Courseiva

Certified Cloud Security Professional CCSP (CCSP) — Questions 601–675

934 questions total · 13pages · All types, answers revealed

Page 8

Page 9 of 13

Page 10
601
MCQeasy

A startup is deploying a new cloud application that stores user profile pictures in an object storage bucket. The security team wants to ensure that data at rest is encrypted and that the encryption keys are managed by the cloud provider with minimal operational overhead. Which encryption option should they choose?

A.Server-side encryption with customer-provided keys (SSE-C).
B.Server-side encryption with provider-managed keys (SSE-S3 or equivalent).
C.Client-side encryption with keys stored in an on-premises hardware security module (HSM).
D.Server-side encryption with customer-managed keys in the cloud KMS (SSE-KMS).
AnswerB

Server-side encryption with provider-managed keys automatically encrypts data at rest and the cloud provider handles all key management, including rotation and storage. This meets the requirement for encryption at rest with minimal operational overhead, as the startup does not need to manage any keys. It is the simplest and most appropriate choice for this scenario.

Why this answer

Server-side encryption with provider-managed keys automatically encrypts data at rest and the cloud provider handles all aspects of key management, including generation, rotation, and storage. This requires no effort from the startup, perfectly aligning with the goal of minimal operational overhead while ensuring data at rest is encrypted.

Exam trap

The trap here is assuming that customer-managed keys in the cloud KMS require no overhead; in reality, they still involve key management tasks, whereas provider-managed keys are fully handled by the provider.

602
MCQhard

A company uses a cloud key management service (KMS) and wants to ensure that keys can be used only within a specific geographic region. Which of the following should be configured?

A.VPC endpoint for KMS
B.CloudTrail logging
C.Key policy with a condition for allowed regions
D.Key rotation policy
AnswerC

Key policies with conditions can restrict use to specific regions.

Why this answer

A key policy with a condition using the `kms:CallerRegion` or `aws:RequestRegion` condition key can explicitly restrict the geographic region where the KMS key can be used. This ensures that any cryptographic operation (e.g., Encrypt, Decrypt) attempted from an unauthorized region is denied, enforcing regional data sovereignty requirements.

Exam trap

ISC2 often tests the distinction between network-level controls (like VPC endpoints) and policy-level controls (like key policy conditions), leading candidates to mistakenly choose VPC endpoints for geographic restrictions when only a condition-based policy can enforce regional key usage.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint for KMS only restricts network access to the KMS API via a private IP within a VPC, but does not enforce geographic region restrictions on key usage; the key could still be used from any region if the request reaches the endpoint. Option B is wrong because CloudTrail logging records API calls for auditing but does not enforce any access control or geographic restriction on key usage. Option D is wrong because a key rotation policy controls how often the key material is rotated, not where the key can be used; it has no effect on geographic restrictions.

603
Multi-Selecthard

Which THREE of the following are typical requirements for compliance with eDiscovery in a cloud environment?

Select 3 answers
A.Documentation of chain of custody
B.Search and retrieval capabilities across data sources
C.Ability to place legal hold on data
D.Encryption of data at rest
E.Data minimization principles
AnswersA, B, C

Documenting chain of custody satisfies eDiscovery's evidentiary integrity requirement: it records who handled data, when, and how, proving collected cloud artefacts were not altered. Without this audit trail, evidence may be ruled inadmissible, so it is a typical compliance requirement for cloud eDiscovery processes.

Why this answer

Option A is correct because eDiscovery requires an auditable chain of custody documenting who collected, handled, and preserved electronically stored information (ESI), so its integrity and admissibility can be proven. Option B is correct because compliance demands search and retrieval capabilities across all relevant data sources (mailboxes, SharePoint/OneDrive, Teams, etc.) so responsive ESI can be identified and produced under FRCP rules. Option C is correct because the ability to place a legal hold is essential to prevent deletion or alteration of potentially relevant data once litigation or investigation is reasonably anticipated.

Option D does not belong because encryption at rest is a general data-protection control, not an eDiscovery-specific requirement, and Option E does not belong because data minimization is a privacy principle (e.g., GDPR) rather than an eDiscovery capability.

Exam trap

CCSP often tests the confusion between general security controls (encryption, data minimization) and specific eDiscovery requirements (legal hold, chain of custody, search), causing candidates to select security best practices instead of legal discovery capabilities.

604
MCQeasy

A company is deploying a cloud application that processes credit card transactions. Which standard must they comply with regarding data security?

A.GDPR
B.PCI DSS
C.HIPAA
D.ISO 27001
AnswerB

PCI DSS governs the storage, processing and transmission of cardholder data, so any application handling credit card transactions must comply. It mandates controls such as encryption, access restriction and network segmentation specifically for payment card environments.

Why this answer

PCI DSS (Payment Card Industry Data Security Standard) is the mandatory security standard for any organization that handles credit card transactions. It defines strict requirements for protecting cardholder data, including encryption, access control, and network segmentation. Since the application processes credit card transactions, compliance with PCI DSS is legally and contractually required.

Exam trap

ISC2 often tests the distinction between mandatory regulatory standards (like PCI DSS) and voluntary frameworks (like ISO 27001), leading candidates to mistakenly choose ISO 27001 because it is a well-known security standard.

How to eliminate wrong answers

Option A is wrong because GDPR (General Data Protection Regulation) governs the protection of personal data of EU citizens, not specifically credit card transaction security. Option C is wrong because HIPAA (Health Insurance Portability and Accountability Act) applies to protected health information (PHI) in healthcare, not payment card data. Option D is wrong because ISO 27001 is a voluntary international standard for information security management systems (ISMS), not a mandatory compliance requirement for credit card processing.

605
MCQmedium

An organization uses a continuous integration/continuous deployment (CI/CD) pipeline to deploy infrastructure as code. The security team wants to ensure that all cloud resources comply with internal security policies before deployment. Which of the following is the MOST effective method to enforce this?

A.Restrict the IAM permissions of developers to only approved roles.
B.Run automated policy compliance checks as part of the CI/CD pipeline.
C.Conduct manual security reviews after each deployment.
D.Deploy resources and then scan for compliance after deployment.
AnswerB

Embedding automated policy checks in the CI/CD pipeline evaluates infrastructure-as-code templates before provisioning, so non-compliant resources are blocked pre-deployment. This satisfies the stem's requirement to enforce compliance before deployment, shifting control left rather than detecting drift after resources already exist in the cloud environment.

Why this answer

Running automated policy compliance checks inside the CI/CD pipeline enforces security policies before resources are deployed, shifting compliance left. Tools like Terraform Sentinel, Checkov, or OPA/Conftest evaluate the IaC against policy and fail the pipeline on violations, preventing non-compliant infrastructure from ever reaching the cloud. This is the most effective because it is preventive, automated, and repeatable.

Exam trap

CCSP often tests the shift-left principle — candidates pick post-deployment scanning or manual review because they sound thorough, but the exam wants preventive, automated enforcement inside the pipeline.

How to eliminate wrong answers

Option A is wrong because restricting IAM permissions limits what developers can do but does not validate that the IaC itself complies with security policies — a developer with approved roles can still deploy misconfigured resources. Option C is wrong because manual security reviews after each deployment are slow, error-prone, and not scalable, and they occur after the risk is already live. Option D is wrong because scanning after deployment is detective, not preventive — non-compliant resources exist in the environment until remediated, which is exactly what the security team wants to avoid.

606
MCQeasy

Which risk assessment method uses subjective scales to assign probabilities and impacts?

A.Semi-quantitative risk assessment
B.Quantitative risk assessment
C.Qualitative risk assessment
D.Bottom-up risk assessment
AnswerC

Qualitative risk assessment ranks likelihood and impact using descriptive or ordinal scales, such as low, medium and high, rather than monetary values or annualised loss figures. That subjective scoring is precisely the mechanism the stem describes.

Why this answer

Qualitative risk assessment (option C) is correct because it relies on subjective scales (e.g., high, medium, low) to assign probabilities and impacts, rather than numerical data. This method is commonly used in cloud security to quickly evaluate risks when precise data is unavailable, aligning with the CCSP domain of Legal, Risk and Compliance.

Exam trap

ISC2 often tests the distinction between qualitative and semi-quantitative methods, where candidates confuse subjective scales (qualitative) with ordinal numerical scales (semi-quantitative), leading them to incorrectly select semi-quantitative risk assessment.

How to eliminate wrong answers

Option A is wrong because semi-quantitative risk assessment uses numerical values (e.g., 1-5 scales) to assign probabilities and impacts, not purely subjective scales. Option B is wrong because quantitative risk assessment uses objective numerical data (e.g., monetary values, statistical probabilities) to calculate risk, not subjective scales. Option D is wrong because bottom-up risk assessment is a structural approach that identifies risks from individual components upward, not a method for assigning probabilities and impacts via subjective scales.

607
MCQeasy

A startup wants to deploy a new web application without purchasing servers or managing operating systems, and it prefers to focus only on writing code while the provider handles runtime, scaling, and patching. Which cloud service model aligns BEST with this goal?

A.Platform as a Service (PaaS)
B.Software as a Service (SaaS)
C.Infrastructure as a Service (IaaS)
D.Desktop as a Service (DaaS)
AnswerA

PaaS supplies a managed runtime, middleware, and scaling environment so developers deploy code without provisioning servers or patching operating systems. This matches the startup's objective of writing code while the provider handles runtime, scaling, and patching, offering the right abstraction level between raw infrastructure and a finished application.

Why this answer

PaaS is designed to abstract away servers, operating systems, and runtime management while still allowing custom application deployment. The startup wants to write code and let the provider handle patching and scaling, which is exactly the division of labor PaaS provides, unlike IaaS where infrastructure remains the customer's concern or SaaS where no custom code is deployed.

Exam trap

The trap here is conflating PaaS with IaaS by assuming any cloud model removes server management, when only PaaS removes operating system and runtime administration while preserving custom code deployment.

608
Multi-Selectmedium

Which TWO of the following are primary objectives of a cloud application security program?

Select 2 answers
A.Maintaining application availability
B.Performing continuous deployment
C.Implementing a microservices architecture
D.Ensuring data confidentiality and integrity
E.Adopting Agile development practices
AnswersA, D

Availability is a core security objective because a cloud application rendered unreachable effectively fails its security posture. Resilience, redundancy and DDoS mitigation preserve service continuity, satisfying the program's mandate to keep applications accessible to legitimate users.

Why this answer

Option A (Maintaining application availability) is correct because a cloud application security program must protect against denial-of-service, misconfiguration, and resilience failures so that applications remain accessible to authorized users, aligning with the availability pillar of the CIA triad. Option D (Ensuring data confidentiality and integrity) is correct because the core purpose of application security is to prevent unauthorized disclosure and unauthorized modification of data, typically enforced through encryption, access controls, and integrity checks. Options B (continuous deployment), C (microservices architecture), and E (Agile development practices) are incorrect because they are software delivery and architectural methodologies, not security objectives; they may support security when implemented well but are not primary goals of a cloud application security program.

Exam trap

ISC2 often tests the distinction between security objectives and operational or architectural practices, trapping candidates who confuse 'continuous deployment' or 'microservices' with security goals because they are commonly discussed in cloud security contexts but are not primary objectives.

609
MCQmedium

A cloud security team wants to automatically block malicious requests to a web application before they reach the application servers. Which solution should they implement?

A.Intrusion Detection System (IDS)
B.Runtime Application Self-Protection (RASP)
C.Cloud Web Application Firewall (WAF)
D.Static Application Security Testing (SAST)
AnswerC

A cloud WAF inspects inbound HTTP/S requests against managed and custom rules, blocking malicious payloads at the edge before they reach origin servers. This satisfies the stem's requirement to automatically block attacks such as SQL injection and cross-site scripting prior to application processing.

Why this answer

A Cloud Web Application Firewall (WAF) is the correct solution because it operates at the application layer (Layer 7) to inspect HTTP/HTTPS traffic and block malicious requests—such as SQL injection, cross-site scripting (XSS), and OWASP Top 10 attacks—before they reach the application servers. Unlike an IDS, a WAF can actively block traffic in real time, and it is deployed at the network edge or cloud gateway, providing inline prevention without requiring changes to the application code.

Exam trap

The trap here is that candidates confuse IDS (passive alerting) with IPS (inline blocking), or assume RASP can block traffic before it reaches the application, when in fact RASP operates within the application runtime and cannot prevent initial request arrival at the server boundary.

How to eliminate wrong answers

Option A is wrong because an Intrusion Detection System (IDS) is a passive monitoring tool that only alerts on suspicious activity (e.g., via signature matching or anomaly detection) and cannot automatically block malicious requests; it lacks inline enforcement capabilities. Option B is wrong because Runtime Application Self-Protection (RASP) runs inside the application runtime environment (e.g., integrated into the JVM or .NET CLR) to detect and block attacks from within the application, but it does not operate before requests reach the application servers—it protects the application from the inside, not at the perimeter. Option D is wrong because Static Application Security Testing (SAST) is a development-phase code analysis tool that scans source code for vulnerabilities (e.g., buffer overflows, insecure APIs) but does not provide runtime protection or block live traffic; it is a preventive measure, not a real-time defense.

610
MCQhard

A cloud customer is considering adopting a multi-cloud strategy to avoid vendor lock-in. Which risk is this strategy primarily intended to mitigate?

A.Third-party risk from a specific provider
B.Concentration risk
C.Residual risk after controls
D.Inherent risk of data leaving premises
AnswerB

Multi-cloud spreads workloads across independent providers, so an outage, pricing change, or failure at one provider cannot disrupt all services. This directly reduces concentration risk—dependence on a single vendor—rather than portability, compliance, or interoperability concerns.

Why this answer

A multi-cloud strategy is primarily intended to mitigate concentration risk—the risk of over-reliance on a single provider, which can lead to systemic failures, vendor lock-in, and limited negotiating power. By distributing workloads across multiple providers, an organization reduces the impact of an outage, pricing change, or security incident at any one provider. This diversification is a classic risk management technique.

Exam trap

CCSP often tests the difference between concentration risk and third-party risk, so candidates must recognize that multi-cloud is a diversification strategy specifically aimed at reducing dependence on one provider.

How to eliminate wrong answers

Option A is wrong because third-party risk from a specific provider is a broader category that includes many factors (security, compliance, performance), and multi-cloud does not eliminate third-party risk—it merely spreads it across more providers. Option C is wrong because residual risk is the risk remaining after controls are applied; multi-cloud is a strategy to reduce concentration risk, not a control that directly addresses residual risk. Option D is wrong because inherent risk of data leaving premises relates to data residency and sovereignty concerns, which multi-cloud may exacerbate rather than mitigate if data is spread across jurisdictions.

611
MCQhard

A security operations center (SOC) uses AWS GuardDuty and wants to automatically isolate an Amazon EC2 instance that generates a high-severity finding. The isolation must block all network traffic except for forensic analysis traffic from a specific security subnet. Which combination of actions should be taken?

A.Modify the instance's security group to allow only traffic from the forensic subnet and remove all other rules.
B.Detach the instance's Elastic Network Interface (ENI) and attach a new ENI with a restrictive security group.
C.Move the instance to a new subnet with a network ACL that denies all traffic except from the forensic subnet.
D.Apply a new IAM role to the instance that denies all network access.
AnswerA

Modifying the security group to allow only forensic subnet traffic effectively isolates the instance while permitting necessary forensic access. This is a common isolation technique that blocks all other inbound and outbound traffic, aligning with the requirement to block all network traffic except forensic analysis traffic.

Why this answer

The most effective and least disruptive method to isolate an EC2 instance is to modify its security group to allow only traffic from a specific forensic subnet and remove all other rules. This blocks all other network traffic while enabling forensic analysis, and it can be automated via Lambda triggered by GuardDuty findings.

Exam trap

The trap here is confusing IAM roles with network security controls; IAM roles manage API permissions, not network traffic, so they cannot isolate an instance at the network level.

612
MCQhard

A cloud application uses containers orchestrated by Kubernetes. The security team wants to enforce that containers cannot run as root and that file systems are read-only at runtime. Which Kubernetes security context configuration should be applied?

A.Use a RuntimeClass that disables root capabilities
B.Set the container's user to a non-root user in the Dockerfile
C.Apply a PodSecurityPolicy that blocks privileged containers
D.Configure a SecurityContext with runAsNonRoot: true and readOnlyRootFilesystem: true
AnswerD

SecurityContext fields runAsNonRoot and readOnlyRootFilesystem directly enforce the two stated constraints: the container process cannot run as UID 0, and its root filesystem is mounted read-only, blocking runtime writes. Pod Security Admission alone would not guarantee both.

Why this answer

Kubernetes SecurityContext allows fine-grained control over container permissions at the pod or container level. Setting `runAsNonRoot: true` ensures the container cannot run as UID 0, and `readOnlyRootFilesystem: true` mounts the container's root filesystem as read-only, preventing unauthorized writes at runtime. This directly satisfies the security team's requirements without relying on external policies or image-level configurations.

Exam trap

The trap here is that candidates confuse image-level defaults (like a non-root user in a Dockerfile) with runtime enforcement via SecurityContext, or they think PodSecurityPolicy (a deprecated feature) is the only way to enforce these restrictions, when in fact SecurityContext is the direct and correct mechanism.

How to eliminate wrong answers

Option A is wrong because a RuntimeClass primarily selects a container runtime (e.g., gVisor, Kata Containers) for isolation, not a mechanism to disable root capabilities or enforce read-only filesystems; it does not directly set runAsNonRoot or readOnlyRootFilesystem. Option B is wrong because setting a non-root user in the Dockerfile only affects the image's default user; it can be overridden at runtime (e.g., by specifying `securityContext.runAsUser: 0`), so it does not enforce the restriction. Option C is wrong because PodSecurityPolicy (PSP) is a deprecated, cluster-level admission controller that can block privileged containers but does not directly enforce `runAsNonRoot: true` or `readOnlyRootFilesystem: true`; it requires additional policy rules and is being replaced by Pod Security Standards.

613
MCQmedium

A healthcare organization has deployed a cloud-based application that handles protected health information (PHI). The application runs on virtual machines in a virtual private cloud (VPC). The security team has implemented security groups to control traffic to the VMs. Recently, an external penetration test revealed that a web server VM is accessible from the internet on port 22 (SSH) from any IP address (0.0.0.0/0). The security team also discovered that the SSH key pair used for the web server was created with a weak algorithm (1024-bit RSA). The team needs to remediate these issues without causing downtime for the application. Additionally, the application logs must be sent to a centralized logging solution that is encrypted in transit and at rest. Which combination of actions should the security team take?

A.Restrict inbound SSH access to only a bastion host's IP address, generate a new 2048-bit RSA key pair, configure the application to send logs via TLS to a centralized logging service, and enable server-side encryption for the logging bucket.
B.Implement a VPN connection for all administrative access, keep the existing key pair, and use a third-party logging tool with TLS.
C.Change the SSH port to a non-standard port, keep the existing key pair, and enable logging to a cloud storage bucket without encryption.
D.Disable SSH access entirely and use a serial console for administration, keep the existing key pair, and send logs via plaintext syslog to a logging server.
AnswerA

Narrowing the security group to the bastion host's address removes internet-wide SSH exposure, and regenerating the key pair at 2048-bit RSA replaces the weak algorithm. TLS transport plus server-side encryption satisfies the encrypted-in-transit and at-rest logging requirement without downtime.

Why this answer

It addresses both critical vulnerabilities without downtime: restricting SSH to a bastion host's IP eliminates internet-wide exposure, and generating a new 2048-bit RSA key pair replaces the weak 1024-bit key. For logging, TLS ensures encryption in transit, and server-side encryption for the logging bucket ensures encryption at rest, meeting compliance requirements for PHI.

Exam trap

ISC2 often tests the distinction between security by obscurity (e.g., changing ports) and actual security controls (e.g., restricting IPs and using strong keys), leading candidates to pick options that seem quick but fail compliance requirements.

How to eliminate wrong answers

Option B is wrong because keeping the existing 1024-bit RSA key pair leaves a weak cryptographic algorithm in place, which is a security risk and non-compliant with standards like NIST SP 800-57. Option C is wrong because changing the SSH port to a non-standard port is security by obscurity and does not prevent scanning or brute-force attacks, and sending logs to a bucket without encryption violates encryption-at-rest requirements for PHI. Option D is wrong because disabling SSH entirely and using a serial console is impractical for cloud VMs and often causes downtime, and sending logs via plaintext syslog lacks encryption in transit, violating HIPAA and other regulations.

614
MCQmedium

A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. After a recent penetration test, the team must ensure that only HTTP and HTTPS traffic reaches the instances from the load balancer, and that no instance can accept SSH from the internet. The instances currently have a security group named 'web-sg' that allows all inbound traffic from 0.0.0.0/0. Which action should the team take to meet these requirements with the LEAST administrative effort while following AWS best practices?

A.Keep the existing 'web-sg' rules but configure the load balancer to use a target group that only forwards traffic on ports 80 and 443, and enable connection draining.
B.Replace the 'web-sg' security group with a new security group that allows inbound HTTP and HTTPS from 0.0.0.0/0, and add a rule to deny SSH from 0.0.0.0/0.
C.Modify the 'web-sg' security group to allow inbound HTTP and HTTPS from the load balancer's security group, and remove all other inbound rules.
D.Create a new network ACL that allows inbound HTTP and HTTPS from the load balancer subnet and denies all other traffic, then associate it with the instance subnets.
AnswerC

This is correct because referencing the load balancer's security group as the source in the instance security group ensures only traffic from the load balancer is allowed, and removing other rules eliminates internet SSH. It uses security group referencing, which is the AWS-recommended least-privilege approach and requires no changes to the load balancer or instances.

Why this answer

Referencing the load balancer's security group in the instance security group is the most precise and least-effort method to restrict inbound traffic to only the load balancer. It leverages AWS security group referencing, which is stateful and supports least privilege without needing CIDR calculations. Removing all other inbound rules ensures no direct internet SSH access, satisfying both requirements.

Exam trap

The trap here is assuming that security groups can contain explicit deny rules or that network ACLs can reference security groups, when in fact security groups are allow-only and network ACLs are stateless and cannot reference security groups.

615
MCQmedium

A company uses a cloud provider's managed database service. The security team is concerned about the shared responsibility model for patching the operating system and database engine. According to the shared responsibility model, who is responsible for applying security patches to the database engine?

A.The customer, because they control the database configuration
B.A third-party vendor contracted by the customer
C.The cloud provider, because it is a managed service
D.Both the customer and the cloud provider equally
AnswerC

In a managed database service, the provider operates the underlying infrastructure and database engine, so patching that engine falls to them under the shared responsibility model. The customer retains responsibility only for data, access and configuration.

Why this answer

In the cloud shared responsibility model, for a managed database service (such as Amazon RDS or Azure SQL Database), the cloud provider is responsible for patching the underlying operating system and the database engine. The customer is responsible for data, access management, and configuration within the database, but not for engine patching. Therefore the cloud provider applies security patches to the database engine (option C).

Exam trap

CCSP often tests the shared responsibility model by blurring the line between configuration responsibility and patching responsibility — candidates may think that because they control database configuration, they also patch the engine, which is false for managed services.

How to eliminate wrong answers

Option A is wrong because while the customer controls database configuration, patching the database engine is not the customer's responsibility in a managed service — the provider handles it. Option B is wrong because a third-party vendor is not part of the shared responsibility model unless explicitly contracted, and the question asks about the standard model. Option D is wrong because responsibility is not split equally; the provider owns the patching of the managed engine and OS, while the customer owns data and access.

616
Multi-Selecteasy

Which TWO of the following are secure coding practices that help prevent injection attacks?

Select 2 answers
A.Printing stack traces in production error messages
B.Using parameterized queries for database calls
C.Using stored procedures exclusively
D.Validating and sanitizing all user inputs
E.Storing user passwords in plaintext
AnswersB, D

Parameterised queries separate SQL code from user-supplied data, so the database engine treats input strictly as values rather than executable statements. This structurally prevents injection by ensuring untrusted data cannot alter query logic, directly satisfying the stem's requirement for a secure coding practise that mitigates injection attacks.

Why this answer

Option B is correct because parameterized queries (prepared statements) separate SQL code from user-supplied data, so the database engine treats input as data rather than executable SQL, which neutralizes SQL injection. Option D is correct because validating and sanitizing all user inputs enforces expected formats and strips or escapes dangerous characters, reducing the attack surface for SQL, command, and other injection attacks. Option A is incorrect because printing stack traces in production leaks internal details such as file paths, query fragments, and framework versions that aid attackers, and it does nothing to prevent injection.

Option C is incorrect because stored procedures are not inherently safe—if they build dynamic SQL by concatenating user input, they remain vulnerable to injection, so they are not a guaranteed secure coding practice. Option E is incorrect because storing passwords in plaintext is a severe confidentiality failure that enables credential theft and has no bearing on preventing injection attacks.

Exam trap

ISC2 often tests the misconception that stored procedures are inherently safe against injection, but the trap is that stored procedures can still be vulnerable if they dynamically construct SQL strings using concatenated input, so parameterization must be applied inside the procedure as well.

617
MCQeasy

Which characteristic of cloud computing allows a user to provision resources automatically without requiring human interaction with the service provider?

A.Rapid elasticity
B.Broad network access
C.On-demand self-service
D.Resource pooling
AnswerC

On-demand self-service is the essential characteristic that lets consumers unilaterally provision computing capabilities, such as server time and network storage, automatically as needed, without requiring human interaction with each service provider, directly satisfying the stem's constraint.

Why this answer

On-demand self-service is the cloud characteristic defined by NIST SP 800-145 that allows a consumer to unilaterally provision computing capabilities, such as server time and network storage, automatically without requiring human interaction with each service provider. This exactly matches the scenario of automatic provisioning without provider interaction.

Exam trap

The trap is that candidates conflate 'automatic provisioning' with 'rapid elasticity' — both involve automation, but elasticity is about scaling up/down with demand, whereas on-demand self-service is specifically about the consumer provisioning resources without provider interaction.

How to eliminate wrong answers

Option A (Rapid elasticity) is wrong because it describes the ability to scale resources outward and inward commensurate with demand, not the self-service provisioning mechanism itself. Option B (Broad network access) is wrong because it refers to capabilities being available over the network through standard mechanisms and heterogeneous client platforms, not automated provisioning. Option D (Resource pooling) is wrong because it describes the provider's multi-tenant model where resources are pooled to serve multiple consumers, which is about provider-side architecture, not consumer self-service.

618
MCQmedium

A cloud security team wants to automatically remediate misconfigured S3 buckets that are publicly accessible. Which combination of AWS services can be used to detect and automatically fix this issue?

A.AWS GuardDuty and AWS Lambda
B.AWS CloudTrail and AWS Lambda
C.AWS Config and AWS Lambda
D.AWS Security Hub and AWS CloudTrail
AnswerC

AWS Config rules continuously evaluate bucket policies and ACLs, flagging public access as non-compliant. The configuration change then triggers a Lambda function that programmatically removes the public permissions, delivering automated detection and remediation without manual intervention.

Why this answer

AWS Config continuously monitors and records resource configurations, including S3 bucket policies and ACLs, and can evaluate them against desired rules. When a bucket is found to be publicly accessible, AWS Config can trigger an AWS Lambda function to automatically remediate the misconfiguration, such as by applying a restrictive bucket policy or blocking public access. This combination provides detection and automated remediation.

Exam trap

CCSP often tests the difference between threat detection (GuardDuty), auditing (CloudTrail), and configuration compliance (Config), so candidates must match the service to the requirement of detecting and remediating misconfigurations.

How to eliminate wrong answers

Option A is wrong because AWS GuardDuty is a threat detection service that identifies malicious activity and unauthorized behavior, but it does not evaluate resource configuration compliance or trigger remediation for misconfigured S3 buckets. Option B is wrong because AWS CloudTrail records API activity for auditing, but it does not assess resource configuration state or provide compliance evaluation; it cannot detect a publicly accessible bucket by itself. Option D is wrong because AWS Security Hub aggregates findings but does not directly detect misconfigured S3 buckets (it relies on Config or other services) and CloudTrail is for logging, not remediation.

619
Multi-Selectmedium

A company is deploying a critical application on a public cloud IaaS platform. To ensure high availability and disaster recovery, which TWO of the following strategies should the company implement? (Choose two.)

Select 2 answers
A.Deploy the application across multiple availability zones within a region.
B.Use an active-passive configuration with both instances in the same availability zone.
C.Configure the application to run in only one region to simplify management.
D.Implement automated snapshots and replicate data to a different geographic region.
E.Use a single, large virtual machine instance to handle all traffic.
AnswersA, D

Spreading instances across multiple availability zones places them in physically separate data centres with independent power and networking, so a single zone failure does not take the application down. This satisfies the stem's high availability requirement within one region.

Why this answer

Option A is correct because deploying across multiple availability zones within a region protects against a single AZ failure, since AZs have independent power, cooling, and networking, and the application can fail over to another AZ while staying in the same region for low latency. Option D is correct because automated snapshots plus cross-region data replication provide disaster recovery against a full region outage, enabling restoration or failover to a different geographic region with an acceptable RPO. Option B is not appropriate because an active-passive pair in the same availability zone shares the same failure domain, so an AZ outage takes down both instances.

Option C is wrong because confining the application to one region removes geographic redundancy and increases the blast radius of a regional failure. Option E is wrong because a single large VM is a single point of failure and cannot provide high availability or disaster recovery.

Exam trap

ISC2 often tests the distinction between high availability (fault tolerance within a region using multiple AZs) and disaster recovery (cross-region data replication and failover), and the trap is that candidates confuse active-passive in the same AZ (which is not HA) with a valid HA strategy.

620
MCQhard

A healthcare organization wants to perform analytics on encrypted patient data without decrypting it first, to maintain privacy. Which cryptographic technique supports this use case?

A.Homomorphic encryption
B.Tokenization
C.Format-preserving encryption (FPE)
D.Cryptographic hashing
AnswerA

Homomorphic encryption permits computation directly on ciphertext, so analytics produce encrypted results that decrypt to match operations on the plaintext. This satisfies the healthcare constraint of processing patient data while it remains encrypted, preserving privacy since plaintext is never exposed to the analytics platform.

Why this answer

Homomorphic encryption allows computations to be performed directly on ciphertext, producing an encrypted result that, when decrypted, matches the result of operations performed on the plaintext. This enables the healthcare organization to run analytics on encrypted patient data without ever exposing the underlying sensitive information, thus preserving privacy throughout the processing lifecycle.

Exam trap

ISC2 often tests the distinction between 'processing on encrypted data' and 'protecting data at rest or in transit'—candidates mistakenly choose FPE or tokenization because they see 'encrypted' or 'token' and assume it supports analytics, but neither allows computation without decryption.

How to eliminate wrong answers

Option B (Tokenization) is wrong because it replaces sensitive data with non-sensitive tokens, but the original data must be stored in a separate vault and analytics cannot be performed on the tokens without detokenization, which breaks the 'no decryption' requirement. Option C (Format-preserving encryption) is wrong because it produces ciphertext that retains the original data format (e.g., 16-digit credit card numbers), but all operations require decryption first; it does not support computation on encrypted data. Option D (Cryptographic hashing) is wrong because it is a one-way function that cannot be reversed, and it does not allow any meaningful analytics on the hash values (e.g., you cannot compute an average or sum of hashed patient ages).

621
MCQhard

A cloud architect is designing VPC connectivity for a global organization with multiple AWS accounts. They need a central hub for connecting many VPCs together, supporting transitive routing. Which service should they use?

A.Private Link
B.Transit Gateway
C.VPN Connection
D.VPC Peering
AnswerB

Transit Gateway acts as a regional hub attaching many VPCs and on-premises networks, with transitive routing between attachments. That satisfies the central-hub and transitive-routing constraints, unlike VPC peering, which is non-transitive and requires a mesh of individual connections.

Why this answer

AWS Transit Gateway acts as a central hub that connects multiple VPCs and on-premises networks, supporting transitive routing between all attached VPCs. It simplifies network architecture by eliminating the need for complex full-mesh VPC peering and allows scalable, hub-and-spoke connectivity. For a global organization with many VPCs across accounts, Transit Gateway is the designed solution.

Exam trap

CCSP often tests the confusion between VPC Peering (non-transitive, one-to-one) and Transit Gateway (transitive, hub-and-spoke), leading candidates to pick VPC Peering for scalable multi-VPC connectivity.

How to eliminate wrong answers

Option A is wrong because AWS PrivateLink provides private connectivity to services, not a hub for connecting many VPCs with transitive routing; it is used for service-level access, not network-level peering. Option C is wrong because a VPN Connection connects on-premises networks to a single VPC, not multiple VPCs with transitive routing. Option D is wrong because VPC Peering is non-transitive and requires a full mesh for many-to-many connectivity, which does not scale for a global organization with numerous VPCs.

622
Multi-Selectmedium

A cloud security architect is designing a multi-tenant SaaS application that must ensure strong isolation between tenants. Which TWO mechanisms are most effective for achieving multitenancy isolation?

Select 2 answers
A.Hypervisor-based virtual machine isolation
B.Network micro-segmentation
C.Encryption at rest for all tenant data
D.Database row-level permissions
E.API rate limiting per tenant
AnswersA, B

Hypervisor-based virtual machine isolation places each tenant's workload in a separate VM, so the hypervisor enforces hardware-level separation of memory, CPU and devices. This strong boundary satisfies the stem's requirement for robust isolation between tenants in a multi-tenant SaaS design.

Why this answer

Hypervisor-based virtual machine isolation (A) is correct because each tenant runs in its own VM with a separate guest OS, so the hypervisor enforces hardware-level separation of CPU, memory, and I/O, preventing one tenant from accessing another tenant's resources even if the guest OS is compromised. Network micro-segmentation (B) is correct because it applies granular, workload-level policies (e.g., security groups, NSGs, or service-mesh rules) that restrict east-west traffic so tenants can only reach their own components, containing lateral movement and enforcing tenant boundaries at the network layer. Encryption at rest (C) is not the most effective isolation mechanism because it protects data confidentiality if storage media is compromised but does not prevent a tenant from accessing another tenant's data through a running application or shared service.

Database row-level permissions (D) provide logical access control within a shared schema but rely on correct query and policy configuration, so they are weaker than infrastructure-enforced isolation and can be bypassed by application or SQL flaws. API rate limiting per tenant (E) addresses fairness, abuse prevention, and availability (e.g., throttling to protect against noisy-neighbor effects) but does not isolate tenants' data or execution environments.

Exam trap

CCSP often tests the difference between confidentiality controls (encryption) and isolation controls (hypervisor, network segmentation), causing candidates to select encryption at rest as an isolation mechanism when it only protects data at rest.

623
MCQhard

A cloud service provider (CSP) includes a limitation of liability clause capped at the total fees paid in the past 12 months. A customer suffers a data breach due to provider negligence, losing $2M in business. The customer's annual spend is $500K. What is the customer's likely recovery?

A.The amount of direct damages only
B.Up to $500K, the total fees paid in the past 12 months
C.Full $2M because negligence overrides liability caps
D.Zero because the customer accepted the terms
AnswerB

The contract's limitation of liability caps recovery at fees paid in the preceding 12 months, so the $2M loss is irrelevant. The customer recovers at most $500K, the annual spend, regardless of the provider's negligence causing the breach.

Why this answer

The clause limits liability to fees paid (12 months = $500K), so the customer can recover up to that amount, not the full $2M loss. Option B correctly states this limitation.

624
MCQmedium

A security engineer is reviewing container image security. Which of the following practices best ensures that a container image has not been tampered with and originates from a trusted source?

A.Scanning the image with Trivy for CVEs
B.Using a minimal base image like Alpine
C.Setting the image tag to :latest
D.Signing the image with Cosign and verifying it at deployment
AnswerD

Cosign applies a cryptographic signature tied to the publisher's private key, and verification at deployment rejects any image whose digest or signature fails validation. This satisfies the tamper-evidence and trusted-origin constraint, since unsigned or altered images cannot pass admission.

Why this answer

Signing a container image with Cosign and verifying it at deployment ensures integrity and provenance by cryptographically binding the image to a trusted signer. Cosign uses public-key cryptography to sign the image digest, and verification at deployment (e.g., via admission controllers) ensures only signed images run. This directly addresses tampering and trusted source requirements.

Exam trap

The trap is equating vulnerability scanning or using minimal base images with integrity verification; only cryptographic signing and verification provide tamper-evidence and provenance.

How to eliminate wrong answers

Option A is wrong because scanning with Trivy detects known vulnerabilities (CVEs) but does not verify image integrity or origin; a tampered image could still pass a vulnerability scan. Option B is wrong because using a minimal base image like Alpine reduces attack surface but does not provide any cryptographic assurance of integrity or source. Option C is wrong because setting the image tag to :latest is an anti-pattern that can lead to unpredictable deployments and does not ensure integrity; tags are mutable and can be overwritten.

625
MCQeasy

During a cloud security audit, it is discovered that a cloud storage bucket is configured to allow access from any IP address. The bucket contains sensitive customer data. What is the BEST immediate action to secure the bucket?

A.Modify the bucket policy to deny access from all IP addresses except trusted ranges.
B.Enable bucket logging to track access attempts.
C.Notify the security team and wait for a formal change request.
D.Enable server-side encryption on the bucket.
AnswerA

Rewriting the bucket policy to deny all access except trusted IP ranges immediately removes the public exposure while preserving legitimate access. This satisfies the stem's requirement for the best immediate action, since the bucket holds sensitive customer data and any-IP access is the exposure.

Why this answer

The immediate risk is that the bucket is publicly accessible from any IP address, exposing sensitive customer data. Modifying the bucket policy to deny access from all IP addresses except trusted ranges directly addresses this exposure by restricting network-level access. This is the most effective first step because it removes the broad, unrestricted access while maintaining necessary access for authorized users.

Exam trap

ISC2 often tests the distinction between access control and other security controls, trapping candidates who confuse encryption or logging with network-level access restriction.

How to eliminate wrong answers

Option B is wrong because enabling bucket logging only records access attempts; it does not prevent unauthorized access, so the data remains exposed. Option C is wrong because waiting for a formal change request delays remediation, leaving the sensitive data vulnerable during the wait period. Option D is wrong because server-side encryption protects data at rest but does not control network access; the bucket remains accessible from any IP address, so encryption alone does not secure the bucket from unauthorized access.

626
MCQhard

A multinational corporation uses a cloud-based data warehouse to store aggregated analytics data. The data includes anonymized user behavior logs that, when combined with a separate dataset of user identifiers, could re-identify individuals. The security team wants to implement a data masking technique that preserves the statistical properties of the data for analytics while preventing re-identification. Which technique BEST meets these requirements?

A.Data generalization that replaces specific values with broader categories, such as age ranges instead of exact ages.
B.Differential privacy that adds controlled noise to query results or data values to protect individual privacy.
C.Format-preserving encryption that encrypts user identifiers while maintaining their original format.
D.Tokenization that replaces user identifiers with randomly generated tokens stored in a secure vault.
AnswerB

Differential privacy adds mathematical noise to data or query results, ensuring that the inclusion or exclusion of any single individual does not significantly affect the output. This preserves aggregate statistical properties while preventing re-identification. It is specifically designed for analytics scenarios where utility must be maintained. Unlike masking or tokenization, it provides a quantifiable privacy guarantee, making it the best fit for this requirement.

Why this answer

Differential privacy is the only technique that provides a formal privacy guarantee while allowing accurate statistical analysis. It works by injecting noise calibrated to the sensitivity of the data, ensuring that individual records cannot be distinguished. This preserves the overall distribution and correlations, which are essential for analytics.

Other techniques either destroy statistical utility or provide weaker privacy guarantees that can be compromised through auxiliary data.

Exam trap

The trap here is confusing data masking techniques that preserve format or referential integrity with those that preserve statistical properties, which is a unique characteristic of differential privacy.

627
MCQeasy

A company wants to enforce data classification in its cloud environment. They need to automatically identify and label sensitive data such as credit card numbers in cloud storage. Which service should they use?

A.Cloud KMS
B.Cloud DLP
C.Cloud Audit Logs
D.Cloud IAM
AnswerB

Cloud DLP scans storage repositories and uses pattern matching and checksums to detect credit card numbers, then applies classification labels automatically. This directly satisfies the requirement to identify and label sensitive data at scale, which manual tagging or generic encryption services cannot achieve.

Why this answer

Cloud DLP (Data Loss Prevention) is designed to automatically discover, classify, and label sensitive data such as credit card numbers, social security numbers, and personally identifiable information in cloud storage and other services. It uses built-in and custom infoType detectors (including regex and checksum validation for credit cards) to identify and tag sensitive content, directly fulfilling the requirement to automatically identify and label sensitive data.

Exam trap

The trap is that candidates may choose Cloud KMS thinking 'protecting sensitive data' means encryption — but the question specifically asks for automatic identification and labeling of data content, which is DLP's unique classification capability, not encryption or access control.

How to eliminate wrong answers

Option A (Cloud KMS) is wrong because Key Management Service handles cryptographic key creation, rotation, and usage — it protects data via encryption but does not inspect or classify content. Option C (Cloud Audit Logs) is wrong because audit logs record API activity and administrative actions for compliance and forensics, not data content classification. Option D (Cloud IAM) is wrong because Identity and Access Management controls who can access resources via roles and policies, but it does not scan or label data based on sensitivity.

628
MCQmedium

A cloud security architect is designing a data retention policy for a cloud-based document management system. The policy must ensure that documents are automatically deleted after a specified retention period, and that deletion is verifiable and irreversible. Which cloud-native feature should be implemented to meet these requirements?

A.Bucket versioning with a retention policy.
B.Client-side encryption with key deletion after the retention period.
C.Manual deletion by administrators on a scheduled basis.
D.Object lifecycle management policies with expiration actions.
AnswerD

Object lifecycle management policies allow administrators to define rules that automatically delete objects after a specified period. These policies are enforced by the cloud provider, and deletion is typically permanent and irreversible (unless versioning or soft delete is enabled). The provider logs lifecycle actions, providing verifiability. This meets the requirements for automatic, verifiable, and irreversible deletion.

Why this answer

Object lifecycle management policies are cloud-native features that automatically transition or delete objects based on age or other criteria. They are enforced by the provider, ensuring consistent application, and typically log actions for audit. When configured to delete after a retention period, they provide automatic, verifiable, and irreversible removal of data, meeting the policy requirements.

Exam trap

The trap here is confusing crypto-shredding (key deletion) with actual data deletion; key deletion leaves the encrypted data in place and may not satisfy legal retention requirements.

629
MCQhard

A company is migrating a critical application to the cloud and must ensure that its security operations center (SOC) can detect and respond to threats in real time. The application generates high volumes of logs. Which combination of services would provide the MOST efficient and cost-effective solution for centralized logging, analysis, and alerting?

A.Deploy a basic monitoring tool that triggers alerts based on static thresholds.
B.Implement a Security Information and Event Management (SIEM) system with real-time correlation and a log management solution that auto-scales.
C.Use a cloud-native log storage service with long retention and no analysis.
D.Store logs in a centralized log server and have SOC analysts manually review them.
AnswerB

A SIEM with real-time correlation satisfies the SOC's detection requirement by matching events across sources as they arrive, rather than batch-searching later. The auto-scaling log management tier absorbs high log volumes without manual capacity planning, keeping ingestion cost-effective. Together they deliver centralised collection, immediate alerting and elastic storage for the migration scenario.

Why this answer

A SIEM system with real-time correlation enables the SOC to detect threats as they occur by analyzing log data across multiple sources, while an auto-scaling log management solution ensures cost efficiency by dynamically adjusting resources to handle high log volumes without over-provisioning. This combination provides centralized logging, real-time analysis, and alerting, meeting the requirement for efficient and cost-effective threat detection.

Exam trap

ISC2 often tests the misconception that simple storage or manual review is sufficient for real-time threat detection, but the CCSP emphasizes that centralized logging without analysis and correlation fails to meet SOC operational requirements for real-time response.

How to eliminate wrong answers

Option A is wrong because a basic monitoring tool with static thresholds cannot perform real-time correlation across diverse log sources, leading to high false positives and missed advanced threats, and it lacks the scalability to handle high-volume logs efficiently. Option C is wrong because a cloud-native log storage service with long retention and no analysis fails to provide the real-time detection and alerting required by the SOC, as it only stores logs without any correlation or threat identification. Option D is wrong because storing logs in a centralized log server with manual review is neither efficient nor real-time, as SOC analysts cannot manually analyze high-volume logs quickly enough to detect and respond to threats promptly, and it does not scale cost-effectively.

630
MCQmedium

A cloud operations team is deploying a containerized workload on a managed Kubernetes service. They need to ensure that if a container image is discovered to contain a critical vulnerability, the running pods using that image are automatically replaced with a non-vulnerable version. Which mechanism BEST achieves this?

A.Use a network policy that isolates pods running the vulnerable image until the image is patched.
B.Configure a pod disruption budget that prevents pods with vulnerabilities from being evicted during maintenance windows.
C.Configure an admission controller that rejects the vulnerable image tag and use a deployment strategy that replaces pods when the image tag is updated to a patched version.
D.Enable a runtime security agent that detects the vulnerability at runtime and sends an alert to the security team for manual remediation.
AnswerC

Admission controllers can block new pods that reference a denied image, while a rolling update triggered by changing the image tag replaces existing pods with the patched version. This combination prevents vulnerable images from being scheduled and ensures running workloads converge on the safe image without manual pod deletion, directly satisfying the automatic replacement requirement.

Why this answer

Blocking the vulnerable image through an admission controller stops new pods from using it, and updating the deployment to a patched image tag triggers a rolling update that replaces existing pods. Together these enforce image policy and automatically converge the workload on the safe version, meeting the automatic replacement requirement without relying on manual intervention.

Exam trap

The trap here is assuming that runtime detection or network isolation automatically remediates a vulnerable container image, when only an admission control policy combined with a deployment update actually replaces running pods with a patched image.

631
MCQeasy

A retail company migrates its customer-facing web application to a cloud environment. The security team wants to ensure that security testing is integrated throughout the software development lifecycle (SDLC) rather than only before production deployment. Which approach best aligns with this goal?

A.Adopt a DevSecOps approach with automated security testing in the CI/CD pipeline.
B.Implement security gates at the end of each development sprint.
C.Require developers to complete annual secure coding training.
D.Conduct a penetration test after the application is deployed to production.
AnswerA

A DevSecOps approach integrates security automatically into every stage of the CI/CD pipeline, enabling early detection and remediation of vulnerabilities. This aligns with the goal of continuous security testing throughout the SDLC. Automated tools like SAST, DAST, and dependency scanning run with each build, providing rapid feedback to developers. This reduces risk and cost compared to late-stage testing, and fosters a security-first culture.

Why this answer

Integrating security testing into the CI/CD pipeline through a DevSecOps approach ensures that vulnerabilities are identified and addressed continuously as code is developed and deployed. This shifts security left, reduces remediation costs, and aligns with modern cloud application security best practices. Other options either delay testing or rely solely on human training, which does not provide the continuous automated assurance required.

Exam trap

The trap here is assuming that periodic security gates or annual training are sufficient for continuous security, when the goal requires automated, integrated testing throughout the SDLC.

632
Multi-Selecteasy

Which THREE of the following are effective strategies for ensuring data backup integrity and recoverability in the cloud?

Select 3 answers
A.Maintain at least three copies of data across two different locations.
B.Encrypt all backups with a strong algorithm.
C.Perform regular restore tests to validate backup usability.
D.Set backup schedules to run daily for all critical data.
E.Store backups in immutable storage to prevent modification or deletion.
AnswersA, C, E

Multiple copies and geographic diversity improve recoverability.

Why this answer

The 3-2-1 backup rule (three copies, two different media types, one offsite) is a foundational strategy for data durability and recoverability. In cloud environments, this typically means maintaining a primary copy, a local backup in a different availability zone, and a cross-region copy to protect against region-wide failures. This ensures that even if two copies are compromised, a third remains available for recovery.

Exam trap

ISC2 often tests the distinction between backup security (encryption) and backup integrity/recoverability, leading candidates to mistakenly select encryption as a strategy for recoverability when it only addresses confidentiality.

633
MCQeasy

A cloud security architect is designing a multi-tier application that processes sensitive customer data. To protect data in transit between the web tier and the application tier, which of the following is the MOST appropriate approach?

A.Use standard TLS with server-side certificates only
B.Establish SSH tunnels for all inter-tier communication
C.Use mutual TLS (mTLS) between the tiers
D.Implement IPsec VPN between the tiers
AnswerC

Mutual TLS authenticates both the web tier and application tier with certificates and encrypts the channel between them, so neither side accepts an impostor. This satisfies the requirement to protect sensitive customer data in transit between those specific tiers.

Why this answer

Mutual TLS (mTLS) is the most appropriate approach because it provides bidirectional authentication and encryption between the web tier and application tier. In a multi-tier application processing sensitive customer data, mTLS ensures that both the client (web tier) and server (application tier) present valid certificates, preventing man-in-the-middle attacks and unauthorized inter-tier communication. This is critical for protecting data in transit in zero-trust or internal network segments where simple server-side TLS would not verify the identity of the calling service.

Exam trap

ISC2 often tests the misconception that standard TLS (server-side only) is sufficient for internal service-to-service communication, but the trap here is that without mutual authentication, an attacker who compromises the web tier could impersonate it to the application tier, or a rogue service could connect to the application tier undetected.

How to eliminate wrong answers

Option A is wrong because standard TLS with server-side certificates only authenticates the server to the client, but does not authenticate the client (web tier) to the application tier, leaving the application tier vulnerable to unauthorized or spoofed connections. Option B is wrong because SSH tunnels provide point-to-point encryption but are designed for interactive shell access or port forwarding, not for high-throughput, persistent inter-tier service communication; they introduce management overhead and lack the certificate-based identity verification that mTLS offers for service-to-service authentication. Option D is wrong because IPsec VPN operates at the network layer and encrypts all traffic between subnets, but it is overly complex for application-layer communication, adds latency, and does not provide application-level identity verification between specific services; it is more suited for site-to-site connectivity rather than fine-grained inter-tier authentication.

634
MCQmedium

A cloud storage bucket is configured with versioning enabled. A ransomware attack encrypts all objects in the bucket. How can the organization recover the original data?

A.Use the cloud provider's backup service to restore the bucket
B.Replicate data from the cross-region replica
C.Use the cloud provider's ransomware recovery service
D.Restore from previous versions of the objects
AnswerD

Versioning retains prior copies of each object, so overwritten or encrypted current versions can be replaced by restoring an earlier, unencrypted version. This recovers the original data without paying a ransom or relying on provider intervention.

Why this answer

Object versioning retains every prior version of an object, so when ransomware overwrites or encrypts the current version, the original unencrypted versions remain accessible. Recovery is performed by restoring the previous version (or promoting it to current) via the object versioning API or console.

Exam trap

The trap is reaching for a dedicated 'backup' or 'replication' answer when the question explicitly states versioning is enabled — versioning itself is the recovery mechanism.

How to eliminate wrong answers

Option A is wrong because the question specifies versioning is enabled — the recovery mechanism is versioning itself, not a separate provider backup service (which may not exist or may not be configured). Option B is wrong because cross-region replication would replicate the encrypted/overwritten objects too, unless replication of delete markers or versioning semantics is carefully configured; it is not the primary recovery path here. Option C is wrong because there is no generic 'ransomware recovery service' in cloud object storage — this is a fabricated option.

635
MCQmedium

In a public cloud IaaS model, which of the following security controls is the cloud customer primarily responsible for implementing?

A.Hypervisor security
B.Network infrastructure security
C.Physical security of data centers
D.Guest OS patch management
AnswerD

In IaaS the provider secures the physical hosts, hypervisor and network fabric, while the customer controls everything above, including the guest operating system. Patching the guest OS therefore falls to the customer, satisfying the stem's question of primary customer responsibility.

Why this answer

The customer is responsible for securing the guest OS and applications.

636
MCQhard

A multinational corporation uses a cloud-based data warehouse. The security team must ensure that data is irreversibly destroyed when it is no longer needed, even across backups and replicas. The cloud provider offers a cryptographic erase feature. What is the MOST important consideration when relying on cryptographic erase?

A.The data must be overwritten with random patterns before key destruction.
B.The encryption algorithm must be AES-256.
C.The cloud provider must certify that all storage media are physically destroyed.
D.The keys used for encryption must be securely destroyed and not recoverable.
AnswerD

Cryptographic erase works by destroying the encryption keys, rendering the data unreadable. If keys are backed up or escrowed, the data can be recovered, violating the requirement. Therefore, ensuring key destruction and non-recoverability is paramount. This includes removing all copies of the key from backups, HSMs, and key management systems.

Why this answer

Cryptographic erase relies on destroying the encryption keys so that data becomes permanently unrecoverable. The critical factor is ensuring that all copies of the keys are destroyed and cannot be restored from backups or escrow. Without key destruction, the data remains accessible.

Other options are either irrelevant or address different sanitization methods.

Exam trap

The trap here is focusing on the encryption algorithm or physical media destruction instead of the secure destruction of the encryption keys.

637
MCQhard

A company uses a hybrid cloud architecture with on-premises key management and cloud services. They need to ensure that encryption keys used for cloud data are never exposed to the cloud provider. Which key management approach best meets this requirement?

A.Use the cloud provider's native key management service
B.Store keys in a cloud key vault with access logs
C.Use a BYOK solution with an on-premises HSM and key caching
D.Deploy a cloud-based HSM and store keys only there
AnswerC

BYOK allows key generation and lifetime outside the cloud.

Why this answer

A Bring Your Own Key (BYOK) solution with an on-premises Hardware Security Module (HSM) allows the company to generate and store encryption keys locally, then securely transfer them to the cloud for use without exposing the raw key material to the cloud provider. Key caching ensures that the cloud service can perform operations without the provider ever having persistent access to the plaintext keys, meeting the requirement that keys are never exposed to the cloud provider.

Exam trap

ISC2 often tests the misconception that a cloud-based HSM (Option D) is equivalent to on-premises key control, but the trap is that any key stored in the cloud provider's infrastructure is still accessible to the provider, whereas BYOK with an on-premises HSM ensures the provider never has access to the plaintext key material.

How to eliminate wrong answers

Option A is wrong because using the cloud provider's native key management service means the provider generates, stores, and manages the keys, giving them full access to the key material and violating the requirement. Option B is wrong because storing keys in a cloud key vault with access logs still places the keys under the cloud provider's control and infrastructure, exposing them to the provider's administrators and potential breaches. Option D is wrong because deploying a cloud-based HSM and storing keys only there still means the keys reside within the cloud provider's environment, subject to their physical and logical access controls, thus exposing the keys to the provider.

638
Multi-Selecthard

A cloud security architect is hardening the metadata service on a fleet of EC2 instances that host a customer-facing web application. The team wants to reduce the risk of server-side request forgery leading to credential theft, while keeping the application's legitimate ability to retrieve instance role credentials. Which TWO measures should the architect implement? (Choose two.)

Select 2 answers
A.Set the instance metadata service hop limit to 1 so responses cannot traverse additional network hops.
B.Enable AWS CloudTrail data events on the S3 bucket that stores application logs.
C.Attach an IAM role with a permissions boundary that denies all actions except those the application needs.
D.Enforce IMDSv2 by setting the instance metadata options to require tokens (HttpTokens: required).
E.Disable the instance metadata service entirely on all web application instances.
AnswersA, D

A hop limit of 1 prevents metadata responses from being forwarded beyond the instance itself, defeating the common attack pattern where a proxy or container layer relays the request. Combined with token enforcement it closes both the request-forging and the forwarding path, and it does not interfere with direct metadata calls made by the application on the instance.

Why this answer

Requiring IMDSv2 forces token-based requests that SSRF payloads generally cannot produce, and a hop limit of 1 stops metadata responses from being relayed through proxies or container layers. Together they harden the endpoint while preserving legitimate role credential retrieval. The remaining choices either fail to block the retrieval path or break required functionality.

Exam trap

The trap here is believing that tightening the IAM role's permissions neutralizes SSRF credential theft, when the exposure is the metadata endpoint itself and the credentials remain retrievable regardless of how narrowly scoped they are.

639
MCQeasy

An organization is developing a mobile app that communicates with a cloud API. To ensure secure authentication, which of the following should be used?

A.Session cookies for state management
B.Basic authentication with username and password
C.OAuth 2.0 with OpenID Connect
D.API keys sent in HTTP headers
AnswerC

OAuth 2.0 supplies delegated authorisation tokens, while OpenID Connect adds an identity layer with a signed ID token, letting the app verify the end user. This satisfies the secure authentication requirement that plain OAuth 2.0 alone cannot provide.

Why this answer

OAuth 2.0 with OpenID Connect (OIDC) is the correct choice because it provides a delegated authorization framework (OAuth 2.0) combined with an identity layer (OIDC) that enables secure authentication and single sign-on (SSO) for mobile apps communicating with cloud APIs. This combination issues short-lived access tokens and ID tokens (typically JWTs) rather than exposing long-lived credentials, and supports token refresh, scoped permissions, and PKCE (Proof Key for Code Exchange) to prevent authorization code interception on mobile devices.

Exam trap

ISC2 often tests the misconception that API keys or Basic auth are sufficient for mobile-to-cloud authentication, but the trap is that these methods lack the delegation, token lifecycle management, and identity verification that OAuth 2.0 with OpenID Connect provides, which is the industry standard (RFC 6749, RFC 7519) for securing mobile API access.

How to eliminate wrong answers

Option A is wrong because session cookies are designed for server-side web applications with browser-based state management; mobile apps lack a browser context for cookie handling and are vulnerable to CSRF and session hijacking, making cookies unsuitable for native mobile-to-API communication. Option B is wrong because Basic authentication transmits credentials (Base64-encoded username:password) in every request, exposing them to interception and replay attacks; it offers no token expiration, no scoping, and no support for multi-factor authentication, violating cloud security best practices. Option D is wrong because API keys sent in HTTP headers are static, long-lived secrets that are easily leaked in client-side code (e.g., mobile app binaries), provide no user authentication or delegation, and lack built-in revocation mechanisms beyond key rotation.

640
MCQhard

Under GDPR, a cloud data controller must notify the supervisory authority of a personal data breach within what timeframe?

A.24 hours
B.72 hours
C.7 days
D.48 hours
AnswerB

GDPR Article 33 requires controllers to notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms.

Why this answer

GDPR Article 33 mandates that a data controller notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. This 72-hour window is a strict requirement unless the breach is unlikely to result in a risk to data subjects' rights and freedoms.

Exam trap

CCSP often tests the specific 72-hour GDPR breach notification window, and candidates may confuse it with other timelines such as the 24-hour notification for NIS2 or the 30-day notification for HIPAA, leading to wrong answer choices.

How to eliminate wrong answers

Option A is wrong because 24 hours is not the GDPR requirement; it may be a stricter internal policy or apply under other regulations, but not GDPR. Option C is wrong because 7 days exceeds the GDPR limit and would constitute non-compliance. Option D is wrong because 48 hours is not specified in GDPR; the regulation explicitly sets 72 hours.

641
MCQmedium

A developer is designing a microservices-based application in the cloud. They need to ensure communication between services is loosely coupled and resilient to failures. Which design pattern should they implement?

A.API gateway
B.Event-driven messaging
C.Service mesh
D.Database per service
AnswerB

Event-driven messaging decouples producers from consumers via an intermediary broker, so a failing or slow service does not block callers; messages queue and retry. This satisfies the loose-coupling and failure-resilience requirements better than synchronous request-response calls between microservices.

Why this answer

Event-driven messaging (B) is correct because it enables asynchronous, decoupled communication between microservices, allowing them to operate independently and remain resilient to failures. When a service publishes an event, other services consume it at their own pace, preventing cascading failures and ensuring the system can handle partial outages without blocking. This pattern directly supports loose coupling and fault tolerance, which are critical for cloud-based microservices architectures.

Exam trap

ISC2 often tests the distinction between patterns that manage communication (like service mesh) versus patterns that decouple communication (like event-driven messaging), and the trap here is that candidates confuse a service mesh's ability to handle retries and circuit breakers with the fundamental loose coupling provided by asynchronous event-driven architectures.

How to eliminate wrong answers

Option A (API gateway) is wrong because it acts as a single entry point for client requests and typically handles synchronous communication, which can introduce a bottleneck and tight coupling between services, not the loosely coupled, failure-resilient pattern required. Option C (Service mesh) is wrong because it focuses on managing service-to-service communication at the infrastructure layer (e.g., with sidecar proxies like Envoy) and does not inherently provide the asynchronous, event-driven decoupling needed for resilience; it handles traffic management and observability but not failure isolation through loose coupling. Option D (Database per service) is wrong because it is a data management pattern that ensures each microservice has its own database to avoid tight coupling at the data layer, but it does not address communication resilience or asynchronous messaging between services.

642
MCQeasy

A security engineer needs to ensure that all API calls made to cloud resources are logged for auditing. Which cloud auditing feature should be enabled to capture management and data events?

A.Cloud monitoring and logging service
B.Configuration management service
C.Threat detection service
D.Cloud audit logging service
AnswerD

A cloud audit logging service records API activity, capturing both management events (control-plane operations) and data events (object-level reads and writes) with caller identity, timestamp and source IP. Enabling it satisfies the requirement to log all API calls for auditing.

Why this answer

Cloud audit logging service (e.g., AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) is the correct feature because it captures API calls made to cloud resources, including management and data events, for auditing purposes. It records who made the call, when, from where, and what was done, providing the necessary audit trail. This is the standard service for logging API activity across cloud providers.

Exam trap

CCSP often tests the confusion between monitoring/logging services (operational) and audit logging services (compliance/auditing), so candidates who pick monitoring or threat detection fall into the trap.

How to eliminate wrong answers

Option A is wrong because cloud monitoring and logging services (e.g., CloudWatch, Azure Monitor) focus on metrics, logs, and alarms for operational monitoring, not specifically on capturing API calls for auditing — though they may integrate with audit logs, they are not the primary audit logging feature. Option B is wrong because configuration management services (e.g., AWS Config, Azure Policy) track resource configurations and compliance, not API call logging. Option C is wrong because threat detection services (e.g., GuardDuty, Security Center) analyze for malicious activity but do not provide the raw audit log of all API calls.

643
MCQeasy

Which characteristic of cloud computing allows a user to provision computing resources automatically without requiring human interaction with the service provider?

A.Rapid elasticity
B.Broad network access
C.On-demand self-service
D.Measured service
AnswerC

On-demand self-service lets consumers provision capabilities, such as server time and network storage, automatically through a provider's portal or API, with no human interaction on the provider side. This directly satisfies the stem's requirement for automatic provisioning without provider involvement, distinguishing it from broad network access or rapid elasticity.

Why this answer

On-demand self-service is the NIST SP 800-145 characteristic that lets a consumer unilaterally provision computing capabilities, such as server time and network storage, automatically as needed without requiring human interaction with each service provider. This is exactly the ability described in the question. The other characteristics address elasticity, network reachability, and metering, not automated provisioning without provider involvement.

Exam trap

The trap here is confusing on-demand self-service with rapid elasticity, since both involve automatic scaling; the key differentiator is that self-service is about provisioning without provider interaction, while elasticity is about scaling capacity to demand.

How to eliminate wrong answers

Option A is wrong because rapid elasticity refers to capabilities appearing to be unlimited and scaling out/in quickly to match demand, not to the consumer's ability to self-provision without provider interaction. Option B is wrong because broad network access means services are available over the network through standard mechanisms and heterogeneous client platforms, which is about reachability, not automated provisioning. Option D is wrong because measured service means resource usage is monitored, controlled, and reported for billing and optimization, which is about metering rather than self-service provisioning.

644
MCQhard

A cloud customer stores regulated data with a provider that uses sub-processors in multiple countries. The customer's legal team wants to ensure that international transfers of personal data remain lawful under the General Data Protection Regulation (GDPR). Which mechanism is the most appropriate to implement with the provider?

A.A binding corporate rules framework filed only by the cloud provider with its own supervisory authority.
B.Standard Contractual Clauses approved by the European Commission, supported by a transfer impact assessment.
C.A verbal assurance from the provider that data will remain within the European Economic Area.
D.A data processing agreement alone, because it binds the provider to GDPR terms regardless of where processing occurs.
AnswerB

For transfers to third countries without an adequacy decision, Standard Contractual Clauses are a recognized Chapter V mechanism. Following Schrems II, they should be paired with a transfer impact assessment and supplementary measures where laws create undue access risk. This combination directly addresses lawful transfer obligations in the cloud supply chain.

Why this answer

Transfers of personal data outside the European Economic Area require a Chapter V mechanism. Standard Contractual Clauses are a widely used appropriate safeguard, and after Schrems II they must be supported by a transfer impact assessment and, where needed, supplementary measures. This pairing best satisfies the customer's need for lawful, defensible international transfers.

Exam trap

The trap here is treating a data processing agreement as sufficient for international transfers, when Article 28 agreements and Chapter V transfer tools are separate requirements.

645
MCQmedium

A cloud customer is preparing for an audit of its cloud environment. The provider offers a SOC 2 Type II report covering security and availability. What does this report provide to the customer's auditors?

A.A certification issued by the AICPA that the provider fully complies with all applicable laws and regulations.
B.An opinion on the design and operating effectiveness of the provider's controls over a period of time.
C.A guarantee that the provider's controls will remain effective for the next twelve months.
D.A point-in-time description of controls without any testing of operating effectiveness.
AnswerB

A SOC 2 Type II report covers a period and includes the service auditor's opinion on both the suitability of design and the operating effectiveness of controls. This gives the customer's auditors evidence that controls functioned consistently, which is more persuasive than a point-in-time description.

Why this answer

A SOC 2 Type II report is an attestation covering a period, with the service auditor opining on the design and operating effectiveness of controls against selected trust services criteria. For the customer's auditors, it supplies independent evidence of sustained control operation, though they must still consider scope, period, and complementary user entity controls.

Exam trap

The trap here is conflating SOC 2 Type I and Type II reports, treating a point-in-time design description as evidence of operating effectiveness over time.

646
MCQeasy

A small business wants to use a cloud service but has limited in-house IT expertise. Which cloud service model requires the least customer management responsibility?

A.IaaS
B.SaaS
C.PaaS
D.FaaS
AnswerB

SaaS delivers a complete, provider-managed application; the customer only manages users, access and data, not the underlying platform, runtime or infrastructure. This satisfies the constraint of limited in-house IT expertise, unlike IaaS or PaaS, which require patching, scaling and configuration effort.

Why this answer

SaaS (Software as a Service) delivers a complete application managed entirely by the cloud provider, so the customer only needs to use the software without managing underlying infrastructure, platforms, or runtime. For a small business with limited IT expertise, this model minimizes operational overhead because the provider handles maintenance, patching, and availability.

Exam trap

ISC2 often tests the misconception that PaaS requires less management than SaaS because candidates confuse 'platform management' with 'application management,' but PaaS still leaves the customer responsible for application code and its dependencies.

How to eliminate wrong answers

Option A is wrong because IaaS requires the customer to manage virtual machines, storage, and networking, which demands significant IT expertise for OS patching, security groups, and configuration. Option C is wrong because PaaS still requires the customer to manage application code, runtime settings, and sometimes database configurations, though the provider manages the underlying platform. Option D is wrong because FaaS (Function as a Service) involves writing and deploying individual functions, which still requires development skills and management of function triggers, dependencies, and scaling logic.

647
MCQmedium

A cloud customer is concerned about the right to erasure under GDPR because the cloud provider replicates data across multiple regions and keeps backups. What technical challenge does this create for complying with a erasure request?

A.The data must be anonymized instead of deleted.
B.The customer must notify all other users who may have accessed the data.
C.The cloud provider may not be able to delete data from all replicas and backups within the required time frame.
D.The cloud provider must retain the data for audit purposes.
AnswerC

Replication across regions and retained backups mean erasure cannot propagate instantly; the provider must locate and purge every copy, including immutable or archived backups, within GDPR's one-month response window, which is the technical obstacle the stem describes.

Why this answer

The right to erasure (Article 17) requires controllers to delete personal data without undue delay. However, in cloud environments, data is often replicated across multiple regions for availability and durability, and backups may be retained for disaster recovery or legal compliance. Ensuring deletion from all replicas and backups within the required timeframe is technically challenging because backups are typically immutable and may not be immediately overwritten.

Exam trap

CCSP often tests the technical limitations of erasure in distributed cloud systems, and candidates may incorrectly assume that deletion is instantaneous or that anonymization is always an acceptable substitute, missing the nuance of backup and replication challenges.

How to eliminate wrong answers

Option A is wrong because anonymization is an alternative to deletion only in specific cases (e.g., for research or statistical purposes) and does not satisfy an erasure request when deletion is technically feasible. Option B is wrong because notifying other users who accessed the data is not a GDPR requirement for erasure; it may be relevant for data portability or access requests, but not for erasure. Option D is wrong because while audit retention may be a legal obligation, it does not override the right to erasure unless a specific exemption applies; the primary challenge is technical, not a blanket retention requirement.

648
MCQmedium

A company is adopting a hybrid cloud model to run sensitive workloads on-premises and less critical applications in the public cloud. Which security consideration is most critical for this environment?

A.Using a single cloud provider for both environments
B.Ensuring high-speed network connectivity
C.Maintaining consistent security policies across both environments
D.Implementing data encryption at rest only
AnswerC

Hybrid splits workloads across two trust domains, so a single control framework must span both. Consistent policies satisfy the stem's need to govern sensitive on-premises systems and public cloud workloads under one security posture, preventing gaps where data crosses the boundary.

Why this answer

In a hybrid cloud model, the most critical security consideration is maintaining consistent security policies across both on-premises and public cloud environments. This ensures that security controls, access management, data protection, and compliance requirements are uniformly enforced, reducing gaps that attackers could exploit. Inconsistencies can lead to misconfigurations, unauthorized access, and data leakage between environments.

While network connectivity and encryption are important, they are components of a broader policy consistency strategy.

Exam trap

CCSP often tests the misconception that encryption or network speed alone solves hybrid cloud security, but the exam expects recognition that policy consistency and unified governance are the foundation for secure hybrid architectures.

How to eliminate wrong answers

Option A is wrong because using a single cloud provider does not address the hybrid nature; the company already has on-premises workloads, and a single provider may not be feasible or optimal. Option B is wrong because high-speed network connectivity is an availability and performance consideration, not the most critical security consideration; it does not ensure security policy enforcement. Option D is wrong because implementing data encryption at rest only is insufficient; it ignores data in transit, access controls, and policy consistency across environments, and encryption alone does not address all security risks.

649
MCQhard

A cloud security architect is designing an API gateway for a microservices application. The gateway must authenticate requests, enforce rate limiting, and log all transactions for audit. Which of the following security controls is most critical to protect against API abuse?

A.Implement rate limiting and throttling based on client identity and request volume.
B.Use TLS 1.3 to encrypt all traffic between clients and the gateway.
C.Validate and sanitize all input parameters to prevent injection attacks.
D.Require API keys for all requests and revoke keys of suspicious clients.
AnswerA

Rate limiting and throttling keyed to client identity directly counters API abuse by capping request volume per consumer, mitigating credential-stuffing, scraping and denial-of-service bursts. It satisfies the stem's enforcement requirement while complementing authentication and audit logging, making it the most critical control against abusive API usage patterns.

Why this answer

Rate limiting and throttling directly prevent API abuse by limiting request frequency based on client identity and volume. Option B is incorrect because encryption protects data in transit but does not prevent abuse. Option C is incorrect because input validation prevents injection attacks but not volume-based abuse.

Option D is incorrect because API keys authenticate clients but do not limit usage; rate limiting is required for abuse protection.

650
MCQmedium

A security team is reviewing a cloud application's CI/CD pipeline. They want to ensure that only approved open-source libraries are used in production builds. Which approach best addresses this requirement?

A.Segment the build network to limit internet access
B.Perform static code analysis after each build
C.Implement a software composition analysis (SCA) tool in the pipeline
D.Require manual approval for all library updates
AnswerC

Software composition analysis inventories every open-source component and its transitive dependencies, then matches them against vulnerability and licence databases. Embedding SCA in the CI/CD pipeline enforces the approval constraint by failing builds that introduce unapproved libraries, giving the gate the stem requires before artefacts reach production.

Why this answer

A Software Composition Analysis (SCA) tool is specifically designed to automatically scan open-source libraries for known vulnerabilities, licensing issues, and version compliance. By integrating SCA into the CI/CD pipeline, the team can enforce a policy that only approved libraries (e.g., those passing a security and license review) are allowed in production builds, blocking unapproved or vulnerable components before deployment.

Exam trap

ISC2 often tests the distinction between SAST (static code analysis), DAST (dynamic analysis), and SCA, expecting candidates to recognize that only SCA directly addresses the management and approval of third-party open-source components and their associated risks.

How to eliminate wrong answers

Option A is wrong because segmenting the build network to limit internet access only restricts network connectivity, but does not prevent developers from introducing unapproved libraries already cached or stored locally; it also breaks legitimate dependency resolution from approved repositories. Option B is wrong because static code analysis (SAST) focuses on source code flaws (e.g., SQL injection, buffer overflows) and does not inspect third-party library metadata, licenses, or known CVEs in dependencies. Option D is wrong because requiring manual approval for all library updates is an operational process that does not scale, lacks automated detection of unapproved libraries, and introduces human error and delay without providing a technical enforcement gate in the pipeline.

651
MCQeasy

A cloud security architect is designing a multi-tenant virtualized environment. Which type of hypervisor is considered most secure for cloud deployments due to its reduced attack surface and direct hardware control?

A.Type 1 bare-metal hypervisor
B.Type 2 hosted hypervisor
C.Emulated hypervisor (e.g., QEMU without KVM)
D.Container runtime (e.g., Docker)
AnswerA

A Type 1 hypervisor runs directly on the host hardware, so it exposes no underlying general-purpose OS for a guest escape to target. That smaller attack surface, plus direct hardware control, satisfies the multi-tenant isolation requirement where a compromised tenant must not reach others or the platform.

Why this answer

A Type 1 bare-metal hypervisor runs directly on the host's hardware, controlling hardware resources and managing guest VMs without an underlying operating system. This architecture reduces the attack surface because there is no general-purpose OS to exploit, and it provides direct hardware control for performance and security. It is considered the most secure for cloud deployments.

Exam trap

The trap is assuming that containers or Type 2 hypervisors provide equivalent security to Type 1 hypervisors, when the additional layers or shared kernel increase risk.

How to eliminate wrong answers

Option B is wrong because a Type 2 hosted hypervisor runs as an application on top of a host OS, which adds an additional layer (the host OS) that increases the attack surface and potential for privilege escalation. Option C is wrong because an emulated hypervisor like QEMU without KVM uses software emulation, which is slower and more complex, often introducing more vulnerabilities; it does not provide direct hardware control. Option D is wrong because a container runtime like Docker shares the host OS kernel and does not provide the same level of isolation as a Type 1 hypervisor; containers are not virtual machines and are more susceptible to kernel exploits.

652
MCQmedium

A cloud application uses IAM roles to grant permissions to compute instances. What is the primary security advantage of this approach over hardcoding credentials?

A.Simplified load balancing
B.Elimination of hardcoded secrets
C.Improved application performance
D.Reduced network latency
AnswerB

IAM roles let compute instances obtain short-lived credentials automatically from the instance metadata service, so no long-lived secret is stored in code or configuration. This directly satisfies the stem's constraint: removing hardcoded credentials eliminates the primary leak vector, since rotating tokens expire and cannot be extracted from source repositories.

Why this answer

IAM roles issue short-lived, automatically rotated temporary credentials to compute instances via instance metadata (e.g., AWS IMDSv2, Azure Managed Identity, GCP service accounts), so no long-lived secret ever exists in code, config files, or repos. This removes the primary attack vector of credential theft via source code leaks, container image scraping, or log exposure. Because the credentials are ephemeral and scoped to the role's policy, blast radius from a compromised instance is also limited.

Exam trap

CCSP often tests the misconception that IAM roles improve performance or simplify networking, when the actual benefit is eliminating long-lived static credentials and enabling least-privilege, short-lived access.

How to eliminate wrong answers

Option A is wrong because load balancing is a traffic-distribution concern handled by ELB/ALB and has no relationship to credential management. Option C is wrong because IAM role assumption adds a metadata-service call and STS token exchange, which if anything adds minor latency rather than improving performance. Option D is wrong because network latency is determined by topology, routing, and distance — not by how credentials are issued to an instance.

653
MCQeasy

After decommissioning a cloud database, a company is concerned about data remanence. They have overwritten all storage blocks with zeros. However, regulatory auditors require proof that the data is unrecoverable. What additional step should the company take?

A.Physically destroy the storage media
B.Shred the hard drives
C.Request a certificate of destruction from the cloud provider
D.Degauss the drives
AnswerC

Overwriting blocks with zeros is insufficient evidence for auditors, since the cloud provider controls the underlying media and cannot prove physical erasure. A certificate of destruction documents that the provider securely sanitised or destroyed the media, satisfying the regulatory proof requirement.

Why this answer

In a cloud environment, the customer does not have physical access to the underlying storage media. Overwriting with zeros is a software-based sanitization method, but cloud providers typically do not allow customers to perform physical destruction or degaussing. The correct additional step is to request a certificate of destruction from the cloud provider, which serves as auditable proof that the provider has performed its own secure disposal process (e.g., NIST SP 800-88 compliant media sanitization) and that the data is unrecoverable.

Exam trap

The trap here is that candidates mistakenly apply on-premises data destruction methods (physical destruction, shredding, degaussing) to a cloud environment, forgetting that the customer lacks physical access and must rely on the provider's attestation and compliance documentation.

How to eliminate wrong answers

Option A is wrong because physically destroying storage media is not feasible for a cloud customer who lacks physical access to the provider's data centers; such actions would violate the shared responsibility model and the cloud provider's security policies. Option B is wrong because shredding hard drives is a physical destruction method that requires possession of the drives, which the customer does not have in a cloud IaaS/PaaS/SaaS model; the provider handles physical media lifecycle. Option D is wrong because degaussing (using a strong magnetic field to erase data) is only effective on magnetic media (e.g., HDDs) and cannot be performed by the customer on cloud infrastructure; it also does not work on SSDs or flash-based storage, which are common in cloud environments, and the customer lacks physical access to apply degaussing equipment.

654
Multi-Selectmedium

A retail enterprise is defining its cloud governance program before migrating workloads to a public cloud provider. The CISO wants controls that address the loss of direct physical control inherent in the cloud. Which TWO governance elements are MOST important to establish first? (Choose two.)

Select 2 answers
A.An identity and access management framework with least privilege and centralized federation
B.A mandate that all production data remain on dedicated physical hosts owned by the enterprise
C.A data classification and handling policy that maps each data category to approved cloud services
D.A policy prohibiting any use of provider-managed encryption keys for data at rest
E.A requirement that all cloud workloads use the provider's default security configuration
AnswersA, C

In the cloud, identity is the primary security perimeter because there is no physical gate to guard. A federated identity provider with role-based, least-privilege assignments ensures that access to consoles, APIs, and data is centrally granted, reviewed, and revoked. Without this, the enterprise cannot demonstrate who can reach which resources, which is fundamental to governing a multi-tenant environment.

Why this answer

Governance replaces lost physical control with policy and identity. A data classification and handling policy translates business risk into rules about which services, regions, and protections each data category requires, while a federated identity framework with least privilege governs who and what can reach those resources. Default configurations, dedicated-host mandates, and blanket key prohibitions are either too permissive or too rigid to serve as foundational governance.

Exam trap

The trap here is believing that adopting provider defaults or demanding dedicated hardware substitutes for governance, when control in the cloud comes from enterprise-defined policy and identity.

655
MCQeasy

A company is migrating to a public cloud and must ensure compliance with PCI DSS. Which responsibility does the cloud customer retain under the shared responsibility model?

A.Patching the hypervisor and underlying host operating systems
B.Configuring security groups and access controls for its workloads
C.Managing physical security of the data center
D.Ensuring the cloud provider's network is segmented from other tenants
AnswerB

Under the shared responsibility model, the cloud customer is always responsible for securing its own data, applications, and configurations, including security groups and access controls. The provider secures the infrastructure, but the customer must manage logical access to its instances and data. This is a fundamental tenet of cloud security and PCI DSS compliance.

Why this answer

In the shared responsibility model, the cloud customer is responsible for security 'in' the cloud, which includes configuring security groups, identity and access management, and application-level controls. The provider is responsible for security 'of' the cloud, such as physical security, hypervisor patching, and network infrastructure. For PCI DSS, the customer must ensure its configurations meet the standard's requirements.

Exam trap

The trap here is assuming that the cloud provider's PCI DSS compliance covers the customer's own configurations; the customer must still secure its own environment.

656
MCQmedium

A company uses Azure Defender for Cloud to protect its hybrid environment. Which of the following is a feature of Azure Defender that provides vulnerability assessment for virtual machines?

A.Azure Secure Score
B.Azure Policy
C.Defender for Servers
D.Azure Sentinel
AnswerC

Defender for Servers includes Microsoft Defender for Endpoint integration, delivering agent-based vulnerability assessment for Azure, AWS, GCP and on-premises VMs. This satisfies the stem's hybrid-environment constraint, since the same scanning capability extends beyond Azure to non-Azure machines, unlike agentless scanning limited to Azure and AWS resource types.

Why this answer

Azure Defender includes integrated vulnerability assessment via Qualys or Microsoft built-in scanner, available for Defender for Servers.

657
MCQeasy

Which of the following is the primary benefit of using client-side encryption for data stored in the cloud?

A.Automatic key rotation
B.Maximum control over encryption keys
C.Simplified key management
D.Reduced latency for data access
AnswerB

Client-side encryption means data is encrypted before it leaves the organisation, so the cloud provider never holds the plaintext or the keys. That gives maximum control over key management, unlike server-side options where the provider participates.

Why this answer

Client-side encryption means the data is encrypted before it is sent to the cloud, and the customer retains full control over the encryption keys. This gives the customer maximum control over key management, including key generation, rotation, and storage, ensuring that the cloud provider never has access to the plaintext data or the keys.

Exam trap

CCSP often tests the misconception that client-side encryption simplifies key management or provides automatic rotation, when in fact it increases customer responsibility and control.

How to eliminate wrong answers

Option A is wrong because automatic key rotation is a feature that can be provided by cloud key management services (e.g., AWS KMS, Azure Key Vault) and is not exclusive to client-side encryption; in fact, client-side encryption often requires manual key rotation. Option C is wrong because simplified key management is typically a benefit of server-side encryption where the cloud provider manages keys; client-side encryption increases key management complexity. Option D is wrong because reduced latency is not a primary benefit; client-side encryption can add latency due to encryption/decryption overhead on the client side.

658
MCQmedium

A healthcare SaaS company runs containerized microservices on Google Kubernetes Engine (GKE). The security team scans containers with a vulnerability scanner and finds that base images have several critical vulnerabilities. The container build process uses a Dockerfile that pulls the latest Ubuntu image from Docker Hub. The team wants to reduce the attack surface without delaying feature releases. What is the best approach?

A.Place a network security policy to restrict outbound traffic from pods
B.Schedule weekly automated rebuilds with the latest base image
C.Adopt minimal hardened base images and integrate vulnerability scanning into CI/CD
D.Refactor all applications to use scratch as base image
AnswerC

Minimal hardened base images strip unnecessary packages, shrinking the exploitable surface, while CI/CD scanning catches vulnerabilities before release rather than after. Together they satisfy the stem's constraint of reducing attack surface without delaying feature releases, unlike pinning tags alone.

Why this answer

Adopting minimal hardened base images (e.g., distroless, Alpine, or UBI-minimal) reduces the number of packages and thus the attack surface, while integrating vulnerability scanning into CI/CD catches issues early without slowing releases. This directly addresses the root cause—vulnerable base images—and provides continuous feedback. The other options either don't fix the base image problem or are too disruptive.

Exam trap

CCSP often tests the misconception that network controls or periodic rebuilds alone can mitigate image vulnerabilities, when the core issue is the base image and lack of continuous scanning.

How to eliminate wrong answers

Option A is wrong because network policies restrict traffic but do not remove vulnerabilities from container images. Option B is wrong because weekly rebuilds with the latest base image may still include vulnerable packages and do not guarantee a reduced attack surface; they also don't integrate scanning. Option D is wrong because refactoring all applications to use scratch as a base image is often impractical (e.g., requires static binaries, no shell) and would delay feature releases.

659
Multi-Selecthard

A cloud security team is reviewing a provider's architecture documentation to assess multi-tenancy risks before migrating regulated workloads. The team wants to verify that logical isolation between tenants is enforced at multiple layers. Which TWO provider controls are MOST directly relevant to preventing one tenant from accessing another tenant's data or processes? (Choose two.)

Select 2 answers
A.A disaster recovery plan with a documented recovery time objective
B.A provider-published privacy policy describing data handling practices
C.Tenant-scoped encryption keys with strict key separation and access controls
D.Hypervisor-level virtual machine isolation with separate virtual network segments per tenant
E.A published service level agreement guaranteeing 99.99 percent availability
AnswersC, D

Encrypting each tenant's data with distinct keys, managed under strict access controls, ensures that even if storage media or backups are shared, one tenant cannot decrypt another's data. This cryptographic separation complements logical isolation by protecting data at rest and in transit, directly reducing the impact of any isolation failure in the shared infrastructure.

Why this answer

Preventing cross-tenant access requires controls that enforce boundaries at the compute, network, and data layers. Hypervisor isolation with per-tenant network segmentation separates running workloads and their traffic, while tenant-scoped encryption keys protect data even on shared storage. Governance documents such as SLAs, privacy policies, and disaster recovery plans do not create technical isolation boundaries.

Exam trap

The trap here is selecting contractual or governance artifacts as isolation controls, when only technical mechanisms that enforce separation of execution, networking, or cryptographic keys actually prevent cross-tenant access.

660
MCQmedium

A company stores sensitive backups in cloud object storage. The security policy requires that backups be recoverable even if the primary cloud region suffers a catastrophic outage, and that the backup data remain encrypted with keys the company controls throughout replication. Which configuration best satisfies both requirements?

A.Single-region storage with versioning and object lock enabled
B.Cross-region replication with client-side encryption using keys held only in the source region
C.Cross-region replication with customer-managed keys replicated to the destination region
D.Cross-region replication with provider-managed encryption keys in both regions
AnswerC

Replicating objects to a second region protects against a regional outage, and using customer-managed keys that are also replicated to the destination region ensures the company retains cryptographic control and can decrypt in the secondary region without provider key custody. This combination satisfies both durability and key ownership requirements, and it is the standard pattern for regulated backup architectures.

Why this answer

The scenario imposes two independent requirements: survive a regional outage and keep encryption keys under company control throughout replication. Cross-region replication satisfies the first, and customer-managed keys replicated to the destination region satisfy the second. Client-side encryption with keys confined to the source region fails because a regional outage would strand the keys, leaving replicated ciphertext unrecoverable.

Exam trap

The trap here is focusing only on where the ciphertext is replicated while forgetting that the decryption keys must also survive the same regional failure.

661
Multi-Selectmedium

A cloud architect is designing a multi-tenant SaaS application. Which TWO design principles are critical for ensuring tenant isolation? (Select TWO.)

Select 2 answers
A.Network isolation between tenants
B.Single shared database for all tenants
C.Using the same OS image for all tenants
D.Data isolation (e.g., schema per tenant or encryption)
E.Resource pooling across tenants
AnswersA, D

Segmenting tenant traffic through separate VLANs, subnets or security groups prevents one tenant's workloads from reaching another's, satisfying the isolation constraint at the network layer. Without this, lateral movement across a shared multi-tenant environment becomes possible even when application-level controls are correctly configured.

Why this answer

Network isolation between tenants (A) is critical because it prevents cross-tenant traffic and lateral movement by placing each tenant in separate VPCs, subnets, security groups, or namespaces, ensuring that one tenant's workloads cannot reach another's over the network. Data isolation (D), such as a schema-per-tenant model or per-tenant encryption keys, is equally essential because it guarantees that tenant data is logically or cryptographically separated, preventing unauthorized reads or writes even if application-layer bugs occur. Together, A and D address the two primary isolation dimensions—network and data—required for a secure multi-tenant SaaS design.

A single shared database for all tenants (B) is not a critical isolation principle; without additional controls it actually weakens isolation by co-mingling tenant records. Using the same OS image for all tenants (C) is a standardization and patching benefit, not a tenant-isolation mechanism. Resource pooling across tenants (E) improves cost efficiency and utilization but, by itself, increases the risk of cross-tenant interference rather than ensuring isolation.

Exam trap

CCSP often tests the misconception that resource pooling or shared databases are sufficient for multi-tenancy, but the exam expects recognition that isolation must be enforced at network and data layers to prevent cross-tenant access.

662
MCQeasy

A development team is building a cloud application that stores sensitive customer data in a managed database service. The security policy requires that data be encrypted at rest with keys that the organization controls and can rotate independently of the cloud provider. Which approach meets this requirement?

A.Encrypt sensitive columns at the application layer using a key derived from a static passphrase embedded in the source code.
B.Enable transparent data encryption on the database and store the master key in the application's configuration file.
C.Encrypt the database volume with a customer-managed key stored in the cloud provider's key management service, with key rotation and access policies defined by the organization.
D.Use the cloud provider's default service-managed encryption keys and enable automatic key rotation in the provider console.
AnswerC

Customer-managed keys in the provider's KMS give the organization control over key lifecycle, rotation, and access policies while integrating with the managed database. This satisfies both encryption at rest and independent key control. The organization can rotate, disable, or revoke keys and audit their use, meeting the policy requirement.

Why this answer

The requirement is encryption at rest with organizational control over keys. Customer-managed keys in the cloud KMS allow the organization to define rotation, access policies, and revocation while integrating with the managed database. Provider-managed keys, keys in config files, and passphrase-derived keys do not provide the required control and lifecycle management.

Exam trap

The trap here is equating encryption at rest with key control, when service-managed keys do not give the organization independent rotation and revocation authority.

663
MCQmedium

An organization is using Azure and wants to centrally collect activity logs from multiple subscriptions into a single Log Analytics workspace for cross-account analysis and retention management. What is the best approach?

A.Use Azure Monitor Agent on all VMs to collect logs.
B.Enable Azure Sentinel on each subscription and aggregate using cross-workspace queries.
C.Use Azure Policy to deploy Diagnostic Settings on each subscription to stream Activity Logs to a central Log Analytics workspace.
D.Use Azure Storage account with event grid to forward logs to a central location.
AnswerC

Azure Policy's deployIfNotExists effect assigns Diagnostic Settings at scale, streaming each subscription's Activity Log to one central Log Analytics workspace. This satisfies the cross-subscription collection and retention requirement without per-subscription manual configuration, since policy remediation enrols new subscriptions automatically.

Why this answer

Azure Policy can enforce the deployment of Diagnostic Settings across all subscriptions, automatically streaming Activity Logs to a central Log Analytics workspace. This ensures centralized collection, cross-account analysis, and retention management without manual configuration per subscription.

Exam trap

A common mistake is confusing Azure Monitor Agent (for VM guest OS logs) with Diagnostic Settings (for Azure platform logs), leading candidates to mistakenly choose agent-based collection for subscription-level Activity Logs.

How to eliminate wrong answers

Option A is wrong because Azure Monitor Agent collects OS-level performance and event logs from VMs, not Azure Activity Logs (which are subscription-level control plane logs). Option B is wrong because Azure Sentinel is a SIEM that can use cross-workspace queries, but it does not natively aggregate Activity Logs from multiple subscriptions into a single workspace; it requires Diagnostic Settings to forward logs first, making it an unnecessary extra layer. Option D is wrong because Azure Storage with Event Grid can forward logs, but it introduces latency, complexity, and lacks the native querying and retention management capabilities of Log Analytics workspaces.

664
MCQhard

An organization needs to migrate a legacy application to the cloud. The application requires full control over the operating system, middleware, and runtime. The team wants to minimize management overhead while retaining OS-level access. Which cloud service model is most appropriate?

A.IaaS
B.SaaS
C.FaaS
D.PaaS
AnswerA

IaaS provides raw compute, storage, and networking while the customer retains full control of the operating system, middleware, and runtime. The provider manages only the underlying infrastructure, satisfying the OS-level access requirement while offloading hardware management, minimising overhead.

Why this answer

IaaS provides virtualized compute, storage, and networking where the customer manages the OS, middleware, and runtime while the provider manages the underlying physical infrastructure. This matches the requirement for full OS-level control with reduced management overhead compared to on-premises. SaaS, PaaS, and FaaS abstract away the OS, so they cannot satisfy the need for OS-level access.

Exam trap

CCSP often tests the shared responsibility boundary, tricking candidates into picking PaaS when the requirement explicitly mentions OS-level control, which only IaaS provides.

How to eliminate wrong answers

Option B is wrong because SaaS delivers a complete application managed by the provider, giving the customer no control over OS, middleware, or runtime. Option C is wrong because FaaS (serverless) abstracts all infrastructure including the runtime, so the customer only supplies function code and has no OS access. Option D is wrong because PaaS provides a managed platform for deploying code but hides the OS and middleware, preventing OS-level control.

665
MCQmedium

A cloud engineer must ensure that data written to a cloud block storage volume is encrypted at rest using keys the organization controls, while allowing the provider to perform snapshots. The organization wants to avoid re-encrypting data in the application and wants minimal performance impact. Which approach BEST meets these requirements?

A.Enable volume encryption using a customer-managed key stored in a cloud key management service, integrated with the block storage service.
B.Store the volume on encrypted hardware and document the provider's physical controls in the risk register.
C.Use provider-managed encryption with provider-owned keys and rely on the provider's compliance attestations.
D.Implement application-level encryption before writing blocks, managing keys in an on-premises HSM.
AnswerA

Volume-level encryption with a customer-managed key encrypts data at rest transparently to the application, so no application changes are needed. The organization controls the key lifecycle in the cloud KMS, and the provider can still take snapshots because encryption is handled at the storage layer. Performance impact is minimal since encryption is offloaded to the storage infrastructure.

Why this answer

Volume encryption with a customer-managed key in a cloud KMS satisfies both the at-rest encryption mandate and the key-control requirement while remaining transparent to the application. The provider can still snapshot the volume because encryption occurs at the storage layer, and performance impact is minimal. Application-level encryption and provider-managed keys fail one or more stated constraints.

Exam trap

The trap here is equating provider-managed encryption with customer-controlled keys, when only customer-managed keys in a KMS give the organization lifecycle control.

666
MCQmedium

A cloud security engineer is configuring an Amazon S3 bucket that must store sensitive financial data. The requirement is that all data must be encrypted at rest with keys that the organization controls and can rotate, and that access to the keys must be auditable and separable from the data access permissions. Which S3 encryption option BEST meets these requirements?

A.SSE-C where the customer provides the encryption key with each request, and the key is stored in AWS Secrets Manager for automatic retrieval.
B.SSE-KMS with a customer managed key in AWS KMS, with a key policy that grants decrypt permissions only to specific roles and enables automatic key rotation.
C.SSE-S3 with default bucket encryption enabled and S3 Block Public Access turned on.
D.Client-side encryption using the AWS Encryption SDK with a master key stored in an on-premises HSM, and uploading the encrypted objects to S3.
AnswerB

SSE-KMS with a customer managed key gives the organization control over the key, supports automatic rotation, and allows a key policy that is separate from S3 bucket policies. AWS CloudTrail logs all KMS key usage, providing auditability, and access to keys can be granted independently of access to the S3 data.

Why this answer

The requirement calls for customer-controlled keys, rotation, and auditable, separable key access. SSE-KMS with a customer managed key in AWS KMS satisfies all three: the organization creates and controls the key, can enable automatic rotation, and uses key policies and IAM to separate key access from S3 data access. CloudTrail logs every KMS operation, providing the needed audit trail.

Other options either use AWS-managed keys or shift key management outside AWS, failing at least one requirement.

Exam trap

The trap here is choosing SSE-C or client-side encryption because they seem to offer more control, while overlooking that SSE-KMS with a customer managed key already provides control, rotation, and integrated auditability without the operational burden.

667
Multi-Selectmedium

A cloud security team is implementing tokenization for a payment system. Which THREE statements correctly describe tokenization characteristics?

Select 3 answers
A.Tokenization uses encryption algorithms to protect data.
B.The original sensitive data is stored in a secure token vault.
C.The token is a randomly generated string with no mathematical relationship to the original data.
D.Tokens can be used for transactions without exposing the original data.
E.Tokenization is reversible using the token alone.
AnswersB, C, D

Tokenisation replaces sensitive data with a token and stores the original value in a secured token vault, which is the only place the mapping can be reversed. The vault therefore becomes a high-value asset requiring strict access controls and encryption.

Why this answer

Option B is correct because tokenization requires a secure token vault (a protected data store, often encrypted and access-controlled) that maps each token back to its original sensitive value, such as a PAN, so the real data is never held in the transaction environment. Option C is correct because a token is a randomly generated surrogate value (for example, a 16-digit number) that has no mathematical or algorithmic relationship to the original data, unlike ciphertext produced by encryption. Option D is correct because the token can be passed through payment and business processes in place of the real data, allowing transactions to complete without exposing the original sensitive value.

Option A is not correct as stated because tokenization itself is a substitution technique, not an encryption algorithm, even though encryption is often used to protect the vault. Option E is not correct because detokenization requires access to the token vault and its mapping; the token alone cannot reverse the process.

Exam trap

ISC2 often tests the misconception that tokenization is a form of encryption, but the key distinction is that tokenization uses a lookup table (vault) rather than a mathematical algorithm, making it non-reversible without vault access.

668
MCQeasy

A cloud application uses OAuth 2.0 for authorization. What is the primary purpose of using a refresh token in this flow?

A.To obtain a new access token when the current one expires without user interaction.
B.To grant the same access token indefinitely.
C.To authenticate the user without a password.
D.To store user credentials on the resource server for later use.
AnswerA

A refresh token lets the client request a fresh access token from the authorisation server after expiry, avoiding repeated user consent. It satisfies the constraint of maintaining sessions without re-authentication while access tokens stay short-lived.

Why this answer

In OAuth 2.0, access tokens are short-lived by design to limit the window of compromise. A refresh token is a long-lived credential that allows the client to obtain a new access token from the authorization server without requiring the user to re-authenticate or re-consent. This enables seamless, ongoing access to protected resources while maintaining security through short-lived access tokens.

Exam trap

ISC2 often tests the misconception that refresh tokens are used for authentication or that they extend the life of the same access token, rather than understanding they are a separate credential used to obtain a new access token.

How to eliminate wrong answers

Option B is wrong because refresh tokens do not grant indefinite access; they can be revoked, have their own expiration, and are used to obtain new access tokens, not to extend the life of the same token. Option C is wrong because refresh tokens are not used for authentication; they are an authorization grant that assumes prior authentication has already occurred. Option D is wrong because refresh tokens are stored on the client (or client's backend), not on the resource server, and they are never used to store user credentials.

669
MCQmedium

A security analyst is configuring an API Gateway for a cloud application. The application must handle high traffic and prevent abuse from a single client. Which feature should the analyst enable to limit the number of requests from a client within a specified time window?

A.Rate limiting
B.TLS enforcement
C.Web Application Firewall (WAF) integration
D.API key authentication
AnswerA

Rate limiting caps the number of requests a client may send within a defined time window, returning throttling responses once the threshold is exceeded. This directly satisfies the requirement to prevent a single client from abusing the API during high traffic.

Why this answer

Rate limiting is the API Gateway feature that restricts the number of requests a client can make within a specified time window (e.g., 1000 requests per minute). It directly addresses the requirement to handle high traffic and prevent abuse from a single client by throttling or rejecting excess requests. This protects backend services from being overwhelmed and ensures fair usage.

Exam trap

The trap is confusing authentication (API keys) or encryption (TLS) with abuse prevention — candidates may think that requiring an API key stops abuse, but the exam tests whether you know that only rate limiting enforces request quotas per client.

How to eliminate wrong answers

Option B is wrong because TLS enforcement ensures encrypted communication between clients and the API Gateway; it does not limit request volume or prevent abuse from a single client. Option C is wrong because WAF integration protects against web application attacks (SQL injection, XSS) by filtering malicious payloads; it does not enforce request quotas per client. Option D is wrong because API key authentication identifies and authenticates clients but does not limit how many requests they can make — a valid API key can still be used for abuse unless rate limiting is also applied.

670
MCQeasy

A cloud administrator needs to ensure that all data transferred between an on-premises data center and a cloud VPC is encrypted in transit. Which solution should be used?

A.A cloud transit hub
B.A cloud DNS resolver
C.A site-to-site VPN connection
D.A dedicated private connection
AnswerC

A site-to-site VPN uses IPsec to encrypt traffic traversing the public internet between the on-premises gateway and the cloud VPC, satisfying the in-transit encryption requirement. Direct Connect or peering alone carries data unencrypted unless a separate encryption layer is added.

Why this answer

A site-to-site VPN connection creates an encrypted tunnel between an on-premises data center and a cloud VPC using IPsec (IKEv1/IKEv2) to protect all data in transit. This directly meets the requirement for encryption, as traffic traverses the public internet or a dedicated private connection with encryption enabled.

Exam trap

The trap here is that candidates often assume a dedicated private connection inherently encrypts traffic because it is a private connection, but it does not; encryption must be explicitly implemented, and the VPN is the direct solution for encryption in transit.

How to eliminate wrong answers

Option A is wrong because AWS Transit Gateway is a network transit hub that interconnects VPCs and on-premises networks, but it does not itself provide encryption; it can route traffic through a VPN attachment, but the encryption comes from the VPN, not Transit Gateway. Option B is wrong because AWS Route 53 Resolver is a DNS resolution service that resolves domain names to IP addresses; it has no role in encrypting data in transit. Option D is wrong because AWS Direct Connect provides a private, dedicated network connection that bypasses the public internet, but by default it does not encrypt traffic; encryption must be added separately (e.g., via IPsec over Direct Connect or a VPN).

671
MCQmedium

A cloud application uses an IAM role with a policy that allows 's3:*' on all buckets. This is an example of which cloud security issue?

A.Exposed S3 bucket
B.Over-permissive IAM
C.Insecure API endpoint
D.Hardcoded credentials
AnswerB

Granting 's3:*' on all buckets violates least privilege by allowing every S3 action across every bucket, far beyond any legitimate need. This is precisely the over-permissive IAM issue the stem describes, not privilege escalation, credential exposure or insecure defaults.

Why this answer

Over-permissive IAM roles with wildcard permissions grant excessive privileges, violating least privilege.

672
MCQmedium

A security engineer discovers that a cloud application can access the metadata service endpoint at 169.254.169.254. Which vulnerability is most likely being exploited?

A.Server-Side Request Forgery (SSRF)
B.SQL Injection
C.Cross-Site Scripting (XSS)
D.Insecure Deserialization
AnswerA

SSRF occurs when attacker-controlled input makes the server fetch an arbitrary URL. Here the application reaches the link-local metadata address 169.254.169.254, which is reachable only from the instance itself, confirming the server is being coerced into issuing the request on the attacker's behalf.

Why this answer

Server-Side Request Forgery (SSRF) can be used to target the cloud metadata endpoint (169.254.169.254) to retrieve IAM credentials or other sensitive information. This is a cloud-specific vulnerability.

673
MCQmedium

A company is storing sensitive customer data in an S3 bucket. They need to ensure data is encrypted at rest and that the encryption keys are managed by the cloud provider. Which encryption strategy should they use?

A.SSE-C (Server-Side Encryption with Customer-Provided Keys)
B.Client-side encryption
C.SSE-KMS (Server-Side Encryption with AWS KMS)
D.SSE-S3 (Server-Side Encryption with S3-Managed Keys)
AnswerD

SSE-S3 uses keys managed by AWS, meeting the requirement.

Why this answer

SSE-S3 (Server-Side Encryption with S3-Managed Keys) encrypts data at rest using AES-256, with the encryption keys fully managed by AWS. This meets the requirement for the cloud provider to handle key management without any customer involvement in key generation, storage, or rotation.

Exam trap

ISC2 often tests the distinction between 'managed by the provider' and 'managed by the customer' — candidates confuse SSE-KMS (customer-managed KMS keys) with provider-managed keys, but SSE-KMS still gives the customer control over key lifecycle, making SSE-S3 the only option where the provider fully manages keys.

How to eliminate wrong answers

Option A is wrong because SSE-C requires the customer to provide and manage their own encryption keys, which contradicts the requirement that the cloud provider manages the keys. Option B is wrong because client-side encryption occurs before data is sent to S3, meaning the customer manages the keys and encryption process, not the cloud provider. Option C is wrong because SSE-KMS uses AWS Key Management Service, which gives the customer control over key policies, rotation, and auditing, meaning the customer retains management responsibility even though AWS hosts the keys.

674
MCQeasy

An organization is moving sensitive customer data to the cloud and must ensure that data is encrypted before being sent to the cloud provider. They want to maintain full control over the encryption keys and not rely on the cloud provider for any key management. Which approach should they use?

A.VPN encryption
B.Server-side encryption with AWS KMS
C.Transparent Data Encryption (TDE)
D.Client-side encryption
AnswerD

Client-side encryption encrypts data before transmission, so plaintext never reaches the provider. Because the organisation generates and retains its own keys, the cloud provider performs no key management, satisfying the requirement for full customer control.

Why this answer

Client-side encryption means the organization encrypts data before it ever leaves their environment, so the cloud provider only ever receives ciphertext and never has access to the plaintext or the keys. This satisfies both requirements: data is encrypted prior to transmission and the customer retains full control of key management (often via their own HSM or KMS). Because the provider never holds the keys, it cannot decrypt the data even if compelled or breached.

Exam trap

CCSP often tests the distinction between encryption in transit (VPN/TLS), server-side encryption (provider-managed keys), and client-side encryption (customer-managed keys) — candidates frequently pick server-side encryption with KMS assuming 'customer-managed key' equals 'full customer control,' when the provider still performs the cryptographic operations.

How to eliminate wrong answers

Option A is wrong because VPN encryption only protects data in transit between endpoints and terminates at the cloud edge, leaving data at rest unencrypted and under provider control. Option B is wrong because server-side encryption with AWS KMS means the cloud provider performs encryption and manages keys (even with customer-managed keys, the provider's infrastructure handles the cryptographic operations), which violates the requirement to not rely on the provider for key management. Option C is wrong because Transparent Data Encryption encrypts data at rest at the database layer, typically with keys managed by the database or platform, and does not encrypt data before it is sent to the cloud.

675
MCQhard

A company is migrating to a hybrid cloud and needs to ensure consistent security policies across both on-premises and cloud environments. Which of the following is the MOST critical consideration?

A.Implementing single sign-on (SSO) for all users
B.Using dedicated private network connections
C.Choosing the same cloud provider for all public cloud workloads
D.Ensuring that security policies are uniformly applied and enforced across all environments
AnswerD

Uniform enforcement ensures the same controls govern on-premises and cloud resources, closing gaps where workloads move between environments. This directly addresses the stem's requirement for consistent security policies, since inconsistent application creates exploitable seams during and after migration.

Why this answer

The most critical consideration for consistent security policies across hybrid cloud is ensuring that security policies are uniformly applied and enforced across all environments. This ensures that no matter where workloads reside, the same security controls, access rules, and compliance requirements are met, reducing gaps and misconfigurations. While SSO, private connections, and single cloud provider can aid security, they do not guarantee policy consistency; only uniform enforcement does.

Exam trap

CCSP often tests the difference between enabling technologies (like SSO or private links) and the overarching need for consistent policy enforcement, as candidates may focus on specific tools rather than the holistic requirement.

How to eliminate wrong answers

Option A is wrong because implementing SSO improves user authentication convenience and centralizes identity, but it does not ensure that all security policies (e.g., network, data protection) are consistently applied across environments. Option B is wrong because dedicated private network connections enhance security and performance for data transfer, but they do not enforce policy consistency; policies could still diverge. Option C is wrong because choosing the same cloud provider for all public cloud workloads may simplify management but does not address on-premises integration and does not guarantee uniform policy enforcement across hybrid environments.

Page 8

Page 9 of 13

Page 10