Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 376–450

934 questions total · 13pages · All types, answers revealed

Page 5

Page 6 of 13

Page 7
376
MCQhard

A bank is designing a new payment API that must run in a public cloud. The security team wants the application to run in an isolated, logically separated section of the provider's network where the bank controls inbound and outbound traffic, defines its own IP addressing, and can connect privately to the provider's object storage without traversing the internet. Which cloud architecture construct should the bank use?

A.A virtual private cloud with private subnets and a service endpoint
B.A web application firewall in front of the API gateway
C.A content delivery network with origin shielding
D.A dedicated hardware security module cluster
AnswerA

A virtual private cloud gives the bank a logically isolated network in which it defines its own address ranges, subnets, route tables, and gateways. Private subnets keep the payment API off the public internet while security groups and network ACLs control traffic. A service endpoint lets the VPC reach the provider's object storage over the provider's private backbone instead of the public internet, satisfying the private-connectivity requirement.

Why this answer

The requirement combines network isolation, customer-defined addressing and traffic control, and private access to a provider service. A virtual private cloud supplies the isolated network and its subnets, route tables, and gateways; security groups and network ACLs provide the traffic control; and a service endpoint keeps storage traffic on the provider backbone. Content delivery, web application firewalls, and hardware security modules address latency, application attacks, and key protection, not network isolation.

Exam trap

The trap here is treating a security appliance such as a web application firewall or hardware security module as if it establishes network isolation, when isolation comes from the virtual network construct itself.

377
MCQhard

A serverless function needs to access a private RDS database inside a VPC. What configuration is required to enable this without using public IP addresses?

A.Store database credentials in the function code
B.Use a NAT Gateway to allow inbound traffic
C.Place the Lambda function inside the VPC using VPC configuration
D.Attach an Internet Gateway to the VPC
AnswerC

Placing the Lambda function inside the VPC via VPC configuration gives it an elastic network interface in a private subnet, allowing it to reach the RDS instance over private IP addresses. No public IP or internet gateway is required for the database connection.

Why this answer

Serverless functions can be configured with VPC integration to access resources inside a VPC via private IP.

378
MCQeasy

A cloud administrator is configuring a new object storage bucket that will hold internal project files. The organization's policy states that data must be encrypted at rest, but the team wants the cloud provider to handle all key management with no additional operational overhead. Which configuration meets this policy with the least administrative effort?

A.Use a third-party encryption gateway that proxies all uploads and encrypts objects before they reach the bucket.
B.Enable the bucket's default server-side encryption using provider-managed keys.
C.Store the files in a bucket without encryption but restrict access using bucket policies.
D.Encrypt each file on the client side before uploading it to the bucket.
AnswerB

Server-side encryption with provider-managed keys encrypts objects at rest automatically and the provider handles key creation, storage, and rotation. It requires no customer key infrastructure or application changes, so it meets the policy of encryption at rest with minimal operational overhead. This is the standard baseline for object storage and is usually enabled by default in modern cloud platforms.

Why this answer

Server-side encryption with provider-managed keys encrypts objects at rest automatically and delegates key lifecycle to the cloud provider. It requires no customer key handling, no application changes, and no extra infrastructure, so it satisfies the encryption-at-rest policy with the least administrative effort. Client-side encryption and third-party gateways add operational burden, while access policies alone do not encrypt data.

Exam trap

The trap here is conflating access control with encryption, when bucket policies restrict who can read data but leave the stored bytes unencrypted.

379
Multi-Selecthard

A global company uses a cloud provider that stores data in multiple jurisdictions. During an eDiscovery request from a US court, which three challenges are most likely to arise? (Choose three.)

Select 3 answers
A.Jurisdictional conflicts over which court has authority
B.Lack of encryption options
C.Ensuring data is preserved without alteration (legal hold)
D.Inability to perform forensically sound collection due to lack of physical access
E.Excessive cost of cloud storage
AnswersA, C, D

Data spanning multiple jurisdictions triggers conflicting legal demands, as foreign privacy or blocking statutes may prohibit disclosure that a US court orders. This jurisdictional conflict over authority is a primary eDiscovery challenge in cross-border cloud environments.

Why this answer

Option A is correct because when data resides in multiple jurisdictions, US court orders can conflict with local data-protection or blocking statutes (e.g., GDPR or foreign blocking laws), creating disputes over which court or legal regime has authority over the data. Option C is correct because eDiscovery requires a legal hold to preserve potentially relevant data in place, and in multi-jurisdiction cloud environments this is complicated by distributed storage, automated lifecycle deletion, and differing retention rules that can alter or destroy evidence. Option D is correct because cloud tenants typically lack physical access to the provider's hardware, so forensically sound collection must rely on provider APIs, snapshots, and chain-of-custody documentation rather than direct disk imaging, which can be challenged in court.

Option B is not correct because major cloud providers offer extensive encryption options (at rest, in transit, and customer-managed keys), so lack of encryption is not an inherent eDiscovery challenge. Option E is not correct because while cloud storage costs exist, excessive cost is not a legal or forensic challenge specific to cross-jurisdiction eDiscovery and is not among the primary issues courts focus on.

Exam trap

The trap is assuming that encryption or cost are major eDiscovery challenges, when the real issues are legal jurisdiction, data preservation, and forensic collection limitations.

380
MCQhard

A cloud security engineer is responsible for a SaaS application hosted on a public cloud provider. The application uses a relational database to store customer data. The security team recently conducted a vulnerability assessment and discovered that the database can be accessed over the internet without any network restrictions. Additionally, the database admin user has the same password as the root account, and the password has not been changed in 18 months. The company is subject to GDPR and PCI DSS compliance requirements. The engineer needs to remediate these issues immediately. Which of the following actions should be taken FIRST?

A.Change the database admin password to a complex new password immediately.
B.Upgrade the database to the latest version with all security patches applied.
C.Configure the database security group to allow traffic only from the application server's IP address range.
D.Enable encryption at rest for the database to protect the data if it is stolen.
AnswerC

Internet-exposed database access is the most severe issue, so restricting the security group to the application server's IP range immediately removes public reachability. This satisfies GDPR and PCI DSS network segmentation requirements before addressing the shared, stale admin password.

Why this answer

The most critical immediate action is to restrict network access to the database, as it is currently exposed to the internet without restrictions. This is the highest risk because it allows anyone to attempt to connect, potentially leading to unauthorized access. Configuring the security group to allow traffic only from the application server's IP range is the first step to remediate the exposure.

While changing the password is also important, the network exposure is the most severe and immediate threat.

Exam trap

The trap is prioritizing password change or encryption over network restriction. Candidates might think that changing the password is the first step, but the exposure to the internet is the most critical vulnerability that must be addressed immediately to prevent unauthorized access.

How to eliminate wrong answers

Option A is wrong because although changing the password is important, it does not address the immediate risk of the database being publicly accessible; an attacker could still attempt to brute-force or exploit vulnerabilities. Option B is wrong because upgrading the database, while good practice, does not address the immediate exposure and is not the first priority. Option D is wrong because enabling encryption at rest protects data if the storage is stolen, but does not prevent unauthorized network access.

381
MCQeasy

A small business is migrating its customer database to a cloud-based database service. The security team wants to ensure that data is encrypted at rest using keys that the business controls, but they do not want to manage the underlying hardware security modules. Which cloud key management option should they choose?

A.Client-side encryption with keys stored on-premises.
B.Provider-managed keys with automatic rotation.
C.Bring your own key (BYOK) using a third-party key management service.
D.Customer-managed keys stored in a cloud KMS.
AnswerD

Customer-managed keys in a cloud KMS allow the business to control key lifecycle and permissions while the provider manages the HSM infrastructure. This meets the requirement for customer-controlled keys without the burden of managing hardware. It also integrates with cloud database services for encryption at rest.

Why this answer

Customer-managed keys in a cloud KMS provide the business with control over key lifecycle and access policies while the cloud provider handles the HSM infrastructure. This balances control with operational simplicity, making it ideal for organizations that want key control without managing hardware.

Exam trap

The trap here is confusing customer-managed keys with provider-managed keys; only customer-managed keys give the business control, but they still rely on the provider's HSM.

382
MCQmedium

A European retailer stores customer personal data in a cloud-hosted e-commerce platform. The cloud provider processes data only on documented instructions from the retailer, which determines the purposes and means of processing. Under the General Data Protection Regulation (GDPR), which role does the cloud provider hold?

A.Independent controller, because it makes technical decisions about storage locations and backup schedules.
B.Data processor, because it processes personal data on behalf of, and only on documented instructions from, the retailer.
C.Data controller, because it operates the physical infrastructure where the personal data resides.
D.Joint controller, because both organizations participate in the processing activity.
AnswerB

GDPR defines a processor as a natural or legal person that processes personal data on behalf of the controller. Because the retailer sets the purposes and means and the provider acts only on documented instructions, the provider is the processor, and Article 28 requires a binding data processing agreement between the two parties.

Why this answer

The GDPR distinguishes controllers, who determine the purposes and means of processing, from processors, who act on the controller's behalf. The retailer decides why and how personal data is processed, while the cloud provider follows documented instructions, making it a processor. This triggers Article 28 obligations, including a mandatory data processing agreement and appropriate technical and organizational measures.

Exam trap

The trap here is assuming that owning or operating the underlying infrastructure automatically makes the cloud provider a controller rather than a processor.

383
MCQhard

A security engineer applies the above bucket policy to an S3 bucket containing sensitive data. Which of the following best describes the effect of this policy?

A.It allows all access to the bucket.
B.It denies access to objects over HTTPS, but allows HTTP.
C.It denies access to objects over HTTP, but allows HTTPS.
D.It denies all access to the bucket.
AnswerC

The policy's condition evaluates the request protocol, so any request arriving over plain HTTP is rejected while TLS-encrypted HTTPS requests proceed normally. This enforces encryption in transit without blocking legitimate secure access to the sensitive objects.

Why this answer

The bucket policy uses a `Deny` effect with a `Condition` block that checks `aws:SecureTransport` equals `false`. This condition denies access when the request is made over HTTP (non-secure transport), effectively blocking HTTP requests while allowing HTTPS requests. The policy does not affect HTTPS requests because the condition only triggers when `SecureTransport` is false.

Exam trap

The trap here is that candidates confuse the `Deny` effect with a blanket denial, missing the conditional `aws:SecureTransport` check, or they misinterpret the condition as denying HTTPS instead of HTTP.

How to eliminate wrong answers

Option A is wrong because the policy explicitly denies access under a specific condition (HTTP), not allowing all access. Option B is wrong because the policy denies HTTP access, not HTTPS; it does not deny access over HTTPS. Option D is wrong because the policy does not deny all access; it only denies access when the request uses HTTP (non-secure transport), leaving HTTPS access permitted.

384
MCQeasy

A company is migrating a legacy application to the cloud. The application uses hardcoded database credentials. Which secure development practice should be implemented to address this?

A.Use code signing for all deployments
B.Implement input validation on all user inputs
C.Enable encryption at rest for the database
D.Use a secrets management service
AnswerD

A secrets management service stores database credentials outside the codebase and injects them at runtime, removing hardcoded values from the application. This satisfies the secure development requirement by centralising rotation, access control and auditing of those credentials.

Why this answer

Hardcoded database credentials in application code create a severe security risk because they are exposed in version control, logs, and static analysis. Using a secrets management service (e.g., AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) allows credentials to be stored securely, rotated automatically, and accessed at runtime via API calls, eliminating the need to embed secrets in code. This aligns with the principle of least privilege and secure credential management in cloud application security.

Exam trap

ISC2 often tests the distinction between 'protecting data at rest' (encryption) and 'protecting access credentials' (secrets management), leading candidates to mistakenly choose encryption at rest when the real issue is credential exposure in code.

How to eliminate wrong answers

Option A is wrong because code signing ensures the integrity and authenticity of the deployed code, but it does not address the problem of hardcoded credentials—it does not remove secrets from the codebase. Option B is wrong because input validation prevents injection attacks (e.g., SQLi, XSS) by sanitizing user-supplied data, but it has no effect on static credentials embedded in the application source code. Option C is wrong because encryption at rest protects data stored in the database (e.g., on disk), but it does not protect the credentials used to access the database—those credentials remain exposed in the code.

385
MCQhard

A cloud security engineer is implementing API Gateway security for a public-facing API. Which combination of controls best protects against both injection attacks and excessive usage?

A.IAM authentication and VPC endpoint
B.JWT validation and WAF integration
C.WAF integration and rate limiting
D.API keys and TLS enforcement
AnswerC

WAF integration inspects HTTP requests and blocks injection payloads such as SQL or command strings, while rate limiting caps requests per client to prevent abuse and denial-of-service. Together they satisfy both the injection and excessive-usage constraints.

Why this answer

WAF integration (C) inspects and filters HTTP requests to block injection attacks like SQLi and XSS, while rate limiting throttles excessive usage to prevent abuse and DoS. Together they address both the content-based threat (injection) and the volume-based threat (excessive usage) in a single combination. This pairing is the standard API Gateway protection pattern for public-facing APIs.

Exam trap

CCSP often tests whether candidates can map threats to controls — the trap is picking authentication or encryption options that sound secure but do not address injection payload inspection or request-volume throttling.

How to eliminate wrong answers

Option A is wrong because IAM authentication and VPC endpoints control access and network path but do not inspect request payloads for injection or throttle request volume. Option B is wrong because JWT validation authenticates callers and WAF blocks injection, but neither addresses excessive usage — there is no rate limiting control. Option D is wrong because API keys provide identification/quota tracking and TLS enforces encryption in transit, but neither inspects payloads for injection nor robustly throttles abusive volume.

386
Multi-Selectmedium

A cloud customer is building its compliance monitoring program for a provider-hosted workload that processes regulated data. The customer must ensure it can demonstrate ongoing compliance to regulators between audits. Which TWO provider commitments should the customer secure in the contract to sustain continuous compliance evidence? (Choose two.)

Select 2 answers
A.A right to obtain current independent audit reports, bridge letters, and certification evidence at least annually and after significant changes.
B.A right to receive the provider's internal penetration test raw findings and unfiltered vulnerability backlog for continuous review.
C.A right to require the provider to adopt the customer's internal control framework verbatim across all its tenants.
D.A right to embed the customer's own auditors full-time inside the provider's data centers to observe live operations.
E.A right to receive timely notification of material changes to the provider's control environment, sub-processors, and security certifications.
AnswersA, E

Regulators expect current evidence, and audit reports are point-in-time. Contractual access to updated SOC 2 reports, bridge letters covering gaps, and renewed certifications ensures the customer can refresh its compliance file without renegotiating each time. This right also supports due diligence when the provider changes its architecture or service scope.

Why this answer

Sustaining compliance between audits requires current evidence and early awareness of change. Contractual rights to timely notification of material changes and to updated audit reports, bridge letters, and certification evidence let the customer refresh its compliance file, reassess risk, and respond to regulator requests without waiting for the next scheduled audit cycle or renegotiating access each year.

Exam trap

The trap here is assuming that continuous compliance requires intrusive continuous access, such as on-site auditors or raw vulnerability data, when the workable contractual levers are change notification and periodic refreshed attestation evidence.

387
MCQhard

A cloud customer is reviewing a provider's SOC 2 Type II report. What does this report primarily attest to?

A.The provider's financial controls and accuracy of billing
B.The design and operating effectiveness of controls over a period
C.Compliance with international data protection regulations like GDPR
D.Penetration test results and vulnerability assessments
AnswerB

A SOC 2 Type II report attests to both the suitability of control design and the operating effectiveness of those controls throughout a specified review period. This period-based testing distinguishes it from Type I, which covers design at a single point in time.

Why this answer

A SOC 2 Type II report attests to the design and operating effectiveness of a service organization's controls over a specified period (typically 3–12 months). It goes beyond a Type I report, which only evaluates control design at a point in time, by testing whether controls operated effectively throughout the audit period.

Exam trap

The trap is confusing SOC 2 Type II with SOC 1 (financial controls) or with regulatory compliance attestations like GDPR — candidates must remember that SOC 2 Type II specifically addresses the design and operating effectiveness of controls over a period, based on the AICPA Trust Services Criteria.

How to eliminate wrong answers

Option A is wrong because SOC 2 focuses on security, availability, processing integrity, confidentiality, and privacy — not financial controls or billing accuracy (that would be SOC 1 or financial audits). Option C is wrong because GDPR compliance is a legal/regulatory determination, not what a SOC 2 report attests to; SOC 2 is based on the AICPA Trust Services Criteria, not GDPR. Option D is wrong because penetration test results and vulnerability assessments are separate artifacts; a SOC 2 report may reference them as evidence but does not primarily attest to them.

388
MCQhard

A healthcare organization runs a multi-tenant SaaS application on a public cloud. Each tenant's data is stored in a shared database with a tenant identifier column. A penetration test shows that a crafted API request can return records belonging to another tenant. The application already authenticates users and validates their tenant membership at login. Which control most directly addresses the root cause of this finding?

A.Enforce tenant scoping in the data access layer by deriving the tenant identifier from the authenticated session and applying it to every query, ignoring any tenant value supplied by the client.
B.Move each tenant's data into a separate database schema and grant the application role access only to the schema matching the authenticated tenant.
C.Require tenants to authenticate with mutual TLS and bind each client certificate to a tenant identifier that the API validates on every request.
D.Add a web application firewall rule that inspects API request bodies for tenant identifier values that differ from the authenticated user's tenant.
AnswerA

The vulnerability is broken object-level authorization: the API trusts a client-supplied tenant identifier instead of binding queries to the authenticated principal. Deriving the tenant from the validated session and injecting it into every query ensures a user can never read another tenant's rows, regardless of what the request contains. This fixes the root cause at the point where data is retrieved.

Why this answer

The penetration test demonstrates broken object-level authorization, where the API accepts a client-controlled tenant identifier and uses it to scope queries. The durable fix is to derive the tenant from the authenticated session and enforce that scope in the data access layer so client input can never widen it. WAF rules, schema separation, and mutual TLS each add defense in depth but do not correct the authorization flaw that allows cross-tenant reads.

Exam trap

The trap here is treating a cross-tenant data leak as an authentication or network problem when the actual defect is server-side authorization of each data access.

389
MCQmedium

An administrator applies the above bucket policy to an S3 bucket containing sensitive data. What is the EFFECT of this policy?

A.Allows public read access
B.Allows access only from specific IP addresses
C.Denies access if the request does not use HTTPS
D.Denies access if the request uses HTTPS
AnswerC

The policy's condition evaluates the aws:SecureTransport key; when the request arrives over plain HTTP, that condition is false, so the explicit Deny statement takes effect. This blocks any non-TLS access to the sensitive bucket contents.

Why this answer

The bucket policy uses a `Deny` effect with a condition `aws:SecureTransport` set to `false`, which means any request that does not use HTTPS (i.e., plain HTTP) is denied. This enforces encryption in transit for all access to the S3 bucket, ensuring sensitive data is not transmitted over an unencrypted channel. Option C correctly identifies that the policy denies access if the request does not use HTTPS.

Exam trap

ISC2 often tests the distinction between `Deny` and `Allow` effects in S3 bucket policies, and the trap here is that candidates misread the condition as denying HTTPS instead of denying non-HTTPS, or they assume the policy grants public access because they overlook the absence of an `Allow` statement.

How to eliminate wrong answers

Option A is wrong because the policy does not contain any `Effect: Allow` statement for public access; it only has a `Deny` statement, so public read access is not granted. Option B is wrong because the policy does not reference the `aws:SourceIp` condition key or any IP address range; it only checks the `aws:SecureTransport` condition. Option D is wrong because the policy denies access when `aws:SecureTransport` is `false`, meaning it denies HTTP, not HTTPS; requests using HTTPS have `aws:SecureTransport` set to `true` and are not denied by this condition.

390
MCQhard

A cloud provider discovers a security incident affecting a customer's personal data stored in its platform. The customer acts as the data controller under the General Data Protection Regulation (GDPR). Which obligation does the provider have regarding notification of this breach?

A.Notify affected data subjects directly, because the provider holds the data and knows which records were exposed.
B.Notify the customer without undue delay after becoming aware of the personal data breach.
C.Notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
D.Publish a public incident report within 24 hours and wait for the customer to respond.
AnswerB

Under GDPR Article 33(2), a processor must notify the controller without undue delay after becoming aware of a personal data breach. The controller then decides whether to notify the supervisory authority within 72 hours. The processor does not notify the authority or data subjects directly in this scenario; its duty runs to the controller.

Why this answer

GDPR splits breach notification duties: processors must notify controllers without undue delay after becoming aware of a personal data breach, while controllers assess risk and handle authority and data subject notifications. The cloud provider, acting as processor, therefore owes prompt notice to its customer, enabling the customer to meet the 72-hour authority deadline if required.

Exam trap

The trap here is assuming the processor must notify the supervisory authority or data subjects directly, when GDPR places those duties on the controller.

391
MCQeasy

A small business uses a cloud provider's default server-side encryption (SSE) to encrypt data at rest in their cloud storage. They are concerned about key management overhead. Which statement best describes the key management responsibility for SSE?

A.The customer and provider share key management responsibilities.
B.Keys are not used; encryption is transparent.
C.The customer generates and manages the keys.
D.The cloud provider manages the keys entirely.
AnswerD

With provider-managed SSE, the cloud provider generates, stores and rotates the data encryption keys entirely within its own key infrastructure; the customer never handles key material. This directly satisfies the small business's stated concern about key management overhead, since no customer-side key lifecycle tasks remain.

Why this answer

With default SSE (e.g., SSE-S3 in AWS), the cloud provider manages the encryption keys entirely. The customer is not involved in key generation, rotation, or storage. CMEK and CSEK require customer involvement.

BYOK involves importing customer keys.

392
MCQmedium

A company is adopting a serverless architecture using AWS Lambda. The security team is concerned about potential injection attacks via event payloads. Which practice is most effective at mitigating such attacks?

A.Use a web application firewall (WAF) in front of the API Gateway
B.Assign the least privilege IAM role to each Lambda function
C.Validate and sanitize all input data from event sources
D.Encrypt environment variables containing sensitive configuration
AnswerC

Validating and sanitising event payloads strips or rejects malicious content before Lambda processes it, breaking the injection path regardless of event source. This addresses the stem's concern directly, since serverless functions cannot rely on network-layer defences to inspect event data.

Why this answer

Serverless functions like AWS Lambda are directly invoked by event payloads, and without input validation and sanitization, an attacker can inject malicious code (e.g., SQL, NoSQL, OS commands) that the function executes. This is the most effective mitigation as it addresses the root cause at the application layer, regardless of any perimeter controls.

Exam trap

ISC2 often tests the misconception that perimeter controls (like WAFs) or IAM permissions are sufficient to prevent application-layer attacks, but the trap here is that injection vulnerabilities are code-level flaws that only input validation can directly remediate.

How to eliminate wrong answers

Option A is wrong because a WAF operates at the HTTP/HTTPS layer and cannot inspect or block injection attacks that originate from non-HTTP event sources (e.g., S3 events, DynamoDB Streams, SQS messages) or from payloads that are already inside the trusted network path. Option B is wrong because least privilege IAM roles control what resources the Lambda function can access (e.g., read from a database), but they do not prevent the function from executing malicious input passed in the event payload. Option D is wrong because encrypting environment variables protects sensitive configuration data at rest and in transit, but it has no effect on injection attacks that exploit unsanitized input in the event payload.

393
MCQmedium

A company is adopting DevSecOps and wants to incorporate security testing into their continuous integration pipeline. They have decided to run SAST (static analysis) and SCA (software composition analysis) tools. Which of the following is the PRIMARY reason for including SCA in addition to SAST?

A.To detect insecure runtime behavior
B.To identify known vulnerabilities in third-party libraries and dependencies
C.To reduce false positives identified by SAST
D.To scan for vulnerabilities in custom APIs
AnswerB

SAST analyses your own source code for coding flaws, so it cannot detect risks inside compiled third-party packages. SCA inventories dependencies and maps them to known CVE databases, satisfying the stem's requirement to cover libraries pulled into the CI pipeline.

Why this answer

SCA (Software Composition Analysis) is specifically designed to identify known vulnerabilities in third-party libraries and dependencies by comparing their versions against public vulnerability databases like the National Vulnerability Database (NVD) or OWASP Dependency-Check. SAST (Static Application Security Testing) analyzes custom source code for security flaws but cannot inspect external libraries that are often pulled in via package managers (e.g., npm, Maven, pip). Including SCA ensures that the organization addresses supply chain risks, which is a primary goal in DevSecOps pipelines.

Exam trap

ISC2 often tests the distinction between SAST (custom code analysis) and SCA (third-party dependency analysis), and the trap here is that candidates may confuse SCA with DAST or think SCA can reduce SAST false positives, when in reality SCA addresses a completely different attack surface—open-source library vulnerabilities.

How to eliminate wrong answers

Option A is wrong because detecting insecure runtime behavior is the domain of DAST (Dynamic Application Security Testing) or IAST (Interactive Application Security Testing), not SCA, which focuses on static analysis of dependency manifests. Option C is wrong because SCA does not reduce false positives from SAST; false positive reduction is typically achieved by tuning SAST rules, using IAST for verification, or implementing manual triage processes. Option D is wrong because scanning for vulnerabilities in custom APIs is a function of SAST (for code-level flaws) or DAST (for runtime API endpoints), not SCA, which only analyzes third-party components and their known CVEs.

394
Multi-Selecteasy

Which THREE of the following are essential characteristics of cloud computing as defined by NIST SP 800-145?

Select 3 answers
A.Multi-tenancy
B.Resource pooling
C.Virtualization
D.On-demand self-service
E.Measured service
AnswersB, D, E

Correct. Resource pooling is one of the five essential characteristics.

Why this answer

Resource pooling is correct because NIST SP 800-145 defines it as one of the five essential characteristics, where the provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with physical and virtual resources dynamically assigned and reassigned according to consumer demand. This enables economies of scale and location independence, as the customer generally has no control or knowledge over the exact location of the provided resources.

Exam trap

ISC2 often tests the distinction between 'multi-tenancy' (a design goal) and 'resource pooling' (the NIST-defined characteristic), and between 'virtualization' (an implementation detail) and the essential characteristics, leading candidates to incorrectly select options that are common in cloud but not in the NIST definition.

395
MCQmedium

A cloud security team is implementing a centralized logging solution for AWS. They need to ensure that all API activity in their production account is logged and that the logs are stored immutably for 7 years to meet compliance requirements. Which service should they use to capture the API activity?

A.Amazon CloudWatch Logs
B.AWS Config
C.Amazon VPC Flow Logs
D.AWS CloudTrail
AnswerD

AWS CloudTrail records API activity in an AWS account, including actions taken by users, roles, and AWS services. It provides event history and can deliver logs to an S3 bucket, which can be configured with Object Lock for immutability. This meets the requirement to capture all API activity and retain logs immutably for 7 years.

Why this answer

AWS CloudTrail is the service that records API activity in an AWS account, making it the correct choice for capturing all API calls. It integrates with Amazon S3, where logs can be stored with Object Lock to enforce immutability for compliance. The other services either focus on resource configuration, network traffic, or application logs, and cannot provide the comprehensive API auditing required.

Exam trap

The trap here is confusing AWS Config with CloudTrail, as both are auditing services, but only CloudTrail records API activity.

396
MCQhard

A company is implementing a serverless application using AWS Lambda. The function processes S3 events and writes to a DynamoDB table. Which of the following is the MOST secure way to grant the necessary permissions?

A.Use resource-based policies on the Lambda function
B.Attach a managed policy that grants full access to S3 and DynamoDB
C.Use the root user credentials of the AWS account
D.Create a custom IAM role with only the required actions on specific resources
AnswerD

A custom IAM role grants only the specific S3 read and DynamoDB write actions on named resource ARNs, enforcing least privilege. Lambda assumes this role at runtime, avoiding broad managed policies or long-lived access keys embedded in the function.

Why this answer

AWS Lambda functions require an IAM role (execution role) to access other AWS services. By creating a custom IAM role with only the required actions (e.g., s3:GetObject for the specific S3 bucket and dynamodb:PutItem for the specific DynamoDB table), you adhere to the principle of least privilege, minimizing the attack surface and ensuring secure, auditable access.

Exam trap

ISC2 often tests the misconception that resource-based policies on the Lambda function can grant the function permissions to other services, when in fact they only control invocation permissions, not the function's outbound access to resources like S3 or DynamoDB.

How to eliminate wrong answers

Option A is wrong because resource-based policies on a Lambda function control who can invoke the function, not what the function can access; they do not grant the function permissions to S3 or DynamoDB. Option B is wrong because attaching a managed policy that grants full access to S3 and DynamoDB violates least privilege, potentially allowing the function to perform unintended actions (e.g., delete data) and increasing the blast radius of a compromise. Option C is wrong because using root user credentials is a severe security risk—root credentials have unrestricted access, should never be used for programmatic access, and violate AWS best practices and compliance requirements.

397
MCQhard

A cloud customer is subject to a regulatory audit and must provide evidence of the cloud provider's security controls. The provider refuses to allow direct audits of its data centers. Which artifact should the customer rely on to satisfy the auditors?

A.Provider's self-assessment questionnaire
B.Penetration test summary
C.ISO/IEC 27001 certificate
D.SOC 2 Type II report
AnswerD

A SOC 2 Type II report provides independent attestation of a service organization's controls over security, availability, processing integrity, confidentiality, and privacy over a period. It is designed for cloud providers to share with customers to demonstrate effective controls without granting direct audit rights. Auditors typically accept SOC 2 Type II as sufficient evidence, making it the appropriate artifact in this scenario.

Why this answer

A SOC 2 Type II report is specifically designed to provide independent assurance over a period, covering the Trust Services Criteria. It is widely accepted by auditors as evidence of a cloud provider's security controls when direct audits are not feasible. Other artifacts like ISO 27001 certificates or self-assessments do not offer the same level of detailed, independent validation of control operation.

Exam trap

The trap here is confusing an ISO/IEC 27001 certificate, which certifies the management system, with a SOC 2 Type II report, which attests to the effectiveness of specific controls over time.

398
MCQmedium

Which of the following is an example of a cloud interoperability standard that facilitates portability of containerized applications across different cloud environments?

A.SOC 2 Type II
B.CSA STAR
C.ISO 27001
D.Kubernetes
AnswerD

Kubernetes is an open-source container orchestration standard whose portable API and workload definitions let containerised applications move between cloud environments without provider-specific rewriting. That vendor-neutral abstraction directly delivers the portability the stem requires, unlike proprietary platform services.

Why this answer

Kubernetes is an open-source container orchestration platform whose API and manifests (pods, deployments, services) are portable across cloud providers, making it the de facto interoperability standard for containerized workloads. It is governed by the CNCF and implemented by AWS EKS, Azure AKS, GCP GKE, and on-prem distributions, enabling workload portability.

Exam trap

The trap is conflating security/compliance frameworks (SOC 2, ISO 27001, CSA STAR) with technical interoperability standards — candidates who see 'standard' and think 'certification' may pick an audit framework instead of the actual orchestration technology (Kubernetes).

How to eliminate wrong answers

Option A is wrong because SOC 2 Type II is an auditing attestation about a service organization's controls, not a technical interoperability standard for containers. Option B is wrong because CSA STAR is a cloud security assurance program (based on the Cloud Controls Matrix) that assesses provider security posture, not a portability standard. Option C is wrong because ISO 27001 is an information security management system standard — a governance/audit framework, not a container portability specification.

399
MCQmedium

A financial services company runs sensitive workloads on a public IaaS cloud. The security team wants to cryptographically prove to auditors that the virtual machine hosting their data booted an unmodified, approved hypervisor and firmware image. Which cloud infrastructure security capability should they require from the provider?

A.Full-disk encryption of the guest operating system volumes
B.Measured boot with attestation using a virtual TPM
C.Security groups restricting inbound management ports
D.Immutable infrastructure with golden VM images
AnswerB

A virtual TPM records hashes of firmware, bootloader, and hypervisor components into platform configuration registers during the boot chain, and remote attestation lets the tenant verify those measurements against a known-good baseline. This gives cryptographic evidence that the platform was not tampered with, directly satisfying the auditor's requirement for proof of an untampered boot.

Why this answer

Measured boot combined with remote attestation uses a virtual TPM to hash each stage of the boot chain and expose those measurements for verification. Because the auditor needs cryptographic proof that firmware and hypervisor code were unmodified, this is the only listed control that observes the platform boot itself rather than the guest workload or network perimeter.

Exam trap

The trap here is assuming that guest-level controls such as disk encryption or hardened images can attest to the integrity of the provider-controlled hypervisor and firmware beneath them.

400
Multi-Selecthard

A cloud security team is implementing data discovery and classification for a multi-cloud environment. They need to identify sensitive data such as personally identifiable information (PII) and protected health information (PHI) across structured and unstructured data stores. Which TWO approaches are MOST effective for accurate and scalable data discovery in this scenario? (Choose two.)

Select 2 answers
A.Use cloud-native data discovery services that integrate with the provider's storage and database services.
B.Deploy a third-party data discovery tool that supports multiple cloud providers and can scan both structured and unstructured data.
C.Use encryption to protect all data and assume that encrypted data does not need classification.
D.Implement network-based data loss prevention (DLP) appliances to inspect data in transit.
E.Rely on manual data tagging by data owners during data creation.
AnswersA, B

Cloud-native discovery services are designed to work with the provider's storage and database offerings, offering deep integration, automatic scaling, and reduced operational overhead. They can scan objects, files, and databases for sensitive data patterns and often include prebuilt classifiers for PII, PHI, and other data types. This makes them highly effective for multi-cloud environments when used per provider, though cross-cloud management may require additional tooling.

Why this answer

Cloud-native discovery services offer deep integration and scalability within each provider, while third-party multi-cloud tools provide a unified, cross-provider view and consistent classification. Together, they enable accurate and scalable discovery across structured and unstructured data in a multi-cloud environment. Manual tagging and network DLP are not sufficient for comprehensive data-at-rest discovery, and encryption does not remove the need for classification.

Exam trap

The trap here is assuming that encryption eliminates the need for data discovery and classification, or that manual tagging can scale in a multi-cloud environment.

401
Multi-Selectmedium

A cloud application uses IAM roles with wildcard permissions (e.g., iam:* or *:*). Which TWO risks are directly associated with such over-permissive IAM policies?

Select 2 answers
A.Denial of service against other cloud services
B.Privilege escalation to administrative roles
C.Increased cost due to unnecessary resource usage
D.Difficulty in auditing permissions due to logging overhead
E.Unauthorized data exfiltration from S3 buckets or databases
AnswersB, E

Wildcard actions such as iam:* let a compromised principal create policies, attach roles, or pass roles to resources, granting itself full administrative rights. This satisfies the stem's over-permissive IAM role constraint, where the absence of least privilege permits direct escalation to administrative access.

Why this answer

Option B is correct because wildcard IAM policies such as iam:* or *:* allow an identity to perform sensitive IAM actions like CreatePolicyVersion, AttachRolePolicy, or PutRolePolicy, which an attacker can abuse to grant themselves administrative privileges and escalate beyond their intended role. Option E is correct because *:* or broad service wildcards (for example s3:* or rds:*) permit actions like s3:GetObject, s3:ListBucket, or rds:DownloadDBLogFilePortion, enabling unauthorized reading and exfiltration of data from S3 buckets or databases. Option A is not directly tied to over-permissive IAM policies; denial of service typically stems from resource exhaustion, throttling, or destructive actions rather than the breadth of permissions alone.

Option C is a possible side effect of misuse but is not a direct risk of wildcard permissions themselves. Option D is incorrect because wildcard policies reduce audit clarity by obscuring which actions are actually granted, not because of logging overhead.

402
MCQhard

A cloud architect is designing a data lifecycle policy for a SaaS application. According to the cloud data lifecycle, which phase immediately follows the 'Share' phase?

A.Store
B.Archive
C.Use
D.Destroy
AnswerB

In the cloud data lifecycle, Archive directly follows Share, since data no longer actively used moves into long-term retention. This satisfies the stem's requirement for the phase immediately after Share, distinguishing it from Create, Store, Use, and Destroy.

Why this answer

In the CSA cloud data lifecycle (Create, Store, Use, Share, Archive, Destroy), the Archive phase immediately follows Share. Archiving moves data that is no longer actively used but must be retained for compliance or business reasons into long-term, lower-cost storage.

Exam trap

CCSP often tests memorization of the exact CSA data lifecycle sequence — the trap is confusing the order of Use, Share, and Archive, since intuitively one might think Use comes after Share or that Store follows Share, when the canonical order is Create → Store → Use → Share → Archive → Destroy.

How to eliminate wrong answers

Option A is wrong because Store occurs earlier in the lifecycle (after Create), before Use and Share — it is not the phase after Share. Option C is wrong because Use precedes Share in the CSA lifecycle model; data is used by applications/users before it is shared with others. Option D is wrong because Destroy is the final phase, occurring after Archive, not immediately after Share.

403
Multi-Selectmedium

A cloud architect is evaluating cloud service models for a new application. Which two characteristics are advantages of PaaS over IaaS? (Choose two.)

Select 2 answers
A.Greater control over the underlying OS
B.Lower cost due to shared infrastructure
C.Reduced management of middleware and runtime
D.Higher flexibility to customize networking
E.Built-in scalability and high availability
AnswersC, E

PaaS abstracts the middleware and runtime layers, so the provider patches, scales and maintains application servers, message brokers and language runtimes. IaaS leaves these to the customer, who must install and update them on provisioned virtual machines, adding operational overhead that PaaS removes.

Why this answer

Option C is correct because PaaS abstracts the middleware, runtime, and often the OS layer, so the provider handles patching, configuration, and upgrades of components such as application servers, language runtimes, and databases, leaving the customer to focus on code and data. Option E is correct because PaaS platforms typically include built-in autoscaling, load balancing, and high-availability features (e.g., managed instance groups, health checks, and multi-zone deployment) that the customer would otherwise have to architect and operate manually on IaaS. Option A is not an advantage of PaaS over IaaS, since IaaS gives greater control over the guest OS (root/admin access, custom kernels, and OS-level tuning) while PaaS restricts that control.

Option B is not inherently true, as PaaS pricing is usually higher per compute unit than raw IaaS VMs because it bundles managed services, and cost depends on workload and usage patterns rather than being automatically lower. Option D is also not an advantage of PaaS, because IaaS offers more flexibility to customize networking (VPCs, subnets, route tables, security groups, and virtual appliances) than the more opinionated networking model of most PaaS offerings.

Exam trap

ISC2 often tests the misconception that PaaS is always cheaper than IaaS due to shared infrastructure, but the real advantage is reduced management of middleware and runtime, not guaranteed cost savings.

404
Drag & Dropmedium

Drag and drop the steps for performing a cloud migration using the 'lift and shift' strategy into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First assess, then set up target, replicate, transfer data, and finally test and cut over.

405
MCQmedium

A company wants to use a cloud KMS to encrypt data but requires that the encryption key never leaves their on-premises hardware security module (HSM) due to compliance. Which key management model should they adopt?

A.Customer-Managed Encryption Key (CMEK)
B.Customer-Supplied Encryption Key (CSEK)
C.Hold Your Own Key (HYOK)
D.Bring Your Own Key (BYOK)
AnswerC

Hold Your Own Key keeps cryptographic material inside the customer's on-premises HSM, so encryption and decryption occur locally and only ciphertext reaches the cloud KMS. This satisfies the compliance constraint that the key never leaves the HSM, unlike cloud-hosted models where key material resides in the provider's infrastructure.

Why this answer

HYOK (Hold Your Own Key) is the only model where the encryption key material is generated, stored, and used exclusively within the customer's on-premises HSM and never exported to the cloud provider. The cloud KMS is used only to wrap or reference the key, satisfying compliance mandates that keys must remain under customer physical control. CMEK, CSEK, and BYOK all involve the key material being imported into or generated within the cloud provider's infrastructure at some point.

Exam trap

CCSP often tests the distinction between BYOK (import your key into the cloud KMS) and HYOK (key never leaves your premises), so candidates who assume 'bring your own key' means the key stays on-premises pick BYOK incorrectly.

How to eliminate wrong answers

Option A is wrong because CMEK keys are generated and stored inside the cloud provider's KMS, so the key material resides in the provider's HSM, not the customer's on-premises HSM. Option B is wrong because CSEK keys are supplied by the customer at request time but are still transmitted to and used by the cloud service, meaning the key leaves customer control. Option D is wrong because BYOK typically means the customer generates the key on-premises but then imports it into the cloud KMS, after which the key material resides in the provider's HSM.

406
Drag & Dropmedium

Drag and drop the steps for setting up a cloud access security broker (CASB) in a SaaS environment into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Start with policy definition, then deploy, configure, test, and finally full rollout.

407
Multi-Selectmedium

Which TWO data states must be encrypted to meet common compliance requirements for data in the cloud? (Choose two.)

Select 2 answers
A.Data in audit logs
B.Data in backup
C.Data at rest
D.Data in transit
E.Data in use
AnswersC, D

Required by regulations like PCI DSS, HIPAA.

Why this answer

Data at rest (C) must be encrypted because compliance frameworks like PCI DSS, HIPAA, and GDPR require protection of stored data against unauthorized access. Encryption at rest typically uses AES-256 or similar algorithms to secure data on disks, databases, or object storage, ensuring that even if physical media is compromised, the data remains unreadable.

Exam trap

ISC2 often tests the distinction between data states and data locations, so the trap here is that candidates confuse 'data in backup' or 'data in audit logs' as separate states when they are actually subsets of data at rest or in transit.

408
MCQeasy

A company has a contractual requirement that the CSP must delete all customer data within 30 days of contract termination. Which document should specify this requirement?

A.Business Associate Agreement (BAA)
B.Data Processing Agreement (DPA)
C.Memorandum of Understanding (MOU)
D.Service Level Agreement (SLA)
AnswerB

A DPA is the contractual instrument that binds the processor to the controller's data-handling terms, so the 30-day deletion obligation belongs here. It satisfies the stem's contractual requirement by making deletion enforceable, unlike a generic SLA or security whitepaper.

Why this answer

The Data Processing Agreement (DPA) outlines data handling obligations, including deletion requirements. SLAs cover performance, BAAs are for HIPAA, and MOUs are high-level.

409
MCQmedium

An organization wants to assess the security controls of a cloud provider before entering into a contract. What is the most efficient method?

A.Request a penetration test report
B.Conduct an on-site audit
C.Perform vulnerability scanning
D.Review a SOC 2 Type II report
AnswerD

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of a cloud provider's controls over a period, giving efficient assurance without on-site assessment. It satisfies the pre-contract due diligence requirement more efficiently than questionnaires or point-in-time attestations.

Why this answer

Reviewing a SOC 2 Type II report provides an independent assessment of a provider's controls over time. On-site audits are costly and time-consuming. Vulnerability scanning and penetration test reports may not be available or comprehensive.

410
MCQeasy

An organization is using GCP and wants to collect audit logs for all API calls made within the project. Which GCP service should be enabled to capture these logs?

A.VPC Flow Logs
B.Cloud Audit Logs
C.Cloud Monitoring
D.Cloud Security Command Center
AnswerB

Cloud Audit Logs captures Admin Activity and Data Access entries for every API call in the project, satisfying the requirement to record all API activity. Enabling it at project level provides the audit trail directly, unlike Cloud Logging, which aggregates logs but does not itself generate API audit records.

Why this answer

Cloud Audit Logs is the correct GCP service because it automatically records API calls and administrative activities within a GCP project. It captures Admin Activity, Data Access, System Event, and Policy Denied logs, providing a comprehensive audit trail of who did what, where, and when. This is essential for security, compliance, and forensic investigations.

Exam trap

CCSP often tests the confusion between network-level logging (VPC Flow Logs) and API-level auditing (Cloud Audit Logs), so candidates must remember that audit logs capture control plane and data plane API calls, not packet flows.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) for VPC subnets, not API calls or audit events. Option C is wrong because Cloud Monitoring is for collecting metrics, traces, and dashboards to observe system performance, not for auditing API activity. Option D is wrong because Cloud Security Command Center aggregates security findings and asset inventory, but it does not itself capture API audit logs; it may consume them, but the primary service for audit logs is Cloud Audit Logs.

411
MCQmedium

A client is negotiating a cloud service agreement and wants to conduct on-site audits of the provider's data centers. The provider argues that on-site audits are unnecessary due to SOC 2 reports. Which is the best approach for the client?

A.Request a right to review SOC 2 reports and conduct limited assessments
B.Insist on on-site audits
C.Terminate negotiations
D.Accept SOC 2 reports as sufficient
AnswerA

SOC 2 reports provide independent assurance but do not grant the client contractual audit rights. Requesting report review plus limited assessment rights preserves oversight and satisfies the client's assurance need without forcing costly full on-site audits the provider resists, balancing diligence against operational practicality.

Why this answer

The client should request a right to review SOC 2 reports and conduct limited assessments because SOC 2 reports provide a point-in-time snapshot of controls, but they do not cover real-time operational changes, custom configurations, or specific contractual requirements. On-site audits may be impractical due to multi-tenancy and shared infrastructure, so a balanced approach of reviewing SOC 2 reports plus targeted assessments (e.g., reviewing evidence of key controls, interviewing staff, or examining specific systems) gives the client sufficient assurance without disrupting the provider's operations.

Exam trap

The trap here is that candidates assume on-site audits are always necessary for compliance, but the CCSP exam emphasizes that cloud providers typically rely on third-party attestations (like SOC 2, ISO 27001) and that physical audits are often impractical due to multi-tenancy and security risks.

How to eliminate wrong answers

Option B is wrong because insisting on on-site audits ignores the provider's legitimate concerns about security, multi-tenancy, and operational disruption; in cloud environments, on-site audits are often replaced by third-party attestations like SOC 2, and the provider may not allow physical access due to shared infrastructure. Option C is wrong because terminating negotiations is premature and disproportionate; the client can still achieve reasonable assurance through SOC 2 reports and limited assessments without walking away. Option D is wrong because accepting SOC 2 reports as sufficient without any additional verification fails to account for the report's scope limitations (e.g., it may not cover all relevant controls, and it is a snapshot in time), leaving the client exposed to risks not addressed by the report.

412
MCQhard

A healthcare organization is migrating its electronic health record (EHR) system to a public cloud. The system stores sensitive patient data subject to HIPAA. The cloud architect has designed a multi-tier architecture with load balancers, web servers, application servers, and a PostgreSQL database. The database contains ePHI. To meet compliance, the architect plans to encrypt the database at rest using AWS RDS encryption with KMS. However, during a security review, the compliance officer notes that the database backups are stored in an S3 bucket that is not encrypted. Additionally, the application logs, which may contain patient data, are sent to CloudWatch Logs without encryption. The compliance officer insists that all data stores containing ePHI must be encrypted at rest. Which action should the architect take to ensure compliance?

A.Enable S3 bucket encryption for backups and enable encryption for CloudWatch Logs using KMS.
B.Disable automated backups and rely on point-in-time recovery.
C.Enable encryption on the RDS instance and use encrypted replicas.
D.Enable encryption on the S3 bucket only, since backups are the main concern.
AnswerA

Enabling SSE-KMS on the S3 backup bucket and KMS encryption on the CloudWatch log group closes the two unencrypted ePHI stores the compliance officer identified, satisfying the mandate that every data store holding ePHI be encrypted at rest.

Why this answer

HIPAA requires encryption of ePHI at rest in all data stores. The S3 bucket containing unencrypted database backups and the CloudWatch Logs that may contain patient data both need encryption enabled via KMS to meet compliance. AWS RDS encryption protects the live database, but backups and logs are separate storage locations that must also be encrypted.

Exam trap

The trap here is that candidates assume encrypting the RDS instance automatically encrypts all associated data stores, such as backups exported to S3 and CloudWatch Logs, when in fact each service requires separate encryption configuration.

How to eliminate wrong answers

Option B is wrong because disabling automated backups does not address the existing unencrypted backups in S3 or the unencrypted CloudWatch Logs, and point-in-time recovery still relies on encrypted storage. Option C is wrong because the RDS instance is already encrypted with RDS encryption; the issue is the backups in S3 and CloudWatch Logs, not the database itself. Option D is wrong because it only addresses the S3 bucket and ignores the CloudWatch Logs, which also contain ePHI and must be encrypted to comply with HIPAA.

413
MCQmedium

A cloud customer stores personal data of EU residents in a SaaS application. The customer's contract with the SaaS provider includes a data processing addendum. The customer's legal team wants to understand the allocation of GDPR responsibilities. Which of the following best describes the roles of the customer and the SaaS provider under GDPR?

A.The customer is the processor and the SaaS provider is the controller because the provider hosts the data
B.The SaaS provider is the sole controller because it owns the infrastructure and determines the security measures
C.The customer is the controller and the SaaS provider is the processor, unless the provider processes data for its own purposes, in which case it may also be a controller for those specific activities
D.Both the customer and the SaaS provider are joint controllers for all processing activities
AnswerC

Under GDPR, the customer typically determines the purposes and means of processing and is the controller. The SaaS provider acts as a processor when it processes personal data solely on the customer's instructions. However, if the provider uses data for its own purposes, such as improving its services or marketing, it becomes a controller for those activities. This nuanced allocation is common in cloud contracts and data processing addenda.

Why this answer

In a typical SaaS arrangement, the customer is the controller and the provider is the processor. The provider may become a controller for specific processing done for its own purposes, such as service analytics or marketing. This dual role is recognized in GDPR and should be addressed in the data processing addendum.

Exam trap

The trap here is assuming that the cloud provider is always just a processor, when in fact it can also be a controller for certain activities, or conversely assuming that hosting data makes the provider the controller.

414
MCQmedium

An organization wants to ensure that all resources are compliant with CIS benchmarks. Which cloud service provides a unified view of compliance posture and recommendations?

A.Security Information and Event Management (SIEM) tool
B.Cloud Security Posture Management (CSPM) tool
C.Cloud monitoring and logging service
D.Policy-as-code enforcement service
AnswerB

A CSPM tool continuously assesses cloud resources against benchmarks such as CIS, aggregating findings into a unified compliance dashboard with prioritised remediation recommendations. This directly satisfies the stem's requirement for a single view of compliance posture, unlike native logging or inventory services that report raw configuration data without benchmark mapping.

Why this answer

A cloud security posture management (CSPM) tool provides a unified, centralized view of an organization's security and compliance posture, including specific recommendations aligned with CIS benchmarks. It aggregates findings from various security controls into a single score and actionable guidance, making it the correct service for monitoring compliance against CIS standards.

Exam trap

The trap here is that candidates confuse a policy enforcement service (which enforces rules) with a cloud security posture management (CSPM) tool (which provides the unified compliance posture and scoring), or they mistakenly think cloud monitoring and logging or SIEM services can serve as a compliance dashboard when they are designed for other purposes.

How to eliminate wrong answers

Option A is wrong because Azure Sentinel is a cloud-native SIEM/SOAR solution focused on threat detection, investigation, and response, not on providing a unified compliance posture view or CIS benchmark recommendations. Option C is wrong because Azure Monitor collects and analyzes telemetry data (metrics, logs) for performance and health monitoring, but it does not natively aggregate compliance posture or provide CIS benchmark-specific recommendations. Option D is wrong because Azure Policy enforces and audits compliance rules (e.g., tagging, allowed locations) but does not present a unified, scored compliance posture view; it is a building block that feeds into Secure Score, not the unified dashboard itself.

415
Multi-Selectmedium

A cloud security team is implementing data loss prevention (DLP) for a SaaS application that stores sensitive documents. They need to detect and prevent unauthorized sharing of documents containing personally identifiable information (PII). Which two cloud data security controls should be implemented? (Choose two.)

Select 2 answers
A.Data classification and labeling of documents based on content
B.Encryption of documents at rest with customer-managed keys
C.Regular security awareness training for employees
D.Multi-factor authentication (MFA) for all users accessing the SaaS application
E.Cloud access security broker (CASB) with DLP policies
AnswersA, E

Data classification and labeling automatically identify and tag documents containing PII. This enables DLP policies to be applied based on labels, ensuring that sensitive documents are subject to stricter sharing controls. It is a foundational control for effective DLP, as it helps the system understand which data requires protection.

Why this answer

To detect and prevent unauthorized sharing of PII in a SaaS application, the team needs both a CASB with DLP policies and data classification and labeling. The CASB provides the enforcement mechanism to inspect and control data flows, while classification and labeling identify which documents contain PII so that DLP policies can be applied effectively. Together, they form a comprehensive DLP solution.

Exam trap

The trap here is assuming that encryption or MFA alone can prevent data loss; they protect data but do not detect or stop sharing by authorized users.

416
MCQeasy

Which NIST-defined cloud characteristic ensures that resources can be scaled up and down rapidly based on demand?

A.Broad network access
B.Rapid elasticity
C.Measured service
D.Resource pooling
AnswerB

Rapid elasticity is the NIST characteristic permitting capabilities to be provisioned and released elastically, scaling outward and inward commensurate with demand. It directly satisfies the stem's requirement that resources scale up and down rapidly as demand changes.

Why this answer

Rapid elasticity is the NIST-defined essential characteristic that allows cloud resources to be provisioned and released automatically, scaling outward and inward commensurate with demand. It enables the cloud consumer to scale capabilities elastically, often in near real-time, without human intervention. This characteristic directly addresses the ability to scale up and down rapidly based on demand, as stated in the question.

Exam trap

CCSP often tests the confusion between rapid elasticity and resource pooling, as both involve dynamic resource allocation, but only rapid elasticity specifically addresses scaling up and down based on demand.

How to eliminate wrong answers

Option A is wrong because broad network access refers to the capability of resources being available over the network through standard mechanisms, not to scaling. Option C is wrong because measured service relates to monitoring, controlling, and reporting resource usage for billing and metering, not to rapid scaling. Option D is wrong because resource pooling describes the multi-tenant model where physical and virtual resources are dynamically assigned and reassigned according to demand, but it does not specifically ensure rapid scaling up and down.

417
MCQmedium

An organization uses a cloud-based DLP solution to monitor outbound traffic. They want to prevent the exfiltration of credit card numbers. Which detection technique is most appropriate for this requirement?

A.Exact data matching against a list of known card numbers
B.Machine learning classification of sensitive data
C.Fingerprinting of known credit card documents
D.Regular expression matching for credit card number patterns
AnswerD

Credit card numbers follow a fixed numeric structure with defined prefixes and lengths, so regular expression matching reliably identifies candidate patterns in outbound traffic. This signature-based technique targets the specific data type the organisation wants to block from leaving.

Why this answer

Regular expression matching (option D) is the most appropriate technique because credit card numbers follow well-defined, predictable patterns (e.g., 16 digits, specific starting digits for each issuer like 4 for Visa, 5 for MasterCard, and Luhn algorithm validation). This allows the DLP solution to detect credit card numbers in outbound traffic without requiring a pre-populated list or prior training, making it ideal for real-time monitoring of unknown or new card numbers.

Exam trap

ISC2 often tests the misconception that machine learning (option B) is always the most advanced or accurate technique, but for structured data like credit card numbers, regex is simpler, faster, and more precise.

How to eliminate wrong answers

Option A is wrong because exact data matching requires a pre-compiled list of known credit card numbers, which is impractical for detecting unknown or newly issued cards and does not scale for outbound traffic monitoring. Option B is wrong because machine learning classification is better suited for identifying unstructured or context-dependent sensitive data (e.g., legal documents) and introduces latency and false positives for a well-defined pattern like credit card numbers. Option C is wrong because fingerprinting of known credit card documents is designed to detect specific files (e.g., PDFs or spreadsheets) containing card numbers, not to identify card numbers in arbitrary outbound traffic such as emails or web requests.

418
Multi-Selecteasy

A security engineer is implementing automated incident response for common cloud threats. Which TWO cloud services can be used together to create a serverless orchestration workflow for incident response? (Choose two.)

Select 2 answers
A.Orchestration service for serverless workflows
B.Serverless compute service
C.Infrastructure as code service
D.Virtual machine service
E.Vulnerability management service
AnswersA, B

A serverless orchestration service, such as AWS Step Functions, sequences incident response steps, branching and retrying between Lambda invocations. It satisfies the serverless orchestration workflow requirement by coordinating state across tasks without provisioning servers, complementing the serverless compute service chosen alongside it.

Why this answer

Option A, an orchestration service for serverless workflows (such as AWS Step Functions), is correct because it provides the state-machine logic that coordinates, sequences, and branches incident-response steps without managing servers. Option B, a serverless compute service (such as AWS Lambda), is correct because it executes the actual response actions—enriching findings, isolating resources, or notifying teams—as event-driven functions invoked by the orchestration workflow. Together, A and B form a fully serverless orchestration pipeline: the workflow service defines the incident-response state machine while the compute service runs the per-step code.

Option C, infrastructure as code, is for declaratively provisioning resources, not for orchestrating runtime incident-response logic. Option D, a virtual machine service, requires managing persistent instances and is not serverless. Option E, vulnerability management, identifies weaknesses but does not orchestrate or execute response workflows.

Exam trap

The trap is confusing orchestration with infrastructure as code or monitoring services; candidates might pick CloudFormation or Inspector, but the key is serverless workflow orchestration and compute.

419
MCQeasy

Which characteristic of cloud computing allows a user to automatically provision computing resources without requiring human interaction with the service provider?

A.On-demand self-service
B.Rapid elasticity
C.Broad network access
D.Resource pooling
AnswerA

On-demand self-service lets consumers provision compute, storage and networking capabilities unilaterally through automated interfaces, with no human interaction from the provider. This matches the stem's requirement precisely, distinguishing it from broad network access or rapid elasticity.

Why this answer

On-demand self-service is the essential cloud characteristic that enables a consumer to unilaterally provision computing capabilities, such as server time and network storage, automatically without requiring human interaction with each service provider. This is exactly what the question describes: automatic provisioning without human interaction. Rapid elasticity, broad network access, and resource pooling are related but distinct characteristics that do not specifically address the automatic provisioning aspect.

Exam trap

CCSP often tests the distinction between the five essential characteristics of cloud computing, and candidates frequently confuse on-demand self-service with rapid elasticity because both involve automatic scaling; however, the key differentiator is that on-demand self-service is about provisioning without human interaction, while rapid elasticity is about scaling capabilities.

How to eliminate wrong answers

Option B is wrong because rapid elasticity refers to the ability to scale resources outward and inward commensurate with demand, but it does not inherently include the automatic provisioning without human interaction; elasticity can be achieved manually or automatically, and it focuses on scaling rather than the self-service provisioning mechanism. Option C is wrong because broad network access means capabilities are available over the network through standard mechanisms, but it does not address the automatic provisioning without human interaction; it is about accessibility, not self-service. Option D is wrong because resource pooling refers to the provider's resources being pooled to serve multiple consumers using a multi-tenant model, but it does not describe the user's ability to automatically provision resources without human interaction; it is about the provider's architecture, not the user's self-service capability.

420
MCQeasy

Which of the following is the most granular method to grant time-limited access to a specific object in a cloud storage bucket without requiring the requester to have cloud provider credentials?

A.Bucket ACLs
B.Bucket policies with conditions
C.Identity-based policies
D.Signed URLs
AnswerD

Signed URLs embed a cryptographic signature and expiry directly in the URL, granting time-limited access to one specific object. The requester needs no cloud provider credentials, satisfying the granularity and credential-free constraints in the stem.

Why this answer

Signed URLs (also called presigned URLs) are generated by the object owner using their own credentials and embed a cryptographic signature plus an expiration timestamp directly in the URL. Anyone holding the URL can retrieve that single object until the expiry time, without needing any cloud provider identity or credentials. This makes them the most granular, time-limited access mechanism for a specific object.

Exam trap

CCSP often tests the distinction between identity-based access (requires credentials) and resource-based, time-limited access (signed URLs), so candidates who reflexively pick 'bucket policy' or 'IAM role' miss the credential-free, per-object granularity requirement.

How to eliminate wrong answers

Option A is wrong because bucket ACLs grant permissions at the bucket or object level to predefined grantees (users, groups, or authenticated users) and do not natively provide time-limited, credential-free access. Option B is wrong because bucket policies with conditions apply to principals defined in IAM or the account, still requiring the requester to authenticate with cloud credentials. Option C is wrong because identity-based policies are attached to IAM principals and require the requester to have a cloud identity and credentials — the opposite of the requirement.

421
MCQeasy

Which practice helps prevent hardcoded cloud credentials from being committed to source code repositories?

A.Implementing secrets management with a vault service
B.Using environment variables for all configuration
C.Storing credentials in a configuration file with restricted permissions
D.Using a .gitignore file to exclude credential files
AnswerA

A vault service stores credentials outside the repository and injects them at runtime, so no secret ever enters commit history. This directly satisfies the stem's constraint by removing hardcoded values from source code, and rotation invalidates any credential previously exposed.

Why this answer

A secrets management vault (e.g., HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) stores credentials outside the codebase and injects them at runtime, so no secret ever exists in the repository. This directly prevents hardcoded credentials from being committed because developers never need to embed them in source files. Vault services also provide rotation, auditing, and access control, which are not achievable with file-based approaches.

Exam trap

The trap is treating .gitignore or environment variables as sufficient controls — candidates assume 'not in the repo' equals 'not hardcoded,' but the exam wants the control that structurally removes secrets from the codebase entirely.

How to eliminate wrong answers

Option B is wrong because environment variables still require the credential value to be defined somewhere — often in .env files, CI configs, or shell scripts that can be committed or leaked, and they offer no rotation or audit trail. Option C is wrong because a configuration file with restricted permissions is still a file on disk that can be accidentally committed, copied, or exposed; permissions do not prevent source control inclusion. Option D is wrong because .gitignore only prevents untracked files from being added — it does nothing if the file was already committed, if a developer uses 'git add -f', or if the secret is pasted directly into a tracked source file.

422
Multi-Selecthard

A cloud security architect is designing a secure CI/CD pipeline for a containerized application deployed on a Kubernetes cluster. The pipeline must ensure that only approved images are deployed. Which TWO of the following controls should be implemented? (Choose two.)

Select 2 answers
A.Implement role-based access control (RBAC) to restrict who can push images to the registry.
B.Configure the Kubernetes admission controller to reject pods that use unsigned images.
C.Use network policies to restrict pod-to-pod communication.
D.Scan all container images for vulnerabilities in the CI pipeline.
E.Sign container images with a private key and verify signatures before deployment.
AnswersB, E

A Kubernetes admission controller intercepts pod creation requests and rejects those referencing unsigned images, enforcing the approved-images-only constraint at deploy time. This prevents unverified container images from running in the cluster even if they bypass earlier pipeline stages.

Why this answer

Option B is correct because a Kubernetes admission controller (e.g., via an admission webhook or policy engine like OPA Gatekeeper or Kyverno) can enforce at admission time that any Pod referencing an image without a valid signature is rejected, directly ensuring only approved images run on the cluster. Option E is correct because signing container images with a private key (e.g., using cosign/Notation with a key pair) and verifying those signatures before deployment establishes cryptographic provenance, so only images signed by the trusted key are treated as approved. Together, B and E implement the verify-at-admission and sign-at-build halves of a supply-chain control that guarantees only approved images are deployed.

Option A is not correct because RBAC on the registry controls who may push images, but it does not verify that deployed images are approved or untampered. Option C is not correct because network policies only restrict pod-to-pod traffic and have no bearing on image approval. Option D is not correct because vulnerability scanning identifies known CVEs but does not enforce that only approved (signed/trusted) images are deployed.

Exam trap

ISC2 often tests the distinction between controls that prevent unauthorized images from being deployed (signing and admission control) versus controls that manage access or detect vulnerabilities but do not enforce approval at deployment time.

423
MCQmedium

A cloud security engineer is designing a disaster recovery plan for a critical application running on virtual machines. The RTO is 4 hours and RPO is 1 hour. Which approach meets these requirements?

A.Take daily snapshots and restore to a different region.
B.Use synchronous replication to a secondary availability zone.
C.Keep a warm standby in another region with continuous data replication.
D.Use asynchronous replication with a 1-hour lag to a secondary site.
AnswerC

Warm standby with continuous replication meets both RTO and RPO.

Why this answer

Meets both the RTO of 4 hours and RPO of 1 hour by maintaining a warm standby in another region with continuous data replication. Continuous replication ensures data is synchronized with minimal lag (well under 1 hour), and the warm standby VM can be activated quickly to meet the 4-hour RTO. This approach balances cost and recovery speed, as a warm standby is partially running and can be promoted to production faster than a cold standby.

Exam trap

ISC2 often tests the distinction between RPO and RTO, and the trap here is that candidates confuse asynchronous replication with a 1-hour lag as meeting both requirements, overlooking that a cold standby without pre-provisioned compute cannot achieve a 4-hour RTO even if the data is available.

How to eliminate wrong answers

Option A is wrong because daily snapshots provide an RPO of up to 24 hours, far exceeding the required 1-hour RPO, and restoring to a different region would likely exceed the 4-hour RTO due to the time needed to transfer and restore large snapshot data. Option B is wrong because synchronous replication to a secondary availability zone within the same region does not protect against a regional disaster; it only covers zone-level failures, and synchronous replication typically requires low-latency links, making it unsuitable for cross-region DR. Option D is wrong because asynchronous replication with a 1-hour lag exactly matches the RPO of 1 hour, but it does not guarantee the RTO of 4 hours; a secondary site with only replication and no pre-provisioned compute (cold standby) would require additional time to provision and start VMs, likely exceeding the RTO.

424
MCQmedium

A security team is reviewing container image supply chain security. Which tool is specifically designed for signing container images to ensure integrity and provenance?

A.Kube-bench
B.Clair
C.Cosign
D.Trivy
AnswerC

Cosign signs and verifies container images using keys or keyless OIDC identities, producing signatures that establish image integrity and provenance. It directly satisfies the supply chain requirement by letting deployments reject unsigned or tampered images before they run.

Why this answer

Cosign (C) is a tool from the Sigstore project specifically designed to sign, verify, and attach attestations to container images, providing integrity and provenance guarantees in the supply chain. It supports keyless signing via OIDC and integrates with registries and admission controllers. This makes it the purpose-built answer for image signing.

Exam trap

CCSP often tests tool-purpose recognition — the trap is confusing vulnerability scanners (Trivy, Clair) or compliance tools (Kube-bench) with signing tools, when only Cosign provides cryptographic image signing and provenance.

How to eliminate wrong answers

Option A is wrong because Kube-bench checks Kubernetes cluster configuration against CIS benchmarks — it is a compliance/configuration auditing tool, not an image signing tool. Option B is wrong because Clair is a static vulnerability scanner for container images; it identifies CVEs but does not sign or verify image provenance. Option D is wrong because Trivy is also a vulnerability and misconfiguration scanner for images, filesystems, and IaC — it detects issues but does not provide cryptographic signing or provenance attestation.

425
MCQeasy

A company is migrating to the cloud to reduce capital expenditures. They want to pay only for the resources they consume with no upfront investment. Which financial model does this describe?

A.Amortization
B.Capex
C.Leasing
D.Opex
AnswerD

Opex matches the requirement to pay only for consumed resources with no upfront investment, since operational expenditure covers ongoing usage-based costs rather than capitalised purchases. This directly satisfies the stated goal of reducing capital expenditures and avoiding upfront commitment.

Why this answer

The operating expenditure (Opex) model allows a company to pay for cloud resources on a consumption basis without any upfront capital investment. This aligns with the goal of reducing capital expenditures (Capex) by shifting costs to variable, pay-as-you-go operational expenses.

Exam trap

ISC2 often tests the distinction between Capex and Opex by presenting a scenario that describes consumption-based pricing, and the trap is that candidates confuse 'leasing' (which still implies a fixed term) with true pay-as-you-go Opex.

How to eliminate wrong answers

Option A is wrong because amortization is an accounting method that spreads the cost of an intangible asset over its useful life, not a financial model for paying for cloud resources as consumed. Option B is wrong because Capex (capital expenditure) involves upfront investment in physical assets like servers, which contradicts the goal of avoiding upfront costs. Option C is wrong because leasing typically involves fixed periodic payments for a defined term, not a consumption-based model where you pay only for what you use.

426
MCQmedium

Your company, a global e-commerce platform, operates on a multi-cloud environment with workloads in AWS and Azure. You are the lead cloud architect. The platform experiences peak traffic during promotional events, with traffic spikes up to 10x normal. The application is composed of microservices running in containers orchestrated by Kubernetes on both clouds. Each cloud provider's Kubernetes cluster uses cluster autoscaler and horizontal pod autoscaler. Recently, during a flash sale, the AWS cluster failed to scale adequately, causing latency spikes and timeouts. AWS support indicated that the cluster hit a service quota limit for EC2 instances. You need to prevent this from recurring. You have the following options: A) Implement a multi-region deployment on AWS to distribute load. B) Pre-warm the AWS environment by requesting a service quota increase and using a pod priority class to ensure critical pods scale first. C) Migrate all workloads to Azure to simplify management. D) Use a global load balancer to route traffic to the cloud with the most available capacity. Which option is the best course of action?

A.Implement a multi-region deployment on AWS to distribute load.
B.Pre-warm the AWS environment by requesting a service quota increase and using a pod priority class to ensure critical pods scale first.
C.Migrate all workloads to Azure to simplify management.
D.Use a global load balancer to route traffic to the cloud with the most available capacity.
AnswerB

The failure stemmed from an EC2 service quota ceiling, so raising that quota directly removes the scaling blocker. Pre-warming plus pod priority classes ensures critical pods schedule first during 10x spikes, addressing capacity and scheduling constraints without architectural change.

Why this answer

The root cause is a hard AWS service quota for EC2 instances, which prevents the cluster autoscaler from launching new nodes. Requesting a quota increase removes this bottleneck, while pod priority classes ensure that critical microservices are scheduled first when resources are constrained, preventing latency spikes during flash sales.

Exam trap

ISC2 often tests the misconception that scaling issues are always solved by distributing load (e.g., multi-region or global load balancers), when the actual root cause is a hard resource quota that prevents any new compute capacity from being provisioned. In this scenario, the correct first step is to address the quota limit directly.

How to eliminate wrong answers

Option A is wrong because migrating all workloads to Azure does not address the underlying scaling issue—it merely shifts the problem to another cloud, which may also have its own quotas. Option B is wrong because a global load balancer can distribute traffic but does not resolve the AWS quota limit; the cluster will still fail to scale if it cannot launch new EC2 instances. Option C is wrong because multi-region deployment on AWS distributes load but does not increase the per-region EC2 instance quota; the cluster autoscaler would still be blocked by the same quota in each region.

427
Drag & Dropmedium

Drag and drop the steps for responding to a security incident involving a compromised cloud VM into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First isolate, then capture forensics, terminate, analyze, and finally remediate and restore.

428
MCQmedium

A company uses a cloud KMS to manage encryption keys for its cloud storage buckets. The security team wants to ensure that keys are rotated automatically every 90 days and that access to keys is restricted based on user roles. Which key management feature should they configure?

A.Key versioning and deletion policies
B.Key rotation policy and access control key policies
C.Key import and export policies
D.Key expiration and renewal policies
AnswerB

Configuring a rotation policy enforces automatic key replacement every 90 days, satisfying the stem's rotation constraint without manual intervention. Access control key policies bind permissions to user roles, restricting key usage to authorised principals. Together they deliver both required capabilities within the cloud KMS, whereas alternative options address only one requirement or none.

Why this answer

A cloud KMS rotation policy lets the security team schedule automatic key rotation (e.g., every 90 days) without manual intervention, while key policies (IAM/resource policies attached to the key) enforce role-based access control over who can use, manage, or view the key. Together these two features directly satisfy both stated requirements: automatic 90-day rotation and role-restricted key access.

Exam trap

CCSP often tests the confusion between key rotation (limiting cryptographic exposure over time) and key versioning/deletion (retention and destruction) — candidates pick versioning because it sounds related to lifecycle, but only a rotation policy satisfies an automatic 90-day schedule.

How to eliminate wrong answers

Option A is wrong because key versioning only retains prior key versions for decryption/recovery and deletion policies only govern scheduled destruction of keys — neither automates rotation nor restricts access by role. Option C is wrong because import/export policies govern bringing externally generated key material into or out of the KMS (BYOK/HYOK scenarios) and have nothing to do with rotation schedules or role-based access. Option D is wrong because 'expiration and renewal' is not a standard KMS feature set — keys do not auto-renew like certificates; rotation, not expiration, is the mechanism for limiting key lifetime.

429
MCQhard

An organization uses GCP and wants to detect container threats such as privilege escalation attempts within Kubernetes Engine. Which GCP service is designed specifically for this purpose?

A.Container Threat Detection
B.Cloud Security Scanner
C.Event Threat Detection
D.Cloud Audit Logs
AnswerA

Container Threat Detection continuously monitors Kubernetes Engine runtime activity, flagging privilege escalation, suspicious binaries and reverse shells inside containers. It operates at the workload level rather than scanning images or network flows, directly matching the requirement to detect in-cluster container threats.

Why this answer

Container Threat Detection (CTD) is a GCP service purpose-built to identify threats within Google Kubernetes Engine (GKE) containers, including privilege escalation attempts, by analyzing runtime behavior and Kubernetes audit logs. It uses machine learning and rule-based detection to spot anomalies like container breakout, unauthorized system calls, and attempts to escalate privileges via capabilities or security contexts. This makes it the correct choice for detecting container-specific threats in GKE.

Exam trap

ISC2 often tests the distinction between general threat detection services (like Event Threat Detection) and container-specific services (like Container Threat Detection), so candidates may confuse Event Threat Detection as covering all cloud threats, missing that it does not analyze container runtime behavior.

How to eliminate wrong answers

Option B (Cloud Security Scanner) is wrong because it is designed to scan web applications for vulnerabilities like XSS and SQL injection, not to detect runtime container threats or privilege escalation in Kubernetes. Option C (Event Threat Detection) is wrong because it focuses on identifying threats from cloud events such as suspicious IAM activity or compromised service accounts, not container-level runtime threats within GKE. Option D (Cloud Audit Logs) is wrong because it is a logging service that records API calls and administrative actions, not a detection service; it provides raw data but does not analyze or alert on container threats like privilege escalation.

430
MCQmedium

A security analyst is investigating a potential compromise of an AWS EC2 instance. Which step should be taken FIRST to contain the incident and prevent further damage?

A.Terminate the EC2 instance immediately.
B.Take a snapshot of the instance for forensic analysis.
C.Isolate the EC2 instance by updating the security group to deny all traffic.
D.Disable the IAM role attached to the instance.
AnswerC

Replacing the instance's security group with one denying all inbound and outbound traffic cuts attacker access instantly while leaving the instance running. Memory, processes and disk state remain intact for forensic capture, unlike termination or reboot, which would destroy volatile evidence.

Why this answer

The first priority in incident response is containment. Updating the security group to deny all traffic immediately isolates the EC2 instance from network communication, preventing lateral movement or data exfiltration while preserving the instance for further investigation. This aligns with the NIST SP 800-61 incident response framework, which emphasizes containment before eradication or recovery.

Exam trap

A common misconception is that immediate termination (Option A) is the fastest containment method, but this violates the principle of preserving evidence and may hinder forensic investigation.

How to eliminate wrong answers

Option A is wrong because terminating the instance destroys volatile data (e.g., memory, running processes, network connections) and prevents forensic analysis, which may be critical for understanding the attack vector. Option B is wrong because taking a snapshot is a forensic step that should occur after containment, not before; performing it first could allow the attacker to continue exfiltrating data or spreading to other resources. Option D is wrong because disabling the IAM role does not stop network-level attacks or data exfiltration; the instance could still communicate with external hosts, and the attacker might already have established persistence or backdoor access.

431
MCQhard

A cloud security team is implementing a data classification scheme for objects stored in a cloud environment. They need to ensure that classification labels persist with the data, travel with it when copied or moved between services, and can be used to enforce access and DLP policies automatically. Which approach BEST achieves these outcomes?

A.Store classification labels in a separate spreadsheet maintained by the data governance team and update it after each data movement.
B.Use file naming conventions that include the classification level in the object name and enforce policies based on name patterns.
C.Embed classification metadata as tags or object metadata that are preserved through supported copy and move operations and referenced by policy engines.
D.Apply classification only at the storage bucket level and rely on bucket policies to enforce access.
AnswerC

Embedding classification as tags or object metadata keeps labels attached to the data, and supported copy and move operations preserve them when configured correctly. Policy engines and DLP services can reference these labels to enforce access and handling rules automatically. This satisfies persistence, portability, and automated enforcement in a scalable way.

Why this answer

Embedding classification as tags or object metadata keeps labels attached to the data and allows them to be carried through supported copy and move operations. Policy engines and DLP services can then enforce access and handling rules automatically based on those labels. Spreadsheets, bucket-level classification, and naming conventions lack persistence, portability, and reliable automated enforcement.

Exam trap

The trap here is assuming that bucket-level classification or naming conventions provide object-level, portable labels, when only embedded metadata or tags travel with the data and drive automated enforcement.

432
MCQhard

A healthcare analytics company processes electronic protected health information (ePHI) for multiple covered entities using a public cloud provider. The company signs a Business Associate Agreement (BAA) with each covered entity and also signs a BAA with the cloud provider. A security analyst discovers that the cloud provider stores backups of the ePHI in a region outside the United States and refuses to sign a separate BAA for that region. Which of the following is the MOST appropriate action for the company to take to maintain compliance with HIPAA?

A.Encrypt the ePHI backups in the offshore region and continue operations without a BAA for that region.
B.Terminate the BAA with the cloud provider and migrate all ePHI to an on-premises data center.
C.Require the cloud provider to sign a BAA that covers all regions where ePHI is stored, including the offshore region, or disable backup replication to that region.
D.Report the cloud provider to the HHS Office for Civil Rights (OCR) and continue using the service while awaiting guidance.
AnswerC

Under HIPAA, a covered entity or business associate must have a BAA with any subcontractor that creates, receives, maintains, or transmits ePHI. The cloud provider is a business associate, and its offshore backup storage is a subcontractor relationship. The company must ensure the BAA covers all locations where ePHI is stored, or prevent storage in non-covered regions. This is the most direct and compliant action.

Why this answer

HIPAA requires a Business Associate Agreement (BAA) with any entity that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or another business associate. A cloud provider storing ePHI backups in an offshore region acts as a subcontractor, so a BAA must cover that region. If the provider refuses, the company must either negotiate an expanded BAA or disable replication to that region to maintain compliance.

Exam trap

The trap here is assuming that encrypting ePHI or reporting the provider to OCR eliminates the need for a BAA with the cloud provider for all regions where ePHI is stored.

433
MCQmedium

A security team implements Kubernetes RBAC. They want to ensure that a service account can only create pods in the 'dev' namespace. Which RBAC resource should they use?

A.ClusterRole and ClusterRoleBinding
B.Role and RoleBinding in the 'dev' namespace
C.PodSecurityPolicy (deprecated)
D.NetworkPolicy
AnswerB

A Role defines permissions within a single namespace, and a RoleBinding grants those permissions to the service account only in that namespace. This satisfies the stem's constraint that pod creation is limited to the 'dev' namespace, unlike ClusterRole and ClusterRoleBinding.

Why this answer

RBAC uses Role and RoleBinding for namespace-scoped permissions. ClusterRole and ClusterRoleBinding are cluster-scoped. A Role with permissions to create pods in the 'dev' namespace, bound via RoleBinding, achieves the goal.

434
MCQmedium

Which practice is most effective for preventing the deployment of container images with known vulnerabilities in a DevSecOps pipeline?

A.Post-deployment vulnerability scanning
B.Image scanning in CI pipeline before push
C.Using only official base images
D.Runtime monitoring with a WAF
AnswerB

Scanning images in CI before push catches known CVEs in base layers and dependencies while the artefact is still mutable, blocking vulnerable images from ever entering the registry. This satisfies the stem's prevention constraint, unlike runtime scanning which detects only after deployment.

Why this answer

Scanning images in the CI pipeline before they are pushed to a registry catches known vulnerabilities (CVEs) at the earliest possible stage, preventing flawed images from ever reaching production. This 'shift-left' approach blocks the build or fails the pipeline when critical vulnerabilities are found, so vulnerable images never get deployed. It is the most effective preventive control because it stops the problem at the source.

Exam trap

The trap is choosing 'post-deployment scanning' or 'runtime monitoring' because they sound thorough — but the question asks for prevention, and only pre-push CI scanning stops vulnerable images from being deployed at all.

How to eliminate wrong answers

Option A is wrong because post-deployment scanning detects vulnerabilities after the image is already running in production, which is detection, not prevention — the vulnerable workload has already been exposed. Option C is wrong because official base images can still contain unpatched CVEs or become vulnerable as new CVEs are disclosed; using them reduces but does not prevent vulnerable deployments. Option D is wrong because a WAF operates at the application layer (HTTP/HTTPS) and cannot detect or prevent vulnerabilities inside a container image, such as a vulnerable OpenSSL library or misconfigured package.

435
MCQmedium

Which cloud characteristic allows a consumer to automatically provision computing resources, such as server time and storage, as needed without requiring human interaction with the service provider?

A.On-demand self-service
B.Rapid elasticity
C.Broad network access
D.Resource pooling
AnswerA

On-demand self-service lets the consumer unilaterally provision capabilities such as server time and storage automatically, with no human interaction required from the provider. That directly matches the stem's requirement for self-provisioning without service provider involvement.

Why this answer

On-demand self-service is the NIST-defined characteristic where a consumer can unilaterally provision computing capabilities, such as server time and storage, automatically without human interaction with the provider. This matches the question's wording exactly.

Exam trap

CCSP often tests the distinction between the five NIST characteristics; candidates confuse on-demand self-service with rapid elasticity because both involve automatic scaling.

How to eliminate wrong answers

Option B is wrong because rapid elasticity refers to capabilities scaling outward and inward commensurate with demand, not the self-provisioning act itself. Option C is wrong because broad network access means capabilities are available over the network via standard mechanisms. Option D is wrong because resource pooling means provider resources are pooled to serve multiple consumers using a multi-tenant model.

436
Multi-Selecthard

A security team is deploying a Kubernetes cluster on a cloud platform and wants to harden the worker nodes against container breakout and privilege escalation. They are reviewing kubelet and container runtime configurations. Which TWO of the following measures are MOST effective at reducing the attack surface and preventing a compromised container from gaining node-level privileges? (Choose two.)

Select 2 answers
A.Enable the kubelet read-only port and disable anonymous authentication to the kubelet API.
B.Run containers with a read-only root filesystem and drop all Linux capabilities except those explicitly required.
C.Configure the container runtime to use the overlay2 storage driver with a dedicated volume for each container.
D.Use a Pod Security Admission policy that enforces the restricted profile, which requires non-root execution and disallows privilege escalation.
E.Enable audit logging on the Kubernetes API server and ship logs to a central SIEM for alerting.
AnswersB, D

A read-only root filesystem prevents attackers from writing malicious binaries or modifying system files inside the container, and dropping unnecessary Linux capabilities removes the ability to perform privileged operations such as mounting filesystems or loading kernel modules. Together they significantly reduce the container's ability to escalate privileges or break out to the node.

Why this answer

Hardening worker nodes against container breakout requires preventive controls that limit what a compromised container can do. Running with a read-only root filesystem and dropping unnecessary Linux capabilities removes the tools and privileges needed for escalation. Enforcing the restricted Pod Security Standard via Pod Security Admission ensures workloads cannot run as root, cannot escalate privileges, and must meet seccomp and capability restrictions.

Together these measures significantly reduce the attack surface and block common escape techniques.

Exam trap

The trap here is selecting detective controls like audit logging or general kubelet hardening instead of the preventive, workload-level restrictions that actually stop privilege escalation and breakout.

437
MCQhard

An organization is required to use client-side encryption for all data uploaded to a cloud storage service to ensure that the cloud provider has no access to plaintext. However, they also need to allow the cloud provider to perform server-side operations like indexing and search on the encrypted data. Which technology can address this conflict?

A.Format-preserving encryption
B.Searchable encryption
C.Tokenization
D.Homomorphic encryption
AnswerB

Searchable encryption lets the provider index and query ciphertext without decrypting it, preserving client-side key custody. It resolves the conflict by enabling server-side search operations over encrypted objects while the provider never gains plaintext access, satisfying both the no-plaintext constraint and the indexing requirement.

Why this answer

Searchable encryption allows data to remain encrypted at rest while still supporting server-side operations such as keyword search and indexing over the ciphertext. It enables the cloud provider to perform searches without decrypting the data, satisfying both the client-side encryption requirement and the need for server-side search functionality. This directly resolves the conflict described.

Exam trap

CCSP often tests the distinction between encryption technologies that enable computation versus those that enable search — candidates may confuse homomorphic encryption (computation) with searchable encryption (search/indexing).

How to eliminate wrong answers

Option A is wrong because format-preserving encryption maintains the format of plaintext (e.g., credit card numbers) but does not inherently enable searchable operations on encrypted data. Option C is wrong because tokenization replaces sensitive data with non-sensitive tokens, but the tokens are typically stored and mapped by a tokenization system, and search is limited to exact token matches, not general indexing. Option D is wrong because homomorphic encryption allows computation on ciphertext but is computationally expensive and not designed for efficient indexing and search at scale.

438
MCQhard

A cloud provider's API is used by an application to retrieve secrets from a managed secrets store. The security team wants to ensure that if a secret is compromised, its use is limited to a short window and that all access is attributable to a specific workload identity. Which combination best meets these requirements?

A.Use the secrets store's dynamic secrets feature to issue short-lived credentials tied to the workload's authenticated identity, with audit logging of each issuance.
B.Store the secret in an environment variable on the compute instance and rotate it every 90 days using a scheduled job.
C.Encrypt the secret with a customer-managed key and require two administrators to approve each retrieval.
D.Embed the secret in the container image and rely on image signing to ensure only trusted images run.
AnswerA

Dynamic secrets generate credentials on demand with a short time-to-live and bind them to the requesting workload's authenticated identity. Each issuance is logged, providing attribution. If compromised, the credential expires quickly, limiting the window of use. This directly satisfies both the short-lived use and attribution requirements.

Why this answer

Dynamic secrets issued to an authenticated workload identity provide short-lived credentials and per-issuance audit trails. If a credential leaks, its TTL limits the damage, and logs attribute each issuance to a specific workload. Static secrets in environment variables, encrypted secrets with dual approval, and secrets embedded in images do not provide both short-lived use and workload-level attribution.

Exam trap

The trap here is assuming that encrypting a static secret or adding approval steps limits its use after compromise, when only short-lived, identity-bound credentials reduce the exposure window.

439
Multi-Selectmedium

An organization uses Azure Functions and wants to secure its API endpoints exposed via Azure API Management. Which TWO security controls should they implement at the API Gateway level?

Select 2 answers
A.Configure IP whitelisting for all users
B.Store secrets in Azure Function environment variables
C.Enable TLS enforcement
D.Implement JWT validation
E.Disable API keys
AnswersC, D

TLS enforcement at the gateway encrypts traffic between clients and API Management, preventing credential and token interception in transit. This satisfies the requirement to secure exposed API endpoints at the gateway layer, independent of backend Azure Functions configuration.

Why this answer

Option C (Enable TLS enforcement) is correct because enforcing TLS at the API Management gateway ensures all client-to-gateway traffic is encrypted in transit using HTTPS, protecting credentials and tokens from interception, and API Management supports configuring the minimum TLS version and cipher suites on the gateway. Option D (Implement JWT validation) is correct because API Management has a built-in validate-jwt policy that verifies the signature, issuer, audience, and expiration of OAuth 2.0/OpenID Connect bearer tokens at the gateway, so unauthenticated or tampered requests are rejected before reaching the backend Functions. Option A is not a gateway-level authentication control and whitelisting 'all users' is contradictory and impractical for public APIs.

Option B is a backend configuration concern for the Function app, not a control applied at the API Gateway. Option E is wrong because disabling API keys removes a subscription-based access control rather than adding security at the gateway.

440
MCQmedium

A company uses a cloud-based database that contains personally identifiable information (PII). They need to allow developers to run queries against the database for testing purposes without exposing actual PII. Which technique should they use?

A.Encrypt the PII fields at rest
B.Grant developers direct access to a copy of the production data
C.Apply dynamic data masking to the PII columns
D.Tokenize the PII fields with a one-way hash
AnswerC

Masking provides realistic but fake data.

Why this answer

Dynamic data masking (DDM) allows the database to return masked PII to developers in real time without altering the underlying stored data. This technique applies masking rules at query runtime, so developers can run functional tests against production-like data while sensitive values are obfuscated. It avoids the need for separate sanitized copies and preserves referential integrity for testing.

Exam trap

ISC2 often tests the distinction between dynamic data masking and tokenization, where candidates mistakenly choose tokenization because they think a one-way hash is sufficient for testing, but they overlook that testing requires reversible or format-preserving transformations to maintain data utility.

How to eliminate wrong answers

Option A is wrong because encrypting PII at rest protects data on disk but does not prevent developers from seeing plaintext when they query the database; decryption keys are typically available to authorized users, so the PII would still be exposed in query results. Option B is wrong because granting developers direct access to a copy of production data, even if it is a copy, still exposes actual PII and violates the principle of least privilege and data minimization for testing environments. Option D is wrong because tokenization with a one-way hash is irreversible and would break the ability to run meaningful queries that require relationships or pattern matching; tokenization for testing typically uses reversible tokens or format-preserving encryption, not a one-way hash.

441
MCQhard

A company uses a cloud KMS service with an HSM backing for key storage. The security policy requires that keys be rotated automatically every 90 days and that old keys be retained for at least one year to decrypt archived data. Which key management feature should be configured to meet these requirements?

A.Key hierarchy with root key separation
B.Key versioning with rotation schedule
C.Key policy with conditions for automatic rotation
D.Key import with manual rotation
AnswerB

Key versioning retains prior key versions alongside the current one, so scheduled rotation every 90 days generates new versions while old versions persist to decrypt archived data. This satisfies both the 90-day automatic rotation and one-year retention constraints simultaneously.

Why this answer

Key versioning with a rotation schedule allows the KMS to automatically rotate keys every 90 days while retaining old key versions for decryption of archived data. Each rotation creates a new key version, and old versions remain available for decryption but are not used for new encryption. This meets both the rotation and retention requirements without manual intervention.

Exam trap

CCSP often tests the difference between key rotation, key versioning, and key policies, and candidates may choose key policies or key hierarchy thinking they enable automatic rotation, when in fact versioning with a rotation schedule is the specific feature.

How to eliminate wrong answers

Option A (Key hierarchy with root key separation) is wrong because it describes the structure of keys (root, data encryption keys) but does not provide automatic rotation or retention of old versions. Option C (Key policy with conditions for automatic rotation) is wrong because key policies define access permissions, not rotation schedules; while policies can enforce rotation, they do not themselves rotate keys or retain versions. Option D (Key import with manual rotation) is wrong because it requires manual rotation and does not automatically retain old versions for decryption; it also does not meet the 90-day automatic rotation requirement.

442
MCQhard

A cloud security team is using AWS Lambda functions to process sensitive data. The functions are triggered by Amazon S3 events and write to an Amazon DynamoDB table. The team wants to ensure that the Lambda functions have only the permissions they need and that any compromised function cannot access other AWS resources. Which of the following is the MOST effective approach?

A.Attach a resource-based policy to the DynamoDB table that allows all Lambda functions in the account to write to it.
B.Create a separate IAM role for each Lambda function with permissions scoped to only the specific S3 bucket and DynamoDB table it needs.
C.Use AWS Lambda environment variables to store IAM credentials and rotate them regularly.
D.Create a single IAM role with broad permissions to all necessary services and assign it to all Lambda functions.
AnswerB

Using a distinct IAM role per function with narrowly scoped permissions ensures that each function can only access its required resources. If one function is compromised, the attacker cannot use its role to access other resources. This is the most effective way to enforce least privilege and limit lateral movement.

Why this answer

The most effective approach is to create a separate IAM role for each Lambda function with permissions scoped to only the resources that function needs. This enforces least privilege and ensures that a compromised function cannot access other AWS resources. Other options either grant excessive permissions, use insecure credential storage, or are overly permissive.

Exam trap

The trap here is thinking that a single role with broad permissions or resource-based policies are sufficient, when in fact per-function roles with least privilege are needed to contain a compromised function.

443
MCQhard

An organization uses a private artifact registry for approved packages. What attack does this practice primarily defend against?

A.Dependency confusion attacks
B.Denial of service attacks
C.Man-in-the-middle attacks
D.Injection attacks
AnswerA

A private artifact registry restricts package resolution to vetted internal sources, so a malicious public package sharing a name with an internal dependency cannot be pulled in. This directly neutralises dependency confusion, where attackers publish higher-versioned public packages to hijack internal build resolution.

Why this answer

A private artifact registry restricts package resolution to a curated, organization-controlled source, so an attacker cannot trick the build system into pulling a malicious package with the same name from a public repository. Dependency confusion exploits the fact that public registries are often checked before or alongside private ones, allowing a higher-versioned public package to override the internal one. By using only a private registry, the organization removes that public lookup path entirely.

Exam trap

CCSP often tests the distinction between supply chain attacks that target package resolution (dependency confusion) and those that target the package contents themselves (typosquatting, malicious commits), so candidates must read the scenario carefully to identify which mechanism is being defended.

How to eliminate wrong answers

Option B is wrong because denial of service attacks target availability through traffic flooding or resource exhaustion, which a private registry does not inherently prevent. Option C is wrong because man-in-the-middle attacks intercept network traffic and are mitigated by TLS and certificate validation, not by registry scoping. Option D is wrong because injection attacks exploit unsanitized input in application code, and a private registry does not sanitize application inputs.

444
Multi-Selecthard

A cloud operations team is hardening the management plane of a production VPC. The security architect wants to reduce the risk of credential compromise and lateral movement through management interfaces. Which TWO measures best address this goal? (Choose two.)

Select 2 answers
A.Enforce least privilege on management roles and require multi-factor authentication for privileged sessions
B.Enable verbose API logging and forward all management events to a central log repository
C.Place management interfaces behind a bastion host reachable only from a corporate IP range
D.Replace long-lived access keys with short-lived credentials issued through a federated identity provider
E.Increase the password complexity policy for all administrative accounts to twenty characters
AnswersA, D

Least privilege limits what a compromised management credential can do, and mandatory multi-factor authentication makes stolen passwords or tokens insufficient on their own. Together they constrain both the likelihood of credential compromise succeeding and the scope of damage if it does. This combination is a core control for protecting administrative interfaces in cloud environments.

Why this answer

Reducing management plane risk centers on making credentials short-lived and limiting what they can do. Federated identity with temporary credentials removes static keys that can be stolen and reused, while least privilege plus multi-factor authentication constrains the impact of any single compromised session. Together these directly attack credential compromise and lateral movement, whereas logging is detective and password length and bastion placement are secondary hardening steps.

Exam trap

The trap here is selecting detective controls such as logging or perimeter controls such as bastion hosts, when the goal calls for preventive controls that shorten credential life and limit privilege.

445
MCQmedium

A financial services company uses a cloud DLP API to scan data stored in Cloud Storage and BigQuery. They need to reduce the risk of exposing credit card numbers in reports by replacing the first 12 digits with asterisks while preserving the last four. Which de-identification technique should they apply?

A.Pseudonymization
B.Bucketing
C.Tokenization
D.Masking
AnswerD

Masking replaces characters with a substitute such as asterisks, so the first 12 digits become masked while the last four remain readable for reporting. Tokenisation would substitute the whole value, and bucketing or date shifting cannot preserve the trailing digits.

Why this answer

Masking replaces sensitive data with a redacted or partially obscured version while preserving the format and often the last few characters for referential purposes. Replacing the first 12 digits of a credit card number with asterisks while keeping the last four is the textbook definition of masking — it preserves usability (e.g., for customer service verification) while removing the sensitive payload. Cloud DLP APIs such as Google Cloud DLP provide a masking transformation (e.g., 'maskingCharacter' with 'numberToMask') that performs exactly this operation.

Exam trap

The trap is conflating masking with tokenization or pseudonymization — candidates see 'replace digits' and think 'tokenize,' but tokenization replaces the whole value with a token, whereas masking partially obscures while preserving format.

How to eliminate wrong answers

Option A is wrong because pseudonymization replaces identifiers with consistent surrogate values (e.g., a hash or token) that allow re-identification via a mapping table — it does not obscure digits with asterisks. Option B is wrong because bucketing groups values into ranges (e.g., age 30-39) to generalize data, which is useless for credit card numbers where the last four must remain visible. Option C is wrong because tokenization substitutes the entire value with a non-sensitive token stored in a secure vault; the original digits are not partially preserved, and the format is not maintained for display.

446
MCQeasy

A development team is building a cloud application and needs to store API keys and database passwords securely. The team wants to minimize management overhead and ensure automatic rotation of secrets. Which AWS service should they use?

A.AWS IAM roles
B.AWS Systems Manager Parameter Store
C.Amazon S3 with server-side encryption
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is designed to store and manage secrets such as API keys and database passwords. It provides built-in rotation for supported services like RDS, Redshift, and DocumentDB, and allows custom rotation via Lambda. This reduces management overhead and enhances security by automatically rotating secrets, meeting the team's requirements.

Why this answer

AWS Secrets Manager is purpose-built for storing and managing secrets, offering automatic rotation for many AWS services and custom rotation via Lambda. This minimizes management overhead and ensures secrets are regularly rotated, reducing the risk of compromise. The team can focus on application development while Secrets Manager handles the lifecycle of secrets securely.

Exam trap

The trap here is assuming that Parameter Store provides automatic rotation like Secrets Manager, when it requires custom implementation.

447
Multi-Selectmedium

A company is considering migrating its customer relationship management (CRM) system to a SaaS provider. Which TWO of the following security responsibilities typically remain with the customer in a SaaS deployment?

Select 2 answers
A.Physical security of data centers
B.Operating system patching
C.User access management
D.Application vulnerability management
E.Data classification and access control
AnswersC, E

In SaaS, the provider secures the application and infrastructure, but the customer still governs its own tenants, roles and credentials. User access management stays with the customer because it controls who within the organisation may reach the CRM data, satisfying the stem's split of responsibility.

Why this answer

In a SaaS deployment, the customer retains responsibility for managing its own users and identities, so user access management (C) — provisioning, deprovisioning, role assignment, and enforcing least privilege through SSO/MFA — stays with the customer. Likewise, data classification and access control (E) remain customer duties because the customer owns the data and must define its sensitivity, retention, and who may access it, even though the provider secures the underlying platform. Physical security of data centers (A) is handled by the SaaS provider, which owns and operates the facilities.

Operating system patching (B) is the provider's responsibility since the customer has no access to the underlying OS in a SaaS model. Application vulnerability management (D) also belongs to the provider, as it develops, hosts, and maintains the SaaS application itself.

Exam trap

The trap is assuming the customer still patches the OS or manages application vulnerabilities in SaaS; those shift to the provider, leaving identity and data governance with the customer.

448
MCQeasy

When assessing cloud risk, an organization identifies that if a single cloud provider fails, the organization cannot operate. This risk is known as:

A.Third-party risk
B.Inherent risk
C.Concentration risk
D.Residual risk
AnswerC

Concentration risk arises when dependency on a single provider creates correlated failure exposure, so one outage halts all operations. Unlike operational or compliance risk, it specifically measures over-reliance on one entity, matching the stem's single-provider failure scenario.

Why this answer

Concentration risk is the risk that arises from over-reliance on a single provider, system, or counterparty — in cloud terms, if one provider fails and the organization cannot operate, that dependency is a concentration risk. It is a well-known concept in financial services (e.g., reliance on a single clearing bank) and applies directly to cloud, where multi-cloud or hybrid strategies are often adopted specifically to mitigate it. The scenario describes exactly this single-point-of-failure dependency.

Exam trap

CCSP often tests the distinction between concentration risk and general third-party risk — candidates pick 'third-party risk' because a cloud provider is a third party, but the specific scenario of single-provider dependency is concentration risk, a narrower and more precise term.

How to eliminate wrong answers

Option A is wrong because third-party risk is the broader category of risks introduced by using external vendors (security, compliance, operational) — concentration risk is a specific subtype of third-party risk focused on over-dependence on one provider. Option B is wrong because inherent risk is the level of risk that exists before any controls are applied — it describes risk exposure in the absence of mitigation, not the dependency on a single provider. Option D is wrong because residual risk is the risk that remains after controls and mitigations have been applied — it is a post-treatment measure, not the description of single-provider dependency.

449
MCQhard

A cloud provider's SLA guarantees 99.95% uptime for a service. Over a one-year period (365 days), what is the maximum allowed downtime in minutes to meet this SLA?

A.525.6 minutes
B.262.8 minutes
C.87.6 minutes
D.438 minutes
AnswerB

A 99.95% uptime guarantee permits 0.05% annual downtime. Converting 365 days to 525,600 minutes and multiplying by 0.0005 yields 262.8 minutes, satisfying the stem's one-year calculation constraint. This matches the permitted outage budget exactly, unlike options derived from monthly figures or incorrect percentage conversions.

Why this answer

99.95% uptime over 365 days allows 0.05% downtime. 365 days is 525,600 minutes; 0.05% of 525,600 is 262.8 minutes. Therefore the maximum allowed downtime is 262.8 minutes.

Exam trap

The trap is miscomputing the percentage or using the wrong base (e.g., 365 days vs. 30 days), leading to selecting 525.6 or 87.6 minutes instead of 262.8.

How to eliminate wrong answers

Option A is wrong because 525.6 minutes corresponds to 99.9% uptime (0.1% downtime), not 99.95%. Option C is wrong because 87.6 minutes corresponds to 99.9833% uptime (0.0167% downtime), which is stricter than the stated SLA. Option D is wrong because 438 minutes corresponds to approximately 99.9167% uptime, not 99.95%.

450
MCQeasy

A company wants to migrate its customer relationship management (CRM) system to the cloud and requires that the provider manages the underlying infrastructure, operating system, and middleware, while the company manages only the application and data. Which cloud service model best meets these requirements?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerB

PaaS delivers managed runtime, middleware, and operating system, leaving the customer responsible only for the application and its data. This precisely matches the stem's split of duties: the provider handles infrastructure through middleware, while the company retains the CRM application and data. IaaS would leave OS patching to the company; SaaS would remove application control.

Why this answer

PaaS provides a managed platform where the provider handles the underlying infrastructure, operating system, and middleware (runtime, databases, web servers), while the customer manages only the application and data. This exactly matches the requirement that the company manages only the application and data. Examples include AWS Elastic Beanstalk, Google App Engine, and Azure App Service.

Exam trap

The trap is selecting SaaS because it sounds like the most managed option — but SaaS means the provider manages the application, whereas the question requires the company to manage the application and data, which is PaaS.

How to eliminate wrong answers

Option A is wrong because SaaS delivers a fully managed application where the customer manages only configuration and data — the provider manages the application itself, so the company would not be managing the application as required. Option C is wrong because IaaS provides only virtualized infrastructure (compute, storage, network), leaving the customer responsible for the OS, middleware, and application — far more than the company wants to manage. Option D is wrong because FaaS (serverless functions) abstracts even the application runtime, requiring the customer to deploy only code snippets; it does not fit a CRM system where the company manages the full application.

Page 5

Page 6 of 13

Page 7