Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 526–600

934 questions total · 13pages · All types, answers revealed

Page 7

Page 8 of 13

Page 9
526
MCQhard

An organization is evaluating cloud service providers and notices that one provider's SLA offers 99.99% availability for a specific service, while another offers 99.9%. If the service costs $100,000 per month, what is the maximum allowable downtime per month for the 99.99% SLA?

A.8.64 minutes
B.43.2 minutes
C.2.16 minutes
D.4.32 minutes
AnswerD

99.99% availability permits 0.01% downtime. In a 30-day month of 43,200 minutes, that equals 4.32 minutes of maximum allowable downtime, matching the stem's monthly cost basis. The 99.9% figure would instead allow roughly 43.2 minutes.

Why this answer

The 99.99% SLA allows for a maximum of 0.01% downtime per month. Assuming a 30-day month (43,200 minutes), 0.01% of 43,200 minutes is 4.32 minutes. Therefore, the correct answer is 4.32 minutes.

Exam trap

CCSP often tests the ability to convert availability percentages into actual downtime, and candidates frequently misplace a decimal point or confuse 99.9% with 99.99%, leading to errors like choosing 43.2 minutes instead of 4.32 minutes.

How to eliminate wrong answers

Option A is wrong because 8.64 minutes corresponds to 99.98% availability (0.02% downtime), not 99.99%. Option B is wrong because 43.2 minutes corresponds to 99.9% availability (0.1% downtime), which is the other SLA mentioned. Option C is wrong because 2.16 minutes corresponds to 99.995% availability (0.005% downtime), a higher availability tier than 99.99%.

527
Multi-Selecthard

A company is adopting a microservices architecture on Kubernetes and needs to ensure least privilege for pod-to-pod communication. Which THREE controls should be implemented?

Select 3 answers
A.Service accounts with minimal permissions
B.Network policies to allow only necessary traffic between pods
C.RBAC to limit what pods can do within the cluster
D.Pod Security Admission to enforce that containers run as root
E.Horizontal Pod Autoscaler
AnswersA, B, C

Service accounts bound to minimal RBAC permissions limit what API actions each pod identity can perform, so a compromised pod cannot escalate cluster-wide. This satisfies least privilege for pod-to-pod communication by constraining the credentials pods present to the API server.

Why this answer

Option A is correct because assigning each microservice a dedicated Kubernetes ServiceAccount with minimal RBAC permissions ensures pods authenticate to the API server with only the rights they actually need, which is a core least-privilege practice. Option B is correct because NetworkPolicy objects (enforced by a CNI plugin such as Calico or Cilium) provide default-deny ingress/egress and then explicitly allow only the required pod-to-pod flows on specific ports and protocols, directly restricting lateral movement. Option C is correct because RBAC Roles/ClusterRoles bound to those ServiceAccounts limit what pods can do within the cluster, such as which resources and verbs (get, list, watch, create) they may access, preventing privilege escalation.

Option D is not correct because Pod Security Admission enforcing containers to run as root is the opposite of least privilege; the restricted profile should require runAsNonRoot, drop capabilities, and disallow privileged containers. Option E is not correct because the Horizontal Pod Autoscaler only scales replica counts based on metrics like CPU or memory and has no bearing on authorization or network access control.

Exam trap

CCSP often tests whether candidates confuse scalability controls (HPA) or misconfigured security controls (running as root) with actual least-privilege mechanisms — always map each option to identity, authorization, or network enforcement.

528
MCQmedium

A cloud security architect is designing a multi-tenant IaaS deployment where tenants run untrusted workloads on shared physical hosts. The architect wants to reduce the risk of cross-tenant data remanence in the storage layer. Which control is MOST effective?

A.Enable server-side encryption with a single provider-managed key for the whole storage service.
B.Implement storage QoS and IOPS throttling to isolate tenant workloads on shared volumes.
C.Rely on the hypervisor's memory scrubbing between VM lifecycles to prevent data leakage.
D.Enable encryption at rest with per-tenant customer-managed keys and cryptographic erasure on deprovisioning.
AnswerD

Per-tenant customer-managed keys allow the provider to cryptographically shred data by destroying the tenant-specific key, so remanence risk is eliminated even if physical blocks are later reallocated to another tenant. This satisfies CCSP expectations for data isolation and secure disposal in multi-tenant storage.

Why this answer

Cryptographic erasure with per-tenant customer-managed keys is the strongest control against storage remanence in multi-tenant environments because destroying the key renders residual ciphertext unrecoverable. Provider-managed shared keys, memory scrubbing, and QoS controls do not address persistent-block reuse by other tenants, leaving confidentiality risk unresolved.

Exam trap

The trap here is assuming that encryption at rest with any key management scheme automatically solves data remanence, when only per-tenant keys enabling cryptographic erasure actually eliminate cross-tenant recovery risk.

529
MCQmedium

A company is migrating on-premises workloads to IaaS. They need to ensure that virtual machine images are secure and free of malware. Which approach is best practice?

A.Use a golden image from the cloud provider's marketplace.
B.Rely on host-based firewalls to protect instances.
C.Perform vulnerability scanning on running instances only.
D.Create a hardened baseline image and store it in a secure repository.
AnswerD

A hardened baseline image removes known vulnerabilities and malware before any instance launches, and storing it in a secure repository ensures every deployed VM derives from that trusted, scanned source rather than an unverified public image.

Why this answer

Creating a hardened baseline image ensures that the virtual machine is built from a known, secure configuration with all necessary security patches, minimal services, and no malware. Storing this image in a secure repository (e.g., encrypted and access-controlled) prevents tampering and allows consistent deployment of secure instances. This approach follows the principle of immutable infrastructure and is a foundational practice for secure IaaS migrations.

Exam trap

ISC2 often tests the misconception that using a cloud provider's marketplace image is sufficient for security, but the trap is that these images are not tailored to the organization's specific hardening requirements and may contain default credentials or unnecessary services.

How to eliminate wrong answers

Option A is wrong because cloud provider marketplace images are generic and may not meet the organization's specific security requirements; they can contain unnecessary software or default configurations that introduce vulnerabilities. Option B is wrong because host-based firewalls only control network traffic and do not detect or remove malware already present in the virtual machine image; they are a perimeter control, not a secure image creation practice. Option C is wrong because vulnerability scanning on running instances only identifies issues after deployment, leaving the initial image potentially compromised; it does not prevent the deployment of a malicious or unhardened image.

530
Multi-Selecthard

Which TWO of the following are required elements of a valid Business Continuity Plan (BCP) in the cloud?

Select 2 answers
A.Communication plan for notifying stakeholders during a disruption.
B.Strategy to avoid vendor lock-in with the CSP.
C.A detailed risk assessment for all cloud services.
D.Network topology diagrams of the cloud environment.
E.Recovery Point Objective (RPO) and Recovery Time Objective (RTO) for critical systems.
AnswersA, E

A communication plan is critical for coordinating response.

Why this answer

A communication plan is a mandatory component of any BCP, as defined by ISO 22301 and NIST SP 800-34. In a cloud context, this plan must specify how to notify stakeholders—including the CSP, internal teams, and customers—during a disruption, ensuring coordinated response and compliance with SLAs.

Exam trap

ISC2 often tests the distinction between what is required *in* a BCP versus what is required *to create* a BCP, causing candidates to mistakenly include risk assessments or network diagrams as core BCP elements.

531
Multi-Selecthard

A company is deploying a microservices architecture on Kubernetes and wants to implement supply chain security. Which THREE of the following practices should be adopted?

Select 3 answers
A.Signing container images with Cosign
B.Allowing all images from public registries
C.Scanning images for CVEs using Trivy
D.Using the :latest tag for all images
E.Configuring an admission controller like Kyverno to verify image signatures
AnswersA, C, E

Cosign signs container images with a private key, producing a verifiable signature stored in the registry alongside the image. This establishes provenance and integrity, letting downstream admission controls confirm the image was built by a trusted publisher before deployment.

Why this answer

Option A is correct because signing container images with Cosign (part of the Sigstore project) creates a verifiable cryptographic attestation of the image's provenance and integrity, which is a foundational supply chain security control. Option C is correct because scanning images for CVEs with Trivy detects known vulnerabilities in OS packages and application dependencies before deployment, enabling remediation prior to running workloads in the cluster. Option E is correct because an admission controller such as Kyverno can enforce policy at admission time, verifying Cosign signatures and rejecting unsigned or untrusted images so that only validated artifacts run in the cluster.

Option B is incorrect because allowing all images from public registries removes provenance controls and exposes the cluster to untrusted or malicious images. Option D is incorrect because using the :latest tag is mutable and non-deterministic, preventing reliable signature verification and reproducible, auditable deployments.

Exam trap

CCSP often tests whether candidates recognize that image signing alone is insufficient without enforcement — the trap is selecting signing and scanning but omitting the admission controller that actually blocks unsigned images at deploy time.

532
MCQeasy

A cloud team is designing a new microservices application deployed on a managed Kubernetes service. The security architect requires that all service-to-service traffic be encrypted with mutual TLS (mTLS) without modifying application code. Which cloud-native component should be implemented to meet this requirement?

A.An API gateway with TLS termination at the ingress
B.Kubernetes NetworkPolicy objects with default deny rules
C.A service mesh such as Istio or Linkerd
D.A web application firewall (WAF) in front of each service
AnswerC

A service mesh injects sidecar proxies that transparently intercept and encrypt traffic between services using mTLS, satisfying the no-code-change requirement. It also provides identity-based authentication and authorization. This is the standard cloud-native approach for zero-trust service communication in Kubernetes environments, and it operates at the platform layer rather than within the application.

Why this answer

A service mesh is the correct cloud-native solution because it provides transparent mTLS between services through sidecar proxies, requiring no application code changes. It also enables fine-grained authorization and observability. Other options address perimeter security or network segmentation but do not deliver encrypted, mutually authenticated service-to-service communication inside the cluster.

Exam trap

The trap here is assuming that a WAF or API gateway provides internal service-to-service encryption, when they only protect traffic at the perimeter or ingress.

533
MCQeasy

A cloud operations team is deploying a web application behind a load balancer in a VPC. The application servers must be reachable only from the load balancer, never directly from the internet. Which configuration achieves this?

A.Place the application servers in a public subnet and attach a network ACL that denies inbound traffic from 0.0.0.0/0.
B.Keep the application servers in a public subnet but enable a host-based firewall on each instance.
C.Place the application servers in a private subnet and attach a security group that allows inbound traffic only from the load balancer's security group.
D.Assign elastic IP addresses to the application servers and restrict access using a VPN.
AnswerC

A private subnet removes the route to an internet gateway, and referencing the load balancer's security group as the source restricts traffic to that balancer. This layered approach ensures no direct internet path and no unauthorized source can reach the application servers.

Why this answer

Private subnets eliminate the internet route, and referencing the load balancer's security group as the allowed source ensures only that balancer can reach the application servers. Public subnets, host firewalls, and elastic IPs all leave direct internet reachability in place, so they fail the isolation requirement.

Exam trap

The trap here is believing that a network ACL or host firewall alone can isolate servers that still reside in a public subnet with an internet route, when subnet placement is the foundational control.

534
Multi-Selecthard

A cloud security team is designing the management plane for a regulated workload on a public IaaS platform. They must ensure that administrative access to the cloud console and APIs is strongly controlled. Which TWO measures best satisfy this requirement? (Choose two.)

Select 2 answers
A.Restrict administrative API calls to approved source networks using provider policy conditions
B.Issue long-lived access keys to automation accounts to simplify pipeline authentication
C.Deploy a content delivery network in front of the provider's management console endpoints
D.Enable verbose object storage access logging for all buckets in the account
E.Enforce phishing-resistant multifactor authentication for all administrative identities
AnswersA, E

Many cloud providers let administrators attach conditions to IAM policies that evaluate the source network of an API call. Requiring administrative actions to originate from a known corporate range or a bastion network means a stolen credential used from an attacker's location is rejected outright, adding a strong contextual control independent of the credential itself.

Why this answer

Protecting the management plane requires both strong authentication and contextual authorization. Phishing-resistant multifactor authentication stops credential theft, while policy conditions that restrict administrative API calls to approved source networks ensure that even a stolen credential cannot be replayed from an untrusted location. Together they address identity and context, which are the two levers tenants control over the provider's management plane.

Exam trap

The trap here is selecting logging or network acceleration measures that sound like security controls but only observe or optimize traffic rather than preventing unauthorized administrative access.

535
MCQeasy

Which of the following is a key difference between a security group and a network ACL in a VPC?

A.Security groups are stateless, while NACLs are stateful
B.Security groups are applied at the subnet level, while NACLs are applied at the instance level
C.Security groups support both allow and deny rules
D.Security groups are stateful, while NACLs are stateless
AnswerD

Security groups track connection state, so return traffic is automatically permitted regardless of inbound rules. Network ACLs evaluate each packet independently against their rules, requiring explicit inbound and outbound allowances for both directions of a flow.

Why this answer

Security groups are stateful, meaning return traffic is automatically allowed regardless of inbound rules. NACLs are stateless, requiring explicit inbound and outbound rules.

536
MCQmedium

A company uses Azure Functions for serverless data processing. To securely access an Azure SQL database, which of the following is the most secure method for managing the database connection string?

A.Embed the connection string in the function code and encrypt the code file
B.Store the connection string as an environment variable in the function app settings
C.Use Azure Policy to enforce encryption of the connection string at rest
D.Reference the connection string from Azure Key Vault using a managed identity
AnswerD

A managed identity lets Azure Functions authenticate to Key Vault without stored credentials, and the connection string is retrieved at runtime rather than embedded in code or configuration. This satisfies the stem's most-secure requirement by eliminating secrets from the application entirely.

Why this answer

Referencing the connection string from Azure Key Vault using a managed identity eliminates secrets from code and configuration entirely: the Function App authenticates to Key Vault via its Azure AD managed identity, and Key Vault returns the secret at runtime. This removes the need to store, rotate, or transmit the credential manually and is Microsoft's recommended pattern for secret management.

Exam trap

The trap is treating 'encrypted at rest' or 'environment variable' as equivalent to secure secret management; the exam expects you to know that only a dedicated secret store (Key Vault) accessed via managed identity removes the secret from code and configuration entirely.

How to eliminate wrong answers

Option A is wrong because embedding a connection string in code — even encrypted — still ships the secret with the artifact, exposes it to anyone with source or deployment access, and requires code changes to rotate. Option B is wrong because Function App settings (environment variables) are stored in plaintext in the Azure control plane, visible to anyone with Reader/Contributor access, and are not a secure secret store. Option C is wrong because Azure Policy enforces configuration compliance (e.g., requiring encryption at rest) but does not itself manage or retrieve secrets; encrypting a string that is still stored in app settings does not remove the exposure.

537
Multi-Selectmedium

A cloud security architect is designing a data loss prevention (DLP) strategy for a cloud environment that stores sensitive customer data. Which TWO techniques should be implemented to proactively identify and protect sensitive data? (Select TWO.)

Select 2 answers
A.Cross-region replication
B.De-identification transforms
C.Automated DLP scanning for sensitive data
D.Bucket policies blocking all public access
E.Enabling object versioning
AnswersB, C

De-identification transforms (tokenisation, masking, generalisation) remove or replace direct identifiers so stored records no longer expose customer identities, satisfying the requirement to protect sensitive data at rest. Unlike detection-only controls, they proactively reduce the data's sensitivity before exposure, limiting breach impact and supporting privacy compliance.

Why this answer

Option B (de-identification transforms) is correct because techniques such as tokenization, masking, pseudonymization, and generalization remove or obscure personally identifiable information (PII) so that sensitive customer data is protected even when accessed or processed, directly supporting a proactive DLP strategy. Option C (automated DLP scanning for sensitive data) is correct because continuous automated discovery and classification of sensitive data (e.g., using pattern matching, regex, and ML-based classifiers) lets the organization proactively locate and tag PII across storage and data flows so protection controls can be applied. Option A (cross-region replication) is not a DLP control; it improves durability and availability but can actually widen the data exposure footprint.

Option D (bucket policies blocking all public access) is a useful access control, but it is reactive perimeter hardening rather than a technique for identifying sensitive data. Option E (enabling object versioning) supports recovery and immutability but does nothing to discover, classify, or de-identify sensitive data.

Exam trap

CCSP often tests the distinction between preventive access controls (bucket policies, versioning) and proactive data-centric controls (DLP scanning, de-identification) — candidates pick access controls that do not actually identify or transform sensitive data.

538
MCQeasy

A cloud architect needs to protect data in transit between an on-premises data center and a cloud virtual private cloud (VPC). Which solution is MOST appropriate?

A.SSL certificate on web server
B.TLS for each application
C.VPN with IPsec
D.Direct Connect without encryption
AnswerC

IPsec operates at the network layer, encrypting every packet between the on-premises gateway and the VPC's virtual private gateway. This satisfies the requirement to protect data in transit across the public internet, providing confidentiality and integrity for site-to-site traffic without application changes.

Why this answer

An IPsec VPN is the most appropriate solution for protecting data in transit between an on-premises data center and a cloud VPC because it provides network-layer encryption and authentication for all IP traffic between the two sites. IPsec operates at Layer 3, securing the entire tunnel without requiring per-application configuration, and is designed specifically for site-to-site connectivity. This ensures confidentiality, integrity, and replay protection for all data traversing the public internet or a direct connect link.

Exam trap

ISC2 often tests the misconception that TLS or SSL is sufficient for all data-in-transit scenarios, but the trap here is that TLS is application-layer and cannot secure non-HTTP traffic or provide a site-to-site tunnel, whereas IPsec is the correct network-layer solution for connecting entire networks.

How to eliminate wrong answers

Option A is wrong because an SSL certificate on a web server only protects HTTP traffic (Layer 7) and does not secure other protocols or the entire data stream between the data center and VPC. Option B is wrong because implementing TLS for each application is application-specific, requires individual configuration per service, and does not provide a unified, network-level security boundary for all traffic between the two sites. Option D is wrong because Direct Connect without encryption leaves all data in transit unencrypted, exposing it to potential interception or tampering, and does not meet the requirement to protect data in transit.

539
MCQhard

A cloud security engineer is responsible for securing a Kubernetes cluster running on Google Kubernetes Engine (GKE). They need to detect and respond to runtime threats such as cryptomining and reverse shell attempts. They want a solution that integrates natively with GKE and provides detailed container-level visibility. Which GCP service should they use?

A.Google Cloud's Cloud IDS
B.Google Cloud's Container Threat Detection
C.Google Cloud's Anthos Service Mesh
D.Google Cloud Security Command Center (SCC)
AnswerB

Container Threat Detection is a built-in service in GKE that monitors container runtime activity. It detects threats like cryptomining, reverse shells, and malware execution by analyzing system calls and process behavior. It provides detailed container-level visibility and integrates natively with GKE, sending findings to Security Command Center. This meets the requirement for runtime threat detection.

Why this answer

Container Threat Detection is a GKE-native service that monitors runtime activity within containers. It detects threats such as cryptomining and reverse shells by analyzing system calls and process behavior. It provides container-level visibility and integrates with Security Command Center for centralized findings.

This makes it the correct choice for runtime threat detection in GKE.

Exam trap

The trap here is confusing network-level intrusion detection (Cloud IDS) or posture management (SCC) with container runtime security, which requires deep introspection of container processes.

540
MCQeasy

A healthcare company stores regulated data in Amazon S3. An auditor requires proof that objects are protected against accidental deletion or overwrite for a fixed period, and that the protection cannot be removed even by the root account. Which S3 feature should the security team implement?

A.S3 Object Lock in compliance mode with a retention period matching the required fixed duration.
B.S3 Object Lock in governance mode with a retention period matching the required fixed duration.
C.A bucket policy that denies s3:DeleteObject and s3:PutObject to all principals except a dedicated backup role.
D.S3 Versioning with a lifecycle rule that transitions noncurrent versions to S3 Glacier Deep Archive.
AnswerA

S3 Object Lock in compliance mode prevents object versions from being overwritten or deleted for the specified retention period. Critically, compliance mode cannot be bypassed or shortened by any user, including the AWS account root user, satisfying the auditor's immutability requirement. Governance mode, by contrast, allows privileged users to alter retention.

Why this answer

S3 Object Lock in compliance mode creates a write-once-read-many (WORM) protection that no principal, including the root account, can bypass or shorten during the retention period. Governance mode and bucket policies are administratively changeable, and versioning alone does not prevent deletion. Compliance mode directly satisfies the immutability and fixed-duration requirements.

Exam trap

The trap here is treating versioning or a restrictive bucket policy as equivalent to WORM protection, when both can be reversed by privileged accounts.

541
MCQmedium

A cloud customer is reviewing its contract with a cloud provider. The customer wants to ensure that if the provider subcontracts any part of the service to a third party, the customer's data remains protected. Which contract provision is most critical to address this risk?

A.Requirement for provider to flow down data protection obligations to subcontractors
B.Right to terminate for convenience
C.Service level agreement (SLA) with penalties for downtime
D.Right to audit the provider's subcontractors
AnswerA

This provision ensures that any subcontractor engaged by the provider is bound by the same data protection and security obligations as the provider. It creates a chain of responsibility, so the customer's data remains protected even when handled by third parties. It is a fundamental requirement in cloud contracts, especially under regulations like GDPR, to maintain compliance throughout the supply chain.

Why this answer

Flow-down obligations ensure that subcontractors are contractually bound to the same data protection standards as the primary provider. This maintains protection throughout the cloud supply chain and is often a regulatory requirement. Other options focus on audit rights, availability, or exit, which do not directly ensure subcontractor compliance with data protection obligations.

Exam trap

The trap here is thinking that a right to audit subcontractors is sufficient, when the more fundamental control is contractual flow-down of obligations.

542
MCQhard

A cloud application processes credit card numbers. To reduce PCI DSS scope, the company wants to remove the original PAN from its databases and use a surrogate value that can be reversed only by a privileged application. Which data protection technique should they use?

A.Truncation of the first 6 and last 4 digits
B.Dynamic data masking in the application tier
C.Tokenization using a cloud-based token vault
D.Symmetric encryption with a key stored in the database
AnswerC

Tokenization replaces PAN with a token and the token vault controls detokenization.

Why this answer

Tokenization replaces the original PAN with a randomly generated surrogate value (token) that has no mathematical relationship to the original data. The token can be reversed only by a privileged application that has access to the token vault, which stores the mapping between tokens and actual PANs. This effectively removes the PAN from the application's databases, reducing PCI DSS scope because the tokenized data is not considered sensitive cardholder data.

Exam trap

ISC2 often tests the distinction between tokenization and encryption, where candidates mistakenly choose symmetric encryption (Option D) because they think encryption alone removes data from scope, but PCI DSS requires that the decryption key be stored separately from the encrypted data, and even then, encrypted PANs are still considered cardholder data unless the key is managed by a third-party service.

How to eliminate wrong answers

Option A is wrong because truncation (showing only the last 4 digits) still leaves the full PAN stored elsewhere in the system, and the truncated value cannot be reversed to recover the original PAN, so it does not meet the requirement for a reversible surrogate value. Option B is wrong because dynamic data masking only hides data at query time from unauthorized users, but the original PAN remains stored in the database, so it does not remove the PAN from databases or reduce PCI DSS scope. Option D is wrong because symmetric encryption with a key stored in the database keeps the key co-located with the ciphertext, violating the principle of separation of duties and failing to reduce PCI DSS scope, as the encrypted data is still considered cardholder data under PCI DSS requirements.

543
MCQeasy

Which of the following best describes the purpose of the Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) program?

A.To offer a certification program for cloud security professionals
B.To define mandatory security requirements for all cloud services
C.To provide a legal framework for cloud contracts
D.To allow cloud providers to publicly document their security controls and achieve different levels of assurance
AnswerD

The CSA STAR program lets cloud providers publish security control documentation through self-assessment, third-party audit or certification, satisfying the stem's requirement to describe its purpose. Its three assurance tiers — Level 1 self-assessment, Level 2 third-party audit, and continuous monitoring — directly match "different levels of assurance".

Why this answer

The CSA STAR program allows cloud providers to publicly document their security controls and achieve different levels of assurance through self-assessment, third-party audits, or certifications. It provides transparency and trust by mapping controls to recognized standards like ISO 27001 and SOC 2.

Exam trap

CCSP often tests the confusion between CSA STAR as a cloud provider assurance program and other CSA offerings like the CCSK certification, leading candidates to select options about professional certification or mandatory standards.

How to eliminate wrong answers

Option A is wrong because CSA STAR is not a certification program for individuals; it is for cloud service providers to demonstrate security posture. Option B is wrong because CSA STAR does not define mandatory requirements; it offers a framework for voluntary disclosure. Option C is wrong because CSA STAR is not a legal framework for contracts; it focuses on security assurance and transparency.

544
MCQmedium

A company uses cloud storage for sensitive data and wants to ensure that the cloud provider cannot access their encryption keys. Which approach should they implement?

A.Cloud KMS with software keys
B.Cloud KMS with hardware keys
C.Cloud HSM
D.Cloud External Key Manager (EKM)
AnswerD

Cloud External Key Manager stores and manages keys in an external, customer-controlled system outside the cloud provider's infrastructure. The provider only brokers cryptographic operations, so it never holds the key material and cannot access the encrypted data.

Why this answer

Cloud External Key Manager (EKM) allows the customer to manage and store encryption keys outside the cloud provider's infrastructure, often in an on-premises HSM or a third-party key management system. This ensures the cloud provider never has access to the plaintext keys, meeting the requirement that the provider cannot access the encryption keys. EKM typically uses protocols like PKCS#11 or KMIP to allow the cloud service to perform cryptographic operations without exposing the keys to the provider.

Exam trap

ISC2 often tests the distinction between 'cloud-managed' and 'customer-managed' keys, where candidates mistakenly think that using hardware keys (HSM) automatically prevents provider access, but the trap is that provider-managed HSMs still give the provider administrative control over the hardware.

How to eliminate wrong answers

Option A is wrong because Cloud KMS with software keys stores keys within the cloud provider's infrastructure, and the provider can potentially access them, especially if the keys are managed by the provider's software. Option B is wrong because Cloud KMS with hardware keys still stores keys in the cloud provider's HSM, meaning the provider has logical access and control over the key management process, even if the keys are in hardware. Option C is wrong because Cloud HSM, while providing dedicated hardware security modules, is still managed by the cloud provider, and the provider retains administrative access to the HSMs, which could allow them to access keys if they chose to.

545
MCQhard

An organization uses a multi-cloud architecture with applications running on both AWS and Azure. They need to implement a secrets management solution that works across both platforms and supports automated rotation. Which approach best meets these requirements?

A.Deploy HashiCorp Vault as a centralized secrets manager
B.Store secrets as encrypted environment variables in each environment
C.Use Azure Key Vault with a federation bridge to AWS
D.Use AWS Secrets Manager for all secrets
AnswerA

HashiCorp Vault runs platform-agnostically, so a single control plane issues and rotates secrets for both AWS and Azure workloads. Its dynamic secrets engines and API-driven rotation satisfy the cross-platform and automated rotation constraints that native AWS Secrets Manager or Azure Key Vault cannot meet alone.

Why this answer

HashiCorp Vault is a platform-agnostic secrets management solution that runs on any cloud or on-premises environment, supports dynamic secrets, and provides automated secret rotation via leases and rotation policies. It is the only option that natively spans AWS and Azure with consistent APIs and automated rotation.

Exam trap

The trap is assuming a single-cloud native service (AWS Secrets Manager or Azure Key Vault) can manage secrets across both clouds — only a cloud-agnostic tool like Vault natively satisfies multi-cloud rotation.

How to eliminate wrong answers

Option B is wrong because encrypted environment variables are static, platform-specific, and lack automated rotation or centralized audit — they do not meet the multi-cloud rotation requirement. Option C is wrong because Azure Key Vault is Azure-native and does not natively manage AWS secrets; a 'federation bridge' is not a standard product feature and would require custom integration. Option D is wrong because AWS Secrets Manager is AWS-native and cannot manage secrets for Azure workloads without custom cross-cloud plumbing, and its rotation Lambdas are AWS-specific.

546
MCQmedium

A cloud customer requires that its data stored by a provider be irretrievably destroyed after contract termination, even if the provider uses backup tapes and replicated storage. Which contractual and technical provision best supports this requirement?

A.A right-to-audit clause that allows the customer to inspect the provider's data centers annually.
B.A clause requiring the provider to sanitize or crypto-shred all customer data, including backups and replicas, and to provide a certificate of destruction upon termination.
C.A service level agreement that guarantees 99.99% data durability during the contract term.
D.A data retention schedule that specifies how long the provider may keep customer data before automatic deletion.
AnswerB

This directly addresses irretrievable destruction by requiring sanitization or crypto-shredding across all copies, including backups and replicas, and by demanding a certificate of destruction. Crypto-shredding destroys the encryption keys, rendering data unreadable. The certificate provides evidence. This combination is the standard contractual and technical mechanism to meet secure deletion requirements in cloud contracts.

Why this answer

Irretrievable destruction requires more than retention limits or audit rights; it demands a contractual obligation to sanitize or crypto-shred all copies, including backups and replicas, and to certify destruction. Crypto-shredding is effective when data is encrypted and keys can be destroyed. The certificate of destruction provides verifiable evidence that the obligation was met.

Exam trap

The trap here is confusing data retention limits or audit rights with actual secure deletion obligations, which require explicit sanitization and certification clauses.

547
MCQeasy

A cloud security administrator needs to ensure that all API calls to the cloud provider's management plane are logged for audit purposes. Which service should be enabled?

A.Cloud configuration service
B.Cloud threat detection service
C.Cloud audit logging service
D.Cloud monitoring service
AnswerC

Cloud audit logging captures control-plane API activity, recording who invoked which management operation, when and from where. Enabling it satisfies the audit requirement because management-plane calls are logged natively, unlike data-plane or application-level logging services.

Why this answer

The cloud audit logging service should be enabled to log all API calls to the management plane for audit purposes. This service captures API activity, including who made the call, when, and from where, providing an audit trail. It is specifically designed for compliance and security auditing.

Exam trap

CCSP often tests the confusion between audit logging (CloudTrail) and monitoring (CloudWatch) or configuration (Config); candidates must select the service specifically for API audit logging.

How to eliminate wrong answers

Option A is wrong because a cloud configuration service (e.g., AWS Config) records resource configurations and changes, but not all API calls; it focuses on configuration state. Option B is wrong because a cloud threat detection service (e.g., Amazon GuardDuty) identifies malicious activity but does not provide comprehensive API logging for audit. Option D is wrong because a cloud monitoring service (e.g., CloudWatch) monitors performance and metrics, not API audit logs.

548
MCQeasy

A company is migrating its on-premises workloads to a public cloud environment. The security team is concerned about maintaining visibility into network traffic between virtual machines in the same virtual network. Which cloud architecture component should be implemented to address this concern?

A.Security groups
B.Virtual network traffic mirroring
C.Virtual private cloud (VPC) peering
D.Network access control lists (NACLs)
AnswerB

Virtual network traffic mirroring copies packets from virtual machine network interfaces to an analysis destination, restoring the east-west visibility that physical taps provided on-premises. Security teams can then inspect intra-virtual-network traffic that flow logs alone cannot capture at packet level.

Why this answer

Virtual network traffic mirroring (or port mirroring) enables the capture and inspection of all network packets flowing between virtual machines within the same virtual network, including east-west traffic. This provides the security team with the deep packet visibility needed for threat detection, compliance auditing, and troubleshooting without requiring changes to the VM configurations or routing paths.

Exam trap

The trap here is that candidates often confuse security groups or NACLs with visibility tools, mistakenly believing that filtering or logging features (like flow logs) provide the same packet-level capture as traffic mirroring, when in fact flow logs only record metadata (e.g., source/destination IP, port, protocol) and not the full packet payload.

How to eliminate wrong answers

Option A is wrong because security groups act as a stateful virtual firewall that filters traffic based on rules (e.g., source IP, port), but they do not capture or mirror traffic for analysis; they only permit or deny packets. Option C is wrong because VPC peering connects two separate virtual networks, allowing traffic between them, but it does not provide visibility into traffic within a single virtual network. Option D is wrong because network access control lists (NACLs) are stateless packet filters applied at the subnet boundary, not a mechanism for copying or monitoring traffic flows between VMs inside the same subnet.

549
MCQeasy

A startup is designing its first cloud landing zone and wants a guardrail that prevents any principal in the organization from disabling AWS CloudTrail logging in any account, including the management account, while still allowing normal administrative work. Which control achieves this with the LEAST operational overhead?

A.A CloudWatch Logs metric filter on the CloudTrail log group that triggers an AWS Lambda function to restart the trail.
B.An IAM permissions boundary on every administrator role that denies the CloudTrail modification actions.
C.An organization-level service control policy attached to the root that denies cloudtrail:StopLogging, cloudtrail:DeleteTrail, and cloudtrail:UpdateTrail.
D.An AWS Config rule that detects when a trail is stopped and sends an Amazon SNS notification to the security team.
AnswerC

A service control policy attached at the organization root sets the maximum available permissions for every account in the organization, including the management account when applied at the root. Denying the trail-modification actions blocks the operation regardless of identity-based policy, giving a single preventive guardrail with no per-account maintenance.

Why this answer

An organization root service control policy denies the trail-modification API calls for all principals in every account, making the guardrail preventive rather than detective and requiring no per-account upkeep. Detection rules, permissions boundaries, and remediation automation either act after the fact or leave uncovered principals.

Exam trap

The trap here is reaching for a detective control such as AWS Config or a CloudWatch alarm when the requirement is to prevent the action from succeeding at all.

550
MCQmedium

A media company uses a CI/CD pipeline to deploy a web application to a cloud platform. The security team wants to integrate security testing that can detect vulnerabilities in third-party libraries and base images before deployment, without significantly slowing the pipeline. Which practice should be implemented?

A.Static application security testing (SAST) on the application source code only.
B.Software composition analysis (SCA) and container image scanning integrated into the pipeline.
C.Dynamic application security testing (DAST) against the staging environment after each deployment.
D.Interactive application security testing (IAST) with agents in the staging environment.
AnswerB

SCA examines dependency manifests and lockfiles to identify known vulnerabilities in third-party libraries, while container image scanning inspects image layers for vulnerable packages and misconfigurations. Both run early in the pipeline, provide fast feedback, and can fail builds on policy violations, meeting the requirement to detect issues before deployment without heavy slowdown.

Why this answer

Detecting vulnerabilities in third-party libraries and base images before deployment requires tools that inspect dependencies and image contents. SCA reads dependency manifests for known CVEs, and container image scanning checks layers for vulnerable packages. Both integrate into CI/CD with fast, automated feedback.

DAST and IAST need running environments and target runtime behavior, while SAST covers only first-party code, so none of those alone meets the requirement.

Exam trap

The trap here is assuming that any security testing in CI/CD covers third-party libraries and base images, when each tool type has a distinct scope.

551
MCQmedium

A company is subject to a legal hold order and uses a cloud storage service with object replication across multiple regions. Which cloud feature should the company use to prevent deletion or modification of relevant data?

A.Versioning of objects
B.Cross-region replication
C.Backup to another provider
D.Legal hold policies (e.g., S3 Object Lock)
AnswerD

S3 Object Lock enforces write-once-read-many (WORM) protection at the object level, blocking deletion or modification for a defined retention period even by root users. This directly satisfies the legal hold constraint, unlike replication, which merely copies data and propagates deletions across regions.

Why this answer

Legal hold policies, such as Amazon S3 Object Lock in compliance mode, prevent objects from being deleted or overwritten for a specified retention period, even by privileged users. This directly satisfies a legal hold order requiring preservation of data against alteration or destruction. Object Lock uses a write-once-read-many (WORM) model that is purpose-built for litigation holds and regulatory retention.

Exam trap

CCSP often tests immutability versus durability — candidates pick 'versioning' or 'cross-region replication' because they sound protective, but only Object Lock/legal hold provides true WORM protection against deletion or modification.

How to eliminate wrong answers

Option A is wrong because versioning alone does not prevent deletion — a user can still delete objects or delete versions, and without MFA delete or Object Lock, versioning is not a legal hold. Option B is wrong because cross-region replication improves durability and availability but does not prevent modification or deletion of the source or replica objects. Option C is wrong because backing up to another provider is a resilience measure, not an immutable retention control, and backups can also be altered or deleted unless separately protected.

552
MCQmedium

A company subject to PCI DSS is considering a cloud provider to process credit card transactions. What must the cloud provider present to demonstrate compliance with PCI DSS?

A.A CSA STAR Level 1 self-assessment
B.A PCI DSS Attestation of Compliance (AOC) from a QSA
C.A SOC 2 Type II report
D.An ISO 27001 certificate
AnswerB

A PCI DSS Attestation of Compliance issued by a Qualified Security Assessor formally documents the provider's validated compliance status, giving the customer the evidence needed for its own PCI DSS obligations when processing card transactions.

Why this answer

PCI DSS compliance for a cloud provider is demonstrated through a PCI DSS Attestation of Compliance (AOC) validated by a Qualified Security Assessor (QSA) or, for service providers, a Report on Compliance (ROC). The AOC is the formal document that attests the provider meets the 12 PCI DSS requirements for the services in scope. Customers rely on the provider's AOC to inherit controls and reduce their own assessment scope.

Exam trap

CCSP often tests the difference between general security certifications (SOC 2, ISO 27001, CSA STAR) and payment-specific validation — candidates pick SOC 2 or ISO 27001 because they sound rigorous, but only a QSA-validated AOC demonstrates PCI DSS compliance.

How to eliminate wrong answers

Option A is wrong because CSA STAR Level 1 is a self-assessment of cloud security controls, not a PCI DSS validation, and self-attestation carries far less assurance than a QSA-validated AOC. Option C is wrong because a SOC 2 Type II report covers trust services criteria (security, availability, confidentiality) but does not map to or satisfy PCI DSS requirements. Option D is wrong because ISO 27001 certifies an information security management system, not cardholder data protection, and is not accepted as PCI DSS evidence.

553
Multi-Selecthard

Which THREE controls help protect data in use within a cloud environment? (Choose three.)

Select 3 answers
A.Confidential computing
B.Tokenization
C.Access control lists
D.Secure enclaves (e.g., Intel SGX)
E.Homomorphic encryption
AnswersA, D, E

Encrypts data in use in memory.

Why this answer

Confidential computing protects data in use by executing computations within a hardware-based Trusted Execution Environment (TEE), such as Intel SGX or AMD SEV, which isolates the data and code from the host operating system and hypervisor. This ensures that even privileged users or cloud administrators cannot access the plaintext data while it is being processed in memory.

Exam trap

ISC2 often tests the distinction between data-at-rest, data-in-transit, and data-in-use controls, and the trap here is that candidates confuse tokenization (which protects data at rest) or access control lists (which protect data at rest/in transit) with technologies that specifically protect data during active processing in memory.

554
MCQeasy

A small business wants to use a cloud-based email and collaboration suite where the provider manages the application, servers, and operating system. The business only needs to configure user accounts and settings. Which cloud service model is being used?

A.Software as a Service (SaaS)
B.Platform as a Service (PaaS)
C.Infrastructure as a Service (IaaS)
D.Function as a Service (FaaS)
AnswerA

SaaS delivers a complete application managed by the provider, including servers, operating system, and application maintenance. The customer only configures user accounts and settings. This exactly matches the scenario where the business uses a cloud-based email and collaboration suite without managing infrastructure or the application itself.

Why this answer

SaaS is the model where the provider manages the entire application stack, and the customer only handles configuration and user management. The scenario explicitly states the provider manages the application, servers, and operating system, leaving only account and settings configuration to the business. IaaS, PaaS, and FaaS all require more customer responsibility for the application or runtime.

Exam trap

The trap here is equating any cloud-hosted application with PaaS, when a fully managed application with only user configuration is SaaS.

555
MCQmedium

A company uses Microsoft Azure and wants to implement just-in-time (JIT) virtual machine access to reduce the attack surface. They need to ensure that only authorized users can access VMs on specific management ports, and that access is granted for a limited time. Which Azure service should they use?

A.Azure Bastion
B.Network security groups (NSGs) with service tags
C.Azure Firewall
D.Azure Security Center (now Microsoft Defender for Cloud) just-in-time VM access
AnswerD

Microsoft Defender for Cloud's just-in-time VM access allows you to lock down inbound traffic to VMs, permitting access only when needed and for a specified duration. It integrates with Azure RBAC and network security groups to grant temporary access on management ports, reducing exposure to attacks.

Why this answer

Microsoft Defender for Cloud's just-in-time VM access is designed to reduce the attack surface by allowing access to VMs only when needed, for a limited time, and on specific ports. It uses Azure RBAC to control who can request access and NSGs to enforce the temporary rules. This meets the requirement for time-limited, authorized access.

Exam trap

The trap here is assuming that Azure Bastion or NSGs provide just-in-time access, but they do not have the time-bound, request-based access control that JIT VM access offers.

556
MCQmedium

An enterprise uses a cloud-based relational database service (e.g., AWS RDS) to store customer order data. The database is encrypted at rest using the cloud provider's default encryption. The security team is concerned about the risk of a rogue database administrator (DBA) exfiltrating data by creating unencrypted backups or snapshots and moving them to a different account. Which of the following controls would BEST mitigate this risk while maintaining operational efficiency?

A.Use a customer-managed key (CMK) in KMS and configure the database to use that key for encryption, and restrict the DBA's IAM permissions to prevent using the key on snapshots.
B.Disable the ability for any user to create database snapshots.
C.Implement database activity monitoring (DAM) to alert on snapshot creation.
D.Enable automatic snapshot encryption and ensure that only the database service role can access snapshots.
AnswerA

Ensures snapshots are encrypted and DBA cannot decrypt them without key permission.

Why this answer

Using a customer-managed key (CMK) in AWS KMS allows the organization to attach a key policy that explicitly denies the DBA's IAM role the kms:Decrypt permission on the CMK when used with snapshot operations. This prevents the DBA from creating an unencrypted snapshot or from copying an encrypted snapshot to another account, as the snapshot would remain encrypted with the CMK and the DBA cannot decrypt it. This maintains operational efficiency because the DBA can still perform routine database management tasks (e.g., creating backups) but cannot exfiltrate data via snapshots.

Exam trap

ISC2 often tests the misconception that enabling automatic encryption or monitoring alone is sufficient to prevent data exfiltration by a privileged insider, when in reality only a combination of customer-managed keys with strict key policies and IAM permission boundaries can block the DBA's ability to decrypt or re-encrypt snapshots for exfiltration.

How to eliminate wrong answers

Option B is wrong because completely disabling snapshot creation would break critical operational processes such as automated backups, point-in-time recovery, and disaster recovery, making it an impractical and overly restrictive control. Option C is wrong because database activity monitoring (DAM) only provides alerting after the fact; it does not prevent a rogue DBA from successfully exfiltrating data via unencrypted snapshots, as the DBA could still create and move the snapshot before the alert is acted upon. Option D is wrong because enabling automatic snapshot encryption does not prevent the DBA from creating a snapshot that is encrypted with a key they can access (e.g., the default AWS managed key), and restricting access to only the database service role does not stop a DBA with elevated IAM permissions from assuming that role or using their own permissions to copy the snapshot to another account.

557
Multi-Selectmedium

A cloud security team is designing network security for a multi-VPC architecture in AWS. Which TWO of the following are valid considerations for VPC peering?

Select 2 answers
A.VPC peering can be used to connect on-premises networks
B.VPC peering requires an internet gateway for communication
C.VPC peering is a one-to-one relationship
D.VPC peering supports transitive routing across multiple VPCs
E.VPC peering allows private IP connectivity between VPCs
AnswersC, E

VPC peering links exactly two VPCs, so each peering connection is a discrete one-to-one relationship rather than a transitive hub. This satisfies the multi-VPC design constraint: traffic cannot route through a peered VPC to reach a third, requiring explicit mesh or transit gateway topologies.

Why this answer

Option C is correct because a VPC peering connection is strictly a one-to-one relationship between exactly two VPCs; you cannot attach a single peering connection to more than two VPCs, and each pair requires its own peering connection. Option E is correct because VPC peering routes traffic using private IPv4 or IPv6 addresses between the peered VPCs, so instances communicate over the AWS private network without traversing the public internet. Option A is incorrect because connecting on-premises networks to a VPC requires AWS Site-to-Site VPN or AWS Direct Connect, not VPC peering.

Option B is incorrect because peering traffic flows over the AWS backbone and does not require an internet gateway, NAT device, or virtual private gateway. Option D is incorrect because VPC peering does not support transitive routing; to reach a third VPC you must establish a direct peering connection (or use a transit gateway).

Exam trap

CCSP often tests the misconception that VPC peering supports transitive routing or requires an internet gateway, confusing it with VPN or Transit Gateway capabilities.

558
MCQmedium

A company runs a multi-tier cloud application with a web frontend, an API layer, and a database. The application uses OAuth 2.0 for authentication. Recently, users have been experiencing session hijacking attacks. Upon investigation, the security team finds that session tokens are being intercepted in transit. The application uses HTTPS for all communications, but a developer discovers that the application is also accessible via HTTP due to a misconfiguration. The team wants to implement additional security controls to prevent token theft. Which course of action should be taken first?

A.Use IP address binding for session tokens
B.Implement HTTP Strict Transport Security (HSTS) to enforce HTTPS connections
C.Switch from OAuth to SAML for authentication
D.Shorten the session token expiration time
AnswerB

HSTS forces browsers to use HTTPS exclusively for the domain, eliminating the HTTP misconfiguration that exposes tokens to interception. Addressing the transport downgrade first satisfies the requirement to prevent token theft, since encrypted delivery removes the interception vector.

Why this answer

The root cause is that the application is accessible via HTTP due to a misconfiguration, allowing session tokens to be intercepted in transit despite HTTPS being available. Implementing HTTP Strict Transport Security (HSTS) forces the browser to always use HTTPS, preventing any HTTP connections and thus eliminating the interception vector. This directly addresses the misconfiguration before other controls, which would only mitigate but not prevent the theft.

Exam trap

ISC2 often tests the concept that session hijacking prevention must address the root cause (insecure transport) rather than just mitigating the impact of token theft, leading candidates to choose options like shortening expiration or IP binding instead of enforcing HTTPS with HSTS.

How to eliminate wrong answers

Option A is wrong because IP address binding for session tokens is a server-side binding that can help prevent token reuse from different IPs, but it does not prevent the initial interception of the token over HTTP; the token can still be stolen in transit. Option C is wrong because switching from OAuth 2.0 to SAML does not change the transport security issue; both protocols can be used over HTTP and are equally vulnerable to interception if HTTPS is not enforced. Option D is wrong because shortening the session token expiration time reduces the window of opportunity for an attacker to use a stolen token, but it does not prevent the token from being intercepted in the first place over an HTTP connection.

559
MCQmedium

A security analyst is investigating a data breach in a cloud environment. The analyst needs to preserve evidence for legal proceedings. Which of the following actions is most critical to ensure the chain of custody is maintained?

A.Calculate cryptographic hashes of all relevant files.
B.Isolate all affected systems from the network to prevent further data loss.
C.Begin a detailed log documenting all actions, timestamps, and personnel involved.
D.Immediately notify senior management and legal counsel.
AnswerC

Documenting every action, timestamp, and person handling evidence creates the unbroken audit trail that chain of custody demands. This satisfies the stem's legal-preservation constraint by proving evidence integrity from seizure onward, which isolated technical steps alone cannot demonstrate.

Why this answer

Maintaining a detailed log documenting all actions, timestamps, and personnel involved is the most critical action to ensure chain of custody. Chain of custody requires an unbroken record of who handled the evidence, when, and what they did, so that it is admissible in legal proceedings. While hashing, isolation, and notification are important, the log is the foundational element that ties everything together.

Exam trap

CCSP often tests the distinction between integrity (hashing) and chain of custody (documentation) — the trap is choosing hashing as the most critical step when the question specifically asks about chain of custody.

How to eliminate wrong answers

Option A is wrong because calculating cryptographic hashes is important for integrity verification but does not by itself establish chain of custody — it proves the data hasn't changed, not who handled it. Option B is wrong because isolating systems prevents further data loss but is a containment step, not a chain-of-custody documentation step; isolation must still be logged. Option D is wrong because notifying management and legal counsel is a procedural step, but without a detailed log of actions and timestamps, the chain of custody is incomplete and evidence may be challenged.

560
Multi-Selectmedium

Which TWO of the following are effective strategies for protecting sensitive data in a public cloud environment?

Select 2 answers
A.Using the same encryption key for all data to simplify key management.
B.Storing encryption keys in the same storage bucket as the encrypted data.
C.Consolidating all sensitive data into a single storage bucket for easier management.
D.Data masking to obscure sensitive fields in non-production environments.
E.Tokenization to replace sensitive data with non-sensitive placeholders.
AnswersD, E

Masking substitutes realistic but fictitious values for sensitive fields, so non-production environments retain usable data for testing while the actual confidential values never leave the protected production boundary, satisfying the requirement to protect sensitive data in public cloud.

Why this answer

Data masking (option D) and tokenization (option E) are both effective data protection techniques for public cloud environments. Data masking obscures sensitive fields in non-production environments, while tokenization replaces sensitive data with non-sensitive placeholders. Options A, B, and C are insecure or poor practices.

561
Multi-Selectmedium

A cloud application is deployed on Kubernetes and uses a cloud identity and access management (IAM) role for service accounts. Which TWO practices should be implemented to ensure least privilege?

Select 2 answers
A.Grant only the specific permissions required for the application
B.Hardcode the role's credentials in the application code
C.Grant the role the full IAM permissions (e.g., 'iam:*' equivalent)
D.Restrict the role to specific resources using resource identifiers
E.Use a single role for all services in the cluster
AnswersA, D

Granting only the permissions the application actually calls enforces least privilege at the policy level, so the service account cannot perform unrelated actions. This directly satisfies the requirement by eliminating wildcard or broad permissions that exceed the application's operational needs.

Why this answer

Option A is correct because least privilege requires granting only the specific permissions the application actually needs, avoiding broad or wildcard permissions that expand the attack surface. Option D is correct because scoping the IAM role to specific resource identifiers (e.g., a particular bucket or secret) ensures the role can only act on the resources it legitimately requires, further tightening access. Option B is wrong because hardcoding credentials in application code exposes secrets and violates secure credential management, typically handled via workload identity or mounted tokens.

Option C is wrong because granting full IAM permissions such as 'iam:*' is the opposite of least privilege and grants excessive access. Option E is wrong because sharing a single role across all services in the cluster removes per-service isolation and grants each service more permissions than it needs.

Exam trap

The trap is that candidates may think 'encrypting' or 'using a role' is enough, but least privilege specifically requires both minimal permissions and resource-level scoping — broad roles are a common misconfiguration.

562
Multi-Selecteasy

A cloud security team is auditing a cloud environment and needs to ensure compliance with logging requirements. Which TWO actions are essential? (Choose two.)

Select 2 answers
A.Store logs in a publicly accessible bucket.
B.Allow users to modify logs.
C.Encrypt logs at rest.
D.Enable CloudTrail (or equivalent) for all regions.
E.Delete logs after 30 days.
AnswersC, D

Encryption protects log data at rest.

Why this answer

Encrypting logs at rest (Option C) is essential to protect sensitive audit data from unauthorized access if the storage medium is compromised. Cloud providers like AWS offer server-side encryption (SSE-S3 or SSE-KMS) for log buckets, ensuring compliance with standards such as SOC 2, PCI DSS, and ISO 27001. Without encryption, logs could be read by anyone with physical or administrative access to the storage infrastructure.

Exam trap

ISC2 often tests the misconception that deleting logs after a short period is a security best practice, but the trap is that compliance mandates specific retention durations, and premature deletion can lead to audit failures.

563
Multi-Selecthard

A cloud application exposes an API that allows users to view their own orders. Which TWO vulnerabilities could allow an attacker to view another user's orders?

Select 2 answers
A.Excessive Data Exposure
B.SQL Injection
C.Insecure Direct Object Reference (IDOR)
D.Broken Object Level Authorization (BOLA)
E.Cross-Site Scripting (XSS)
AnswersC, D

IDOR occurs when the API trusts a user-supplied object identifier, such as an order ID, without verifying ownership. An attacker simply increments or guesses another user's identifier and the endpoint returns that order, exposing data across tenants.

Why this answer

Insecure Direct Object Reference (IDOR) (C) is correct because the API likely uses a user-controllable identifier such as an order ID or user ID in the request, and if the application fails to verify that the referenced object belongs to the authenticated user, an attacker can simply change that identifier to access another user's orders. Broken Object Level Authorization (BOLA) (D) is correct because it is the API-specific authorization flaw where the server does not properly enforce object-level access checks on each request, allowing an authenticated user to read objects belonging to other users even when the endpoint itself is properly authenticated. Excessive Data Exposure (A) is not correct here because it concerns returning more data fields than necessary in a response, not accessing another user's records.

SQL Injection (B) is not correct because it involves manipulating backend SQL queries through unsanitized input, which is a different attack class than directly referencing another user's object. Cross-Site Scripting (E) is not correct because XSS executes script in a victim's browser and does not by itself grant access to another user's orders.

Exam trap

CCSP often tests the distinction between authentication and authorization, and candidates may confuse IDOR/BOLA with other injection or data exposure flaws; the trap is selecting SQL Injection or Excessive Data Exposure when the core issue is missing object-level access control.

564
MCQmedium

A cloud provider's data center is located in Country A, but the customer's data is subject to litigation in Country B. The court in Country B orders the cloud provider to produce data. The cloud provider refuses, citing Country A's laws that prohibit disclosure. This situation best illustrates which challenge in eDiscovery?

A.Data portability
B.Jurisdiction issues
C.Data preservation
D.Forensic soundness
AnswerB

Two sovereign legal regimes impose conflicting obligations: Country B compels production while Country A prohibits disclosure. This clash of laws governing the same data is a jurisdiction issue, exactly the eDiscovery challenge the stem describes when the provider refuses the court order.

Why this answer

Jurisdictional issues arise when data is stored in multiple legal jurisdictions, and courts in one country may not have authority over data in another, leading to conflicts of law.

565
Multi-Selectmedium

A development team builds a serverless application using AWS Lambda. The security team wants to prevent hardcoded credentials. Which TWO methods should they enforce for secure secrets management?

Select 2 answers
A.Store secrets in environment variables in plain text
B.Assign an IAM role to the Lambda function and retrieve temporary credentials via the AWS SDK
C.Embed secrets directly in the Lambda function code but encrypt the code
D.Use a third-party secrets manager with a hardcoded API key in the code
E.Use AWS Systems Manager Parameter Store with KMS encryption
AnswersB, E

Attaching an IAM role to the Lambda execution role lets the function call AWS STS for short-lived credentials, so no long-term secret is stored in code or environment variables. This directly satisfies the stem's requirement to prevent hardcoded credentials, since rotation is automatic and credentials expire.

Why this answer

Option B is correct because assigning an IAM execution role to the Lambda function lets the AWS SDK obtain temporary credentials from the AWS STS service automatically, eliminating the need to hardcode long-lived access keys in code or configuration. Option E is correct because AWS Systems Manager Parameter Store supports SecureString parameters encrypted with AWS KMS, allowing Lambda to fetch secrets at runtime via the SDK with IAM-controlled access instead of embedding them. Option A is wrong because plain-text environment variables expose credentials in the Lambda console and are not encrypted or rotated.

Option C is wrong because embedding secrets in code, even if the code artifact is encrypted, still hardcodes credentials that persist in source control and deployment packages. Option D is wrong because using a third-party secrets manager with a hardcoded API key simply replaces one hardcoded credential with another.

Exam trap

The trap is that candidates see 'encrypted' or 'third-party manager' and assume security is achieved, missing that the root credential must still be stored securely — hardcoding anything defeats the purpose.

566
MCQeasy

A company wants to ensure that its cloud infrastructure can automatically add capacity during traffic spikes and remove capacity during low demand. Which cloud characteristic is primarily needed?

A.Broad network access
B.Measured service
C.Rapid elasticity
D.Resource pooling
AnswerC

Rapid elasticity directly satisfies the automatic scaling constraint: resources provision and deprovision dynamically to match demand, expanding during spikes and contracting during lulls. Unlike measured service or on-demand self-service, elasticity specifically addresses bidirectional, proportional capacity adjustment, which is the exact behaviour the stem requires.

Why this answer

Rapid elasticity is the cloud characteristic that enables automatic scaling of resources up or down in response to demand, often leveraging orchestration tools like AWS Auto Scaling or Azure VM Scale Sets. This ensures that capacity matches workload spikes and troughs without manual intervention, directly addressing the requirement for dynamic capacity adjustment.

Exam trap

ISC2 often tests the distinction between rapid elasticity and resource pooling, where candidates mistakenly think that sharing resources (pooling) inherently enables scaling, but pooling is about multi-tenancy, not dynamic capacity adjustment.

How to eliminate wrong answers

Option A is wrong because broad network access refers to the ability to access cloud services over standard network protocols (e.g., HTTPS, SSH) from various devices, not the dynamic scaling of resources. Option B is wrong because measured service involves metering and billing based on usage (e.g., per-hour or per-GB charges), not the automatic adjustment of capacity. Option D is wrong because resource pooling describes the multi-tenant model where physical resources are shared among multiple customers using virtualization, not the elasticity to scale resources on demand.

567
MCQmedium

A cloud security architect is designing a data retention strategy for a SaaS application hosted on a public cloud. The application stores user-generated content in a multi-tenant database. Regulatory requirements mandate that user data be permanently deleted upon request within 30 days. The architect needs to ensure that backups and replicas also honor the deletion. Which approach BEST ensures compliance with the deletion requirement?

A.Use a database that supports per-user encryption keys and crypto-shredding by deleting the keys upon user request.
B.Implement soft delete by marking records as deleted and filtering them out in the application, while retaining them in the database for audit purposes.
C.Configure the database to automatically purge records older than 30 days using a time-to-live (TTL) setting.
D.Schedule a nightly job that runs a DELETE SQL statement to remove user records from the primary database and all replicas.
AnswerA

Crypto-shredding involves encrypting each user's data with a unique key and then deleting the key when deletion is requested. This renders the data irrecoverable, even in backups and replicas, because the ciphertext cannot be decrypted. It effectively achieves permanent deletion without having to locate and erase every copy. This is a robust method for complying with deletion requirements in distributed systems.

Why this answer

Crypto-shredding is the most effective way to ensure permanent deletion in a multi-tenant cloud environment with backups and replicas. By encrypting each user's data with a unique key and deleting the key, the data becomes irrecoverable everywhere it exists, including backups. This satisfies the 30-day deletion requirement without needing to track and erase every copy, which is impractical in distributed systems with immutable backups.

Other methods leave data remnants in backups or fail to permanently erase data.

Exam trap

The trap here is assuming that deleting records from the primary database and replicas is sufficient, when backups and immutable storage often retain data beyond the deletion window.

568
MCQhard

An organization has a cloud environment with many accounts. They want to prevent any account from using certain services that are not approved (e.g., outside of a defined list). What is the BEST way to enforce this at the organizational level?

A.Configure each account's access control policy to deny the services.
B.Enable a cloud configuration monitoring service to detect and disable non-approved services.
C.Apply a cloud governance policy at the organization level that denies the services.
D.Use resource-specific access policies on each resource to restrict usage.
AnswerC

An organisation-level governance policy applies a deny rule across every account, blocking unapproved services regardless of individual account configuration. This satisfies the requirement to enforce the approved-service list centrally, rather than relying on per-account controls that could be bypassed or missed.

Why this answer

Cloud governance policies at the organization level are the correct mechanism because they operate across all accounts, allowing centrally defined whitelists or blacklists of services. Unlike account-level access control policies, organizational policies set a permissions boundary that cannot be overridden by account administrators, ensuring that non-approved services are denied across the entire organization. This provides a preventive control that blocks the use of prohibited services before any action can occur.

Exam trap

The trap here is that candidates confuse detective controls (like configuration monitoring) with preventive controls (like organizational governance policies), or assume that account-level access control policies can achieve the same centralized enforcement, missing the fact that organizational policies are the only mechanism that cannot be bypassed by account-level administrators.

How to eliminate wrong answers

Option A is wrong because configuring each account's IAM policy individually is not an organizational-level enforcement; it is decentralized, error-prone, and can be overridden by account administrators with full IAM permissions. Option B is wrong because AWS Config rules are detective controls that can only detect and report non-compliant resources, not prevent their creation or usage; they cannot disable services in real time. Option D is wrong because resource-based policies are attached to individual resources (e.g., S3 buckets, KMS keys) and cannot restrict the use of entire services or apply at the organizational level across all accounts.

569
MCQmedium

A multinational corporation is using a cloud-based data warehouse to analyze customer data. The data includes personally identifiable information (PII) from various countries. The security team needs to ensure that data is anonymized before analysis to comply with privacy regulations. Which technique should they use?

A.Tokenization
B.Data masking
C.Encryption with customer-managed keys
D.Generalization and suppression
AnswerD

Generalization replaces specific values with broader categories, and suppression removes certain data fields. These techniques are core to anonymization frameworks like k-anonymity, making it difficult to re-identify individuals. They align with privacy regulations that require anonymization for data analysis.

Why this answer

Generalization and suppression are anonymization techniques that reduce data granularity and remove identifiers, making re-identification difficult. Tokenization and masking are reversible or not fully anonymizing, and encryption does not anonymize. These techniques help comply with privacy regulations by ensuring data cannot be linked to individuals.

Exam trap

The trap here is equating de-identification techniques like masking or tokenization with true anonymization, which requires irreversibility.

570
Multi-Selectmedium

A cloud security team is implementing a data discovery and classification program for their SaaS applications. Which TWO statements accurately describe best practices for data classification in the cloud?

Select 2 answers
A.Manual classification by users is more accurate than automated methods in large-scale cloud environments.
B.Tokenization can replace data classification by eliminating the need to identify sensitive data.
C.Automated tools can scan cloud storage and apply classification labels based on content inspection.
D.Data loss prevention (DLP) policies can enforce classification by monitoring and controlling data in motion and at rest.
E.Data classification labels must be applied by the cloud service provider to ensure consistency.
AnswersC, D

Automated scanning satisfies the discovery requirement by inspecting object content and metadata across SaaS storage, then applying labels consistently at scale. This removes the manual effort and inconsistency that make human-only classification impractical for large cloud data volumes.

Why this answer

Option C is correct because automated discovery tools (such as CASB or native cloud DLP scanners) can crawl SaaS storage, inspect content using pattern matching, regex, keywords, and ML classifiers, and then apply classification labels (e.g., Public, Confidential, PII) at scale, which is essential in large cloud environments where manual labeling is impractical. Option D is correct because DLP policies consume classification labels and content inspection results to monitor and control data in motion (email, uploads, API traffic) and at rest (SaaS repositories), enforcing rules such as blocking exfiltration of labeled sensitive data, thereby operationalizing the classification scheme. Option A is not correct because manual user classification is inconsistent, error-prone, and unscalable in large cloud environments, so automated methods are preferred.

Option B is not correct because tokenization is a data protection technique that substitutes sensitive values with tokens; it still requires identifying and classifying the sensitive data first, so it cannot replace classification. Option E is not correct because classification labels are typically applied by the data owner or via automated tools under the organization's governance, not by the cloud service provider, since the provider does not know the business context or sensitivity of the customer's data.

Exam trap

CCSP often tests the misconception that the cloud provider is responsible for classifying customer data, when in fact classification is a customer responsibility, and that tokenization alone can replace classification, which is false.

571
MCQmedium

A company is designing a data retention policy for cloud storage. Regulatory requirements mandate that certain records be kept for 7 years and then securely destroyed. Which combination of controls should be used?

A.Lifecycle policy and secure deletion
B.Data masking and encryption
C.Versioning and MFA delete
D.Lifecycle policy and object lock
AnswerA

A lifecycle policy automates the 7-year retention window, transitioning or expiring objects on schedule without manual intervention. Secure deletion then cryptographically erases the data, satisfying the mandated destruction requirement. Together they enforce both constraints — duration and secure disposal — directly within the cloud storage platform.

Why this answer

A lifecycle policy automates the transition and expiration of objects, allowing you to set a rule to delete objects after 7 years. Secure deletion (e.g., overwriting or cryptographic erasure) ensures the data is irrecoverable, meeting the regulatory requirement for secure destruction. Together, they provide a fully automated, auditable process for retention and destruction.

Exam trap

ISC2 often tests the distinction between 'preventing deletion' (object lock) and 'ensuring secure destruction' (secure deletion), leading candidates to choose object lock because it sounds like it handles retention, but it does not guarantee irrecoverable deletion after the retention period ends.

How to eliminate wrong answers

Option B is wrong because data masking and encryption protect data at rest or in use but do not automate deletion or ensure secure destruction after a retention period. Option C is wrong because versioning preserves multiple versions of an object, which could prevent complete deletion, and MFA delete only adds an extra authentication step to deletion operations, not secure destruction. Option D is wrong because object lock enforces a write-once-read-many (WORM) model that prevents deletion or modification during a retention period, but it does not provide secure deletion (e.g., overwriting or cryptographic erasure) after the lock expires; it only allows normal deletion, which may leave recoverable data.

572
MCQmedium

A security team is implementing a web application firewall (WAF) for a cloud-based e-commerce application. The application is built on a microservices architecture and uses a RESTful API. Which of the following is the PRIMARY reason to deploy the WAF at the API gateway level rather than at the individual service level?

A.To provide centralized protection against common web exploits before traffic reaches the microservices.
B.To reduce latency by caching responses at the API gateway.
C.To offload authentication from the microservices to the API gateway.
D.To monitor API usage and detect anomalies in traffic patterns.
AnswerA

Placing the WAF at the API gateway filters malicious traffic once, before it is routed to any microservice, giving centralised coverage of common exploits such as SQL injection and cross-site scripting. This satisfies the microservices constraint, avoiding duplicated per-service rule management.

Why this answer

Deploying the WAF at the API gateway provides a centralized security enforcement point that inspects and filters all incoming HTTP/HTTPS traffic before it is routed to any individual microservice. This ensures that common web exploits—such as SQL injection, cross-site scripting (XSS), and OWASP Top 10 attacks—are blocked at the perimeter, reducing the attack surface and preventing malicious payloads from ever reaching the internal services. It also simplifies policy management and avoids the need to configure and maintain separate WAF instances for each microservice, which would introduce operational complexity and potential gaps in coverage.

Exam trap

The trap here is that candidates confuse the WAF's primary security purpose (centralized exploit prevention) with other common API gateway features like caching, authentication offloading, or traffic monitoring, leading them to select a technically valid but non-primary reason for WAF placement.

How to eliminate wrong answers

Option B is wrong because caching responses at the API gateway is a performance optimization, not a primary security reason for deploying a WAF; WAFs do not inherently cache responses, and caching is typically handled by a separate reverse proxy or CDN. Option C is wrong because offloading authentication to the API gateway is an identity and access management function, not a WAF function; while an API gateway can handle authentication, a WAF's primary role is to inspect and filter traffic for malicious content, not to authenticate users. Option D is wrong because monitoring API usage and detecting anomalies in traffic patterns is typically the responsibility of an API management platform or a dedicated security analytics tool, not the core function of a WAF; a WAF focuses on blocking known attack signatures and behavioral anomalies, but its primary deployment reason is centralized threat protection, not monitoring alone.

573
Multi-Selectmedium

Which THREE of the following are recommended practices for securing cloud application APIs? (Select three.)

Select 3 answers
A.Validate and sanitize all user inputs
B.Expose all API endpoints automatically for transparency
C.Allow mass assignment for ease of development
D.Implement rate limiting to prevent abuse
E.Apply least privilege to API keys and roles
AnswersA, D, E

Input validation prevents injection attacks.

Why this answer

Option A is correct because validating and sanitizing all user inputs defends against injection attacks (SQLi, XSS, command injection) and malformed payloads that could compromise the API or its backend data stores. Option D is correct because rate limiting (e.g., token-bucket or fixed-window throttling at the API gateway) mitigates brute-force, credential-stuffing, and denial-of-service abuse by capping request volume per client, key, or IP. Option E is correct because applying least privilege to API keys and roles ensures each key or IAM role only grants the minimum scopes and permissions needed, limiting blast radius if credentials are leaked.

Option B is wrong because automatically exposing every endpoint increases attack surface and can reveal undocumented or internal APIs; endpoints should be explicitly published and protected. Option C is wrong because mass assignment lets clients bind arbitrary fields to backend objects, enabling privilege escalation or data tampering; allowlists of assignable fields should be enforced instead.

Exam trap

CCSP often tests the misconception that 'transparency' or 'developer convenience' justifies exposing endpoints or allowing flexible object binding, when both directly contradict least privilege and input validation principles.

574
MCQmedium

A multinational corporation operates across multiple cloud providers (AWS, Azure, GCP) and uses a variety of data storage services. They have a requirement to enforce a consistent encryption policy across all providers: all data at rest must be encrypted using a centrally managed key that is rotated every 90 days. The cloud security team is evaluating different key management solutions. They want to minimize operational overhead and avoid vendor lock-in. The team has experience with configuring cloud-native key management services (KMS) but is concerned about managing keys across different regions and providers. Which solution best meets the requirements?

A.Deploy a third-party cloud-agnostic key management solution that supports BYOK and integrates with all providers' KMS
B.Use each cloud provider's native KMS and create identical key policies manually
C.Store the key in an internal secrets manager and configure each provider's KMS to use that key as a root key
D.Implement client-side encryption using a single master key stored in the application configuration
AnswerA

Centralized policy management, consistent enforcement, and reduces vendor lock-in.

Why this answer

A third-party cloud-agnostic key management solution (e.g., HashiCorp Vault, Thales CipherTrust) that supports Bring Your Own Key (BYOK) allows the organization to centrally manage and rotate a single root key every 90 days, while integrating with each provider's native KMS via external key stores (e.g., AWS KMS custom key store, Azure Key Vault managed HSM, GCP Cloud HSM). This minimizes operational overhead by avoiding manual per-provider policy replication and prevents vendor lock-in by decoupling key management from any single cloud provider's proprietary KMS.

Exam trap

ISC2 often tests the misconception that cloud-native KMS services can be centrally managed by simply replicating policies or using an internal secrets manager as a root key, but the trap is that cloud KMS does not allow external key material to be used as a root key for automatic rotation across providers—only a third-party agnostic solution with BYOK can enforce consistent, centrally controlled rotation.

How to eliminate wrong answers

Option B is wrong because manually creating identical key policies across AWS, Azure, and GCP KMS does not centralize key management; each provider's KMS would still use its own independent key material, making consistent rotation every 90 days operationally complex and error-prone. Option C is wrong because storing the key in an internal secrets manager and configuring each provider's KMS to use that key as a root key is technically infeasible—cloud-native KMS services do not accept external keys as root keys; they require keys to be imported as customer-managed keys (CMKs) but still manage them independently, and the secrets manager cannot enforce rotation across all providers' KMS. Option D is wrong because client-side encryption using a single master key stored in application configuration violates the requirement for centrally managed key rotation (the key would be static in config files) and introduces significant security risks, such as key exposure in code repositories or configuration management systems.

575
MCQmedium

A security team needs to implement automated remediation for non-compliant resources in a cloud environment. They want to automatically fix public object storage bucket policies. Which combination of services should be used?

A.Audit logging service and serverless compute function
B.Threat detection service and workflow orchestration service
C.Security hub and vulnerability management service
D.Configuration management service and serverless compute function
AnswerD

A configuration management service continuously evaluates resource configuration against policy and detects non-compliant public bucket policies, then invokes a serverless function to remediate them automatically. This pairing satisfies the requirement for automated, event-driven correction without manual intervention.

Why this answer

Automated remediation of non-compliant resources requires a configuration management service to detect and evaluate compliance (e.g., AWS Config rules) and a serverless compute function (e.g., AWS Lambda) to execute the remediation action, such as modifying a public S3 bucket policy. This combination enables event-driven, automatic correction without manual intervention.

Exam trap

The trap here is confusing detection services (GuardDuty, Security Hub) with remediation services; CCSP candidates must recognize that automated remediation requires both a compliance evaluation engine and an execution mechanism, not just monitoring or alerting.

How to eliminate wrong answers

Option A is wrong because audit logging (e.g., CloudTrail) records API activity but does not evaluate resource compliance or trigger remediation logic. Option B is wrong because threat detection (e.g., GuardDuty) identifies malicious activity, not configuration drift, and workflow orchestration alone lacks the compliance evaluation engine. Option C is wrong because a security hub aggregates findings and vulnerability management scans for weaknesses, but neither automatically remediates bucket policies.

576
MCQeasy

A DevOps team is building a container image for a cloud-native application. To minimize the attack surface and reduce the number of vulnerabilities, which type of base image should they use?

A.A full distribution image like Ubuntu
B.An Alpine-based image
C.A distroless image
D.The 'latest' tag of any official image
AnswerC

A distroless image contains only the application and its runtime dependencies, omitting package managers, shells and other OS utilities. This directly minimises the attack surface and vulnerability count, satisfying the stem's requirement to reduce exploitable components in the container image.

Why this answer

Distroless images contain only the application and its runtime dependencies — no package manager, shell, or OS utilities — which dramatically reduces the attack surface and the number of exploitable CVEs. Because there is no shell or package manager, attackers who gain code execution have far fewer tools to pivot or escalate with. This makes distroless the strongest choice when the explicit goal is minimizing vulnerabilities in a container image.

Exam trap

The trap here is assuming 'smaller image = fewer vulnerabilities' and picking Alpine, when the exam is specifically testing that distroless removes even the shell and package manager, which Alpine retains.

How to eliminate wrong answers

Option A is wrong because a full distribution image like Ubuntu ships hundreds of packages (apt, bash, coreutils, systemd components) that are not needed at runtime and each contributes CVEs and attack surface. Option B is wrong because Alpine, while small, still includes a shell (BusyBox ash), a package manager (apk), and musl libc, so it retains more attack surface than distroless and has historically had its own CVE stream. Option D is wrong because the 'latest' tag is a mutable pointer that provides no version pinning or reproducibility, and official images are typically full distributions — it maximizes both supply-chain risk and vulnerability count rather than minimizing them.

577
MCQmedium

A cloud architect is designing a data retention solution for a SaaS application hosted with a cloud provider. The organization must ensure that customer data is irretrievably destroyed at the end of its retention period, even though the data is stored in a multi-tenant object storage service with underlying solid-state drives. Which approach best satisfies this requirement?

A.Issue a delete command to the object storage API and rely on the provider's background garbage collection to erase the data blocks.
B.Overwrite the objects with random data before deleting them, then request a certificate of media destruction from the provider.
C.Use crypto-shredding: encrypt each customer's data with a unique data encryption key and destroy the key when retention expires.
D.Move the data to an infrequent access storage tier and configure a lifecycle policy to expire it after the retention period.
AnswerC

Crypto-shredding renders data unrecoverable by deleting the encryption key. In a multi-tenant cloud object store, physical destruction of specific data is not feasible, but destroying the unique key makes the ciphertext useless. This meets the irretrievable destruction requirement without relying on provider media sanitization.

Why this answer

Crypto-shredding is the most reliable method for irretrievable destruction in multi-tenant cloud storage because it makes data unreadable by destroying the key. Physical destruction or overwriting is impractical when the provider controls the media and may keep replicas. Destroying a unique key per customer ensures that even residual ciphertext cannot be decrypted.

Exam trap

The trap here is assuming that a standard delete operation or lifecycle expiration physically erases data from cloud storage media.

578
MCQmedium

A cloud security analyst is reviewing data flows for a web application that stores session tokens in a cloud database. The tokens are considered sensitive and must be protected both at rest and in transit. The database supports encryption at rest using provider-managed keys, and the application connects over a private network link. Which additional control best protects the session tokens from being exposed in the event of a database snapshot being copied to another region?

A.Restrict snapshot sharing to the same region using a bucket policy that denies cross-region replication.
B.Configure the application to hash session tokens before storing them so the database never contains the original token values.
C.Enable database audit logging to record every query that accesses the session token table and alert on unusual access patterns.
D.Enable customer-managed keys for the database encryption so snapshots copied to another region remain encrypted under keys the organization controls.
AnswerD

Customer-managed keys ensure that snapshots retain encryption tied to the organization's key policy, so a copied snapshot cannot be decrypted without access to those keys. This protects the session tokens even if the snapshot leaves the original region. Provider-managed keys may still protect the snapshot, but the organization has less control over access and revocation.

Why this answer

Customer-managed keys are the best additional control because they keep snapshot encryption under the organization's key policy, so a snapshot copied to another region remains unreadable without those keys. Audit logging, hashing, and bucket policies either detect rather than prevent, break application functionality, or can be bypassed by privileged actions.

Exam trap

The trap here is assuming that provider-managed encryption or a regional policy is sufficient, when the scenario requires that a copied snapshot remain protected under keys the organization can control and revoke.

579
Multi-Selecteasy

Which TWO of the following are essential characteristics of cloud computing as defined by NIST SP 800-145?

Select 2 answers
A.Measured service
B.Multitenancy
C.Virtualization
D.Auditability
E.Resource pooling
AnswersA, E

Measured service is one of the five essential characteristics in NIST SP 800-145: resource usage is monitored, controlled and reported, providing transparency for both provider and consumer. Metering underpins the pay-per-use billing model that distinguishes cloud from traditional hosting.

Why this answer

NIST SP 800-145 defines five essential characteristics of cloud computing, and 'Measured service' (A) is one of them: cloud systems automatically control and optimize resource use via metering capabilities, providing transparency for both provider and consumer. 'Resource pooling' (E) is also an essential characteristic, where the provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with resources dynamically assigned and reassigned according to demand. Multitenancy (B) is a consequence of resource pooling but is not itself listed as a separate essential characteristic in NIST SP 800-145. Virtualization (C) is a common enabling technology for cloud computing but is not one of the five NIST essential characteristics.

Auditability (D) is a desirable governance property but is not included in the NIST definition of essential cloud characteristics.

Exam trap

CCSP often tests the distinction between NIST's five essential characteristics and commonly associated but non-listed concepts like multitenancy and virtualization, which candidates mistakenly select because they are ubiquitous in cloud implementations.

580
MCQhard

A multi-tier web application is deployed across two VPCs connected via VPC peering. The web tier in VPC A must communicate with the database tier in VPC B on port 3306. Security groups are used for instance-level security. Which security group configuration is MOST secure?

A.In the database security group, add an inbound rule allowing TCP/3306 from the security group ID of the web servers.
B.Configure a VPN connection between VPCs and use route tables to direct traffic.
C.In the network ACL for VPC B's subnet, add an inbound rule allowing TCP/3306 from VPC A CIDR.
D.In the database security group, add an inbound rule allowing TCP/3306 from the VPC A CIDR.
AnswerA

Referencing the web tier's security group ID as the source restricts inbound TCP/3306 to instances carrying that group, rather than opening the port to a CIDR range. This is the most secure option because membership is enforced at the instance level, even across peered VPCs.

Why this answer

Option A is correct because referencing the web tier's security group ID as the source in the database security group's inbound rule creates a dynamic, identity-based trust relationship. Only instances that are members of that specific security group can initiate connections to port 3306, regardless of their IP addresses. This follows the principle of least privilege and is the most secure, maintainable approach in AWS VPC peering scenarios.

Exam trap

CCSP often tests the misconception that CIDR-based rules are equivalent to security group referencing, but the exam expects you to recognize that security group referencing is more secure and granular for instance-level access control.

How to eliminate wrong answers

Option B is wrong because a VPN connection is unnecessary for VPC peering and does not provide security group-level granularity; it also adds complexity and cost without addressing the specific requirement. Option C is wrong because network ACLs are stateless and subnet-level, not instance-level; allowing the entire VPC A CIDR on port 3306 would permit any host in VPC A, violating least privilege. Option D is wrong because allowing the entire VPC A CIDR in the database security group is overly permissive—any instance in VPC A, not just the web tier, could access the database.

581
MCQmedium

A cloud application allows users to upload profile pictures that are stored in Azure Blob Storage. Which vulnerability is most likely if the application does not validate the content type or size of uploaded files?

A.Unrestricted File Upload
B.Server-Side Request Forgery (SSRF)
C.Mass Assignment
D.Broken Object Level Authorization (BOLA)
AnswerA

Without content-type or size validation, attackers upload executable scripts, web shells or oversized files, which may be served or processed by the application. Unrestricted File Upload is the specific vulnerability class covering this missing input validation on Azure Blob Storage uploads.

Why this answer

Without validation, an attacker could upload a malicious file (e.g., a web shell) that could be executed on the server, leading to remote code execution.

582
Multi-Selectmedium

A security team is enhancing logging in AWS to capture detailed data events for S3 buckets. Which TWO of the following should be enabled to achieve comprehensive monitoring of S3 data access? (Choose two.)

Select 2 answers
A.S3 server access logs
B.AWS CloudTrail data events for S3
C.AWS Config
D.VPC Flow Logs
E.Amazon GuardDuty
AnswersA, B

S3 server access logs record every request made to a bucket, including the requester, action, timestamp and response code, giving object-level audit detail. They capture data-plane access that bucket-level logging misses, satisfying the requirement for comprehensive S3 data access monitoring.

Why this answer

S3 server access logs (option A) are correct because they record detailed, bucket-level access requests to S3, including the requester, bucket name, request time, request action, response status, and error code, providing granular visibility into object-level data access. AWS CloudTrail data events for S3 (option B) are also correct because they capture object-level API activity such as GetObject, PutObject, and DeleteObject, which are not recorded by CloudTrail management events, thereby delivering comprehensive monitoring of S3 data access. AWS Config (option C) is not correct because it evaluates and records resource configuration changes and compliance, not individual S3 data access requests.

VPC Flow Logs (option D) is not correct because it captures IP traffic metadata for network interfaces in a VPC, not S3 object-level API operations. Amazon GuardDuty (option E) is not correct because it is a threat detection service that analyzes logs and findings, but it does not itself enable the detailed S3 data event logging required here.

Exam trap

A common pitfall is confusing AWS Config (which monitors configuration changes) with data access logging capabilities. Candidates often incorrectly select AWS Config for monitoring S3 data access because it records resource configurations, but it does not capture individual data access events. The correct choices for comprehensive data access monitoring are S3 server access logs and CloudTrail data events for S3.

583
MCQmedium

A cloud customer wants to ensure that their data is not accessible to the cloud provider's employees. Which of the following controls would best address this requirement?

A.Enable detailed audit logging of all data access.
B.Implement strict IAM policies for CSP employees.
C.Encrypt data client-side before uploading to the cloud.
D.Enable server-side encryption with customer-provided keys.
AnswerC

Client-side encryption ensures data is encrypted before it leaves the customer's control, so the provider stores only ciphertext. Since the customer retains the keys, provider employees cannot decrypt the data, directly satisfying the requirement that provider staff cannot access it.

Why this answer

Client-side encryption ensures that data is encrypted before it leaves the customer's environment, so the cloud provider never has access to the plaintext or the encryption keys. This means that even if a cloud provider employee gains administrative access to the storage infrastructure, they can only retrieve ciphertext, which is useless without the customer-held keys. This control directly addresses the requirement of preventing the provider's employees from accessing the data.

Exam trap

ISC2 often tests the distinction between client-side encryption and server-side encryption with customer-provided keys (SSE-C), where candidates mistakenly think SSE-C gives the customer full control over key access, but the provider's server still handles the plaintext during encryption/decryption.

How to eliminate wrong answers

Option A is wrong because audit logging only records who accessed data and when, but does not prevent access by cloud provider employees. Option B is wrong because IAM policies for CSP employees are managed by the provider, not the customer, and the customer cannot enforce or verify those policies to guarantee data inaccessibility. Option D is wrong because server-side encryption with customer-provided keys (SSE-C) still involves the cloud provider's server performing the encryption/decryption, meaning the plaintext is exposed to the provider's infrastructure during processing, and the provider's employees could potentially access the data if they have administrative privileges to the key management or storage systems.

584
MCQmedium

A financial services company is migrating to the cloud and must retain transaction records for seven years for regulatory compliance. They plan to use object storage with lifecycle policies. What is the most secure configuration for long-term data retention?

A.Configure a lifecycle policy to transition to archive storage after seven years
B.Enable object retention with compliance mode (immutable and cannot be overridden by any user)
C.Store objects using a write-once-read-many (WORM) storage class
D.Use server-side encryption with a customer-managed key
AnswerB

Compliance-mode object retention enforces WORM immutability at the storage layer, so no user — including administrators — can overwrite or delete transaction records before the seven-year regulatory period expires. This satisfies the stem's retention constraint directly, unlike governance mode, which privileged users can bypass.

Why this answer

Retention lock with compliance mode provides the strongest guarantee against data modification or deletion, even by root users. This mode ensures that once an object is written, it cannot be overwritten or deleted until the retention period expires, which is critical for meeting the seven-year regulatory retention requirement. Unlike other options, compliance mode enforces a legal hold that cannot be removed by any user, including cloud administrators, making it the most secure configuration for immutable long-term retention.

Exam trap

ISC2 often tests the distinction between data protection mechanisms (encryption, lifecycle policies) and data immutability (retention lock with compliance mode), leading candidates to choose encryption or archive transitions as sufficient for retention requirements.

How to eliminate wrong answers

Option A is wrong because transitioning to archive storage after seven years does not prevent deletion or modification during the retention period; lifecycle policies only move data between tiers but do not enforce immutability, so records could be altered or deleted before the seven-year mark. Option C is wrong because while WORM storage classes (e.g., S3 Glacier Instant Retrieval with Object Lock) can provide immutability, the term 'WORM storage class' is ambiguous and not a specific service; the correct implementation requires Object Lock with a retention mode, not just a storage class. Option D is wrong because server-side encryption with KMS key protects data at rest and in transit but does not prevent deletion or overwriting of objects; encryption alone does not enforce retention or immutability, so records could still be deleted before seven years.

585
Multi-Selectmedium

A security team is implementing container image scanning in a CI pipeline. Which TWO of the following actions should be performed? (Select TWO)

Select 2 answers
A.Disable scanning to speed up the pipeline
B.Scan the image before pushing to the registry
C.Scan the image after deployment to production
D.Sign the image to ensure integrity
E.Scan the image only if it is based on a public base image
AnswersB, D

Scanning before the push stops vulnerable layers from ever reaching the registry, satisfying the pipeline gate constraint. Once an image is pushed, downstream consumers can pull it immediately, so remediation becomes reactive. Early scanning also blocks the build from proceeding, preventing propagation of known CVEs into production.

Why this answer

Option B is correct because scanning the container image before pushing it to the registry ensures that vulnerabilities are detected and remediated prior to the image being stored or distributed, preventing flawed images from entering the supply chain. Option D is correct because signing the image (e.g., using Docker Content Trust or Sigstore) ensures integrity and authenticity, verifying that the image has not been tampered with and originates from a trusted source. Option A is incorrect because disabling scanning removes a critical security control and exposes the pipeline to known vulnerabilities.

Option C is incorrect because scanning after deployment to production is too late—vulnerable images would already be running in a live environment. Option E is incorrect because scanning should apply to all images regardless of their base image origin, as vulnerabilities can exist in any layer or dependency.

Exam trap

CCSP often tests the misconception that scanning after deployment is sufficient, but security should be shifted left in the CI/CD pipeline.

586
MCQmedium

A DevSecOps team runs workloads on a managed Kubernetes service. The security policy states that no pod may run as the root user, that containers must not mount the host filesystem, and that privilege escalation must be blocked. The team wants a control that evaluates pod specifications at admission time and rejects non-compliant pods before they are scheduled, without modifying application code. Which mechanism should the team implement?

A.A runtime security agent that scans running containers and sends alerts when it detects root processes
B.A PodSecurityPolicy object bound to the service account used by the workloads
C.A validating admission webhook or a Pod Security Admission configuration with the restricted profile enforced
D.A network policy that denies ingress to the pods from all namespaces except the application namespace
AnswerC

Pod Security Admission is the built-in successor to PodSecurityPolicy and enforces the restricted profile, which requires non-root execution, disallows host filesystem mounts, and blocks privilege escalation. A validating admission webhook can enforce custom policies with greater flexibility. Both evaluate pod specifications at admission time and reject non-compliant pods before scheduling, without requiring application code changes.

Why this answer

The requirement is admission-time rejection of pods that run as root, mount the host filesystem, or allow privilege escalation. Pod Security Admission with the restricted profile, or a validating admission webhook, evaluates pod specifications before scheduling and rejects non-compliant pods without code changes. Network policies and runtime agents address different layers and cannot prevent the pods from being admitted.

Exam trap

The trap here is selecting PodSecurityPolicy, which is removed in current Kubernetes, or a runtime tool, which detects rather than prevents non-compliant pods.

587
MCQeasy

A cloud security team wants to integrate security testing early in the development lifecycle to reduce vulnerabilities. Which approach best describes this concept?

A.Runtime application self-protection (RASP)
B.Software bill of materials (SBOM)
C.Web application firewall (WAF)
D.Shift-left security
AnswerD

Shift-left security moves testing and threat modelling into earlier lifecycle phases, so defects are caught during design and coding rather than after deployment. This directly satisfies the team's goal of integrating security testing early to reduce vulnerabilities, lowering remediation cost and exposure.

Why this answer

Shift-left security is the practice of integrating security testing and controls early in the software development lifecycle (SDLC), such as during design and coding phases, rather than waiting until deployment. This proactive approach reduces vulnerabilities by catching flaws when they are cheaper and easier to fix, aligning with DevSecOps principles.

Exam trap

ISC2 often tests the distinction between runtime controls (RASP, WAF) and lifecycle integration practices (shift-left), so candidates mistakenly choose a runtime tool because they associate 'security testing' with active monitoring rather than early development phases.

How to eliminate wrong answers

Option A is wrong because Runtime Application Self-Protection (RASP) is a runtime security technology that monitors and blocks attacks from within the application during execution, not an early lifecycle integration approach. Option B is wrong because a Software Bill of Materials (SBOM) is a formal inventory of software components and dependencies, used for supply chain risk management and vulnerability tracking, not for shifting security left in the development process. Option C is wrong because a Web Application Firewall (WAF) is a network-level security control that filters HTTP traffic to protect applications in production, operating at runtime rather than early in the SDLC.

588
MCQeasy

A cloud customer is reviewing its incident response plan and wants to ensure it can meet regulatory breach notification timelines. The customer's data is hosted by a cloud provider that does not automatically notify customers of security incidents. Which action should the customer take FIRST to address this gap?

A.Include a contractual clause requiring the provider to notify the customer of security incidents within a specified timeframe.
B.Purchase cyber insurance to cover the costs of a breach notification and any regulatory fines.
C.Deploy a third-party vulnerability scanner to continuously monitor the provider's infrastructure for signs of compromise.
D.Rely on the provider's public status dashboard and security blog to learn about incidents affecting the customer's data.
AnswerA

Regulatory breach notification timelines often start when the customer becomes aware of an incident. A contract clause that obligates the provider to notify the customer within a defined period ensures the customer receives timely information and can start its own assessment and notification process. This directly closes the gap.

Why this answer

The customer cannot meet regulatory breach notification deadlines if it learns about a provider-side incident too late. A contractual notification clause with a defined timeframe creates an enforceable obligation and ensures the customer receives timely information to begin its own incident assessment and notification process. This is the foundational step before technical monitoring or insurance can be effective.

Exam trap

The trap here is assuming that public status pages, monitoring tools, or insurance can substitute for a contractual notification requirement from the provider.

589
MCQeasy

A cloud application uses a RESTful API that handles payment transactions. The security team identifies that the API is vulnerable to brute-force attacks on the authentication endpoint. Which control should be implemented to mitigate this?

A.Implement rate limiting on the authentication endpoint
B.Require API keys for all requests
C.Use TLS to encrypt the communication channel
D.Add input validation for all parameters
AnswerA

Rate limiting caps the number of authentication attempts from a given source within a time window, throttling the repeated credential guesses that define brute-force attacks. This directly addresses the stem's identified vulnerability on the authentication endpoint.

Why this answer

Rate limiting restricts the number of authentication requests from a single source within a given time window, directly mitigating brute-force attacks by making it infeasible to guess credentials at high speed. This control is specifically designed for authentication endpoints where repeated failed attempts are the primary attack vector, and it is a standard recommendation in OWASP and NIST guidelines for API security.

Exam trap

ISC2 often tests the distinction between authentication-specific controls (rate limiting) and general security measures (encryption, input validation), leading candidates to choose TLS or API keys because they are commonly associated with API security but do not address brute-force frequency.

How to eliminate wrong answers

Option B is wrong because API keys authenticate the client application, not the user, and do not prevent an attacker from repeatedly trying different passwords or tokens against the authentication endpoint. Option C is wrong because TLS encrypts data in transit to prevent eavesdropping and tampering, but it does not limit the number of requests an attacker can send, leaving the endpoint vulnerable to brute-force attempts. Option D is wrong because input validation prevents injection attacks (e.g., SQLi, XSS) but does not restrict the frequency of requests, so an attacker can still submit unlimited login attempts with valid parameter formats.

590
MCQhard

A healthcare organization recently migrated a patient records management application from on-premises infrastructure to a cloud environment using Infrastructure as a Service (IaaS). The application was originally designed as a monolithic workload running on bare-metal servers. After migration, the application is deployed on a fleet of virtual machines (VMs) of the same instance type. The organization is using a combination of Reserved Instances for baseline capacity and On-Demand instances to handle spikes. However, two months after the migration, the cloud bill is 40% higher than the estimated on-premises total cost of ownership. Additionally, performance reports indicate that the application experiences inconsistent latency and occasional timeouts during peak hours. The operations team has confirmed that the application code has not changed, and the cloud provider's infrastructure is healthy. There is no issue with network bandwidth or storage I/O. The team is considering several options to address both cost and performance issues. What should the team do first?

A.Migrate the application to serverless compute to eliminate the need to manage VMs.
B.Perform a rightsizing analysis of the current VM usage and adjust instance types accordingly.
C.Consolidate the workload into fewer, larger instances to reduce overhead and licensing costs.
D.Replace On-Demand instances with Spot Instances to reduce costs during spikes.
AnswerB

Rightsizing directly addresses the mismatch between the monolithic workload's actual resource consumption and the uniform instance type deployed. Because every VM uses the same specification, over-provisioned instances inflate Reserved Instance and On-Demand spend, while under-provisioned ones cause the latency and timeouts at peak. Matching instance types to measured CPU, memory and I/O demand resolves both the 40% cost overrun and the performance inconsistency.

Why this answer

The first step should be to perform a rightsizing analysis of the current VM usage. The application was migrated from bare-metal servers to VMs of the same instance type, which may not be optimal. Rightsizing identifies over-provisioned or under-provisioned resources, addressing both cost (by reducing waste) and performance (by ensuring adequate resources).

This is a foundational step before considering other optimizations.

Exam trap

CCSP often tests cloud migration optimization. The trap is jumping to advanced solutions like serverless or Spot Instances without first addressing fundamental resource allocation. Candidates may overlook that rightsizing is the most immediate and effective step to address both cost and performance issues.

How to eliminate wrong answers

Option A is wrong because migrating to serverless compute may require significant application refactoring and is not a quick fix; it also may not address the immediate cost and performance issues. Option C is wrong because consolidating into fewer, larger instances may not solve performance inconsistencies and could increase cost if not properly sized. Option D is wrong because replacing On-Demand with Spot Instances can reduce costs but Spot Instances can be terminated unexpectedly, potentially worsening performance and availability during spikes.

591
MCQmedium

A cloud customer wants to ensure that when the contract ends, the cloud provider deletes all customer data, including from backups. Which contractual clause is essential?

A.Right to audit clause
B.Data deletion clause
C.Data portability clause
D.Service Level Agreement
AnswerB

A data deletion clause contractually obliges the provider to erase all customer data, explicitly including backups, once the contract ends. Without it, residual copies may persist indefinitely, breaching the customer's data lifecycle and privacy obligations.

Why this answer

A data deletion clause is essential because it contractually obligates the cloud provider to securely erase all customer data—including replicas and backups—upon contract termination or at the customer's request. Without this clause, data may persist indefinitely in provider backups, snapshots, or archival storage, creating confidentiality and compliance exposure. CCSP emphasizes that the right to deletion must be explicitly negotiated, since default provider terms rarely guarantee backup purging.

Exam trap

CCSP often tests the distinction between contractual clauses that grant visibility (audit) or flexibility (portability) versus those that enforce data lifecycle termination (deletion), so candidates must map each clause to its actual legal obligation.

How to eliminate wrong answers

Option A is wrong because a right to audit clause grants the customer permission to inspect provider controls and processes, but it does not compel deletion of data at contract end. Option C is wrong because data portability addresses the customer's ability to retrieve or migrate their data in a usable format, not the provider's obligation to destroy it. Option D is wrong because an SLA defines availability, performance, and support commitments—not data lifecycle or destruction obligations.

592
MCQmedium

A healthcare organization runs a regulated workload on a public cloud. The security team must ensure that data stored in object storage remains unreadable to the cloud provider's staff even if they have physical access to the storage media. Which approach best meets this requirement?

A.Enable server-side encryption with provider-managed keys
B.Rely on transport-layer encryption using TLS for all uploads and downloads
C.Enable server-side encryption with customer-provided keys that the provider does not retain
D.Encrypt data client-side before upload and retain sole custody of the keys
AnswerD

Client-side encryption performed before the data leaves the customer's environment ensures the provider only ever receives ciphertext. Because the customer never shares the keys, provider personnel cannot decrypt the objects even with full physical access to storage media. This is the classic approach for meeting requirements that the cloud provider itself must be unable to read regulated data, and it directly satisfies the stated constraint.

Why this answer

When the requirement is that the cloud provider itself must be unable to read the data, the customer must control encryption end to end. Encrypting client-side before upload and keeping keys outside the provider's reach guarantees that only ciphertext ever reaches provider infrastructure. Server-side options, whether provider-managed or customer-provided per request, still involve provider systems handling keys or plaintext at some point.

Exam trap

The trap here is treating any server-side encryption option as equivalent to customer-controlled encryption, when only client-side encryption with customer-held keys removes the provider from the trust boundary.

593
MCQmedium

A security team is using AWS and wants to monitor for changes to security groups that could expose resources to the internet. They need to receive an alert when a security group rule is modified to allow inbound traffic from 0.0.0.0/0 on port 22. Which AWS service should they use to detect this change?

A.Amazon GuardDuty
B.AWS Trusted Advisor
C.AWS Config
D.AWS CloudTrail
AnswerC

AWS Config records changes to resource configurations, including security groups. You can create a custom rule or use a managed rule to evaluate security group configurations and trigger an alert when a rule allows inbound SSH from 0.0.0.0/0. AWS Config can also send notifications via Amazon SNS, enabling the security team to respond promptly.

Why this answer

AWS Config is designed to monitor resource configurations and evaluate them against desired settings. It can detect when a security group rule is changed to allow inbound SSH from 0.0.0.0/0 and trigger an alert. The other services either log API calls without evaluation, focus on threat detection, or provide periodic checks, making them less suitable for this specific requirement.

Exam trap

The trap here is assuming CloudTrail alone can detect insecure configurations, but it only records API activity without evaluating the resulting state.

594
MCQmedium

A cloud operations team runs a mission-critical application on Amazon EC2 instances behind an Application Load Balancer. The security policy requires that the instances be patched monthly, but the team wants to minimize downtime and avoid manual patching. They decide to use AWS Systems Manager Patch Manager. Which configuration should they implement to meet the patching requirement while maintaining availability?

A.Use AWS Config rules to automatically apply patches when a new CVE is published, and configure an SNS topic to notify the team.
B.Enable automatic OS updates on the EC2 instances by configuring the operating system's update service to run daily.
C.Create a patch baseline, a maintenance window that targets the instances, and a patch group that associates the instances with the baseline.
D.Create an Amazon EventBridge rule that triggers an AWS Lambda function to run yum update on each instance via AWS Systems Manager Run Command on a schedule.
AnswerC

This approach uses Patch Manager's core components: a patch baseline defines approved patches, a patch group links instances to the baseline, and a maintenance window schedules the patching during a defined period. It automates patching, reduces manual effort, and can be configured to patch one instance at a time or in batches, preserving availability.

Why this answer

Patch Manager simplifies patching by using patch baselines, patch groups, and maintenance windows. The baseline defines which patches are approved, the patch group associates instances with the baseline, and the maintenance window schedules the patching. This integrated approach automates patching, provides compliance visibility, and allows controlled rollout to maintain availability.

Exam trap

The trap here is assuming that AWS Config or EventBridge can directly apply patches, when they are monitoring and orchestration services, not patch deployment tools.

595
MCQhard

A cloud security architect is designing a CI/CD pipeline for a serverless application using AWS Lambda. The application processes sensitive user data and requires encryption at rest and in transit. Which of the following is the BEST approach to securely manage database credentials used by the Lambda function?

A.Store the credentials in AWS Systems Manager Parameter Store with a SecureString parameter.
B.Use AWS Secrets Manager to store the credentials and retrieve them at runtime with least-privilege IAM roles.
C.Store the credentials as encrypted environment variables in the Lambda function configuration.
D.Hardcode the credentials in the Lambda function code and encrypt the deployment package.
AnswerB

Secrets Manager stores credentials outside the function code and rotates them, while runtime retrieval via least-privilege IAM roles avoids hard-coded secrets. This satisfies the encryption and sensitive-data constraints without embedding credentials in Lambda environment variables or code.

Why this answer

AWS Secrets Manager is the best choice because it is purpose-built for securely storing, rotating, and retrieving secrets such as database credentials. It integrates natively with AWS Lambda via the Secrets Manager API, allowing the function to fetch credentials at runtime using a least-privilege IAM role. This approach avoids embedding secrets in code or configuration and supports automatic rotation, which is critical for compliance with encryption and access control requirements.

Exam trap

ISC2 often tests the distinction between AWS Systems Manager Parameter Store (for configuration) and AWS Secrets Manager (for secrets), trapping candidates who think encryption alone is sufficient without considering rotation and lifecycle management.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store with SecureString provides encryption but lacks native automatic rotation and fine-grained access control for secrets; it is designed for configuration data, not secrets management. Option C is wrong because encrypted environment variables are still stored in the Lambda configuration and can be exposed through logs, error messages, or the AWS Management Console; they also do not support rotation. Option D is wrong because hardcoding credentials in code, even with an encrypted deployment package, violates the principle of not embedding secrets in code and makes rotation impossible without redeployment; the encryption key management also adds unnecessary complexity.

596
Multi-Selectmedium

Which TWO practices help protect against insecure deserialization attacks in cloud applications?

Select 2 answers
A.Allow deserialization from untrusted sources
B.Use strong encryption for all serialized data
C.Implement custom deserialization without validation
D.Validate serialized objects before deserialization
E.Restrict deserialization to a whitelist of classes
AnswersD, E

Validating serialised objects before deserialisation rejects unexpected classes and malformed payloads, preventing gadget chains from executing during object reconstruction. This satisfies the stem's requirement for a practise that protects cloud applications against insecure deserialisation attacks.

Why this answer

Option D is correct because validating serialized objects before deserialization ensures that the data being processed matches expected types, structures, and values, which prevents attackers from injecting malicious payloads that exploit deserialization logic. Option E is correct because restricting deserialization to a whitelist of allowed classes ensures that only pre-approved, safe classes can be instantiated, blocking gadget-chain attacks that rely on unexpected or dangerous classes. Option A is incorrect because allowing deserialization from untrusted sources directly enables insecure deserialization attacks.

Option B is incorrect because strong encryption protects data confidentiality in transit or at rest but does not prevent malicious payloads from being deserialized after decryption. Option C is incorrect because implementing custom deserialization without validation removes the safety checks needed to reject malicious or unexpected objects.

Exam trap

ISC2 often tests the misconception that encryption alone (Option B) is sufficient to secure serialized data, but encryption only protects data at rest or in transit, not the deserialization process itself, which is where the attack occurs.

597
Multi-Selecteasy

Which TWO of the following are benefits of using tokenization for credit card data?

Select 2 answers
A.Maintains data format for existing systems
B.Reversible without a key vault
C.Reduces PCI DSS compliance scope
D.Eliminates the need for encryption
E.Slows down database queries
AnswersA, C

Tokenisation substitutes a surrogate value of identical length and character set for the card number, so downstream applications, databases and validation routines continue to accept it without schema or code changes. This satisfies the benefit of preserving the existing data format.

Why this answer

Tokenization replaces sensitive credit card data with a non-sensitive token that retains the same format (e.g., a 16-digit number) and length, allowing existing systems, databases, and applications to process the token without modification. This format-preserving property ensures that legacy systems, such as payment gateways or CRM platforms, can continue to operate without requiring costly re-engineering. By using a token instead of the actual PAN, the organization reduces the scope of PCI DSS compliance because the tokenized data is not considered cardholder data under the PCI DSS standard.

Exam trap

ISC2 often tests the misconception that tokenization eliminates the need for encryption entirely, but the correct understanding is that tokenization reduces PCI DSS scope while encryption (for the vault and transit) remains essential.

598
MCQhard

In a cloud environment using KVM, a security auditor wants to ensure that a tenant VM cannot access the memory of another tenant VM on the same physical host. Which resource isolation mechanism is specifically designed to prevent such memory access?

A.Seccomp profiles
B.CPU pinning
C.Extended Page Tables (EPT)
D.IOMMU
AnswerC

Extended Page Tables provide hardware-assisted second-level address translation, giving each guest VM its own nested page tables managed by the hypervisor. This isolates guest physical memory so one tenant VM cannot map or read another's memory, directly satisfying the auditor's cross-tenant isolation requirement.

Why this answer

Extended Page Tables (EPT) is a hardware virtualization feature (Intel VT-x) that provides second-level address translation, isolating guest physical memory from host physical memory. It ensures that a VM's memory accesses are translated through nested page tables controlled by the hypervisor, preventing one tenant VM from accessing another tenant's memory. EPT, along with AMD's Nested Page Tables (NPT), is specifically designed for memory isolation in virtualized environments.

Exam trap

The trap here is confusing memory isolation mechanisms (EPT) with syscall filtering (Seccomp) or device isolation (IOMMU), leading candidates to pick IOMMU because it also sounds like an isolation technology.

How to eliminate wrong answers

Option A is wrong because Seccomp profiles restrict the system calls a process can make, which is a syscall-level sandboxing mechanism, not a memory isolation technology. Option B is wrong because CPU pinning binds a virtual CPU to a physical core for performance predictability, not for memory isolation between tenants. Option D is wrong because IOMMU (Input-Output Memory Management Unit) isolates device DMA access to memory, protecting against rogue devices, but it does not directly prevent one VM from reading another VM's memory through normal CPU memory accesses.

599
MCQmedium

A security operations team is using AWS Security Hub to aggregate findings from multiple AWS accounts. They want to automatically create a ticket in their IT service management (ITSM) system for any new critical finding. The ITSM system exposes a REST API. Which AWS service should they use to invoke the ITSM API when a critical finding is generated?

A.AWS CloudTrail
B.Amazon EventBridge
C.AWS Config
D.Amazon Simple Notification Service (SNS)
AnswerB

Security Hub publishes findings to EventBridge as events. You can create an EventBridge rule that matches critical findings and targets an AWS Lambda function or directly an API destination. EventBridge supports API destinations, allowing you to invoke external REST APIs. This enables automatic ticket creation in the ITSM system when a critical finding occurs.

Why this answer

Security Hub integrates with EventBridge by sending findings as events. EventBridge rules can filter for critical findings and route them to targets like Lambda or API destinations. API destinations allow EventBridge to invoke external REST APIs directly, enabling automatic ticket creation in the ITSM system without custom code.

Exam trap

The trap here is assuming that SNS or CloudTrail can directly invoke an external REST API based on Security Hub findings, when EventBridge is the native integration point.

600
Multi-Selectmedium

A company is evaluating cloud providers for compliance with the GDPR. Which TWO of the following are mandatory data protection roles under the GDPR?

Select 2 answers
A.Data Processor
B.Data Protection Officer (DPO)
C.Cloud Security Architect
D.Data Controller
E.Data Steward
AnswersA, D

The data processor handles personal data on behalf of the controller, and GDPR Article 4 defines this as a mandatory role whenever a third party processes data for the controller, satisfying the stem's requirement for mandatory roles.

Why this answer

The GDPR defines the Data Controller and Data Processor as mandatory roles. The Data Protection Officer (DPO) is required only under certain conditions (e.g., large-scale monitoring). Cloud Security Architect and Data Steward are not GDPR-defined roles.

Page 7

Page 8 of 13

Page 9