annual downtime. Applied to 525,600 minutes per year, that equals 52.56 minutes, the exact threshold the SLA specifies. Any outage exceeding this figure breaches the agreement, making it the maximum allowable downtime the stem requests.

Why this answer

An SLA of 99.99% availability allows 0.01% downtime per year. A year has 365 days × 24 hours × 60 minutes = 525,600 minutes. 0.01% of 525,600 is 52.56 minutes, so the maximum allowable downtime is 52.56 minutes per year. This is the correct calculation.

Exam trap

CCSP often tests the conversion between availability percentages and actual downtime, and candidates may confuse the number of nines (e.g., 99.9% vs 99.99%) or miscompute the minutes per year.

How to eliminate wrong answers

Option A is wrong because 8.76 hours corresponds to 99.9% availability (0.1% downtime), not 99.99%. Option C is wrong because 5.26 minutes corresponds to 99.999% availability (0.001% downtime). Option D is wrong because 87.6 hours corresponds to 99% availability (1% downtime).

325
MCQhard

A cloud application uses an API that allows users to view other users' profile details by changing the user ID in the request. Which vulnerability is this?

A.Mass assignment
B.Broken authentication
C.Broken object level authorization (BOLA)
D.Excessive data exposure
AnswerC

BOLA arises when the API validates that a user is authenticated but omits an ownership check on the requested object. Substituting another user's ID in the request succeeds because authorisation is enforced at the endpoint level, not per object.

Why this answer

Broken Object Level Authorization (BOLA) occurs when an API fails to verify that the requesting user is authorized to access the specific object (e.g., user profile) referenced in the request. In this case, changing the user ID in the request allows viewing other users' profiles because the API does not check if the authenticated user has permission to access that particular user's data. This is a classic example of BOLA, listed as API1:2019 in the OWASP API Security Top 10.

Exam trap

CCSP often tests the distinction between authentication (verifying identity) and authorization (verifying permissions), and candidates may confuse BOLA with broken authentication or excessive data exposure because all involve improper access to data.

How to eliminate wrong answers

Option A is wrong because mass assignment involves automatically binding client-provided data to internal object properties, allowing attackers to modify fields they shouldn't (e.g., setting 'isAdmin': true), not accessing other users' objects. Option B is wrong because broken authentication refers to flaws in authentication mechanisms (e.g., weak passwords, improper session management) that allow attackers to impersonate users, not to authorization checks after authentication. Option D is wrong because excessive data exposure occurs when an API returns more data than necessary (e.g., including sensitive fields in responses), but here the issue is accessing unauthorized objects, not data filtering.

326
MCQhard

A security team is investigating a potential data exfiltration incident where a large volume of data was downloaded from a cloud storage bucket. Which log source would provide the most granular details about the GET requests, including the requester identity and source IP?

A.VPC flow logs
B.Cloud storage access logs
C.Cloud management events (e.g., CloudTrail equivalent)
D.Log aggregation service for storage (e.g., CloudWatch equivalent)
AnswerB

Cloud storage access logs capture per-request records for object operations, including the GET method, requester identity, source IP address and timestamp. This granular detail satisfies the requirement to identify who downloaded the data and from where during the exfiltration investigation.

Why this answer

Cloud storage access logs provide detailed records of requests made to a bucket, including requester, source IP, and objects accessed. Cloud audit logs (data events) can also log storage operations, but storage access logs are more granular for this purpose.

327
MCQhard

A government agency is comparing cloud providers and must prove to auditors that its workloads will remain available and recoverable during a regional provider outage. The agency wants an objective, contractual commitment about the percentage of time a service will be operational, plus a documented financial remedy if the provider misses that target. Which provider artifact should the agency rely on FIRST?

A.The provider's service level agreement
B.The provider's architecture whitepaper
C.The provider's independent audit report
D.The provider's disaster recovery test summary
AnswerA

A service level agreement states the measurable service levels the provider commits to, such as a monthly uptime percentage, and defines the remedies, typically service credits, when those levels are missed. It is the contractual artifact that turns an availability expectation into an enforceable commitment. Auditors can examine the stated targets and the remedy terms directly, which is exactly what the agency needs.

Why this answer

The agency needs a measurable availability commitment plus a defined remedy, and that is precisely what a service level agreement provides. It sets the uptime percentage, the measurement window, exclusions, and the service credits owed when targets are missed. Audit reports, disaster recovery test summaries, and architecture whitepapers are useful evidence about controls and design, but none of them creates an enforceable service commitment with compensation terms.

Exam trap

The trap here is equating a favorable audit report or architecture document with a contractual availability guarantee, when only the service level agreement sets measurable targets and remedies.

328
MCQmedium

A company has deployed a mission-critical application in the cloud and needs to ensure that it remains available even if an entire cloud region fails. Which architecture pattern should they adopt?

A.Regular backups to a different region
B.Active-passive across regions
C.Vertical scaling within a single region
D.Horizontal scaling within a single availability zone
AnswerB

Active-passive replicates to another region for failover.

Why this answer

(active-passive across regions) is correct because this architecture ensures that if an entire cloud region fails, the passive standby in another region can take over, providing disaster recovery and high availability. Option A (regular backups to a different region) provides data recovery but not immediate failover or service continuity. Option C (vertical scaling within a single region) increases capacity but does not protect against region failure.

Option D (horizontal scaling within a single availability zone) improves scalability within a zone but does not address region-level outages.

329
MCQmedium

A financial institution uses a cloud data warehouse to store transaction data. The data is classified into three tiers: public, internal, and confidential. The current architecture stores all data in a single dataset with column-level encryption for confidential fields. A recent internal penetration test revealed that an analyst with access to the data warehouse could query aggregated statistics that inadvertently revealed confidential individual transactions. The security team needs to implement a solution that prevents such data leakage while preserving analytical capabilities. Which solution BEST addresses this?

A.Deploy a differential privacy framework that adds noise to query results.
B.Implement row-level security to restrict each analyst to only view data related to their assigned region.
C.Use dynamic data masking to obscure confidential fields based on the user's clearance.
D.Encrypt the entire dataset with a key that is only available to a privileged group.
AnswerA

Differential privacy injects calibrated statistical noise into query outputs, so aggregated results no longer disclose individual transactions. This directly closes the inference path the penetration test exploited while still permitting analytical queries, satisfying the requirement to preserve analytics.

Why this answer

Differential privacy is the correct solution because it directly addresses the core issue: aggregated statistics can be reverse-engineered to infer individual records. By adding calibrated noise to query results, it ensures that the output of any query does not reveal whether a specific individual's data is present, thus preventing leakage from aggregate queries while still allowing analysts to derive meaningful trends and patterns.

Exam trap

ISC2 often tests the distinction between access control mechanisms (row-level security, masking, encryption) and privacy-preserving techniques (differential privacy), trapping candidates who confuse restricting direct data access with preventing inference from aggregated outputs.

How to eliminate wrong answers

Option B is wrong because row-level security restricts access based on region, but it does not prevent an analyst from querying aggregated statistics that could reveal confidential individual transactions within their allowed region. Option C is wrong because dynamic data masking obscures fields at the column level, but it does not protect against inference attacks on aggregated results; an analyst could still compute sums or averages that leak individual values. Option D is wrong because encrypting the entire dataset with a key available only to a privileged group would block all analysts from querying the data, destroying analytical capabilities entirely, which is not the goal.

330
MCQmedium

A development team is building a cloud-native application that stores user session data in a managed Redis service. The security architect requires that session data be encrypted at rest and that the application authenticate to Redis without embedding static credentials in code. Which approach best meets these requirements?

A.Rely on network isolation and Redis AUTH with a long-lived password rotated quarterly
B.Enable encryption at rest and store the Redis password in an environment variable
C.Enable encryption at rest on the Redis service and use IAM authentication with short-lived tokens
D.Use client-side encryption before writing to Redis and authenticate with a shared secret stored in a configuration file
AnswerC

Managed Redis services often support encryption at rest and IAM-based authentication, which issues temporary credentials tied to the workload's identity. This eliminates static passwords in code and satisfies both encryption and credential management requirements. It aligns with cloud security best practices for secretless authentication and data protection.

Why this answer

The best approach combines native encryption at rest with IAM authentication using short-lived tokens. This removes static credentials from code and leverages the cloud provider's identity system. Storing passwords in environment variables, configuration files, or using long-lived shared secrets all violate the requirement to avoid static credentials, even if encryption at rest is enabled.

Exam trap

The trap here is thinking that environment variables or configuration files are secure places for credentials, when they are still static secrets that can leak.

331
MCQeasy

Which cloud service model allows customers to manage only their data and user access, while the provider manages everything else including the infrastructure, operating system, and applications?

A.SaaS
B.IaaS
C.CaaS
D.PaaS
AnswerA

SaaS delivers a complete provider-managed application stack, so the customer manages only its data and user access while the provider handles infrastructure, operating system and application. This exactly satisfies the stem's stated division of responsibility.

Why this answer

SaaS (Software as a Service) is the cloud service model where the provider manages the entire stack — infrastructure, operating system, runtime, middleware, and the application itself — leaving the customer responsible only for their data and user access management. Examples include Microsoft 365, Salesforce, and Google Workspace, where the customer configures users and manages data but never touches the underlying platform.

Exam trap

CCSP often tests the boundary between SaaS and PaaS by emphasizing who manages the application — in SaaS the provider manages the app, while in PaaS the customer deploys their own app on a managed platform.

How to eliminate wrong answers

Option B is wrong because IaaS (Infrastructure as a Service) gives the customer control over the operating system, storage, and deployed applications, with the provider managing only the virtualization and physical infrastructure — the customer manages far more than just data and user access. Option C is wrong because CaaS (Containers as a Service) provides a container orchestration platform where the customer still manages container images, orchestration configuration, and often the runtime — not just data and user access. Option D is wrong because PaaS (Platform as a Service) provides a managed runtime and development platform, but the customer still manages their application code, configuration, and sometimes middleware — more than just data and user access.

332
MCQhard

A cloud security team is reviewing a CI/CD pipeline that builds and deploys a containerized application to a production cluster. The pipeline runs in a cloud build service and uses a long-lived service account key stored as a secret in the pipeline configuration to push images and update deployments. A recent audit flagged this as a risk. Which change best reduces the risk of credential compromise while maintaining automated deployments?

A.Grant the service account broader permissions so that fewer distinct credentials are needed across pipeline stages.
B.Rotate the service account key on a weekly schedule and store the new key in the same pipeline secret store.
C.Replace the long-lived key with short-lived credentials obtained through workload identity federation between the build service and the cloud provider.
D.Encrypt the service account key with a customer-managed key and restrict access to the pipeline configuration to a small group of administrators.
AnswerC

Workload identity federation lets the build service exchange its own identity for short-lived cloud credentials, eliminating stored long-lived keys. If a credential is compromised, it expires quickly and is scoped to the build workload. This reduces the blast radius of credential theft while preserving automated deployments, directly addressing the audit finding.

Why this answer

Storing long-lived service account keys in a pipeline creates a persistent credential that attackers can steal and reuse. Workload identity federation replaces that key with short-lived tokens bound to the build service's identity, so credentials expire automatically and are scoped to the workload. This maintains automation while removing the stored secret, which is the most effective way to reduce credential compromise risk.

Exam trap

The trap here is assuming that encrypting or rotating a long-lived key fixes the risk, when the fundamental problem is the existence of a persistent credential that can be stolen.

333
MCQmedium

A company uses a hybrid cloud model where sensitive data resides in a private cloud, while compute-intensive analytics run in a public cloud using anonymized data. What is the primary security consideration for this architecture?

A.Using the same hypervisor in both clouds
B.Implementing network segmentation only in the public cloud
C.Maintaining consistent security policies and secure connectivity between environments
D.Ensuring the public cloud provider has SOC 2 certification
AnswerC

Sensitive data stays private while anonymised analytics run publicly, so the split architecture's core risk is drift between the two domains. Consistent security policies plus secure connectivity (VPN or dedicated link) prevent the public environment becoming a weaker path into private data, satisfying the hybrid model's boundary constraint.

Why this answer

In hybrid cloud, consistent security policies must apply across both environments, and secure connectivity (e.g., VPN or dedicated connection) is essential to protect data in transit and prevent leakage.

334
MCQeasy

A cloud security architect is designing a multi-tenant environment on a hypervisor. Which hypervisor type provides the most robust isolation between tenant virtual machines by running directly on the hardware without a host operating system?

A.Type 2 hosted hypervisor (e.g., VirtualBox)
B.Paravirtualized hypervisor (e.g., Xen)
C.Container runtime (e.g., Docker)
D.Type 1 bare-metal hypervisor (e.g., VMware ESXi)
AnswerD

A Type 1 hypervisor runs directly on bare metal, so each tenant VM's isolation boundary is enforced by the hypervisor kernel itself rather than a general-purpose host OS. That removes the host operating system's larger attack surface, satisfying the requirement for the most robust isolation between tenants.

Why this answer

A Type 1 bare-metal hypervisor (e.g., VMware ESXi) runs directly on the hardware without an underlying host operating system, providing the most robust isolation between tenant VMs. This architecture reduces the attack surface and ensures that each VM is isolated from others and from the hypervisor management layer.

Exam trap

The trap here is assuming that paravirtualized hypervisors provide the most isolation; candidates might think Xen is more secure because it is often used in cloud environments, but the question emphasizes 'without a host operating system,' which points to Type 1 bare-metal hypervisors like ESXi.

How to eliminate wrong answers

Option A is wrong because a Type 2 hosted hypervisor runs on top of a host OS, which introduces additional overhead and potential security vulnerabilities, reducing isolation. Option B is wrong because paravirtualized hypervisors like Xen can be Type 1, but the question specifies 'without a host operating system' and Xen can run in both modes; however, the most robust isolation is typically associated with Type 1 bare-metal hypervisors like ESXi, and Xen's paravirtualization requires modified guests, which may not provide the same level of isolation as full hardware virtualization. Option C is wrong because container runtimes like Docker share the host OS kernel, providing less isolation than hypervisors.

335
MCQmedium

A company using a SaaS application for HR management receives a data subject access request (DSAR) under GDPR from an employee. The cloud provider is the data processor. The company as data controller must respond within what timeframe?

A.One month
B.90 days
C.45 days
D.72 hours
AnswerA

Under GDPR Article 12(3), the controller must respond to a data subject access request without undue delay and in any event within one month of receipt, extendable by two further months for complex requests. The processor's role does not alter this controller deadline.

Why this answer

Under GDPR Article 12(3), the data controller must respond to a data subject access request (DSAR) without undue delay and in any event within one month of receipt of the request. This one-month period can be extended by two further months for complex requests, but the baseline deadline is one month. The cloud provider as processor must assist the controller, but the controller bears the legal obligation to respond within that timeframe.

Exam trap

CCSP often tests the confusion between GDPR timelines: 72 hours for breach notification, one month for DSAR response, and other jurisdictions' deadlines like 45 or 90 days; candidates must distinguish the specific obligation.

How to eliminate wrong answers

Option B is wrong because 90 days is not a GDPR DSAR deadline; it resembles other regulatory timelines (e.g., some US state privacy laws) but does not apply here. Option C is wrong because 45 days is also not a GDPR deadline; it is used in some other privacy frameworks (e.g., certain US state laws) but not GDPR. Option D is wrong because 72 hours is the GDPR deadline for notifying a supervisory authority of a personal data breach under Article 33, not for responding to a DSAR.

336
MCQmedium

An organization is implementing a cloud SIEM solution to centralize security monitoring across multiple AWS accounts. Which service should be used to aggregate security findings and send them to a third-party SIEM like Splunk?

A.AWS CloudTrail
B.AWS Security Hub
C.AWS GuardDuty
D.AWS Config
AnswerB

AWS Security Hub aggregates findings across accounts and Regions via a single pane, then forwards them to third-party SIEMs such as Splunk through native integrations or EventBridge. This satisfies the requirement to centralise findings from multiple AWS accounts before onward delivery.

Why this answer

AWS Security Hub is the correct service because it is designed to aggregate security findings from multiple AWS services (e.g., GuardDuty, Inspector, Macie) and AWS accounts, and then forward them to third-party SIEM solutions like Splunk via AWS EventBridge or direct integration. This centralizes security alerts into a single dashboard and stream, enabling efficient monitoring across a multi-account environment.

Exam trap

CCSP often tests the distinction between services that generate findings (like GuardDuty) versus services that aggregate and normalize findings (like Security Hub), leading candidates to pick GuardDuty because they confuse detection with centralization.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity logs, not security findings, and it does not aggregate findings across accounts or natively forward to a SIEM. Option C is wrong because AWS GuardDuty is a threat detection service that generates findings, but it cannot aggregate findings from multiple accounts or services; it relies on Security Hub for centralization. Option D is wrong because AWS Config tracks resource configuration changes and compliance, not security findings, and it lacks the aggregation and SIEM forwarding capabilities of Security Hub.

337
Multi-Selecthard

A cloud security architect is designing a data retention and deletion strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a combination of object storage, block storage, and a managed database. Regulatory requirements mandate that data be irrecoverably deleted upon customer request. Which TWO of the following measures are MOST effective to ensure secure data disposal in the cloud? (Choose two.)

Select 2 answers
A.Rely on the cloud provider's media sanitization processes when storage is decommissioned.
B.Use a cloud provider's secure deletion API that performs a cryptographic erase on the storage volume.
C.Overwrite the data with zeros or random patterns multiple times.
D.Use cryptographic erasure by deleting the encryption keys associated with the data.
E.Implement a data retention policy that automatically deletes data after a set period.
AnswersB, D

Some cloud providers offer secure deletion APIs that perform cryptographic erasure on volumes or objects. This directly addresses the need for irrecoverable deletion and can be integrated into the application's deletion workflow. It is an effective measure for secure data disposal in the cloud.

Why this answer

Cryptographic erasure by deleting keys and using provider secure deletion APIs are both effective because they render data irrecoverable without relying on physical media destruction. Overwriting is unreliable in cloud environments, retention policies do not ensure immediate deletion, and provider media sanitization is not on-demand.

Exam trap

The trap here is assuming that traditional on-premises data destruction methods like overwriting are effective in the cloud, where storage abstraction prevents such guarantees.

338
Multi-Selecthard

Which THREE of the following are key characteristics of cloud computing as defined by NIST SP 800-145?

Select 3 answers
A.Broad network access
B.On-demand self-service
C.Location independence
D.Dedicated hardware per tenant
E.Rapid elasticity
AnswersA, B, E

Broad network access is one of the five essential NIST SP 800-145 characteristics: capabilities are available over the network through standard mechanisms that promote use by heterogeneous thin or thick client platforms, satisfying the definition's accessibility requirement.

Why this answer

NIST SP 800-145 defines five essential characteristics of cloud computing, and broad network access (A) is one of them because capabilities must be available over the network through standard mechanisms that promote use by heterogeneous thin or thick client platforms. On-demand self-service (B) is also essential, as consumers must be able to unilaterally provision computing capabilities such as server time and network storage automatically without requiring human interaction with each service provider. Rapid elasticity (E) is the third correct characteristic, since capabilities must be elastically provisioned and released, in some cases automatically, to scale rapidly outward and inward commensurate with demand.

Location independence (C) is not one of the five NIST essential characteristics, although resource pooling does mention that resources are pooled and location-independent in a multi-tenant model. Dedicated hardware per tenant (D) is incorrect because cloud computing relies on resource pooling with multi-tenancy, not dedicated hardware per tenant.

Exam trap

ISC2 often tests the distinction between 'location independence' (a common misconception) and the actual NIST-defined characteristic of 'resource pooling,' where the consumer generally has no control over the exact physical location of resources but may specify at a higher level of abstraction (e.g., country, region, or availability zone).

339
MCQmedium

Which of the following is a key benefit of using a hybrid cloud deployment model?

A.Ability to keep sensitive data on-premises while leveraging public cloud for less sensitive workloads
B.Complete isolation from public networks
C.Single vendor management
D.Elimination of shared responsibility
AnswerA

Hybrid cloud combines distinct on-premises and public cloud environments bound by technology enabling data and application portability. This lets the organisation retain sensitive data on its private infrastructure while running less sensitive workloads cost-effectively in the public cloud, satisfying both control and scalability needs.

Why this answer

A key benefit of hybrid cloud is the ability to keep sensitive data on-premises while leveraging public cloud for less sensitive workloads, thus meeting compliance and security requirements while gaining cloud scalability. This flexibility is a primary driver for hybrid adoption.

Exam trap

CCSP often tests the misconception that hybrid cloud eliminates shared responsibility or provides complete isolation; candidates might confuse hybrid cloud with private cloud.

How to eliminate wrong answers

Option B is wrong because complete isolation from public networks is not a benefit of hybrid cloud; hybrid cloud by definition involves some connectivity to public cloud. Option C is wrong because hybrid cloud often involves multiple vendors, not single vendor management. Option D is wrong because hybrid cloud does not eliminate shared responsibility; the organization still retains responsibility for on-premises and some aspects of cloud security.

340
MCQhard

A cloud architect is designing a system that must survive the failure of an entire cloud provider region. The application uses a relational database and object storage. Which design approach BEST achieves regional fault tolerance while minimizing data loss and operational complexity?

A.Deploy the application in a single region with a multi-master database cluster spanning three availability zones and global load balancing.
B.Deploy the application in two availability zones within a single region and rely on the provider's managed backup service for the database.
C.Deploy the application in two regions using synchronous database replication and a single object storage bucket with cross-region access.
D.Deploy the application in two regions with asynchronous database replication and cross-region replication for object storage, then use DNS failover to redirect traffic.
AnswerD

This design places the application in two independent regions, replicates the database asynchronously to bound latency impact, replicates object storage across regions, and uses DNS failover to shift traffic. It directly addresses a full region outage while keeping operational complexity manageable compared with active-active multi-master database designs.

Why this answer

Surviving a full region failure requires resources and data in at least two independent regions. Asynchronous database replication avoids the latency and availability penalties of synchronous cross-region writes, cross-region object storage replication protects unstructured data, and DNS failover provides a practical traffic redirection mechanism with acceptable recovery time objectives.

Exam trap

The trap here is treating multi-availability-zone redundancy inside one region as equivalent to regional fault tolerance.

341
Multi-Selecthard

A multinational corporation must comply with data residency requirements that mandate certain data must remain within the European Union. Additionally, the company needs to ensure high availability and disaster recovery for this data. Which TWO measures should be implemented? (Select TWO.)

Select 2 answers
A.Configure cross-region replication to another EU region
B.Implement IAM policies with conditions restricting data access to EU regions
C.Use cross-region replication to a region outside the EU
D.Select cloud regions located within the EU
E.Enable public access to the bucket for all users
AnswersA, D

Cross-region replication to a second EU region keeps data within the European Union while providing geographic redundancy, satisfying both the residency mandate and the disaster recovery requirement. Replicating to a non-EU region would breach residency, so the paired EU region is the decisive constraint.

Why this answer

Option D is correct because selecting cloud regions physically located within the EU is the foundational measure that ensures data is stored and processed inside EU territory, directly satisfying data residency mandates. Option A is correct because configuring cross-region replication to another EU region provides high availability and disaster recovery while keeping all replicated data within EU boundaries, so residency is not violated. Option B is not correct because IAM policies with region conditions control access authorization but do not by themselves guarantee that data is stored or replicated only within the EU.

Option C is not correct because replicating to a region outside the EU would violate the data residency requirement. Option E is not correct because enabling public access to the bucket weakens security and does nothing to meet residency or availability requirements.

Exam trap

The trap is confusing access control (IAM policies) with data residency; candidates may think restricting access to EU regions ensures residency, but residency is about where data is stored, not who can access it.

342
MCQmedium

An organization is implementing a DevSecOps pipeline for cloud-native applications. Which security testing method should be integrated early in the CI/CD pipeline to analyze source code for vulnerabilities without executing the application?

A.Runtime Application Self-Protection (RASP)
B.Dynamic Application Security Testing (DAST)
C.Interactive Application Security Testing (IAST)
D.Static Application Security Testing (SAST)
AnswerD

SAST analyses source code, bytecode or binaries without executing the application, so it runs on every commit inside the CI/CD pipeline and flags injection, insecure deserialisation and similar flaws before build or deployment. This satisfies the constraint of early analysis without executing the application.

Why this answer

Static Application Security Testing (SAST) scans source code early in the SDLC, aligning with shift-left security.

343
MCQeasy

Which of the following is a key consideration when defining a cloud provider's liability for data breaches?

A.The provider's incident response plan
B.The provider's insurance policy limits
C.The number of previous breaches
D.The limitation of liability clause in the contract
AnswerD

The limitation of liability clause contractually caps the provider's financial exposure for a breach, directly defining the extent of its liability. Other contract terms, such as the shared responsibility model, allocate duties but do not quantify the provider's monetary responsibility.

Why this answer

The limitation of liability clause in the contract defines the maximum liability of the provider in the event of a breach. Provider's insurance, incident response plan, and history of breaches may influence negotiations but are not the contractual definition of liability.

344
MCQmedium

A multinational retailer is selecting a cloud deployment model for a new inventory system. The system must be accessible to stores in several countries, must scale rapidly during seasonal promotions, and must be managed by a third-party provider. The retailer does not want to own or maintain the underlying infrastructure. Which cloud deployment model BEST fits these requirements?

A.Hybrid cloud
B.Community cloud
C.Public cloud
D.Private cloud
AnswerC

A public cloud is owned and operated by a third-party provider and offers rapid elasticity and broad geographic reach. The retailer can deploy the inventory system without owning infrastructure and scale during seasonal promotions, which directly satisfies the stated requirements for global access, elasticity, and outsourced management.

Why this answer

A public cloud is provider-owned and offers on-demand scaling and global availability, which matches the retailer's need to avoid infrastructure ownership while supporting stores in multiple countries and handling seasonal demand spikes. The other models either require dedicated infrastructure, shared governance, or unnecessary private integration.

Exam trap

The trap here is assuming that global reach or third-party management automatically implies hybrid cloud, when a public cloud alone already provides those characteristics.

345
MCQeasy

A small business wants to move its email and productivity suite to a cloud service where the provider manages the application, runtime, and underlying infrastructure, and users access the software through a browser. Which cloud service model is being described?

A.Function as a Service (FaaS)
B.Software as a Service (SaaS)
C.Platform as a Service (PaaS)
D.Infrastructure as a Service (IaaS)
AnswerB

SaaS delivers a complete application managed by the provider, including the runtime and infrastructure, and users access it through a browser or thin client. This matches the scenario where the business consumes email and productivity software without managing any underlying layers, leaving only limited user-specific configuration to the customer.

Why this answer

In SaaS, the provider manages the application, runtime, middleware, operating system, and infrastructure, while the customer consumes the software, often through a browser. Email and productivity suites delivered this way fit the SaaS model precisely, with the customer retaining only limited configuration and user management responsibilities.

Exam trap

The trap here is equating any cloud-hosted application with PaaS, when the distinguishing factor is who manages the application layer.

346
MCQhard

A developer accidentally hardcodes AWS access keys in a public GitHub repository. Which tool is specifically designed to detect such secrets in code repositories?

A.Checkov
B.GitGuardian
C.Snyk
D.tfsec
AnswerB

GitGuardian is a dedicated secrets-detection platform that scans repositories and commit history for exposed credentials such as AWS access keys. It directly matches the stem's requirement for a tool specifically designed to find secrets in code repositories.

Why this answer

GitGuardian is a purpose-built tool for detecting secrets (e.g., AWS access keys, API tokens) in code repositories, including public GitHub repos. It scans commit history and uses pattern matching to identify hardcoded credentials, alerting developers in real time. This directly addresses the scenario of accidental exposure in a public repository.

Exam trap

ISC2 often tests the distinction between infrastructure-as-code security scanners (Checkov, tfsec) and secret detection tools (GitGuardian), trapping candidates who assume any security tool can find hardcoded credentials.

How to eliminate wrong answers

Option A is wrong because Checkov is a static analysis tool for infrastructure-as-code (e.g., Terraform, CloudFormation) that checks for misconfigurations, not for scanning secrets in code repositories. Option C is wrong because Snyk focuses on vulnerability scanning in open-source dependencies and container images, not on detecting hardcoded secrets in source code. Option D is wrong because tfsec is a security scanner for Terraform configurations, similar to Checkov, and lacks secret detection capabilities for general code repositories.

347
MCQmedium

A cloud operations team runs a Kubernetes cluster on Google Kubernetes Engine (GKE). A recent audit found that several pods were scheduled onto nodes that do not meet the organization's hardened baseline, and the team wants to enforce that only nodes with specific labels are eligible for certain workloads. Which Kubernetes mechanism should the team implement?

A.PodDisruptionBudget
B.Horizontal Pod Autoscaler
C.Node affinity combined with node labels
D.NetworkPolicy
AnswerC

Node affinity rules in the pod spec use node labels as match expressions, so only nodes carrying the required hardened baseline label will be eligible. This directly enforces the placement requirement on GKE without needing a custom scheduler, and it can be made mandatory with requiredDuringSchedulingIgnoredDuringExecution.

Why this answer

Node affinity uses node labels as hard or soft match rules in the pod specification, so requiring a specific label ensures the scheduler only places the workload on nodes that carry the hardened baseline. This is the native Kubernetes control for constraining placement without replacing the default scheduler or altering cluster autoscaling behavior.

Exam trap

The trap here is confusing scheduling controls with runtime controls, assuming that a policy or disruption budget can dictate which node a pod lands on.

348
Multi-Selecthard

A healthcare organization stores electronic protected health information (ePHI) in a cloud environment. They need to implement data discovery and classification to meet HIPAA requirements. Which two techniques are most appropriate for identifying ePHI in unstructured data stored in cloud object storage? (Choose two.)

Select 2 answers
A.Regular expression pattern matching for known ePHI formats.
B.Full-disk encryption of the storage volumes.
C.Natural language processing (NLP) to detect medical terminology and context.
D.Metadata tagging based on file extensions and folder names.
E.Manual review of every file by a compliance officer.
AnswersA, C

Regular expressions can identify structured ePHI such as Social Security numbers, medical record numbers, and dates of birth in text files. This is a common technique in data discovery tools to flag potential ePHI. It is effective for known patterns but may produce false positives, so it is often combined with other methods.

Why this answer

Regular expression pattern matching and NLP are both content inspection techniques that can identify ePHI in unstructured data. Pattern matching catches formatted identifiers, while NLP detects medical context. Together they provide a robust discovery strategy.

Encryption, manual review, and metadata tagging do not effectively identify ePHI content at scale.

Exam trap

The trap here is assuming that metadata or file extensions are sufficient for data discovery, when in fact content inspection is required to reliably identify ePHI in unstructured data.

349
MCQhard

A cloud customer is subject to the Health Insurance Portability and Accountability Act (HIPAA). They are considering using a cloud provider that offers infrastructure as a service (IaaS). Which of the following is the customer's responsibility under the HIPAA shared responsibility model?

A.Encryption of data at rest
B.Patching of the hypervisor
C.Network firewall configuration
D.Physical security of the data center
AnswerA

Correct. The customer must ensure ePHI is encrypted at rest, as they control the data.

Why this answer

Under the HIPAA shared responsibility model for IaaS, the customer retains responsibility for securing the data they store and process, including encryption of data at rest. The cloud provider manages the underlying infrastructure (hypervisor, physical security, network fabric), but the customer must implement and manage encryption mechanisms for their stored data, such as using AES-256 encryption with customer-managed keys via services like AWS KMS or Azure Key Vault.

Exam trap

ISC2 often tests the misconception that network firewall configuration is a customer responsibility in IaaS, but the trap is that the provider manages the physical and hypervisor-level firewalls, while the customer only controls virtual firewalls within their isolated tenant environment.

How to eliminate wrong answers

Option B is wrong because patching the hypervisor is the sole responsibility of the cloud provider, as it is part of the underlying virtualization layer that the customer cannot access or modify. Option C is wrong because network firewall configuration at the hypervisor or physical network level is managed by the provider; the customer is only responsible for virtual firewalls or security groups within their own virtual network. Option D is wrong because physical security of the data center, including access controls, surveillance, and environmental safeguards, is exclusively the provider's responsibility under the IaaS model.

350
MCQeasy

A security analyst reviews the bucket policy above. What is the primary security concern?

A.The bucket policy allows public read access to all objects
B.The bucket policy uses an outdated version
C.The bucket policy is missing a Condition element
D.The bucket policy allows public write access to all objects
AnswerA

Allowing GetObject to anonymous users makes all objects publicly readable.

Why this answer

The bucket policy grants public read access to all objects via a Principal set to '*' and an Effect of 'Allow' on the s3:GetObject action. This means any unauthenticated user on the internet can list and download objects in the bucket, leading to potential data exposure. The primary security concern is unauthorized data disclosure, which violates the principle of least privilege.

Exam trap

ISC2 often tests the distinction between read and write permissions in bucket policies, so candidates may mistakenly choose public write access (Option D) when the policy clearly shows read access, or they may overthink the missing Condition element (Option C) as the primary issue rather than the explicit public Principal.

How to eliminate wrong answers

Option B is wrong because the policy version (e.g., '2012-10-17') is the standard AWS IAM policy version and is not outdated; an outdated version would not cause a security concern by itself. Option C is wrong because while a missing Condition element can reduce granularity, it is not inherently a security concern if the policy already allows public access; the absence of a Condition does not create the exposure—the overly permissive Principal and Action do. Option D is wrong because the policy shown allows read access (s3:GetObject), not write access (s3:PutObject); public write access would be a different and equally severe concern, but it is not present in this policy.

351
MCQmedium

A company is migrating sensitive customer data to the cloud. They need to classify data according to the organization's data classification policy, which includes public, internal, confidential, and restricted categories. Which of the following is the MOST important step to ensure data classification is effective in the cloud?

A.Assign a data custodian to manually tag data objects
B.Implement encryption for all data at rest and in transit
C.Integrate classification labels with DLP and access control policies
D.Store each classification level in separate cloud regions
AnswerC

Classification labels only deliver value when enforced; integrating them with DLP and access control policies ensures restricted and confidential data is actually protected in the cloud. Labels alone, without enforcement, leave sensitive data exposed regardless of how accurately it is categorised.

Why this answer

Integrating classification labels with DLP and access control policies ensures that the classification scheme is enforced automatically, not just documented. This allows the cloud infrastructure to apply appropriate protections (e.g., blocking unauthorized access or preventing data exfiltration) based on the label, making classification actionable and effective in a dynamic cloud environment.

Exam trap

ISC2 often tests the misconception that encryption alone is sufficient for data classification, but encryption is a protection mechanism, not a classification or enforcement mechanism; the trap is confusing security controls with data governance processes.

How to eliminate wrong answers

Option A is wrong because manually tagging data objects is error-prone, does not scale in a cloud environment with potentially millions of objects, and lacks automated enforcement; data custodians should define policy, not perform manual tagging. Option B is wrong because encryption protects data confidentiality and integrity but does not classify data or enforce classification-based access controls; it is a security control, not a classification mechanism. Option D is wrong because storing each classification level in separate cloud regions is impractical, costly, and does not inherently enforce access controls; classification should be enforced through policy and labels, not physical or logical separation alone.

352
MCQeasy

Which of the following is a key benefit of using a Software Bill of Materials (SBOM)?

A.It automatically fixes vulnerabilities in dependencies
B.It prevents all zero-day attacks
C.It allows for quick identification of vulnerable components
D.It replaces the need for penetration testing
AnswerC

An SBOM enumerates every direct and transitive component with versions and identifiers, so when a new CVE such as Log4Shell is published you can query the inventory and immediately identify affected builds rather than scanning or guessing. This enables rapid identification of vulnerable components.

Why this answer

An SBOM provides a list of all components and dependencies in an application, enabling organizations to quickly identify which applications are affected by a newly disclosed vulnerability.

353
Multi-Selecthard

Which THREE of the following are required components of a cloud data lifecycle policy?

Select 3 answers
A.Legal hold process
B.Data deletion procedures
C.Data classification
D.Data retention schedule
E.Data encryption algorithm selection
AnswersB, C, D

Correct. Deletion is the final stage of the lifecycle.

Why this answer

Data deletion procedures are a required component of a cloud data lifecycle policy because they define how data is securely and irreversibly removed at the end of its useful life. This includes methods such as cryptographic erasure, overwriting with patterns (e.g., NIST SP 800-88), or degaussing, ensuring compliance with legal and regulatory requirements. Without explicit deletion procedures, data may persist in cloud storage, leading to unauthorized access or retention violations.

Exam trap

ISC2 often tests the distinction between operational security controls (like encryption algorithms) and governance-level lifecycle policy components, leading candidates to mistakenly include technical implementation details as required policy elements.

354
MCQmedium

A financial institution is implementing a data classification scheme for their cloud environment. They have data that, if exposed, could cause severe damage to the organization and is subject to strict regulatory requirements. Which classification level should be applied to this data?

A.Confidential
B.Restricted
C.Public
D.Internal
AnswerB

Restricted classification fits because the stem specifies severe organisational damage plus strict regulatory obligations, which demand the highest confidentiality controls, encryption, and least-privilege access. Unlike Confidential, Restricted typically enforces need-to-know access, formal authorisation, and audit logging, satisfying the financial regulator's requirements.

Why this answer

Restricted data is the highest classification level, typically used for data that, if compromised, could cause severe damage and is subject to strict regulations.

355
MCQmedium

During an audit of a containerized application, you notice that containers are running with the --privileged flag. Which of the following is the most significant security risk associated with this configuration?

A.Container escape to the host
B.Increased memory consumption
C.Inability to use secure base images
D.Excessive network bandwidth usage
AnswerA

The --privileged flag grants the container all Linux capabilities and unrestricted device access, disabling the namespace and cgroup barriers that normally confine it. An attacker inside can then mount the host filesystem or manipulate kernel interfaces to escape onto the host.

Why this answer

Privileged containers have nearly all capabilities of the host, significantly increasing the risk of container escape and host compromise.

356
MCQmedium

Which OWASP Top 10 vulnerability is most directly related to cloud API security when an attacker can modify parameters to access another user's data?

A.Security Misconfiguration
B.Injection
C.Broken Object Level Authorization
D.Cross-Site Request Forgery (CSRF)
AnswerC

Broken Object Level Authorization occurs when an API trusts a client-supplied object identifier without verifying the caller owns it, so manipulating a parameter exposes another user's data. It is the OWASP API Security Top 1 risk.

Why this answer

Broken Object Level Authorization (BOLA) occurs when an API does not properly enforce user permissions on object access.

357
MCQmedium

A security team wants to ensure that only signed container images are deployed in production. Which practice should they implement?

A.Container image scanning with Trivy
B.Implementing a web application firewall (WAF)
C.Using a private registry
D.Image signing and verification
AnswerD

Cryptographic signing lets the admission controller verify image provenance against a trusted key before deployment, rejecting tampered or unsigned artefacts. This directly enforces the stem's constraint that only signed images reach production, binding image integrity to the registry-to-runtime supply chain.

Why this answer

Signing container images with tools like Notary or Sigstore ensures the integrity and authenticity of images, preventing tampered or unauthorized images from being deployed.

358
MCQeasy

A company is implementing a secure software development lifecycle (SSDLC) for its cloud-native applications. Which practice should be automated to detect vulnerabilities early in the development process?

A.Static application security testing (SAST)
B.Penetration testing in production
C.Dynamic application security testing (DAST)
D.Manual code review
AnswerA

SAST scans source code without executing it, detecting vulnerabilities such as injection flaws during coding. Automating it in the CI pipeline satisfies the SSDLC constraint of finding defects early, before deployment, when remediation is cheapest and least disruptive.

Why this answer

Static application security testing (SAST) analyzes source code, bytecode, or binaries without executing the application, making it ideal for early detection of vulnerabilities during the coding phase of the SSDLC. By integrating SAST into the CI/CD pipeline, developers receive immediate feedback on security flaws such as SQL injection or buffer overflows, enabling remediation before the code is built or deployed. This aligns with the 'shift left' principle, catching issues when they are cheapest and easiest to fix.

Exam trap

ISC2 often tests the distinction between SAST (white-box, early) and DAST (black-box, late), and the trap here is that candidates mistakenly choose DAST because they confuse 'dynamic' with 'automated,' forgetting that DAST requires a running application and cannot detect vulnerabilities in source code.

How to eliminate wrong answers

Option B is wrong because penetration testing in production occurs after deployment, not early in development, and can introduce risks to live systems. Option C is wrong because dynamic application security testing (DAST) requires a running application to test, making it a later-stage practice that cannot detect vulnerabilities in code before it is compiled or deployed. Option D is wrong because manual code review is not automated and is slower, less consistent, and more error-prone than automated SAST, failing to meet the requirement for automation to detect vulnerabilities early.

359
MCQmedium

Which of the following is a key benefit of using containers, such as Docker, in a cloud environment to achieve portability?

A.Containers package applications with dependencies to run consistently across environments
B.Containers are always stateless
C.Containers require a specific hypervisor to run
D.Containers provide hardware-level virtualization
AnswerA

Containers bundle the application with its libraries and dependencies into a single image, so the same artefact runs identically on any container host. This dependency packaging, rather than hypervisor abstraction, delivers the portability across cloud environments.

Why this answer

Containers bundle the application code together with its libraries, runtime, and configuration into a single immutable image, so the same image runs identically on a developer laptop, on-premises servers, or any cloud VM/container service. This decoupling from the underlying host OS and infrastructure is precisely what delivers portability across cloud environments.

Exam trap

The trap here is conflating containers with virtual machines — candidates who remember 'virtualization' from VM study material may pick hardware-level virtualization (D) or hypervisor dependency (C), missing that containers virtualize at the OS layer and are defined by packaging dependencies for consistency.

How to eliminate wrong answers

Option B is wrong because containers are not inherently stateless — statefulness depends on how the application is written and whether it uses persistent volumes; many stateful workloads (databases, caches) run in containers. Option C is wrong because containers share the host OS kernel and do not require a hypervisor; a hypervisor is used by virtual machines, not by the container runtime itself. Option D is wrong because containers provide OS-level (process) virtualization, not hardware-level virtualization — hardware virtualization is the domain of hypervisors and VMs.

360
Multi-Selecthard

Which THREE are best practices for implementing secrets management in cloud applications?

Select 3 answers
A.Embed secrets in application logs for debugging
B.Store secrets in version control repositories
C.Use a dedicated secrets management service
D.Rotate secrets regularly
E.Encrypt secrets at rest and in transit
AnswersC, D, E

A dedicated secrets management service centralises storage, access control and auditing, removing hard-coded credentials from source and configuration. It enforces least-privilege retrieval and enables automated rotation, directly satisfying the best-practice requirement for controlling secret sprawl across cloud applications.

Why this answer

Option C is correct because a dedicated secrets management service (e.g., AWS Secrets Manager, Azure Key Vault, HashiCorp Vault) centralizes storage, enforces access control via IAM policies, and provides audit logging and programmatic retrieval, which is the recommended pattern for cloud applications. Option D is correct because regularly rotating secrets limits the blast radius of a leaked credential and is a core requirement of standards like PCI DSS and NIST SP 800-57; managed services can automate rotation via Lambda or native rotation policies. Option E is correct because secrets must be encrypted at rest (e.g., AES-256 via KMS) and in transit (TLS 1.2+) to prevent exposure from compromised storage or network interception.

Option A is not a best practice because embedding secrets in application logs exposes them to anyone with log access and defeats the purpose of secret confidentiality. Option B is not a best practice because storing secrets in version control repositories persists them in history, making them retrievable even after deletion and widely accessible to anyone with repo access.

Exam trap

ISC2 often tests the misconception that logging secrets is acceptable for debugging (Option A) or that version control with .gitignore is sufficient to protect secrets (Option B), but the CCSP exam emphasizes that secrets must never be stored in logs or repositories, and must always be managed via dedicated, rotation-capable services.

361
MCQeasy

A company stores PII in the cloud and needs to ensure compliance with GDPR. What is the first step they should take?

A.Delete all data older than the required retention period
B.Implement encryption for all stored data
C.Sign a Data Processing Agreement with the CSP
D.Perform data classification and mapping
AnswerD

Data classification and mapping identifies what personal data exists, where it resides and how it flows, which is the prerequisite for every subsequent GDPR control. Without this inventory, lawful basis, retention and subject-rights obligations cannot be scoped or evidenced.

Why this answer

The first step is to perform data classification and mapping to identify what PII is held, where it resides, and how it flows. This foundational activity informs all subsequent GDPR compliance actions. Option A is incorrect because deleting data may be part of data minimization but not the first step.

Option B is incorrect because encryption is a security control, not the initial step. Option C is incorrect because a Data Processing Agreement is signed after identifying and understanding data processing activities.

362
MCQeasy

A cloud security administrator is configuring access to a cloud object storage bucket that contains regulated data. The requirement is that only identities with an explicit business need can read objects, and that access decisions are evaluated centrally with fine-grained conditions such as department and time of day. Which capability BEST addresses this requirement?

A.A centralized policy engine that evaluates identity attributes and contextual conditions before granting object reads.
B.Bucket access control lists that grant read permission to specific user accounts.
C.Network ACLs that restrict access to the bucket from approved corporate IP ranges.
D.Pre-signed URLs generated by an administrator and distributed to approved users.
AnswerA

A centralized policy engine can evaluate identity attributes, resource tags, and contextual factors like time of day to make fine-grained authorization decisions. It provides consistent, auditable enforcement across the bucket and scales as identities and resources grow. This directly satisfies the need for explicit business-need-based, condition-aware access control.

Why this answer

A centralized policy engine evaluates identity attributes and contextual conditions, enabling fine-grained, least-privilege authorization for bucket reads. It provides consistent enforcement and auditing across the environment, which ACLs, pre-signed URLs, and network ACLs cannot deliver. Only the policy engine meets the requirement for condition-based, business-need-driven access decisions.

Exam trap

The trap here is treating network restrictions or pre-signed URLs as authorization controls, when they do not evaluate identity attributes or business need.

363
Multi-Selectmedium

Which THREE of the following are key considerations when designing a key management lifecycle for cloud data encryption?

Select 3 answers
A.Key rotation
B.Key usage monitoring
C.Key escrow
D.Key generation
E.Key storage
AnswersA, D, E

Rotation is a key lifecycle phase.

Why this answer

Key rotation is a critical lifecycle operation that limits the exposure of encrypted data if a key is compromised. By periodically replacing encryption keys with new ones, organizations reduce the window of vulnerability and comply with standards like NIST SP 800-57, which recommends cryptographic key rotation based on the key's usage period and security strength.

Exam trap

ISC2 often tests the distinction between lifecycle phases (generate, store, rotate, destroy) and operational controls (monitoring, escrow), so candidates mistakenly include monitoring or escrow as core design steps when they are actually supporting processes.

364
MCQeasy

When data is in transit between an on-premises data center and a cloud service, which of the following is the minimum encryption standard recommended by security best practices?

A.IPsec with 3DES
B.TLS 1.2
C.TLS 1.0
D.SSL 3.0
AnswerB

TLS 1.2 provides authenticated, encrypted transport with modern cipher suites, satisfying the minimum encryption standard for data in transit between on-premises systems and cloud services. Earlier versions such as TLS 1.0 and 1.1 are deprecated due to known vulnerabilities, so TLS 1.2 is the baseline best practice.

Why this answer

TLS 1.2 is the minimum encryption standard recommended by security best practices (NIST SP 800-52 Rev 2, PCI DSS) for data in transit between on-premises and cloud environments. It provides strong cipher suites (e.g., AES-GCM, SHA-256) and supports forward secrecy via ECDHE, which older protocols lack. CCSP candidates must recognize TLS 1.2 as the baseline acceptable protocol for protecting data in motion.

Exam trap

CCSP often tests the misconception that any encryption protocol is acceptable, when in fact deprecated protocols like SSL 3.0, TLS 1.0, and 3DES are explicitly disallowed by modern compliance frameworks.

How to eliminate wrong answers

Option A is wrong because IPsec with 3DES uses a deprecated 64-bit block cipher vulnerable to Sweet32 birthday attacks and is not the recommended minimum for cloud transit. Option C is wrong because TLS 1.0 lacks support for modern AEAD ciphers and is deprecated by RFC 8996 and PCI DSS. Option D is wrong because SSL 3.0 is obsolete, vulnerable to POODLE, and explicitly prohibited by RFC 7568.

365
MCQeasy

Which of the following is an example of a runtime application self-protection (RASP) capability?

A.Checking for misconfigured S3 buckets
B.Blocking an SQL injection attempt during execution
C.Analyzing logs after an attack
D.Scanning source code for vulnerabilities
AnswerB

RASP instruments the running application and inspects calls as they execute, so it can terminate a malicious query mid-flight. Blocking an SQL injection attempt during execution demonstrates this in-process interception, which distinguishes RASP from perimeter controls such as a web application firewall.

Why this answer

Runtime Application Self-Protection (RASP) is a security technology that integrates with an application's runtime environment to detect and block attacks in real time. Blocking an SQL injection attempt during execution is a classic RASP capability because it monitors the application's behavior and interrupts malicious activity as it happens. RASP operates within the application, analyzing both the application's logic and the data flow to prevent exploitation.

Exam trap

The trap here is confusing RASP with other security tools like SAST, DAST, or WAF; candidates might think any runtime protection is RASP, but RASP specifically operates inside the application to block attacks during execution.

How to eliminate wrong answers

Option A is wrong because checking for misconfigured S3 buckets is a cloud security posture management (CSPM) function, not a runtime protection capability. Option C is wrong because analyzing logs after an attack is a forensic or monitoring activity, not real-time protection. Option D is wrong because scanning source code for vulnerabilities is static application security testing (SAST), which occurs before runtime.

366
MCQmedium

A cloud application development team is using a public API gateway to expose microservices. The security team wants to protect the APIs from common web vulnerabilities such as SQL injection and cross-site scripting (XSS). Which control should be implemented at the API gateway?

A.API rate limiting
B.Mutual TLS (mTLS) authentication
C.Web application firewall (WAF)
D.OAuth 2.0 token validation
AnswerC

A WAF inspects incoming HTTP requests and can block or sanitize malicious payloads that target vulnerabilities like SQL injection and XSS. Deploying a WAF at the API gateway provides a centralized enforcement point for all microservices, reducing the need to implement protections in each service. It can be configured with rule sets such as OWASP Core Rule Set to detect and mitigate common attacks, thus protecting the APIs from exploitation.

Why this answer

A web application firewall (WAF) deployed at the API gateway is the appropriate control to protect against SQL injection and XSS. It inspects HTTP requests and can block or sanitize malicious inputs before they reach the microservices. While other controls like rate limiting, mTLS, and OAuth 2.0 are important for availability, authentication, and authorization, they do not analyze request content for injection attacks.

A WAF provides the necessary application-layer protection.

Exam trap

The trap here is assuming that authentication or rate limiting controls also protect against injection attacks, when they operate at different layers and do not inspect payload content.

367
MCQhard

An auditor is reviewing a cloud provider's SOC 2 Type II report. Which aspect of the report is most relevant for assessing the effectiveness of controls over a period?

A.System description
B.Description of tests and results
C.Opinion letter
D.Management's assertion
AnswerB

The description of tests and results details the auditor's procedures and findings across the review period, evidencing whether controls operated effectively throughout. This satisfies the requirement to assess control effectiveness over a period, unlike a point-in-time opinion or management assertion alone.

Why this answer

The SOC 2 Type II report evaluates the operational effectiveness of controls over a specified period (typically 6–12 months). The 'Description of tests and results' section provides the auditor's detailed testing procedures and outcomes, directly showing whether controls operated effectively throughout that period. This makes it the most relevant aspect for assessing control effectiveness over time.

Exam trap

ISC2 often tests the distinction between Type I (point-in-time design) and Type II (period-of-time effectiveness), and candidates mistakenly choose the opinion letter or system description because they focus on the report's overall conclusion rather than the detailed test evidence that proves effectiveness over time.

How to eliminate wrong answers

Option A is wrong because the system description merely outlines the system's boundaries and control objectives, not the actual testing or effectiveness over time. Option C is wrong because the opinion letter gives the auditor's overall conclusion but lacks the granular test details needed to assess specific control effectiveness. Option D is wrong because management's assertion is a self-declaration of control design and implementation, not an independent verification of operational effectiveness over the period.

368
Multi-Selecteasy

A company is deploying a serverless function in AWS Lambda that needs to access a private RDS database. Which TWO configurations are necessary for secure access?

Select 2 answers
A.Disable TLS for the database connection
B.Configure VPC integration for the Lambda function
C.Attach an Internet Gateway to the Lambda function
D.Assign a public IP address to the Lambda function
E.Create an execution role with permissions to the RDS database
AnswersB, E

VPC integration allows Lambda to access resources in a VPC.

Why this answer

Lambda functions must be attached to a VPC using VPC integration to access resources inside a private subnet, such as an RDS database. Without VPC integration, the Lambda function runs in an AWS-managed VPC and cannot reach resources in the customer’s VPC. This configuration requires the Lambda function to be associated with the same VPC, subnets, and security groups as the RDS instance.

Exam trap

The CCSP exam often tests the misconception that Lambda functions can directly access private resources without VPC integration, or that public IPs or Internet Gateways are needed for private connectivity, leading candidates to select options like C or D instead of recognizing the necessity of VPC integration and proper IAM roles.

369
MCQmedium

A cloud customer is subject to eDiscovery requirements in a lawsuit. The data resides in a cloud storage service that uses encryption. What is the primary challenge in collecting this data in a forensically sound manner?

A.Obtaining a search warrant for data stored in the cloud
B.Decrypting the data without the encryption keys
C.Ensuring the integrity and chain of custody when data is collected via API or provider tools rather than physical seizure
D.Identifying the specific geographic location of the data
AnswerC

Collecting via API or provider tooling bypasses physical seizure, so forensic soundness hinges on verifiable integrity and an unbroken chain of custody. Provider-mediated exports may omit metadata, alter timestamps, or lack cryptographic hashes, undermining admissibility under eDiscovery rules. Microsoft Entra ID access logs and immutable audit trails help evidence who accessed the export.

Why this answer

In cloud eDiscovery, data is collected via APIs or provider-native tools rather than by seizing physical media, so the primary forensic challenge is preserving integrity and demonstrating an unbroken chain of custody. Unlike physical seizure where a disk can be hashed and sealed, API-based collection must be logged, hashed, and authenticated to withstand legal scrutiny. The encryption itself is not the main obstacle if the customer holds the keys; the procedural integrity of the collection is what courts and opposing counsel will challenge.

Exam trap

The trap is focusing on encryption or warrants as the main obstacle; candidates must recognize that in cloud eDiscovery the forensic challenge is maintaining integrity and chain of custody through API-based collection rather than physical seizure.

How to eliminate wrong answers

Option A is wrong because obtaining a search warrant is a legal process issue, not a forensic soundness challenge — and in many eDiscovery scenarios the data is the customer's own, so no warrant is needed. Option B is wrong because if the customer controls the encryption keys (common in cloud storage with customer-managed keys), decryption is straightforward; the challenge is not cryptographic access but proving the collection was tamper-free. Option D is wrong because while data location matters for jurisdiction, providers expose region information and it is a compliance consideration rather than the core forensic integrity challenge in collecting the data.

370
MCQeasy

In the NIST SP 800-145 definition, which deployment model is described as infrastructure provisioned for exclusive use by a single organization comprising multiple consumers?

A.Private cloud
B.Public cloud
C.Community cloud
D.Hybrid cloud
AnswerA

NIST SP 800-145 defines the private cloud as infrastructure provisioned for exclusive use by a single organisation comprising multiple consumers, whether business units or employees. Exclusivity plus multi-consumer tenancy within one organisation is the precise axis separating it from public, community and hybrid models.

Why this answer

NIST SP 800-145 defines the private cloud deployment model as infrastructure provisioned for exclusive use by a single organization comprising multiple consumers (e.g., business units). The key characteristic is exclusive use by one organization, whether owned/operated by the organization or a third party, and whether on-premises or off-premises.

Exam trap

CCSP often tests the precise NIST wording — candidates confuse 'single organization comprising multiple consumers' (private) with 'community of consumers from organizations that share concerns' (community).

How to eliminate wrong answers

Option B is wrong because the public cloud is provisioned for open use by the general public and is owned by a cloud provider — it is not exclusive to a single organization. Option C is wrong because the community cloud is provisioned for exclusive use by a specific community of consumers from organizations that share concerns (e.g., mission, security requirements, policy) — it is not a single organization. Option D is wrong because the hybrid cloud is a composition of two or more distinct cloud infrastructures (private, community, or public) bound by technology enabling data and application portability — it is not defined as exclusive use by a single organization.

371
MCQhard

During a cloud migration, a company decides to move a legacy application with no code changes. Which migration strategy are they using?

A.Refactor
B.Repurchase
C.Replatform
D.Rehost (lift and shift)
AnswerD

Rehosting redeploys the legacy application onto cloud infrastructure without modifying its code, directly satisfying the no-code-changes constraint. Unlike refactoring or replatforming, which require code or configuration alterations, lift and shift preserves the existing artefact, making it the fastest migration path.

Why this answer

Rehost (lift and shift) means moving an application to the cloud without modifying its code or architecture. Since the company is migrating a legacy application with no code changes, this is the definition of a rehost strategy. The other strategies involve varying degrees of modification or replacement.

Exam trap

The trap here is confusing rehost with replatform; candidates might think any migration without code changes is replatform, but replatform involves some modifications (e.g., changing OS or database).

How to eliminate wrong answers

Option A is wrong because refactor (re-architect) involves modifying the application code to take advantage of cloud-native features, which contradicts 'no code changes'. Option B is wrong because repurchase means replacing the application with a different product, typically a SaaS solution, not moving the existing application. Option C is wrong because replatform involves making some modifications, such as changing the database engine or OS, to optimize for the cloud, which still requires changes.

372
MCQeasy

What is the primary purpose of cloud security posture management (CSPM) tools?

A.To provide a centralized log storage solution.
B.To detect real-time threats like malware and intrusions.
C.To manage user identities and access permissions.
D.To assess and improve the security configuration of cloud resources against benchmarks.
AnswerD

CSPM continuously assesses cloud resource configurations against benchmarks such as CIS and identifies misconfigurations, drift and compliance gaps. This directly satisfies the stem's focus on the primary purpose: evaluating and hardening the security posture of provisioned cloud resources, rather than runtime workload protection or identity governance.

Why this answer

CSPM tools are designed to continuously monitor cloud environments, assess configurations against industry benchmarks (e.g., CIS, NIST, PCI DSS), and provide remediation guidance. Their primary purpose is to identify misconfigurations and compliance gaps, not to perform real-time threat detection or centralized logging.

Exam trap

ISC2 CCSP often tests the distinction between CSPM (configuration assessment) and other security tools (e.g., SIEM, IDS/IPS, IAM), so the trap here is confusing CSPM's proactive compliance monitoring with reactive threat detection or log management.

How to eliminate wrong answers

Option A is wrong because centralized log storage is the function of services like AWS CloudTrail, Azure Monitor, or GCP Cloud Logging, not CSPM tools which focus on configuration assessment. Option B is wrong because real-time threat detection for malware and intrusions is handled by dedicated security tools like AWS GuardDuty, Azure Defender, or GCP Threat Detection, whereas CSPM tools are configuration-focused and not designed for active threat hunting. Option C is wrong because managing user identities and access permissions is the role of IAM services (e.g., AWS IAM, Azure AD, GCP IAM), not CSPM tools which evaluate the security posture of resources but do not directly manage identities or permissions.

373
MCQmedium

A media company runs a video transcoding workflow on a public cloud. Jobs arrive unpredictably and must be processed within minutes, but the company wants to minimize cost by using spare capacity that can be reclaimed when demand for full-price capacity rises. The jobs are checkpointed every 30 seconds and can resume on a different host. Which cloud service model and purchasing approach BEST fits this requirement?

A.Platform as a Service with a committed use discount
B.Infrastructure as a Service with dedicated hosts
C.Infrastructure as a Service with spot instances
D.Software as a Service with a per-seat subscription
AnswerC

Spot instances sell unused provider capacity at a steep discount and can be reclaimed with a short notice period, which matches the requirement to minimize cost using spare capacity. Because the transcoding jobs checkpoint every 30 seconds and can resume on another host, interruption is tolerable. IaaS also gives the team full control over the runtime needed to install and tune the transcoding software.

Why this answer

The workload is interruption-tolerant because it checkpoints frequently and can resume elsewhere, which is exactly the profile that reclaimable spare-capacity pricing is built for. Using infrastructure as a service preserves control over the transcoding runtime while allowing the team to bid on spare capacity and cut cost. Committed discounts, per-seat subscriptions, and dedicated hosts all price or isolate capacity in ways that do not match unpredictable, bursty batch processing.

Exam trap

The trap here is assuming that any discounted cloud pricing model will reduce cost for bursty work, when committed-use and per-seat models actually require predictable consumption or named users.

374
MCQmedium

A financial services firm stores transaction logs in a cloud object storage bucket. The security team wants to ensure that any modification to a log file is detectable and that the original content cannot be repudiated. Which mechanism should they implement?

A.Use digital signatures with a private key to sign each log file.
B.Apply a cryptographic hash (e.g., SHA-256) to each log file and store the hash separately.
C.Enable object versioning and configure a lifecycle policy to retain all versions.
D.Enable server-side encryption with customer-provided keys (SSE-C).
AnswerA

Digital signatures provide integrity, authentication, and non-repudiation. If the private key is securely held by the log producer, any modification to the log file will invalidate the signature, and the signer cannot deny having signed it. This directly meets the requirements for tamper detection and non-repudiation.

Why this answer

Digital signatures use asymmetric cryptography to bind the signer's identity to the data. When a log file is signed, any alteration invalidates the signature, and the signer cannot deny signing. This satisfies both integrity and non-repudiation requirements.

Encryption alone provides confidentiality but not tamper evidence, while hashing without a signature lacks non-repudiation.

Exam trap

The trap here is assuming that encryption or hashing alone provides non-repudiation, when only a digital signature binds the signer's identity to the data.

375
MCQmedium

A company wants to export its data from a cloud provider to another provider upon contract termination. Which contract clause is essential to ensure the data can be exported in a usable format?

A.Service level agreement
B.Data portability clause
C.Right to audit
D.Data deletion clause
AnswerB

A data portability clause contractually obliges the provider to return customer data in a structured, commonly used, machine-readable format on termination, enabling migration to another provider. This satisfies the stem's requirement for export in a usable format.

Why this answer

A data portability clause contractually obligates the cloud provider to return customer data in a structured, commonly used, and machine-readable format upon termination, ensuring the data can be migrated to another provider. Without this clause, the provider might only offer data in a proprietary or non-standard format, making export impractical. This is a key requirement under GDPR Article 20 and other data protection regulations.

Exam trap

CCSP often tests the distinction between data portability (export rights) and data deletion (destruction rights), as both are termination-related clauses but serve opposite purposes.

How to eliminate wrong answers

Option A is wrong because an SLA defines performance metrics like uptime and latency, not data export rights. Option C is wrong because the right to audit allows customer inspection of provider controls, not data retrieval. Option D is wrong because a data deletion clause ensures data is destroyed after termination, which is the opposite of enabling export.

Page 4

Page 5 of 13

Page 6