Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 451–525

934 questions total · 13pages · All types, answers revealed

Page 6

Page 7 of 13

Page 8
451
MCQeasy

Which of the following is a key benefit of using a software composition analysis (SCA) tool in a cloud application security program?

A.Detects known vulnerabilities in open-source libraries
B.Enforces runtime policies
C.Simulates attacks on running applications
D.Identifies vulnerabilities in proprietary code
AnswerA

Software composition analysis inventories third-party and open-source dependencies, then matches their versions against vulnerability databases to flag known CVEs. This directly satisfies the stem's requirement by identifying inherited risk in libraries the development team did not author, which static code analysis of first-party code alone would miss.

Why this answer

SCA tools automate the identification of open-source components within a codebase and cross-reference them against databases like the National Vulnerability Database (NVD) to detect known vulnerabilities (CVEs). This is a key benefit because cloud applications often heavily rely on open-source libraries, and SCA provides a scalable way to manage that risk without manual auditing.

Exam trap

ISC2 often tests the distinction between SCA (open-source dependency scanning) and SAST (proprietary code scanning), so the trap here is confusing which tool analyzes which type of code, leading candidates to incorrectly select option D.

How to eliminate wrong answers

Option B is wrong because enforcing runtime policies is the function of a Runtime Application Self-Protection (RASP) tool or a cloud workload protection platform (CWPP), not an SCA tool which focuses on static analysis of dependencies. Option C is wrong because simulating attacks on running applications is the purpose of a dynamic application security testing (DAST) tool or a penetration testing framework, not SCA which does not execute code. Option D is wrong because identifying vulnerabilities in proprietary code is the domain of static application security testing (SAST) tools that analyze custom source code, whereas SCA specifically targets open-source and third-party components.

452
Multi-Selectmedium

A cloud architect is designing a data classification strategy for a multi-cloud environment. The strategy must automatically tag resources with classification labels and enforce access controls based on those labels. Which THREE components are essential for this automated classification and enforcement?

Select 3 answers
A.IAM policies that reference classification tags
B.Tagging resources with classification labels
C.Pre-signed URLs for temporary access
D.Automated DLP scanning to identify sensitive data
E.HSM-backed key generation
AnswersA, B, D

IAM policies that reference classification tags enforce access decisions dynamically, so permissions follow the label rather than static resource names. Without tag-based policy evaluation, automated classification produces metadata that never gates access, breaking the enforcement half of the requirement.

Why this answer

Option B is essential because the strategy requires resources to actually carry classification labels (e.g., via cloud-native tagging such as AWS tags, Azure tags, or GCP labels), which serve as the metadata foundation that any automated enforcement mechanism must reference. Option D is essential because automated DLP scanning (e.g., Amazon Macie, Azure Information Protection, or Google Cloud DLP) is what discovers and identifies sensitive data so that classification labels can be applied automatically rather than manually, directly enabling the 'automatically tag' requirement. Option A is essential because IAM policies that reference classification tags (e.g., AWS IAM policy conditions using aws:ResourceTag or azureResourceTags) are the mechanism that translates labels into actual access-control decisions, satisfying the 'enforce access controls based on those labels' requirement.

Option C is not correct because pre-signed URLs only grant temporary access to a specific object and do not perform classification or tag-based policy enforcement. Option E is not correct because HSM-backed key generation addresses cryptographic key protection and management, not data classification or label-based access control.

453
MCQhard

Which cloud design principle is most directly related to ensuring that an organization can migrate workloads from one cloud provider to another without significant re-engineering?

A.Portability
B.Reversibility
C.Multi-tenancy isolation
D.Elasticity
AnswerA

Portability directly addresses the stem's constraint: avoiding significant re-engineering when moving workloads between providers. It relies on provider-neutral abstractions—containers, open APIs, infrastructure-as-code—rather than proprietary services, so workloads can be redeployed elsewhere with minimal modification. Interoperability concerns data exchange between systems, whereas portability concerns relocating the workload itself.

Why this answer

Portability is the cloud design principle specifically concerned with avoiding provider lock-in by designing workloads so they can be moved between cloud providers with minimal re-engineering. It emphasizes use of open standards, containerization, abstraction layers, and portable data formats so that the same workload can run on AWS, Azure, or GCP without significant refactoring. This directly matches the scenario of migrating workloads across providers without significant re-engineering.

Exam trap

The trap here is confusing portability with reversibility — both relate to avoiding lock-in, but portability is about moving workloads between providers, while reversibility is about exiting the cloud entirely or returning data/processing to on-premises.

How to eliminate wrong answers

Option B is wrong because reversibility refers to the ability to exit a cloud relationship and bring data/processing back on-premises or to another environment, focusing on exit strategy and data retrieval rather than cross-provider workload portability. Option C is wrong because multi-tenancy isolation concerns separating tenant data and resources within a shared cloud environment, which is a security/architecture concern, not a migration concern. Option D is wrong because elasticity refers to automatically scaling resources up and down based on demand, which is a scalability characteristic and unrelated to moving workloads between providers.

454
MCQeasy

Which of the following is a best practice for managing secrets in a cloud-native application?

A.Encrypting secrets and storing them in a configuration file
B.Storing secrets in environment variables inside container images
C.Hardcoding secrets in the application source code
D.Using a cloud secrets manager to retrieve secrets at runtime
AnswerD

A cloud secrets manager stores credentials encrypted and injects them at runtime, so secrets never persist in source code, container images or environment files. This satisfies the constraint of keeping credentials out of artefacts while supporting rotation and audit logging.

Why this answer

Using a cloud secrets manager (e.g., AWS Secrets Manager, Azure Key Vault, GCP Secret Manager) is the best practice because it centralizes secret storage, enforces access control via IAM, supports automatic rotation, and provides audit logging. Secrets are retrieved at runtime, so they are never persisted in code, images, or configuration files. This minimizes the attack surface and aligns with the principle of least privilege.

Exam trap

CCSP often tests the misconception that encrypting secrets in configuration files or using environment variables is sufficient, but the exam expects recognition that runtime retrieval from a dedicated secrets manager is the only truly secure and manageable approach.

How to eliminate wrong answers

Option A is wrong because encrypting secrets and storing them in a configuration file still leaves the encrypted secrets and the decryption key on disk or in the deployment artifact, which can be leaked or misconfigured; it also lacks centralized rotation and auditing. Option B is wrong because environment variables inside container images are baked into the image layers, making them visible to anyone with access to the image and easily exposed via debugging endpoints or process listings. Option C is wrong because hardcoding secrets in source code is a critical vulnerability: secrets end up in version control, build logs, and developer machines, and rotation becomes nearly impossible.

455
MCQhard

A company uses Terraform to manage cloud infrastructure. Which infrastructure-as-code (IaC) security scanner can detect misconfigurations such as overly permissive security group rules before deployment?

A.Snyk
B.Dependabot
C.GitGuardian
D.Checkov
AnswerD

Checkov is a static analysis tool for infrastructure-as-code that parses Terraform plans and configurations, flagging misconfigurations such as overly permissive security group rules before deployment. This satisfies the stem's pre-deployment detection requirement for Terraform-managed infrastructure.

Why this answer

Checkov is an open-source static analysis tool specifically designed to scan Infrastructure as Code (IaC) templates, including Terraform, for security misconfigurations such as overly permissive security group rules (e.g., 0.0.0.0/0 ingress on port 22). It uses a policy-as-code framework with hundreds of built-in checks (e.g., CKV_AWS_24 for unrestricted SSH) and can be integrated into CI/CD pipelines to catch issues before deployment, making it the correct choice for pre-deployment IaC scanning.

Exam trap

The ISC2 CCSP exam often tests the distinction between IaC security scanners (like Checkov) and other security tools (like Snyk for dependencies, Dependabot for package updates, and GitGuardian for secrets), so candidates must recognize that only Checkov is purpose-built for scanning Terraform configurations before deployment.

How to eliminate wrong answers

Option A is wrong because Snyk is a general-purpose application security testing tool that focuses on open-source dependency vulnerabilities and container images, not specifically on scanning Terraform or IaC templates for misconfigurations like security group rules. Option B is wrong because Dependabot is a GitHub-native tool that automates dependency updates and alerts for known vulnerabilities in package manifests (e.g., npm, Maven), not for scanning IaC code or cloud resource definitions. Option C is wrong because GitGuardian is a secrets detection tool that scans repositories for exposed credentials, API keys, and tokens, not for analyzing Terraform configurations for cloud security misconfigurations.

456
MCQeasy

Refer to the exhibit. A cloud administrator ran the Azure CLI command to list virtual machines. One VM shows a ProvisioningState of 'Failed'. What is the most likely cause of this state?

A.The VM's resource group has been moved to another subscription.
B.The VM is in a deallocated state.
C.The VM failed to start due to a resource quota limit or configuration error.
D.The VM was deleted by another administrator.
AnswerC

The ProvisioningState reflects the ARM deployment outcome, not guest OS health. A quota breach or invalid configuration (for example, an unsupported VM size or bad NIC reference) aborts resource creation during allocation, leaving the VM in Failed rather than Running.

Why this answer

A 'ProvisioningState' of 'Failed' in Azure indicates that the VM could not be created or started due to a resource quota limit (e.g., vCPU quota exceeded) or a configuration error (e.g., invalid network interface, unsupported VM size). This state is set by the Azure Resource Manager when the deployment or update operation fails, and it persists until the underlying issue is resolved and the VM is redeployed or reconfigured.

Exam trap

ISC2 often tests the distinction between 'ProvisioningState' and 'PowerState' — the trap here is that candidates confuse a 'Failed' provisioning state with a deallocated or stopped VM, but 'ProvisioningState' only reflects the success of the resource creation or update operation, not the runtime status.

How to eliminate wrong answers

Option A is wrong because moving a resource group to another subscription does not change the provisioning state of existing VMs; the VM would remain in its current state (e.g., 'Succeeded') and continue running. Option B is wrong because a deallocated VM shows a 'ProvisioningState' of 'Succeeded' (since it was successfully provisioned) and a 'PowerState' of 'Deallocated'; the 'ProvisioningState' field specifically tracks the success or failure of the provisioning operation, not the power state. Option D is wrong because if a VM is deleted, it no longer appears in the list of VMs; the 'ProvisioningState' field is only relevant for existing resources, and a deleted VM would return a '404 Not Found' error or simply not be listed.

457
MCQeasy

An organization wants to implement a cloud security automation solution that can automatically remediate non-compliant resources in Azure. Which Azure service should be used to create remediation tasks?

A.Azure Policy
B.Azure Security Center
C.Azure Automation
D.Azure Logic Apps
AnswerA

Azure Policy evaluates resources against built-in or custom definitions and, through remediation tasks, automatically corrects non-compliant resources using managed identities. This directly satisfies the requirement for automated remediation in Azure, unlike monitoring or advisory services that only detect and report drift without enforcing configuration changes.

Why this answer

Azure Policy includes 'remediation tasks' that can automatically fix non-compliant resources, often using managed identities.

458
MCQmedium

A container runtime is configured to drop all Linux capabilities, use a read-only root filesystem, and apply a Seccomp profile. Which primary security goal does this configuration achieve?

A.Image integrity verification
B.Ensuring immutability of containers
C.Prevention of container escape
D.Network segmentation between pods
AnswerC

Dropping all Linux capabilities removes the privileges an attacker needs to break out of the container's namespace isolation, while the read-only root filesystem and Seccomp profile block the syscalls and filesystem writes that privilege-escalation exploits rely on. Together these harden the container boundary against escape.

Why this answer

Dropping all Linux capabilities, using a read-only root filesystem, and applying a Seccomp profile collectively harden the container against privilege escalation and syscall-based attacks that are commonly used in container escape techniques. These controls limit what a compromised process can do, making it much harder to break out of the container and access the host. Thus, the primary security goal is prevention of container escape.

Exam trap

CCSP often tests the confusion between runtime hardening controls and other security goals — candidates may pick immutability or image integrity when the combination of capabilities, read-only FS, and Seccomp specifically targets escape prevention.

How to eliminate wrong answers

Option A is wrong because image integrity verification involves signing and verifying container images (e.g., Docker Content Trust, cosign), not runtime restrictions like capabilities or Seccomp. Option B is wrong because immutability refers to preventing changes to the container's filesystem at runtime; while a read-only root filesystem supports immutability, the combination with capability dropping and Seccomp is broader than immutability alone. Option D is wrong because network segmentation between pods is achieved via network policies (e.g., Kubernetes NetworkPolicy, service mesh), not via capability or syscall restrictions.

459
MCQmedium

A media production company needs to process high-resolution video renders that require tightly coupled, low-latency inter-node communication. The company is evaluating cloud deployment models and wants to retain full control over the hardware, hypervisor, and network fabric while still using cloud burst capacity. Which cloud deployment model BEST meets these requirements?

A.Community cloud
B.Public cloud
C.Private cloud
D.Hybrid cloud
AnswerD

Hybrid cloud combines a private cloud that the company controls (hardware, hypervisor, network fabric) with public cloud burst capacity. This matches the requirement to keep tightly coupled, latency-sensitive rendering on controlled infrastructure while elastically extending to public resources during peak demand, preserving both control and scalability.

Why this answer

The scenario requires both exclusive control over the underlying infrastructure and the ability to extend into elastic public capacity on demand. A hybrid cloud is the only model that pairs a controlled private environment with public cloud bursting, satisfying the latency-sensitive rendering requirements while avoiding permanent over-provisioning of owned hardware.

Exam trap

The trap here is assuming that any cloud model offering scalability also offers the infrastructure control needed for tightly coupled, low-latency workloads.

460
MCQmedium

An organization ingests AWS CloudTrail logs into a centralized SIEM for correlation. They want to detect an attacker who exfiltrates data by downloading large volumes from an S3 bucket. Which SIEM correlation rule would best detect this?

A.Alert on multiple failed login attempts
B.Alert on high volume of GetObject requests from a single IP
C.Alert on root account usage
D.Alert when a new IAM user is created
AnswerB

GetObject requests represent actual object downloads, so alerting when a single IP generates an abnormally high volume of them detects bulk data retrieval. Aggregating by source IP over a time window satisfies the exfiltration scenario, distinguishing sustained mass downloading from routine sporadic access.

Why this answer

Exfiltration of data from S3 typically involves a high volume of GetObject API calls from a single source IP. A SIEM correlation rule that triggers on a threshold of GetObject requests from the same IP address directly detects this anomalous download behavior, which is a key indicator of data exfiltration.

Exam trap

This exam often tests the distinction between detection of the exfiltration action itself (high volume of GetObject requests) versus precursor or unrelated events (failed logins, root usage, IAM creation), leading candidates to choose a rule that detects a different phase of the attack chain.

How to eliminate wrong answers

Option A is wrong because multiple failed login attempts indicate a brute-force attack on authentication, not data exfiltration from S3. Option C is wrong because root account usage is a security concern for privilege escalation or configuration changes, but it does not specifically detect bulk data downloads from S3. Option D is wrong because creating a new IAM user is an administrative action that could be part of an attack chain, but it does not directly detect the exfiltration event itself.

461
MCQmedium

A DevOps engineer is configuring a Kubernetes cluster and wants to enforce that containers cannot run as root and cannot mount host paths. Which Kubernetes security mechanism should be used?

A.Pod Security Admission
B.Network policies
C.RBAC
D.Secrets management
AnswerA

Pod Security Admission enforces Pod Security Standards at the namespace level, with the restricted profile rejecting pods that run as root or mount host paths. This declaratively satisfies both constraints the DevOps engineer needs to enforce.

Why this answer

Pod Security Admission (PSA) is the built-in Kubernetes admission controller that enforces Pod Security Standards (Privileged, Baseline, Restricted) at the namespace level. The Restricted profile specifically prohibits running as root (via runAsNonRoot and allowPrivilegeEscalation: false) and blocks hostPath volume mounts, which is exactly what the engineer needs. It replaced the deprecated PodSecurityPolicy and is applied via namespace labels like pod-security.kubernetes.io/enforce=restricted.

Exam trap

The trap here is confusing admission-time pod security controls with runtime network or identity controls — candidates often pick Network Policies or RBAC because they sound like 'security,' but only PSA inspects the pod spec's securityContext and volume definitions.

How to eliminate wrong answers

Option B is wrong because Network Policies only control pod-to-pod and pod-to-external L3/L4 traffic flows; they have no visibility into container user IDs or volume mount types. Option C is wrong because RBAC governs which users/service accounts can perform API actions (verbs on resources), not the runtime security context of a container. Option D is wrong because Secrets management handles storage and retrieval of sensitive data like credentials and tokens; it does not constrain how a container executes or what it mounts.

462
MCQmedium

A community cloud is best suited for which scenario?

A.A startup wanting to minimize costs by sharing resources with the general public
B.A single organization needing dedicated infrastructure
C.A company that needs to burst workloads to the public cloud during peak times
D.Several government agencies with similar security and compliance requirements
AnswerD

A community cloud is shared infrastructure provisioned for a specific community of organisations with common concerns. Several government agencies with similar security and compliance requirements fit this model, sharing cost and controls while excluding the general public.

Why this answer

A community cloud is shared infrastructure provisioned for exclusive use by a specific community of consumers from organizations that have shared concerns (e.g., mission, security requirements, policy, compliance). Several government agencies with similar security and compliance requirements is the canonical example, because they can share costs while meeting common regulatory mandates like FedRAMP or CJIS. The defining trait is a bounded community with shared interests, not the general public.

Exam trap

The trap is that 'community cloud' sounds like it serves the general public, so candidates pick the public-cloud answer — the exam expects you to know the community is a bounded group with shared compliance or mission needs.

How to eliminate wrong answers

Option A is wrong because sharing resources with the general public describes a public cloud, not a community cloud — community clouds are restricted to a defined group. Option B is wrong because a single organization needing dedicated infrastructure describes a private cloud, which is exclusive to one entity. Option C is wrong because bursting to the public cloud during peak times describes a hybrid cloud deployment model, which combines private and public resources.

463
MCQmedium

What additional security benefit does a private network endpoint provide?

A.It encrypts data in transit.
B.It ensures data is not traversing the public internet.
C.It provides an additional layer of authentication.
D.It enables cross-region replication.
AnswerB

A private network endpoint keeps traffic within the provider's private backbone rather than routing over the public internet, reducing exposure to interception and public-path attacks. This satisfies the additional security benefit sought beyond standard encryption.

Why this answer

A private network endpoint (such as an interface or gateway endpoint) allows instances within a virtual network to privately connect to supported cloud services without requiring an internet gateway, NAT device, VPN connection, or dedicated connection. The core security benefit is that all traffic between the virtual network and the service stays entirely within the cloud provider's internal network and never traverses the public internet, eliminating exposure to internet-based threats.

Exam trap

ISC2 often tests the misconception that private network endpoints provide encryption or authentication, but the real security benefit is purely about keeping traffic off the public internet, not about adding cryptographic or identity-layer controls.

How to eliminate wrong answers

Option A is wrong because VPC endpoints do not inherently encrypt data in transit; encryption (e.g., TLS) is a separate configuration on the client side or service side, not a feature of the endpoint itself. Option C is wrong because VPC endpoints do not provide an additional layer of authentication; they rely on IAM policies and endpoint policies for access control, but the endpoint itself does not authenticate users or services beyond standard AWS authentication. Option D is wrong because VPC endpoints are used for private connectivity within a region or to a specific service, not for cross-region replication; cross-region replication is handled by services like S3 replication or RDS cross-region read replicas, not by VPC endpoints.

464
MCQmedium

A covered entity under HIPAA is planning to migrate electronic protected health information (ePHI) to a public cloud environment. Which of the following is a mandatory requirement before using the cloud service?

A.Encrypt all ePHI with keys managed solely by the covered entity
B.Conduct a physical on-site audit of the cloud provider's data centers
C.Obtain a signed Business Associate Agreement from the cloud provider
D.Ensure the cloud provider is certified under the Privacy Shield framework
AnswerC

HIPAA requires a Business Associate Agreement before any covered entity shares ePHI with a cloud provider, since the provider qualifies as a business associate. The signed BAA contractually binds the provider to safeguard ePHI and satisfies the mandatory prerequisite for cloud migration.

Why this answer

HIPAA requires covered entities to obtain satisfactory assurances that PHI will be protected, typically through a Business Associate Agreement (BAA) with the cloud provider.

465
Multi-Selectmedium

A security team is hardening a Kubernetes cluster for production workloads. Which THREE measures should they implement to improve runtime container security?

Select 3 answers
A.Mount the host filesystem as read-write in containers
B.Enable AppArmor or SELinux profiles
C.Drop all unnecessary Linux capabilities
D.Apply Seccomp profiles to restrict system calls
E.Use privileged containers for system daemons
AnswersB, C, D

These MAC systems enforce security policies on containers.

Why this answer

AppArmor and SELinux are Linux Security Modules (LSMs) that enforce mandatory access control (MAC) policies on containers. By applying these profiles, you restrict what processes inside a container can do—such as file access, network operations, and capability use—beyond the default discretionary access controls. This significantly reduces the attack surface and limits the impact of a container breakout.

Exam trap

ISC2 often tests the distinction between runtime security measures (like AppArmor, Seccomp, and capability dropping) versus build-time or network-level controls, and candidates may confuse privileged containers with necessary system daemons, forgetting that privileged mode bypasses all runtime security layers.

466
Multi-Selecthard

Which THREE statements about cryptographic key lifecycle management are correct?

Select 3 answers
A.Key usage should be logged and audited.
B.Key generation should be performed within a secure cryptographic module.
C.Key destruction should render the key irrecoverable.
D.Key backup must be encrypted and stored separately from the keys they protect.
E.Key rotation policies must ensure all data is re-encrypted with the new key immediately.
AnswersA, B, C

Logging provides accountability and helps detect unauthorized use.

Why this answer

Auditing key usage is a fundamental requirement for accountability and compliance in cryptographic key management. Logging every key operation (e.g., generation, encryption, decryption, signing) allows detection of unauthorized use or policy violations, and is mandated by standards like NIST SP 800-57 Part 1, which states that audit logs must be protected and reviewed regularly.

Exam trap

ISC2 often tests the misconception that key rotation requires immediate re-encryption of all existing data, when in practice it uses lazy re-encryption or key wrapping to avoid performance and availability impacts.

467
MCQmedium

A cloud architect is designing a solution that must automatically scale compute resources based on real-time demand. The application is stateless and can tolerate brief interruptions. Which cloud design principle is most directly addressed by this requirement?

A.Broad network access
B.Measured service
C.Rapid elasticity
D.Resource pooling
AnswerC

Rapid elasticity is the principle of automatically provisioning and releasing resources to match demand, which is exactly what the stem's real-time scaling requirement describes. Statelessness and tolerance of brief interruptions make this horizontal, demand-driven scaling viable.

Why this answer

Rapid elasticity is the cloud characteristic that allows resources to scale automatically and dynamically based on demand, including scaling out and in quickly. The requirement for automatic scaling of stateless compute based on real-time demand directly maps to this principle. It ensures capacity matches workload without manual intervention.

Exam trap

The trap is that candidates confuse rapid elasticity with resource pooling or measured service, because all three are cloud characteristics — the exam tests whether you can map a specific requirement (automatic scaling) to the correct NIST characteristic.

How to eliminate wrong answers

Option A is wrong because broad network access refers to services being available over the network via standard mechanisms, not to scaling behavior. Option B is wrong because measured service refers to metering and pay-per-use billing, not automatic scaling. Option D is wrong because resource pooling refers to multi-tenant sharing of physical resources, which enables elasticity but does not itself describe automatic scaling.

468
Multi-Selecthard

Which THREE of the following are valid techniques to protect application programming interfaces (APIs) from abuse?

Select 3 answers
A.Use API gateways to enforce authentication and authorization policies.
B.Use JSON Web Tokens (JWT) without encryption.
C.Use only HTTP GET requests for all API calls.
D.Implement rate limiting and throttling.
E.Require API keys or OAuth tokens for every request.
AnswersA, D, E

An API gateway centralises authentication and authorisation enforcement at the ingress point, validating tokens and applying policy before requests reach backend services. This prevents unauthenticated or unauthorised callers from invoking APIs, directly countering abuse such as credential-less enumeration and privilege escalation.

Why this answer

Option A is correct because an API gateway acts as a centralized enforcement point where authentication (e.g., validating OAuth 2.0 tokens or mTLS client certificates) and authorization policies (e.g., scope or role checks) are applied before requests reach backend services, blocking unauthenticated or unauthorized abuse. Option D is correct because rate limiting and throttling cap the number of requests a client can make per time window (e.g., 100 requests/minute per API key), mitigating brute-force, credential-stuffing, scraping, and denial-of-service abuse. Option E is correct because requiring an API key or OAuth token on every request ensures each call is tied to an identifiable, revocable principal, enabling per-client quotas, auditing, and immediate revocation of compromised credentials.

Option B is not a valid protection technique because an unencrypted JWT is only base64url-encoded and signed, not confidential—its payload can be read by anyone, so it does not protect the API from abuse and may leak sensitive claims. Option C is incorrect because restricting APIs to HTTP GET does not prevent abuse; GET requests can still be replayed, scraped, or flooded, and many legitimate operations require POST, PUT, or DELETE, so this neither authenticates nor limits callers.

Exam trap

The trap here is that candidates may think JWT without encryption is acceptable because JWTs are often signed (JWS), but the CCSP exam emphasizes that confidentiality is a separate requirement—signing alone does not protect sensitive data in the payload, and encryption (JWE) is mandatory when tokens contain private information.

469
MCQhard

A cloud security engineer is designing network isolation for a multi-tier application in a single VPC. The database tier must accept connections only from the application tier, and the application tier must accept traffic only from the web tier. Which mechanism should the engineer use to enforce this at the instance level?

A.Network ACLs applied to the subnets hosting each tier
B.VPC flow logs analyzed by a security information and event management system
C.Security groups that reference other security groups as allowed sources
D.A route table that directs inter-tier traffic through a virtual appliance
AnswerC

Security groups are stateful, instance-level virtual firewalls that support referencing another security group as the source in an inbound rule. The database tier's group can allow traffic only from the application tier's group, and the application tier's group can allow traffic only from the web tier's group. This expresses tier isolation in terms of logical group membership rather than IP addresses, so it remains correct as instances scale.

Why this answer

Security groups are stateful and evaluated at the instance's elastic network interface, and they uniquely support referencing another security group as an allowed source. That lets the engineer define the database tier as reachable only from members of the application tier's group, and the application tier as reachable only from the web tier's group. This logical, identity-based rule set preserves isolation as instances scale and change IP addresses.

Exam trap

The trap here is assuming subnet-level network ACLs can express tier-to-tier trust, when only security groups can reference other security groups as sources for instance-level enforcement.

470
MCQhard

A cloud operations team is deploying a three-tier application across two AWS Availability Zones. The database tier must not be reachable from the internet, and the web tier must accept HTTPS from the public. The security architect wants defense in depth at both the subnet and instance levels. Which combination of controls BEST aligns with a layered network security design?

A.Place both tiers in public subnets and use network ACLs to restrict the database tier to the web tier's CIDR block, with security groups allowing all traffic within the VPC.
B.Use AWS WAF in front of the web tier and AWS Shield Advanced for the database tier, with security groups allowing 3306 from the VPC CIDR.
C.Place the web tier in a public subnet with a security group allowing 443 from 0.0.0.0/0 and a network ACL allowing 443 inbound; place the database tier in a private subnet with a security group allowing 3306 only from the web tier security group and a network ACL denying all internet CIDR ranges.
D.Place both tiers in private subnets, use a NAT gateway for web tier egress, and rely on security groups alone to control inbound traffic.
AnswerC

This design layers stateless network ACLs at the subnet boundary with stateful security groups at the instance level, which is the intended defense-in-depth model in a VPC. The database tier references the web tier's security group rather than a CIDR, so only authorized instances can connect. Denying internet CIDRs at the network ACL adds a second, independent barrier.

Why this answer

A layered VPC design uses network ACLs at the subnet boundary and security groups at the instance level, giving two independent enforcement points. Referencing the web tier's security group as the database source restricts access to authorized instances rather than broad CIDRs. Keeping the database in a private subnet and denying internet CIDRs at the network ACL completes the defense-in-depth model.

Exam trap

The trap here is treating security groups and network ACLs as interchangeable; they operate at different layers and a proper design uses both, with security group references instead of CIDR ranges for internal tiers.

471
MCQeasy

A serverless function needs to access a private database service without traversing the public internet. Which configuration should be used?

A.Assign a public IP to the serverless function
B.Configure the serverless function with virtual private cloud integration
C.Enable public access on the database service
D.Use a network address translation gateway to route traffic
AnswerB

VPC integration places the function's elastic network interfaces inside private subnets, so traffic to the database stays on the AWS private network and never routes through an internet gateway or NAT. This directly satisfies the requirement to avoid public internet traversal.

Why this answer

Virtual private cloud (VPC) integration allows the serverless function to be deployed inside a VPC, enabling private access to resources like a database service. Internet access is not required.

472
MCQhard

A SaaS provider stores customer data in a multi-tenant database. A new regulation requires that data of former customers be completely erased within 30 days of account closure. Which process should the provider implement?

A.Physically destroy the hard drives containing the data.
B.Mark the data as deleted and exclude it from query results.
C.Overwrite the data with zeros using a secure delete tool.
D.Encrypt each customer's data with a unique key and delete the key upon account closure.
AnswerD

Per-customer encryption keys enable crypto-shredding: deleting the unique key renders that customer's ciphertext unrecoverable, achieving complete erasure within 30 days without deleting shared multi-tenant rows. This satisfies the regulatory erasure requirement in a multi-tenant database.

Why this answer

It implements cryptographic erasure, which renders the data permanently inaccessible by deleting the unique encryption key. This approach satisfies the regulation's requirement for complete erasure within 30 days without physically destroying hardware or risking data remnants, as the encrypted data becomes irrecoverable without the key. In a multi-tenant SaaS environment, this method is efficient, scalable, and avoids service disruption to other tenants sharing the same storage.

Exam trap

ISC2 often tests the distinction between logical deletion (soft delete) and cryptographic erasure, trapping candidates who think marking data as deleted or overwriting with zeros is sufficient in a multi-tenant cloud environment, where shared storage and data redundancy make physical overwrite impractical.

How to eliminate wrong answers

Option A is wrong because physically destroying hard drives is impractical for a multi-tenant database, as it would destroy data for all customers, not just former ones, and violates the principle of shared infrastructure. Option B is wrong because marking data as deleted and excluding it from query results only hides the data logically; the underlying data remains on the storage medium and could be recovered through forensic tools, failing the regulation's requirement for complete erasure. Option C is wrong because overwriting data with zeros using a secure delete tool is not feasible in a multi-tenant database environment where data is stored in shared blocks and may be subject to wear-leveling, snapshots, or copy-on-write mechanisms that prevent guaranteed overwrite of all copies.

473
Drag & Dropmedium

Drag and drop the steps for implementing a secure DevOps (DevSecOps) pipeline in a cloud environment into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First SAST at commit, then DAST in staging, IaC scanning, policy enforcement, and runtime monitoring.

474
Multi-Selectmedium

A cloud service provider is expanding into a new jurisdiction and must demonstrate compliance with local data protection laws. The provider's legal team is reviewing the shared responsibilities between the provider and its customers. Which TWO activities are the provider's responsibility under a typical cloud shared responsibility model? (Choose two.)

Select 2 answers
A.Securing the physical facilities, hardware, and network infrastructure that host the cloud services.
B.Configuring encryption for the customer's data at rest using customer-managed keys stored in the customer's environment.
C.Classifying the customer's data and determining which regulatory requirements apply to that data.
D.Providing the hypervisor, storage virtualization, and network isolation controls that separate tenant environments.
E.Managing the customer's identity and access policies for the customer's own users and applications.
AnswersA, D

The provider owns and operates the underlying data centers, servers, and network fabric, so it is responsible for physical security, hardware maintenance, and infrastructure-level network controls. These are foundational controls that customers cannot implement themselves and form the provider's side of the shared responsibility model.

Why this answer

In a cloud shared responsibility model, the provider secures the infrastructure that delivers the service, including physical facilities, hardware, and the virtualization layer that isolates tenants. The customer remains responsible for its data, identity management, and customer-side encryption key custody. Understanding this division is essential for meeting regulatory obligations in any jurisdiction.

Exam trap

The trap here is assuming the provider handles all security controls, when data classification, IAM, and customer-managed encryption keys remain customer responsibilities.

475
MCQeasy

Which cloud service model provides the customer with the most control over the underlying infrastructure, including operating systems and applications?

A.IaaS
B.PaaS
C.SaaS
D.FaaS
AnswerA

IaaS delivers compute, storage and networking while the customer manages operating systems, middleware and applications. That leaves the customer controlling more of the stack than PaaS or SaaS permit, satisfying the stem's requirement for the greatest infrastructure control.

Why this answer

IaaS gives the customer control over the operating system, middleware, runtime, and applications while the provider manages the physical host, hypervisor, and networking fabric. This is the highest level of customer control among the four models listed. PaaS, SaaS, and FaaS progressively abstract away more of the stack, reducing customer control.

Exam trap

The trap is assuming 'most control' means 'most secure' or 'most managed' — the exam tests whether you know IaaS sits at the top of the customer-control spectrum, not the provider-responsibility spectrum.

How to eliminate wrong answers

Option B is wrong because PaaS abstracts the OS and runtime, so the customer controls only the application and its configuration, not the underlying infrastructure. Option C is wrong because SaaS delivers a fully managed application where the customer controls only data and user access, not the OS or infrastructure. Option D is wrong because FaaS (serverless) abstracts even the runtime and scaling, leaving the customer responsible only for function code and configuration.

476
MCQmedium

A company uses Azure Policy with remediation tasks to automatically fix non-compliant resources. Which scenario can be automatically remediated using a built-in policy?

A.A virtual machine missing the Log Analytics agent
B.A user creating a new Azure subscription
C.A SQL database with advanced data security disabled
D.A storage account with public network access enabled
AnswerA

The built-in Deploy Log Analytics agent policy uses the deployIfNotExists effect, so a remediation task installs the missing extension on virtual machines flagged as non-compliant. This directly satisfies the automatic remediation scenario for VMs lacking the Log Analytics agent.

Why this answer

The built-in Azure Policy 'Deploy Log Analytics agent to Windows VMs' includes a remediation task that automatically installs the Log Analytics agent on existing VMs that are missing it. This is a DeployIfNotExists policy effect, which triggers a remediation task to correct non-compliance without manual intervention.

Exam trap

The CCSP exam often tests the distinction between policy effects (Audit, Deny, DeployIfNotExists) and which ones support automatic remediation, leading candidates to assume any non-compliance can be auto-fixed if a policy exists, but only DeployIfNotExists and Modify effects enable remediation tasks.

How to eliminate wrong answers

Option B is wrong because Azure Policy cannot automatically remediate the creation of a new Azure subscription; subscription creation is a tenant-level action that requires Azure RBAC or Azure Blueprints, not a policy with remediation. Option C is wrong because disabling advanced data security on a SQL database is a configuration that can be audited by Azure Policy, but the built-in policies for SQL advanced data security typically use AuditIfNotExists or Deny effects, not DeployIfNotExists with remediation tasks, so automatic remediation is not available out-of-the-box. Option D is wrong because while Azure Policy can audit or deny storage accounts with public network access enabled, the built-in policies for this setting use Deny or Audit effects, not DeployIfNotExists, meaning they block or report non-compliance but do not automatically remediate existing non-compliant resources.

477
MCQeasy

In a hybrid cloud deployment, which of the following is a critical security consideration?

A.Ensuring consistent security policy across environments
B.Using only public cloud for sensitive data
C.Avoiding any use of APIs for integration
D.Eliminating all private cloud resources
AnswerA

Hybrid cloud spans on-premises and cloud environments, so inconsistent policies create gaps attackers can exploit between them. Enforcing a uniform security policy across both satisfies the need for coherent controls, identity, and monitoring regardless of where workloads reside.

Why this answer

Consistent security policy across environments is critical in hybrid cloud because workloads and data span on-premises and cloud boundaries, and inconsistent controls create gaps attackers can exploit. Unified policy ensures identity, encryption, logging, and access controls are applied uniformly. This is a foundational governance requirement for hybrid architectures.

Exam trap

The trap is picking an option that sounds secure but is actually an architectural anti-pattern (e.g., 'use only public cloud' or 'avoid APIs') — the exam wants the governance principle of consistent policy across environments.

How to eliminate wrong answers

Option B is wrong because using only public cloud for sensitive data contradicts hybrid strategy and may violate data residency or compliance requirements; it is not a security consideration but a flawed constraint. Option C is wrong because avoiding APIs for integration is impractical and insecure — APIs are the primary integration mechanism in hybrid cloud, and avoiding them prevents automation and consistent policy enforcement. Option D is wrong because eliminating all private cloud resources defeats the purpose of a hybrid deployment and ignores the security benefits of private environments for sensitive workloads.

478
MCQeasy

A company is moving a legacy application to the cloud. The application uses hard-coded passwords for database connections. Which secure development practice should be implemented to address this issue?

A.Multi-factor authentication
B.Input validation
C.Encryption at rest
D.Secrets management
AnswerD

Secrets management extracts hard-coded credentials into a dedicated vault that issues short-lived, rotated credentials at runtime, removing passwords from source and images. This directly satisfies the stem's constraint by eliminating the embedded database passwords that would otherwise leak through repositories and container layers.

Why this answer

Hard-coded passwords in application code violate the principle of least privilege and create a persistent security risk if the code is exposed. Secrets management (D) addresses this by storing database credentials in a secure, centralized vault (e.g., HashiCorp Vault, AWS Secrets Manager) and retrieving them at runtime via API calls, eliminating the need to embed passwords in source code or configuration files.

Exam trap

ISC2 often tests the distinction between 'encryption at rest' (protecting stored data) and 'secrets management' (protecting credentials used to access that data), leading candidates to confuse data protection with credential protection.

How to eliminate wrong answers

Option A is wrong because multi-factor authentication (MFA) is an identity verification mechanism for user access, not a method to securely store or manage application-level database credentials. Option B is wrong because input validation prevents injection attacks (e.g., SQL injection) by sanitizing user-supplied data, but it does not address the storage or retrieval of hard-coded passwords. Option C is wrong because encryption at rest protects data stored on disk (e.g., database files) from unauthorized access, but it does not prevent the exposure of credentials hard-coded in application code or configuration.

479
MCQmedium

A company wants to enforce that all API calls to its cloud services are authenticated and authorized. Which design pattern should be implemented?

A.Implement OAuth 2.0 with scopes
B.Use API keys with IP whitelisting
C.Allow basic authentication over HTTPS
D.Use shared secrets with HMAC
AnswerA

OAuth 2.0 with scopes satisfies the requirement by issuing access tokens that carry granular permissions, letting the resource server validate both caller identity and the specific operations each token authorises. Scopes constrain what an authenticated client may do, delivering authentication and fine-grained authorisation for every API call without exposing credentials.

Why this answer

OAuth 2.0 with scopes is the correct design pattern because it provides a standardized, token-based authorization framework that allows fine-grained access control to API resources. Scopes define specific permissions (e.g., read, write) and are validated by the resource server, ensuring that each API call is both authenticated (via the access token) and authorized (via the scopes). This aligns with the principle of least privilege and is widely adopted for securing cloud APIs.

Exam trap

The trap here is that candidates often confuse authentication (verifying identity) with authorization (granting permissions) and choose a method like API keys or basic auth that only authenticates, failing to address the authorization requirement explicitly stated in the question.

How to eliminate wrong answers

Option B is wrong because API keys with IP whitelisting only authenticate the client application, not the user or the request context, and IP whitelisting can be bypassed via spoofing or compromised networks; it lacks granular authorization. Option C is wrong because basic authentication over HTTPS sends credentials (username/password) in every request, which is vulnerable to credential leakage if the client or server is compromised, and it does not support scoped authorization. Option D is wrong because shared secrets with HMAC provide message integrity and authentication but do not offer a standardized way to enforce fine-grained authorization scopes; managing shared secrets at scale is also a security risk.

480
MCQmedium

A security engineer is investigating a potential data exfiltration incident involving an Amazon S3 bucket. Which set of logs would provide the most relevant information to identify the source IP and API calls made to the bucket?

A.VPC Flow Logs for the subnet where the bucket resides
B.AWS Config configuration history for the S3 bucket
C.AWS CloudTrail data events for the S3 bucket
D.Amazon CloudWatch Logs for the EC2 instance accessing the bucket
AnswerC

CloudTrail data events record object-level S3 API activity, capturing the caller's source IP and the specific operations performed on the bucket. Management events alone omit object-level calls, so data events are required to trace the exfiltration's origin and API sequence.

Why this answer

AWS CloudTrail data events capture object-level S3 API activity such as GetObject, PutObject, and DeleteObject, including the identity and source IP of the caller. This is exactly the evidence needed to trace who accessed or exfiltrated objects from a specific bucket. Management events alone would not show object reads, so data events must be explicitly enabled for the bucket.

Exam trap

The trap is assuming that network-level logs (VPC Flow Logs) or configuration logs (AWS Config) can reveal API-level activity; candidates must remember that only CloudTrail data events capture S3 object-level operations and caller identity.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs only record IP-level metadata (source/dest IP, port, bytes, accept/reject) for traffic traversing ENIs; S3 is a regional service accessed via public endpoints, and flow logs cannot show S3 API calls or object names. Option B is wrong because AWS Config records configuration state changes (e.g., bucket policy, ACL, encryption settings), not data-plane access activity. Option D is wrong because CloudWatch Logs on an EC2 instance only capture what the instance's OS or application writes locally; they do not record S3 API calls made by other principals or by the instance unless the app explicitly logs them.

481
MCQhard

A multinational corporation uses a cloud access security broker (CASB) to enforce data protection policies across multiple SaaS applications. They discover that sensitive data tagged with 'Confidential' is being shared externally via a file-sharing application. The CASB currently only logs activities. Which action should the security team take to prevent such data loss in the future?

A.Encrypt all files stored in the file-sharing application.
B.Revoke user access to the file-sharing application for all employees.
C.Train employees on data handling policies.
D.Implement a DLP policy that automatically blocks sharing of documents with the 'Confidential' label.
AnswerD

Blocking labelled 'Confidential' documents from external sharing directly addresses the stem's constraint: the CASB only logs, so no enforcement occurs. Inline DLP inspection lets the CASB intercept the upload and apply a block action at the API or proxy layer, converting detection into prevention for that specific label.

Why this answer

A CASB with Data Loss Prevention (DLP) capabilities can enforce real-time policies to block sharing of documents tagged with a specific sensitivity label (e.g., 'Confidential'). Since the CASB currently only logs activities, implementing a DLP policy that automatically blocks the sharing action addresses the root cause—preventing the data loss at the point of egress—rather than merely detecting it after the fact.

Exam trap

ISC2 often tests the distinction between detection (logging) and prevention (blocking), and the trap here is that candidates may choose training (Option C) as a 'best practice' without recognizing that the question explicitly asks for a technical action to prevent data loss, which requires an automated enforcement mechanism like DLP.

How to eliminate wrong answers

Option A is wrong because encrypting all files in the file-sharing application does not prevent sharing; encryption protects data at rest but does not control who can access or share the decrypted content. Option B is wrong because revoking access for all employees is an overly drastic measure that disrupts business operations and does not address the need for granular, policy-based control over specific data labels. Option C is wrong because training employees on data handling policies is a preventive administrative control, but it does not provide a technical enforcement mechanism to automatically block sharing of 'Confidential' documents in real time, leaving the organization reliant on human compliance.

482
MCQhard

A multinational bank uses a cloud provider for a system that processes customer transactions. A regulator asks the bank to demonstrate that it maintains effective control over the data and can meet its legal obligations even if the provider fails. Which activity best demonstrates that the bank has retained accountability for the outsourced processing?

A.Relying on the provider's SOC 2 Type II report as the sole evidence of control effectiveness
B.Maintaining a documented risk assessment and control mapping that assigns responsibility for each obligation
C.Requiring the provider to store all data in the bank's home country to simplify oversight
D.Transferring all security responsibility to the provider through an indemnification clause
AnswerB

Accountability means the bank can show it identified its legal and regulatory obligations, assessed the risks of outsourcing, and mapped each control to a responsible party. This documentation demonstrates that the bank governs the relationship rather than delegating responsibility. It also supports regulatory examination because the bank can evidence continuous oversight and remediation.

Why this answer

Retaining accountability requires documented governance: a risk assessment covering the outsourced activity, a mapping of legal obligations to controls, and clear assignment of responsibility between the bank and provider. This evidence shows the regulator that the bank governs the relationship and can meet its obligations even if the provider fails. Assurance reports, indemnities, and data localization support the program but do not replace accountability.

Exam trap

The trap here is equating contractual liability transfer, such as an indemnification clause, with regulatory accountability, which remains with the regulated entity.

483
MCQmedium

A security engineer is integrating security into a cloud application's CI/CD pipeline. Which practice is an example of 'shift-left' security?

A.Performing a penetration test after deployment
B.Analyzing logs after an incident
C.Running SAST scans during pull request review
D.Scanning container images in production
AnswerC

SAST during pull request review analyses source code before merge, catching flaws while remediation is cheapest and before artefacts are built. This satisfies the stem's shift-left constraint by moving security earlier in the CI/CD pipeline than build-time or runtime controls.

Why this answer

Shift-left security means moving security activities earlier in the software development lifecycle, and running SAST scans during pull request review catches vulnerabilities before code is merged. This is a classic example because it integrates security into the developer's existing workflow at the earliest feasible point. The other options all occur after deployment or after an incident, which is the opposite of shifting left.

Exam trap

CCSP often tests whether candidates can distinguish shift-left (pre-deployment, developer-centric) from shift-right (post-deployment, operations-centric) activities, and a common mistake is to label any automated security scan as shift-left even when it runs in production.

How to eliminate wrong answers

Option A is wrong because penetration testing after deployment is a post-deployment activity, which is shift-right or traditional security, not shift-left. Option B is wrong because analyzing logs after an incident is reactive and occurs after the damage is done, which is the antithesis of shift-left. Option D is wrong because scanning container images in production is a runtime control, not an early SDLC control, and it does not prevent vulnerable code from being deployed in the first place.

484
MCQeasy

A cloud engineer is configuring a storage bucket that will hold publicly accessible marketing images. The security policy requires that data at rest be encrypted, but the images are not sensitive and the team wants to minimize operational overhead. Which cloud storage encryption option is most appropriate?

A.Customer-managed keys stored in a hardware security module that the team rotates manually each quarter.
B.No encryption at rest, because the images are publicly accessible and therefore not confidential.
C.Client-side encryption where the application encrypts each image before uploading and manages its own key store.
D.Provider-managed encryption keys with automatic rotation, using the cloud provider's default encryption at rest.
AnswerD

Provider-managed keys provide encryption at rest with no key management burden on the team, which matches the low-sensitivity, low-overhead requirement. The provider handles key storage, rotation, and access control, so the marketing images remain encrypted without additional configuration. This satisfies the policy while avoiding unnecessary complexity for non-sensitive public content.

Why this answer

Provider-managed encryption keys are the best fit because they satisfy the encryption-at-rest policy while imposing no key management burden on the team. The images are public and non-sensitive, so stronger controls such as customer-managed keys or client-side encryption add cost and complexity without proportional benefit. The policy requirement is met with minimal operational effort.

Exam trap

The trap here is equating stronger key control with better security in every case, when the scenario's low sensitivity and low-overhead requirement make provider-managed keys the appropriate choice.

485
MCQeasy

A financial services company stores customer transaction data in a cloud object storage bucket. The company requires that all data be encrypted at rest using keys that it generates and manages on-premises, with the cloud provider having no access to the keys. Which encryption approach should the company use?

A.Server-side encryption with AES-256
B.Client-side encryption with customer-owned keys
C.Server-side encryption with bring your own key (BYOK) to cloud KMS
D.Server-side encryption with customer-managed keys (CMK) in cloud KMS
AnswerB

Encrypting data before it leaves the organisation means the provider stores only ciphertext, and keys generated and retained on-premises are never exposed to the cloud service. This satisfies the requirement that the provider has no access to keys, unlike provider-managed or customer-managed keys held in the cloud.

Why this answer

Client-side encryption with customer-owned keys means the company encrypts data before uploading it to cloud storage, and the keys never leave the company's on-premises environment. The cloud provider stores only ciphertext and has no access to the plaintext or the keys, satisfying the requirement that the provider cannot access the keys.

Exam trap

CCSP often tests the distinction between BYOK/CMK (provider still holds key material in its KMS) and true client-side encryption (customer retains sole key custody) — candidates who equate 'customer-managed' with 'provider cannot access' pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because server-side encryption with AES-256 is managed by the cloud provider, which holds the keys and can decrypt data — violating the no-provider-access requirement. Option C is wrong because BYOK to cloud KMS still imports the key material into the provider's KMS, where the provider's infrastructure handles it and could theoretically access it. Option D is wrong because customer-managed keys (CMK) in cloud KMS are stored and managed within the provider's KMS, so the provider has access to the key material and can decrypt data.

486
MCQeasy

A cloud security engineer is reviewing the security posture of a web application deployed on AWS. The application uses an Application Load Balancer (ALB) and EC2 instances. The engineer wants to ensure that all incoming traffic is encrypted in transit. Which action should the engineer take?

A.Use AWS Shield Advanced to protect the application from DDoS attacks.
B.Enable encryption at rest on the EC2 instance volumes using AWS KMS.
C.Configure a security group on the EC2 instances to allow only HTTPS traffic from the ALB.
D.Configure the ALB to use an HTTPS listener with an ACM certificate and redirect HTTP to HTTPS.
AnswerD

Configuring the ALB with an HTTPS listener using an AWS Certificate Manager (ACM) certificate encrypts traffic between clients and the ALB. Redirecting HTTP to HTTPS ensures that all incoming traffic uses TLS. This is the standard method to enforce encryption in transit for web applications behind an ALB, providing confidentiality and integrity for data in transit.

Why this answer

To encrypt incoming traffic, the Application Load Balancer must terminate TLS using an HTTPS listener with a valid certificate from AWS Certificate Manager. Redirecting HTTP to HTTPS ensures all clients use encryption. This secures data in transit from clients to the ALB, meeting the requirement.

Exam trap

The trap here is confusing encryption in transit with encryption at rest or network access controls, leading to selection of irrelevant measures like EBS encryption or security groups.

487
MCQeasy

Which of the following is a primary risk specific to virtual machine escape attacks in cloud environments?

A.Unauthorized access to other tenant VMs
B.Data corruption within the same VM
C.Increased latency in virtual networking
D.Denial of service to the attacker's own VM
AnswerA

A VM escape exploits a hypervisor or virtualisation flaw to break out of the guest boundary, letting the attacker execute code on the host. From there they can read or manipulate other tenants' VM memory and data, so unauthorised access to co-resident tenant VMs is the defining risk.

Why this answer

VM escape attacks occur when an attacker breaks out of the guest VM's isolation and gains access to the hypervisor or host. In a multi-tenant cloud environment, the hypervisor manages multiple tenants' VMs, so a successful escape can allow the attacker to access or compromise other tenants' VMs running on the same host. This cross-tenant access is the primary risk specific to cloud VM escape, as it violates the fundamental isolation guarantee of cloud computing.

Exam trap

The trap is selecting a generic attack impact (data corruption, DoS) instead of recognizing that the defining risk of VM escape in cloud is cross-tenant compromise due to shared hypervisor infrastructure.

How to eliminate wrong answers

Option B is wrong because data corruption within the same VM is a consequence of many attacks but not specific to escape; escape implies breaking isolation, not just corrupting local data. Option C is wrong because increased latency in virtual networking is a performance issue, not a security risk of escape. Option D is wrong because denial of service to the attacker's own VM is counterproductive and not a risk of escape; the attacker seeks to compromise others, not self-destruct.

488
Multi-Selectmedium

A company stores sensitive data in cloud object storage and wants to protect against ransomware attacks that could encrypt or delete objects. Which TWO measures should they implement? (Choose two.)

Select 2 answers
A.Use cross-region replication
B.Implement immutable storage (e.g., Object Lock)
C.Configure signed URLs for access
D.Enable object versioning
E.Set short object lifetimes using lifecycle policies
AnswersB, D

Object Lock enforces WORM protection at the object level, preventing overwrite or deletion for a defined retention period — even by compromised credentials or malicious insiders. This directly satisfies the ransomware constraint, since encrypted or deleted objects cannot be altered until retention expires, enabling clean recovery.

Why this answer

Option B (immutable storage such as Object Lock) is correct because it enforces WORM (write once, read many) protection, preventing objects from being modified or deleted for a defined retention period even by compromised or malicious accounts, which directly blocks ransomware encryption or deletion. Option D (object versioning) is correct because it preserves prior versions of each object, so if ransomware overwrites or encrypts the current version, the previous clean versions remain recoverable. Option A (cross-region replication) only copies data to another region and would replicate corrupted or encrypted objects too, so it does not protect against ransomware.

Option C (signed URLs) merely grants time-limited access to specific objects and does not prevent an attacker with valid credentials from encrypting or deleting data. Option E (short object lifetimes via lifecycle policies) actually deletes objects sooner, which increases data loss risk rather than protecting against ransomware.

Exam trap

Candidates often mistakenly choose cross-region replication or lifecycle policies as ransomware defenses, not realizing that replication alone does not prevent deletion/encryption, and lifecycle policies could actually delete data. The correct approach combines immutable storage to prevent modification and versioning to allow recovery of prior states.

489
Multi-Selecthard

An enterprise is evaluating a cloud service provider for a workload that handles regulated data. The security architect must assess whether the provider's cloud architecture supports the organization's data residency and audit obligations. Which TWO of the following are the MOST relevant architectural artifacts to request from the provider? (Choose two.)

Select 2 answers
A.Independent third-party audit reports and certifications such as SOC 2 and ISO/IEC 27001
B.The provider's current stock price and quarterly earnings report
C.A data flow diagram showing where data is stored, processed, and replicated across regions
D.A copy of the provider's internal employee acceptable use policy
E.The provider's marketing brochure describing its global footprint and uptime record
AnswersA, C

Independent audit reports and certifications provide evidence that the provider's controls have been examined against recognized criteria. They support the organization's own audit and compliance obligations by offering verifiable assurance about security, availability, and processing integrity. They also help map provider controls to regulatory requirements during due diligence.

Why this answer

Assessing data residency and audit obligations requires verifiable evidence about where data lives and how controls are validated. A data flow diagram identifies storage, processing, and replication locations, while independent audit reports and certifications demonstrate that controls have been examined against recognized standards. Together they give the architect the factual basis needed for compliance due diligence.

Exam trap

The trap here is accepting vendor-provided assurances or business documents in place of verifiable architectural and audit evidence.

490
MCQeasy

Which cloud-specific attack involves an application making HTTP requests to internal metadata endpoints such as 169.254.169.254 to retrieve cloud instance credentials?

A.Dependency Confusion
B.Server-Side Request Forgery (SSRF)
C.Cross-Site Scripting (XSS)
D.SQL Injection
AnswerB

Server-Side Request Forgery exploits an application's ability to make outbound HTTP requests, letting an attacker redirect them to the link-local address 169.254.169.254. That endpoint serves instance metadata, including temporary IAM credentials, satisfying the stem's requirement for credential theft via internal metadata access.

Why this answer

The attack described is Server-Side Request Forgery (SSRF), where an attacker exploits a vulnerable application to make HTTP requests to internal metadata endpoints like 169.254.169.254 (the link-local address for cloud instance metadata services). This allows the attacker to retrieve cloud instance credentials (e.g., AWS IAM role temporary credentials) that are normally accessible only from within the instance, leading to privilege escalation and lateral movement.

Exam trap

The CCSP exam often tests SSRF by pairing it with the specific IP 169.254.169.254, and the trap here is that candidates may confuse SSRF with Dependency Confusion (both involve external resources) or think XSS/SQLi can be used to access internal endpoints, but only SSRF exploits server-side request handling to reach cloud metadata.

How to eliminate wrong answers

Option A (Dependency Confusion) is wrong because it involves an attacker uploading a malicious package with the same name as an internal dependency to a public repository, tricking the package manager into installing it; it does not involve HTTP requests to metadata endpoints. Option C (Cross-Site Scripting) is wrong because it injects malicious scripts into web pages viewed by other users, targeting client-side browsers rather than server-side requests to internal IPs. Option D (SQL Injection) is wrong because it manipulates database queries through input fields, not HTTP requests to cloud metadata services.

491
MCQeasy

What is the primary purpose of a Data Processing Agreement (DPA) between a data controller and a cloud service provider?

A.To set data retention periods for processed data
B.To specify encryption algorithms to be used
C.To establish data backup and recovery procedures
D.To define roles and responsibilities for data processing
AnswerD

A DPA contractually allocates controller and processor obligations, covering scope, security, sub-processing and data subject rights. Defining these roles and responsibilities satisfies the scenario's core purpose, establishing accountability and lawful processing boundaries between the controller and the cloud service provider.

Why this answer

A Data Processing Agreement (DPA) is a legally binding contract required under regulations like GDPR. Its primary purpose is to define the roles and responsibilities of the data controller and the data processor (the cloud service provider), ensuring the processor acts only on the controller's documented instructions and meets compliance obligations. Without a DPA, the controller cannot legally transfer data to the processor, as the agreement establishes the lawful basis and accountability for processing activities.

Exam trap

ISC2 often tests the distinction between legal/compliance documents (DPA) and operational/technical documents (SLA, security policies), so the trap here is confusing the DPA's role in defining processing roles with specific technical controls like encryption or backup procedures.

How to eliminate wrong answers

Option A is wrong because data retention periods are typically defined in a separate data retention policy or contract clause, not the DPA; the DPA focuses on processing instructions and compliance, not specific retention schedules. Option B is wrong because encryption algorithms are a technical security measure specified in a Security Addendum or SLA, not the DPA; the DPA addresses legal and contractual roles, not cryptographic implementation details. Option C is wrong because backup and recovery procedures are operational controls documented in a Business Continuity Plan or Disaster Recovery Plan, not the DPA; the DPA governs data processing boundaries and liability, not specific recovery steps.

492
Multi-Selectmedium

A cloud application team is adopting a DevSecOps pipeline for a containerized workload. They want to integrate security testing that can detect vulnerable dependencies and misconfigured infrastructure-as-code templates before deployment. Which two practices should be implemented to meet these goals? (Choose two.)

Select 2 answers
A.Perform dynamic application security testing against the staging environment after each deployment to find runtime vulnerabilities.
B.Scan infrastructure-as-code templates with a policy-as-code tool that evaluates them against organizational security baselines and blocks noncompliant changes.
C.Enable runtime application self-protection in production to block exploitation attempts against the running application.
D.Deploy a web application firewall in front of the application and tune it using production traffic logs.
E.Run software composition analysis (SCA) against the application's dependency manifest during the build stage and fail the build on critical findings.
AnswersB, E

Policy-as-code scanning of IaC templates catches misconfigurations such as public storage buckets or overly permissive security groups before resources are created. Blocking noncompliant changes enforces the baseline. This satisfies the misconfiguration detection requirement and operates early in the pipeline, preventing drift and reducing remediation cost.

Why this answer

Detecting vulnerable dependencies requires software composition analysis of dependency manifests during the build. Detecting misconfigured IaC requires policy-as-code scanning of templates before deployment. Both are preventive and shift security left.

Runtime controls such as RASP and WAF, and dynamic testing of a running app, do not analyze dependencies or templates, so they do not meet the stated goals.

Exam trap

The trap here is treating runtime defenses such as RASP or WAF as substitutes for build-time dependency and IaC scanning, when they operate at a different stage and on different artifacts.

493
MCQhard

A security engineer is investigating an incident where an attacker exploited a server-side request forgery (SSRF) vulnerability in a cloud application. The application runs in a cloud environment and uses internal metadata endpoints. Which mitigation should be prioritized to prevent future SSRF attacks?

A.Implement input validation to block malicious URLs
B.Restrict outbound network access from the application instances using network security controls
C.Deploy a web application firewall (WAF) to inspect outgoing requests
D.Require token-based authentication for metadata service access
AnswerB

SSRF abuses the application's ability to make outbound requests, so restricting egress with network security controls prevents instances from reaching internal metadata endpoints such as 169.254.169.254. This directly addresses the cloud metadata exposure described in the stem.

Why this answer

Restricting outbound network access from application instances using security groups directly prevents the application from reaching internal metadata endpoints and other internal services. This is a fundamental network-layer control that stops SSRF attacks at the source, regardless of input validation or request inspection, by blocking the outbound traffic that the attacker would exploit.

Exam trap

ISC2 often tests the misconception that input validation or WAFs are sufficient to stop SSRF, when in reality the most effective mitigation is network-layer egress filtering that blocks access to internal metadata endpoints.

How to eliminate wrong answers

Option A is wrong because input validation to block malicious URLs is easily bypassed by attackers using URL encoding, redirects, or alternative representations of the metadata endpoint (e.g., decimal IP, DNS rebinding), and it does not address the root cause of the application making unauthorized outbound requests. Option C is wrong because a web application firewall (WAF) inspects incoming HTTP requests, not outgoing requests from the application; it cannot block the outbound SSRF traffic that originates from the application server itself. Option D is wrong because disabling IMDSv1 and requiring IMDSv2 tokens only protects the metadata service from unauthorized access via token-based authentication, but it does not prevent the application from making SSRF requests to other internal endpoints or external systems; the attacker could still exploit the application to make outbound requests to arbitrary targets.

494
Drag & Dropmedium

Drag and drop the steps for conducting a cloud security risk assessment using the NIST CSF framework into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Start with identification, then threat/vulnerability assessment, risk analysis, treatment, and monitoring.

495
Multi-Selecteasy

Which of the following is an example of a data sovereignty law that directly affects cloud data storage?

Select 1 answer
A.General Data Protection Regulation (GDPR)
B.Sarbanes-Oxley Act (SOX)
C.California Consumer Privacy Act (CCPA)
D.Payment Card Industry Data Security Standard (PCI DSS)
E.Health Insurance Portability and Accountability Act (HIPAA)
AnswersA

GDPR is a data sovereignty law because it mandates that personal data of EU residents be stored within the EU or in jurisdictions with equivalent protection, directly affecting cloud storage location decisions.

Why this answer

The General Data Protection Regulation (GDPR) is a data sovereignty law because it imposes strict requirements on the storage and processing of personal data of EU residents, mandating that data be stored within the EU or in jurisdictions with equivalent protection, directly affecting where cloud providers can host data. It enforces data localization principles through mechanisms such as Standard Contractual Clauses (SCCs) and Binding Corporate Rules (BCRs), requiring cloud customers to ensure their provider's storage regions comply with these territorial restrictions. In contrast, the California Consumer Privacy Act (CCPA) is a privacy law that grants consumers rights over their personal data but does not mandate where data must be stored geographically, so it is not a data sovereignty law.

The other options (SOX, PCI DSS, HIPAA) are security or sector-specific regulations without territorial storage requirements.

Exam trap

ISC2 often tests the distinction between data sovereignty (geographic storage restrictions) and data security/privacy regulations (which focus on protection controls but not location). This question specifically traps candidates who assume CCPA is a sovereignty law because it is a prominent privacy regulation, but CCPA lacks any data localization mandate, making it an incorrect choice for a data sovereignty question.

496
Multi-Selecthard

A cloud security architect is designing a data retention and destruction strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores customer data in a mix of block storage, object storage, and a managed database. Regulatory requirements mandate that data be irrecoverably destroyed upon customer offboarding, and that the destruction be verifiable. Which TWO of the following practices BEST support these requirements? (Choose two.)

Select 2 answers
A.Maintain an immutable audit log of all data destruction actions, including key deletions and storage reclamation.
B.Implement a secure overwrite process that writes random data to all blocks occupied by the customer's data.
C.Use cryptographic erasure by deleting the customer-specific encryption keys from the cloud KMS.
D.Rely on the cloud provider's shared responsibility model to ensure physical media destruction at end-of-life.
E.Use data anonymization techniques to remove personally identifiable information before deletion.
AnswersA, C

An immutable audit log provides verifiable evidence that destruction actions occurred. It can record key deletion events, storage deletion operations, and timestamps. This supports the requirement for verifiable destruction by creating a tamper-evident record that can be presented to auditors, complementing the actual destruction method.

Why this answer

Cryptographic erasure by deleting customer-specific keys ensures data is irrecoverable, and an immutable audit log provides verifiable evidence of the destruction. Together, they meet the regulatory requirements for irrecoverable and verifiable destruction in a multi-tenant cloud environment where physical media destruction is not customer-controlled.

Exam trap

The trap here is assuming that overwriting data or relying on provider media destruction is sufficient, but in cloud multi-tenant environments, cryptographic erasure with verifiable logs is the only reliable and auditable method.

497
MCQhard

An AWS S3 bucket policy is configured as shown in the exhibit. The security team wants to ensure that only requests from the corporate IP range (203.0.113.0/24) can read objects in the bucket. However, they notice that a CloudFront distribution configured to serve content from this bucket is returning 403 Forbidden errors. What is the MOST likely cause?

A.The bucket policy has a syntax error in the Condition block.
B.There is an implicit deny that overrides the explicit allow.
C.The bucket policy does not allow the s3:GetObject action.
D.CloudFront requests originate from CloudFront IP addresses, not the end user's IP.
AnswerD

CloudFront fetches objects from the bucket using its own edge IP addresses, so the bucket policy's 203.0.113.0/24 condition fails and returns 403. CloudFront must instead be granted access via an origin access identity or origin access control.

Why this answer

D is correct because when CloudFront fetches objects from an S3 origin, it uses its own IP addresses, not the end user's IP address. The bucket policy restricts access to the corporate IP range (203.0.113.0/24), but CloudFront's requests come from AWS's CloudFront edge IP range, which falls outside that range. This causes S3 to deny the request, resulting in a 403 Forbidden error.

Exam trap

ISC2 often tests the misconception that the end user's IP address is preserved through a CDN or proxy, leading candidates to incorrectly assume the bucket policy's IP restriction will work as intended.

How to eliminate wrong answers

Option A is wrong because the Condition block syntax is valid; the policy uses standard AWS IAM policy language with IpAddress condition key, and there is no syntax error indicated. Option B is wrong because there is no implicit deny overriding the explicit allow; the issue is that the condition does not match CloudFront's source IP, not a deny override. Option C is wrong because the policy explicitly allows the s3:GetObject action for the specified IP range, so the action is permitted when the condition is met.

498
MCQmedium

A security engineer is implementing container image security. They want to ensure that only signed images from a trusted registry can be deployed in the Kubernetes cluster. Which tool should they use to enforce this at the admission controller level?

A.Clair
B.Trivy
C.Cosign
D.Snyk Container
AnswerC

Cosign signs container images and stores signatures in the registry, letting an admission controller verify provenance before pods are admitted. This enforces the trusted-registry constraint at admission time, rejecting any unsigned or tampered image before it reaches the cluster.

Why this answer

Cosign is a tool from the Sigstore project that signs and verifies container images. It integrates with Kubernetes admission controllers (e.g., via Kyverno or OPA Gatekeeper policies) to enforce that only images with valid signatures from a trusted registry are deployed. This directly addresses the requirement to enforce signed images at admission time.

Exam trap

The trap is confusing vulnerability scanning tools (Clair, Trivy, Snyk) with image signing and verification tools (Cosign), leading candidates to pick a scanner when the requirement is signature enforcement.

How to eliminate wrong answers

Option A is wrong because Clair is a vulnerability scanner for container images, not a signing or admission enforcement tool. Option B is wrong because Trivy is also a vulnerability and misconfiguration scanner, not a signature verifier. Option D is wrong because Snyk Container scans for vulnerabilities and provides remediation advice, but does not enforce image signatures at admission.

499
MCQmedium

A medium-sized e-commerce company uses a cloud provider's container orchestration service (e.g., Amazon ECS or Google Kubernetes Engine). They have a security requirement to ensure that all containers run with the least privilege principle. The development team often requests containers to run as root for debugging purposes. The security team wants to enforce a policy that prevents containers from running as root in the production environment. However, the development team still needs the ability to troubleshoot occasionally. The cloud security architect must design a solution that restricts root privilege in production but allows controlled troubleshooting. Which of the following approaches is the most effective?

A.Allow containers to run as root but configure host-based intrusion detection to alert on suspicious activities.
B.Grant developers SSH access to the host nodes for troubleshooting.
C.Use a security context constraint (or PodSecurityPolicy) to deny all containers running as root, and require developers to use a sidecar container for debugging.
D.Create two separate clusters, one for production with root restriction, and one for debugging where root is allowed.
AnswerC

Enforces non-root and provides controlled debugging via sidecar.

Why this answer

It uses a security context constraint (SCC) or PodSecurityPolicy (PSP) to enforce a deny-all policy for root containers in production, which aligns with the least privilege principle. The sidecar container provides a controlled debugging mechanism without granting root access to the main application container, allowing developers to troubleshoot via a separate, privileged sidecar that can be audited and restricted.

Exam trap

ISC2 often tests the misconception that allowing root in containers with monitoring (Option A) or using separate clusters (Option D) is acceptable, but the CCSP emphasizes that least privilege must be enforced at the container level, not compensated for by external controls.

How to eliminate wrong answers

Option A is wrong because allowing containers to run as root and relying solely on host-based intrusion detection (HIDS) does not prevent the violation of the least privilege principle; root access in containers can still lead to container breakout or privilege escalation before any alert is triggered. Option B is wrong because granting developers SSH access to host nodes undermines the security boundary, as it exposes the underlying host OS and potentially other containers, violating the principle of isolation and increasing the attack surface. Option D is wrong because maintaining two separate clusters (production and debugging) introduces operational complexity, configuration drift, and does not enforce least privilege in production; developers might still need root access in production for debugging, which the separate cluster does not address without additional controls.

500
MCQhard

An organization is migrating a legacy application to the cloud and wants to minimize vendor lock-in. They plan to use containers orchestrated by Kubernetes. Which design principle is the organization primarily applying?

A.Elasticity
B.Multitenancy isolation
C.Reversibility
D.Portability
AnswerD

Portability is the design principle enabling workloads to move between providers without significant rework. Containers orchestrated by Kubernetes abstract the underlying infrastructure, so the application runs consistently across clouds, directly reducing vendor lock-in as the organisation intends.

Why this answer

Portability is the design principle of avoiding dependence on a specific vendor's proprietary services so workloads can move between environments. Using containers orchestrated by Kubernetes is a classic portability strategy because container images and Kubernetes manifests are largely vendor-neutral. This directly addresses the goal of minimizing vendor lock-in.

Exam trap

The trap is confusing portability with reversibility or elasticity — candidates see 'minimize vendor lock-in' and may pick reversibility, but the container/Kubernetes context signals portability as the primary design principle.

How to eliminate wrong answers

Option A is wrong because elasticity refers to the ability to scale resources up and down automatically based on demand, not to avoiding vendor lock-in. Option B is wrong because multitenancy isolation is about separating tenants' data and workloads in a shared environment, not about portability across providers. Option C is wrong because reversibility is a related but distinct concept — it refers to the ability to revert to a previous state or exit a service, whereas portability is about moving workloads between platforms; the question's emphasis on containers and Kubernetes points to portability as the primary principle.

501
MCQmedium

A cloud customer is migrating a legacy application to a cloud platform. The application currently runs on physical servers and uses local storage. The migration plan involves rehosting the application on virtual machines (VMs) in the cloud. The security team wants to ensure that the VMs are properly hardened before deployment. During the migration testing, the team discovers that the base image used for the VMs contains several unnecessary services and default credentials. The team is concerned that these vulnerabilities could be exploited. The cloud provider offers a shared responsibility model where the customer is responsible for securing the OS. Which of the following is the BEST course of action to address this issue?

A.Deploy the VMs and run vulnerability scans to identify and fix issues after deployment
B.Ask the cloud provider to provide a hardened OS image
C.Create a custom golden image with necessary hardening and approved software only
D.Deploy the VMs and manually apply security patches and remove services after deployment
AnswerC

Under the shared responsibility model the customer hardens the guest OS, so remediating the base image itself is required. Building a golden image with unnecessary services removed and default credentials eliminated fixes the vulnerability at source, rather than patching each deployed VM.

Why this answer

Creating a custom golden image allows the customer to enforce a hardened baseline that removes unnecessary services, disables default credentials, and includes only approved software before any VM is deployed. This aligns with the shared responsibility model, where the customer controls OS-level security, and prevents vulnerabilities from ever reaching production. Pre-hardening the image is more secure and efficient than fixing issues post-deployment, as it eliminates the window of exposure during initial boot and configuration.

Exam trap

The trap here is that candidates may choose Option D (manual patching after deployment) because it seems practical, but they overlook that this approach leaves VMs vulnerable during the initial boot and configuration phase, whereas pre-hardening the image eliminates that risk entirely.

How to eliminate wrong answers

Option A is wrong because deploying VMs with known vulnerabilities and relying on post-deployment vulnerability scans introduces a window of exposure where the VMs could be compromised before patches are applied, and it violates the principle of secure-by-default. Option B is wrong because the cloud provider is responsible for the hypervisor and infrastructure, not the OS image; asking them to provide a hardened OS image shifts responsibility that the customer must own under the shared responsibility model, and providers typically offer only generic base images. Option D is wrong because manually patching and removing services after deployment is error-prone, time-consuming, and leaves the VMs exposed during the time between deployment and remediation, which is especially risky in automated scaling scenarios.

502
MCQeasy

Under the General Data Protection Regulation (GDPR), if a cloud service provider (acting as a data processor) suffers a personal data breach, what is the provider's obligation regarding notification?

A.The processor must notify the data controller without undue delay upon becoming aware of the breach.
B.The processor must notify the supervisory authority within 72 hours.
C.The processor does not have any notification obligation under GDPR.
D.The processor must notify the affected data subjects directly within 72 hours.
AnswerA

Article 33 obliges the processor to notify the controller without undue delay after becoming aware of a personal data breach. The controller then assesses and notifies the supervisory authority within 72 hours; the processor holds no direct regulator notification duty.

Why this answer

Under GDPR Article 33(2), a processor must notify the controller without undue delay after becoming aware of a personal data breach. The controller — not the processor — is the party responsible for notifying the supervisory authority within 72 hours (Article 33(1)) and, where required, the data subjects (Article 34). The processor's obligation is limited to informing the controller so the controller can meet its own regulatory deadlines.

Exam trap

CCSP often tests the controller-versus-processor notification chain, baiting candidates with the familiar 72-hour supervisory authority deadline that actually belongs to the controller, not the processor.

How to eliminate wrong answers

Option B is wrong because the 72-hour supervisory authority notification duty belongs to the controller under Article 33(1), not the processor; a processor has no direct reporting line to the DPA. Option C is wrong because Article 33(2) explicitly imposes a notification obligation on processors toward controllers, so claiming no obligation exists misreads the regulation. Option D is wrong because direct notification of data subjects is a controller responsibility under Article 34 and only applies when the breach poses a high risk to rights and freedoms.

503
MCQhard

A company needs to export data from a cloud service in a machine-readable format to comply with a data subject's right to data portability under GDPR. Which format is most appropriate?

A.HTML
B.PDF
C.CSV (Comma-Separated Values)
D.JPEG
AnswerC

CSV is machine-readable and commonly used for data portability.

Why this answer

GDPR Article 20 grants data subjects the right to receive their personal data in a 'structured, commonly used and machine-readable format.' CSV satisfies all three criteria: it is structured (tabular rows/columns), widely used, and easily parsed by software. It also supports transmission to another controller without hindrance, which is the core purpose of portability.

Exam trap

The trap here is confusing 'human-readable' with 'machine-readable' — PDF and HTML look readable to a person but fail GDPR's structured, machine-parseable requirement.

How to eliminate wrong answers

Option A is wrong because HTML is a presentation markup language designed for rendering in browsers, not a structured data-interchange format, so it fails the 'structured and machine-readable' test. Option B is wrong because PDF is a fixed-layout document format optimized for visual fidelity, and extracting structured fields from it is unreliable. Option D is wrong because JPEG is a lossy image format that cannot represent structured personal data records at all.

504
MCQhard

An organization must implement encryption for data in transit between its on-premises data center and a cloud provider. The data is sensitive and the organization requires a dedicated, encrypted tunnel. Which solution should be used?

A.Client-side encryption before upload
B.TLS 1.2 for API communication
C.VPN connection
D.Cloud KMS for key exchange
AnswerC

A VPN connection builds an encrypted tunnel over the public internet between the on-premises data centre and the cloud provider, satisfying the requirement for encryption in transit. Site-to-site IPsec VPNs provide the dedicated, encrypted tunnel specified, unlike TLS alone, which secures individual application sessions rather than the whole network path.

Why this answer

A VPN connection provides a dedicated, encrypted tunnel between the on-premises data center and the cloud provider, ensuring data in transit is protected. It uses protocols like IPsec or SSL/TLS to encrypt all traffic, meeting the requirement for a dedicated encrypted tunnel for sensitive data.

Exam trap

The trap is confusing data-in-transit encryption methods (TLS, client-side encryption) with a dedicated tunnel solution (VPN), causing candidates to pick a less comprehensive option that doesn't meet the 'dedicated tunnel' requirement.

How to eliminate wrong answers

Option A is wrong because client-side encryption before upload protects data at rest and in transit to the storage service, but does not create a dedicated tunnel; it also requires application changes and does not encrypt all traffic. Option B is wrong because TLS 1.2 for API communication only secures specific API calls, not all data in transit, and does not provide a dedicated tunnel. Option D is wrong because Cloud KMS is for key management, not for establishing encrypted tunnels; it manages encryption keys but does not encrypt data in transit itself.

505
MCQhard

In a Kubernetes environment, a security team wants to enforce that only images signed by a trusted authority can be deployed. Which component can be used to validate image signatures at admission time?

A.Network policies
B.Admission controller (e.g., OPA Gatekeeper)
C.RBAC policies
D.Secrets management with Vault
AnswerB

Admission controllers intercept API server requests before pods persist, so OPA Gatekeeper can query a signature-verification policy and reject unsigned or untrusted images. This enforces the trusted-authority constraint at admission time rather than relying on later scanning or runtime detection.

Why this answer

An admission controller such as OPA Gatekeeper can intercept requests to the Kubernetes API server before objects are persisted, allowing it to validate image signatures. By integrating with tools like Cosign or Notary, the admission controller can reject pods that use unsigned or untrusted images, enforcing the policy at deployment time.

Exam trap

The trap is confusing admission control with other Kubernetes security mechanisms like RBAC or network policies, leading candidates to pick a component that doesn't operate at admission time or doesn't handle image signatures.

How to eliminate wrong answers

Option A is wrong because Network policies control pod-to-pod network traffic, not image admission. Option C is wrong because RBAC policies govern who can perform actions on Kubernetes resources, not the content or provenance of images. Option D is wrong because Secrets management with Vault stores and manages secrets, but does not validate image signatures at admission.

506
MCQhard

A cloud security team needs to implement a logging strategy that captures user activity, API calls, and resource changes across multiple cloud services. The logs must be tamper-proof and retained for at least one year. Which combination of actions best meets these requirements?

A.Stream all logs to a Security Information and Event Management (SIEM) system and retain raw logs for one year on standard storage.
B.Enable logging for all services, encrypt logs at rest, and store them in a centralized log management system.
C.Use separate logging accounts for each cloud service and retain logs in their native format.
D.Centralize logs into a dedicated log archive account with write-once-read-many (WORM) storage and enable anomaly detection alerts.
AnswerD

WORM storage enforces immutability, so archived logs cannot be altered or deleted, satisfying tamper-proofing, while a dedicated archive account isolates them from production credentials. Centralisation plus one-year retention meets the stated scope across multiple cloud services.

Why this answer

Centralizing logs into a dedicated log archive account with WORM (write-once-read-many) storage ensures tamper-proof retention for at least one year, and enabling anomaly detection alerts provides real-time security monitoring. Option A is incorrect because while streaming to a SIEM is good practice, retaining raw logs on standard storage does not guarantee immutability; logs could be modified or deleted. Option B is incorrect because encrypting logs at rest only protects confidentiality, not integrity; a centralized log management system without WORM may allow tampering.

Option C is incorrect because using separate logging accounts for each service creates silos, increases management complexity, and does not inherently provide tamper-proof storage; logs could be altered within individual accounts.

507
MCQeasy

Which cloud service model provides the consumer with the ability to deploy and run custom applications using the provider's programming languages, libraries, and tools, but does not allow management of the underlying infrastructure?

A.PaaS
B.SaaS
C.IaaS
D.CaaS
AnswerA

PaaS supplies runtimes, libraries and tools so the consumer deploys custom code without managing servers, operating systems or middleware. That matches the stem exactly: provider-supplied programming languages and tools, with no control over underlying infrastructure.

Why this answer

PaaS (Platform as a Service) provides a managed runtime environment where consumers deploy applications built with provider-supported languages, libraries, and tools, while the provider manages the underlying servers, storage, networking, and OS. The consumer controls only the deployed application and its configuration, not the infrastructure — exactly matching the scenario described.

Exam trap

CCSP often tests the boundary between PaaS and CaaS — candidates see 'deploy and run applications' and pick CaaS, but the question's mention of provider programming languages, libraries, and tools is the classic PaaS definition, not container orchestration.

How to eliminate wrong answers

Option B (SaaS) is wrong because SaaS delivers fully functional applications to end users (e.g., Office 365, Salesforce), not a development platform where consumers deploy their own custom code. Option C (IaaS) is wrong because IaaS provides raw compute, storage, and networking where the consumer manages the OS, middleware, and runtime — the opposite of 'no infrastructure management.' Option D (CaaS) is wrong because Containers as a Service is a subset of PaaS focused on container orchestration (e.g., EKS, AKS, GKE); while related, the question's emphasis on programming languages, libraries, and tools points to the broader PaaS definition.

508
MCQmedium

A company is evaluating the risk of using a single cloud provider for all critical workloads. Which risk is most directly associated with this scenario?

A.Inherent risk of shared infrastructure
B.Third-party risk
C.Concentration risk
D.Control effectiveness risk
AnswerC

Concentration risk arises when dependence on one provider means a single outage, failure or contractual dispute simultaneously affects all critical workloads, with no failover alternative. This directly matches the stem's scenario of using a single cloud provider for everything.

Why this answer

Concentration risk is the danger that over-reliance on a single provider, service, or region creates a single point of failure whose disruption affects all dependent workloads simultaneously. Using one cloud provider for all critical workloads concentrates operational, financial, and availability exposure in that vendor, so an outage, contract dispute, or bankruptcy cascades across the entire estate. This is precisely the risk regulators and frameworks like the EBA and DORA flag for cloud concentration.

Exam trap

CCSP often tests the distinction between generic third-party risk and concentration risk — candidates pick 'third-party risk' because it sounds broader, missing that the scenario's single-provider dependency is the textbook definition of concentration risk.

How to eliminate wrong answers

Option A is wrong because shared infrastructure risk (noisy neighbors, hypervisor vulnerabilities, multi-tenancy) exists regardless of how many providers you use and is not specific to single-provider reliance. Option B is wrong because third-party risk applies to any external dependency, including in multi-cloud, so it is not the risk most directly tied to using one provider. Option D is wrong because control effectiveness risk concerns whether your own controls work as designed, not the structural exposure created by vendor concentration.

509
MCQeasy

A cloud operations team is setting up a new virtual network in the cloud. They need to segment traffic between different tiers of an application (web, application, database). Which security control should they implement?

A.Network access control lists and security groups
B.Intrusion detection system
C.Data loss prevention
D.Web application firewall
AnswerA

Security groups provide stateful, instance-level filtering, while network ACLs add stateless subnet-level rules. Together they enforce tier isolation between web, application and database segments, satisfying the requirement to segment traffic between application tiers within the new virtual network.

Why this answer

Network access control lists (NACLs) and security groups are the primary tools for segmenting traffic between application tiers in a cloud VPC. Security groups act as stateful firewalls at the instance level, while NACLs are stateless and operate at the subnet level. Together, they enforce least-privilege network access, ensuring that, for example, the web tier can only communicate with the application tier on specific ports, and the database tier is isolated from direct internet access.

Exam trap

The trap is confusing network segmentation with other security controls like IDS, DLP, or WAF. Candidates might think that a WAF or IDS provides segmentation, but they do not enforce traffic flow restrictions between internal tiers.

How to eliminate wrong answers

Option B is wrong because an intrusion detection system (IDS) monitors and alerts on malicious activity but does not segment traffic or enforce access control between tiers. Option C is wrong because data loss prevention (DLP) focuses on preventing exfiltration of sensitive data, not on network segmentation. Option D is wrong because a web application firewall (WAF) protects web applications from HTTP-based attacks but does not provide network-level segmentation between internal tiers.

510
Multi-Selecthard

Which THREE of the following are key components of a cloud data governance framework?

Select 3 answers
A.Data retention policies
B.Data access controls
C.Data masking
D.Data classification
E.Data encryption at rest
AnswersA, B, D

Policies define how long data is kept and when to delete.

Why this answer

Data retention policies are a key component of a cloud data governance framework because they define the lifecycle of data, specifying how long data must be kept and when it should be securely deleted. This ensures compliance with legal, regulatory, and business requirements, such as GDPR or HIPAA, and prevents unnecessary storage costs and security risks from outdated data.

Exam trap

ISC2 often tests the distinction between governance components (policies, roles, processes) and technical security controls (encryption, masking), leading candidates to mistakenly select data masking or encryption as governance framework elements.

511
MCQhard

A security analyst discovers that a container running in a Kubernetes cluster has been compromised. The attacker escalated privileges and accessed the host's kernel. Which of the following misconfigurations most likely allowed this container escape?

A.The container was run with the --privileged flag
B.The container was run with a default Seccomp profile
C.The container was run with a read-only root filesystem
D.The container was run with an AppArmor profile in enforce mode
AnswerA

The --privileged flag disables the default seccomp, AppArmor and capability restrictions, granting the container nearly all Linux capabilities plus access to host devices. That lets an attacker mount the host filesystem or load kernel modules, escaping to the host kernel.

Why this answer

Running a container with the --privileged flag disables container isolation and gives the container almost all capabilities of the host, including access to host devices and kernel. This allows an attacker who compromises the container to easily escape and access the host kernel, as seen in the scenario.

Exam trap

The trap is selecting a security-hardening option (Seccomp, read-only FS, AppArmor) as the cause of escape, when in fact those options prevent escape; the correct answer is the one that removes isolation.

How to eliminate wrong answers

Option B is wrong because a default Seccomp profile restricts system calls, making escape harder, not easier. Option C is wrong because a read-only root filesystem prevents modification of the container's filesystem, which hinders but does not enable escape. Option D is wrong because an AppArmor profile in enforce mode restricts container actions, reducing the likelihood of escape.

512
MCQmedium

A company has a disaster recovery (DR) plan that includes failing over to a secondary cloud region. The plan was tested six months ago and worked, but since then significant infrastructure changes have been made. Which of the following should the company do to ensure the DR plan remains effective?

A.Wait until the next annual DR test to verify the changes.
B.Automate the entire failover process to eliminate human error.
C.Update the DR documentation to reflect the changes and assume the plan still works.
D.Conduct a tabletop exercise now, followed by a partial failover test of critical applications.
AnswerD

Infrastructure drift since the last test invalidates prior validation, so a tabletop exercise cheaply exposes process gaps before a partial failover exercises critical applications against current configuration, confirming the plan still meets its recovery objectives without risking the whole estate.

Why this answer

After significant infrastructure changes, the DR plan may no longer be valid. A tabletop exercise quickly identifies gaps in the plan and updates documentation, while a partial failover test of critical applications validates that the changes work in practice without the risk of a full-scale failover. This combined approach ensures the plan remains effective and current.

Exam trap

CCSP often tests the balance between documentation and testing; candidates may choose to simply update documentation or wait for the next scheduled test, but the correct answer emphasizes immediate validation through exercises and partial tests.

How to eliminate wrong answers

Option A is wrong because waiting until the next annual test leaves the organization exposed to potential failures for up to a year; DR plans must be updated after major changes. Option B is wrong because automation alone does not guarantee the plan is correct; the underlying infrastructure changes must be validated, and automation can introduce new errors if not tested. Option C is wrong because updating documentation without testing assumes the plan still works, which is risky after significant changes; testing is essential to verify effectiveness.

513
Multi-Selectmedium

Which THREE of the following are common risk treatment options in cloud risk management?

Select 3 answers
A.Ignorance
B.Transference
C.Avoidance
D.Deletion
E.Acceptance
AnswersB, C, E

Transference shifts risk to a third party, typically via insurance or contractual clauses. In cloud risk management, the customer transfers residual liability to the provider through the service agreement, making this a recognised treatment option alongside mitigation, avoidance and acceptance.

Why this answer

In cloud risk management, risk treatment follows the standard ISO 27005 / NIST RMF model, and the three marked options are core treatment strategies. B (Transference) is correct because risk can be shifted to another party, typically via cyber-insurance or by contractual allocation of liability to a cloud provider under a shared responsibility model. C (Avoidance) is correct because an organization can eliminate a risk by not performing the activity that creates it, such as choosing not to deploy a workload in the cloud or not using a specific service.

E (Acceptance) is correct because a risk may be knowingly retained when its likelihood or impact is within the organization's risk appetite, documented in a risk register with management sign-off. A (Ignorance) is not a valid treatment because failing to identify or acknowledge a risk does not mitigate it and violates governance requirements. D (Deletion) is not a risk treatment option; deleting data or resources is a technical action that may support avoidance or mitigation, but it is not one of the recognized treatment categories.

Exam trap

Avoidance is a valid risk treatment and should not be dismissed; acceptance is also not the same as ignoring risk.

514
Multi-Selecteasy

A company is adopting a multi-cloud strategy to reduce concentration risk. Which two benefits are directly associated with this approach? (Choose two.)

Select 2 answers
A.Reduced vendor lock-in
B.Increased resilience
C.Simplified compliance management
D.Unified security controls
E.Lower network latency
AnswersA, B

Spreading workloads across multiple providers means no single vendor's proprietary interfaces or commercial terms dictate the estate, directly reducing vendor lock-in. This satisfies the stated concentration-risk reduction goal by removing dependency on one provider's ecosystem.

Why this answer

Option A (Reduced vendor lock-in) is correct because spreading workloads across multiple providers means the company is not dependent on a single vendor's proprietary services, pricing, or roadmap, making it easier to migrate or renegotiate. Option B (Increased resilience) is correct because a multi-cloud strategy reduces concentration risk: an outage, regional failure, or service disruption at one provider does not take down the entire estate, since workloads can fail over to another cloud. Option C is not directly associated because compliance obligations (e.g., GDPR, HIPAA, PCI DSS) must still be met per provider and per region, and multi-cloud often complicates rather than simplifies compliance management.

Option D is not directly associated because each cloud has its own IAM, logging, and security tooling, so unified security controls typically require additional third-party tooling or significant integration effort. Option E is not directly associated because adding more providers and cross-cloud traffic generally increases network latency and complexity rather than lowering it.

Exam trap

The trap is assuming multi-cloud simplifies everything — candidates pick 'simplified compliance' or 'unified security controls' because they sound like benefits, when in fact multi-cloud multiplies compliance and security complexity.

515
MCQeasy

A cloud customer is decommissioning a storage service that contains sensitive data. The cloud provider offers several data destruction options. Which method provides the HIGHEST assurance that data is irrecoverable?

A.Degaussing the storage media
B.Physical shredding of the storage drives
C.Multiple overwrite passes with zeros and ones
D.Cryptographic erasure of encryption keys
AnswerB

Physical shredding destroys the storage media itself, so no residual magnetic or flash state remains recoverable. Cryptographic erasure and overwriting depend on correct key handling or overwrite completion, whereas shredding removes the physical substrate entirely, giving the highest assurance.

Why this answer

Physical shredding of the storage drives provides the highest assurance that data is irrecoverable because it physically destroys the media, making it impossible to reconstruct any data. Unlike degaussing, which may leave residual magnetization, or overwriting, which can leave data in bad sectors, shredding reduces the drives to small particles that cannot be reassembled. Cryptographic erasure is effective only if the encryption keys are securely destroyed and the encryption was properly implemented, but it still relies on the encryption being unbreakable.

Exam trap

CCSP often tests the nuances of data destruction methods, and candidates may assume that cryptographic erasure is always the most secure, but physical shredding provides the highest assurance because it eliminates any possibility of data recovery, even from bad sectors or firmware areas.

How to eliminate wrong answers

Option A is wrong because degaussing can leave data recoverable if the magnetic field is not strong enough or if the drive has shielded areas, and it does not work on solid-state drives (SSDs). Option C is wrong because multiple overwrite passes may not overwrite all areas, such as bad sectors or areas reserved by the drive firmware, leaving data remnants. Option D is wrong because cryptographic erasure depends on the security of the encryption keys and the encryption algorithm; if keys are compromised or the encryption is flawed, data could be recovered.

516
MCQmedium

A cloud security architect needs to allow an application in a VPC to access a cloud database service without traversing the public internet. Which feature should be implemented?

A.VPN Connection
B.Internet Gateway
C.Private Endpoint (Service Endpoint)
D.NAT Gateway
AnswerC

A Private Endpoint (Service Endpoint) maps the database service into the VPC's private address space, so traffic never traverses the public internet. This satisfies the constraint by keeping connectivity on the cloud provider's private backbone rather than via NAT or internet gateway.

Why this answer

Private Endpoint (also known as Service Endpoint or Private Link) enables private connectivity to cloud services without internet exposure.

517
MCQmedium

A financial services company stores customer transaction data in a cloud object storage service. The security team wants to ensure that if a malicious insider gains access to the storage bucket, they cannot read the data. Which encryption approach provides the highest level of protection against the cloud provider and insiders?

A.Client-side encryption using a customer-managed key
B.Server-side encryption with AES-256 (SSE-S3)
C.Server-side encryption with customer-provided keys (SSE-C)
D.Transport Layer Security (TLS) for data in transit
AnswerA

Encrypting before upload means ciphertext reaches the bucket, so the provider and any insider only ever see unreadable data. Because the customer-managed key never leaves the organisation's control, decryption is impossible without it, satisfying the requirement that bucket access alone cannot expose transaction data.

Why this answer

Client-side encryption with a customer-managed key ensures data is encrypted before it leaves the customer's environment, so the cloud provider never possesses the plaintext or the key. This provides the highest protection against both the cloud provider and malicious insiders because even with bucket access, the ciphertext is useless without the customer-held key. This is the strongest option for isolating data from provider and insider threats.

Exam trap

The trap is equating 'encryption at rest' with 'protection from the provider' — candidates forget that server-side encryption options leave key control with the provider, which does not satisfy the insider-threat requirement.

How to eliminate wrong answers

Option B is wrong because SSE-S3 uses keys fully managed by the cloud provider, meaning the provider (and anyone who compromises provider-side controls) can decrypt the data. Option C is wrong because SSE-C, while using customer-provided keys, still requires sending the key to the provider for each request, so the provider transiently handles the key and could theoretically access plaintext. Option D is wrong because TLS only protects data in transit and does nothing to protect data at rest from insider or provider access.

518
MCQeasy

A startup is developing a new mobile application and wants to minimize infrastructure management while focusing on code development. The team has limited operational resources and prefers a serverless approach. Which cloud service model should they adopt?

A.Platform as a Service (PaaS)
B.Infrastructure as a Service (IaaS)
C.Software as a Service (SaaS)
D.Function as a Service (FaaS)
AnswerD

FaaS is a serverless compute model where the cloud provider manages the infrastructure, scaling, and availability. Developers only write and deploy functions that are triggered by events. This aligns perfectly with the startup's need to minimize infrastructure management and focus on code. It also scales automatically and charges only for actual usage, which is cost-effective for sporadic workloads.

Why this answer

FaaS is the most serverless option, allowing developers to run code in response to events without provisioning or managing servers. It aligns with the startup's goal of minimizing infrastructure management and focusing on code development. The provider handles all scaling, patching, and capacity planning, making it ideal for teams with limited operational resources.

Exam trap

The trap here is confusing PaaS with FaaS, as both abstract infrastructure, but FaaS is more serverless and event-driven, requiring even less operational effort.

519
MCQmedium

A cloud-native application is deployed on AWS. During a security review, the team discovers that if an attacker can send a crafted request to the application, the application will make an HTTP request to http://169.254.169.254/latest/meta-data/iam/security-credentials/. Which vulnerability is being exploited?

A.SQL injection
B.Cross-site scripting (XSS)
C.Insecure deserialization
D.Server-Side Request Forgery (SSRF)
AnswerD

The application fetches the instance metadata endpoint on the attacker's behalf, returning temporary IAM credentials. SSRF occurs because user-supplied input controls the server-side request target, letting the attacker reach the link-local address that external clients cannot access directly.

Why this answer

The vulnerability is Server-Side Request Forgery (SSRF). The attacker crafts a request that causes the application to make an HTTP request to the EC2 instance metadata service at 169.254.169.254, potentially retrieving IAM credentials. This is a classic SSRF attack targeting cloud metadata endpoints.

Exam trap

CCSP often tests whether candidates can distinguish SSRF from other injection attacks, especially when cloud metadata endpoints are involved.

How to eliminate wrong answers

Option A is wrong because SQL injection involves injecting malicious SQL statements into input fields to manipulate a database, not making HTTP requests to internal endpoints. Option B is wrong because cross-site scripting (XSS) executes malicious scripts in a victim's browser, not on the server side to access metadata. Option C is wrong because insecure deserialization exploits deserialization of untrusted data to achieve remote code execution, not to make HTTP requests to metadata services.

520
MCQmedium

A company is migrating a legacy application to a cloud provider's infrastructure as a service (IaaS) platform. The security team must ensure that the hypervisor layer is patched and secured, and that tenants cannot access each other's memory or storage. According to the shared responsibility model, which party is responsible for securing the hypervisor and preventing cross-tenant access?

A.The cloud provider, because the hypervisor and underlying infrastructure are part of the provider's managed security scope.
B.A third-party auditor, because independent verification is required to ensure tenant isolation in multi-tenant environments.
C.The customer, because they are responsible for all security controls in IaaS.
D.Both parties share equal responsibility, with the customer patching the hypervisor and the provider monitoring for cross-tenant attacks.
AnswerA

In the shared responsibility model, the cloud provider is always responsible for the security of the cloud, which includes the hypervisor, physical hosts, and the network fabric. The provider patches and secures the hypervisor and enforces tenant isolation. The customer cannot perform these tasks in IaaS, so the provider must own them. This is the correct division of responsibility.

Why this answer

The cloud provider is responsible for securing the hypervisor and preventing cross-tenant access because these are part of the provider's managed infrastructure. Customers cannot access or patch the hypervisor in IaaS. The shared responsibility model always assigns the hypervisor, physical hosts, and network fabric to the provider, while the customer secures the guest OS, applications, and data.

Exam trap

The trap here is assuming that IaaS gives the customer responsibility for all layers, when the hypervisor and physical infrastructure always remain with the cloud provider.

521
MCQhard

An attacker publishes a malicious package to a public registry using the same name as an internal package used by a cloud application. This attack is known as:

A.Dependency confusion
B.Supply chain poisoning
C.Man-in-the-middle attack
D.Typosquatting
AnswerA

Dependency confusion exploits package managers resolving names from public registries when an identically named internal package exists. The attacker registers the same name publicly with a higher version, so resolution pulls the malicious package. This matches the stem's same-name public upload precisely.

Why this answer

Dependency confusion occurs when an attacker publishes a malicious package to a public registry (e.g., npm, PyPI, Maven Central) using the same name as an internal, private package. When a cloud application's build system is configured to fetch dependencies from both public and private registries, the package manager may prioritize the public registry (often due to higher version numbers or default resolution order), causing the malicious package to be installed instead of the legitimate internal one. This exploits the trust in package resolution algorithms and is a specific form of supply chain attack targeting cloud-native CI/CD pipelines.

Exam trap

The CCSP exam often tests the distinction between dependency confusion and typosquatting, so the trap here is that candidates confuse the exact-name-match technique (dependency confusion) with the misspelling-based technique (typosquatting), leading them to incorrectly select typosquatting when the question explicitly states 'same name.'

How to eliminate wrong answers

Option B (Supply chain poisoning) is wrong because it is a broader category encompassing any attack that compromises a component in the software supply chain (e.g., injecting malicious code into a legitimate package, compromising build servers), whereas dependency confusion is a specific technique that relies on name collision and registry priority. Option C (Man-in-the-middle attack) is wrong because it involves intercepting or altering communications between two parties (e.g., between a client and a registry), not exploiting package name resolution logic; dependency confusion does not require network interception. Option D (Typosquatting) is wrong because it relies on registering a package with a name that is a common misspelling or typo of a popular package (e.g., 'requrests' instead of 'requests'), whereas dependency confusion uses the exact same name as an internal package, not a misspelling.

522
MCQmedium

An organization wants to share a large file from a cloud storage bucket with an external partner for a limited time. They need to ensure that the partner can only access the specific file and that the access expires automatically. Which method should they use?

A.Make the bucket public
B.Create a new cloud provider user account for the partner and attach a custom policy to the bucket
C.Use cross-region replication
D.Use a pre-signed URL
AnswerD

A pre-signed URL embeds temporary credentials in the link itself, granting time-limited access to one specific object without exposing bucket permissions or requiring the partner to hold Microsoft Entra ID credentials. The expiry parameter satisfies the automatic revocation constraint, while scoping to a single object meets the least-privilege requirement for external sharing.

Why this answer

A pre-signed URL provides temporary access to a specific object in a cloud storage bucket, with an expiration time. It grants the external partner permission to download the file without needing a cloud account, and access automatically expires. This meets the requirements of limited-time, specific-file access.

Exam trap

The trap is overlooking the need for automatic expiration and specific file access. Candidates might choose making the bucket public for simplicity, but that fails security and expiration requirements.

How to eliminate wrong answers

Option A is wrong because making the bucket public grants access to all objects indefinitely, violating the requirement for limited time and specific file. Option B is wrong because creating a new user account is more complex, may not automatically expire, and grants broader access than needed. Option C is wrong because cross-region replication copies data to another region but does not provide temporary access to an external partner.

523
MCQeasy

An organization is evaluating a cloud service where the provider manages the operating system, runtime, middleware, and application, and subscribers access the software through a thin client such as a web browser. The organization's security team wants to know which layer remains squarely under the subscriber's control in this model. Which responsibility belongs to the cloud consumer in a SaaS arrangement?

A.Applying hypervisor patches to the multi-tenant virtualization layer
B.Patching the guest operating system on the provider's hosts
C.Managing user identities, access rights, and data classification
D.Maintaining the physical security of the provider's data centers
AnswerC

Even when the provider operates the application stack, the subscriber remains accountable for who may access the service and what data is placed in it. Identity lifecycle management, entitlement review, multi-factor authentication enforcement, and classifying the data being uploaded are classic consumer responsibilities. These controls govern the subscriber's own users and information rather than the provider's infrastructure, so they stay with the consumer.

Why this answer

In SaaS the provider secures everything from the physical facility up through the application, while the consumer retains control over its own identities, access entitlements, and the data it chooses to place in the service. Physical security, hypervisor maintenance, and guest operating system patching all sit beneath the application and never move to the subscriber.

Exam trap

The trap here is assuming that because the provider runs the application, the consumer has no security duties left, when identity and data governance always stay with the subscriber.

524
MCQeasy

A cloud service provider (CSP) offers a shared responsibility model. According to this model, who is responsible for patching the hypervisor?

A.The customer.
B.The regulatory authority.
C.The cloud service provider.
D.A third-party auditor.
AnswerC

In the shared responsibility model, the CSP owns the virtualisation layer, so patching the hypervisor sits with the provider. Customers remain responsible for their own guest operating systems, applications and data, not the underlying hypervisor.

Why this answer

In a cloud shared responsibility model, the hypervisor is part of the underlying infrastructure that the cloud service provider (CSP) manages. The CSP is responsible for patching the hypervisor because it controls the virtualization layer that separates tenant workloads. Customers are responsible only for securing their guest operating systems and applications, not the hypervisor itself.

Exam trap

ISC2 often tests the misconception that customers are responsible for all software patching, but the trap here is that the hypervisor is part of the CSP's infrastructure layer, not the customer's virtual environment.

How to eliminate wrong answers

Option A is wrong because the customer does not have administrative access to the hypervisor; patching it would violate the separation of duties and could compromise multi-tenant isolation. Option B is wrong because regulatory authorities (e.g., GDPR, PCI DSS) set compliance requirements but do not perform patching operations. Option D is wrong because a third-party auditor assesses compliance and security controls but has no operational responsibility for applying patches.

525
MCQmedium

A software company develops an API for third-party integrations. They want to ensure that only authorized partners can access the API. Which authentication mechanism is most appropriate?

A.Basic authentication with API keys
B.OAuth 2.0 with client credentials
C.SAML 2.0
D.X.509 certificates
AnswerB

OAuth 2.0 client credentials issues tokens to confidential clients authenticating with their own credentials, without user involvement. This suits machine-to-machine partner integrations, satisfying the requirement that only authorised partners access the API and enabling scoped, revocable access.

Why this answer

OAuth 2.0 with the client credentials grant is the most appropriate mechanism for machine-to-machine API access because it allows the API to authenticate the third-party application itself (the client) using a client ID and client secret, without involving end-user credentials. This grant type is specifically designed for server-to-server integrations where the client is acting on its own behalf, providing a secure, token-based approach that avoids sharing long-lived secrets directly with each API call.

Exam trap

ISC2 often tests the distinction between authentication mechanisms by presenting SAML 2.0 as a plausible answer for API security, but the trap here is that SAML is designed for browser-based user authentication and federation, not for direct API access from third-party applications, leading candidates to confuse identity federation with API authorization.

How to eliminate wrong answers

Option A is wrong because Basic authentication with API keys transmits the API key in plaintext (Base64-encoded) with every request, offering no cryptographic protection and requiring the API key to be stored and sent repeatedly, which increases exposure risk and lacks the token expiration and scoping capabilities of OAuth 2.0. Option C is wrong because SAML 2.0 is an XML-based federated identity protocol designed for browser-based single sign-on (SSO) with user authentication, not for direct API access from third-party applications; it is heavy, not optimized for RESTful APIs, and does not provide a simple client credentials flow. Option D is wrong because X.509 certificates are used for mutual TLS (mTLS) authentication, which is more complex to manage (certificate issuance, renewal, revocation) and is typically reserved for high-security environments or regulatory compliance, not as a standard mechanism for third-party API integrations where OAuth 2.0 is the industry norm.

Page 6

Page 7 of 13

Page 8