Courseiva
Back to Certified Cloud Security Professional CCSP questions

Scenario-based practice

Select Two (Multi-Select) Questions

Practise Certified Cloud Security Professional CCSP practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
CCSP
exam code
ISC2
vendor

Scenario guide

How to approach select two (multi-select) questions

Multi-select questions tell you to 'Choose TWO' or 'Choose THREE'. Getting partial credit is not a thing — you must select all correct answers with no incorrect ones. The stem always states how many to choose, so trust it. These questions require precision, not best-guess elimination.

Quick answer

Select Two (Multi-Select) Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CCSP topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymulti select
Full question →

Which TWO of the following are valid considerations when performing forensic imaging of virtual machines in a public cloud? (Choose two.)

Question 2mediummulti select
Full question →

An organization wants to prevent secrets from being exposed in source code. Which two practices should they adopt? (Choose TWO.)

Question 3easymulti select
Full question →

Which TWO best practices help secure a cloud application's runtime environment?

Question 4mediummulti select
Full question →

A security architect is designing network segmentation for a multi-tier application in the cloud. Which TWO configurations help enforce micro-segmentation? (Choose two.)

Question 5mediummulti select
Full question →

Which TWO of the following are considered best practices for securing containerized applications in a cloud environment?

Question 6mediummulti select
Full question →

Which TWO of the following are key elements of a cloud service agreement (CSA) for legal compliance?

A security auditor is reviewing a cloud provider's virtualisation infrastructure. Which TWO mechanisms ensure VM isolation at the hardware level to prevent one tenant from accessing another's resources?

Question 8mediummulti select
Full question →

A cloud security architect is implementing a CI/CD pipeline for a containerized application on AWS. Which TWO practices should be integrated to enforce container image security?

Question 9hardmulti select
Full question →

A company uses a cloud KMS with HSM-backed keys for regulatory compliance. They need to allow a cloud service to use a key for encryption while retaining the ability to revoke access at any time. Which TWO key management models satisfy this? (Choose two.)

Question 10mediummulti select
Full question →

A company's cloud security policy mandates strict control over encryption keys used for data at rest. Which THREE practices are recommended for secure key management in the cloud?

Question 11hardmulti select
Full question →

Which TWO of the following are required elements of a valid Business Continuity Plan (BCP) in the cloud?

Question 12hardmulti select
Full question →

Which THREE of the following are key characteristics of cloud computing as defined by NIST SP 800-145?

Question 13hardmulti select
Full question →

Which THREE of the following are key considerations when conducting a cloud risk assessment?

Question 14easymulti select
Full question →

Which TWO of the following are best practices for cloud key management?

Question 15easymulti select
Full question →

A security architect is designing a cloud workload protection platform (CWPP) for a hybrid cloud environment. The architect needs to ensure that security policies are consistently applied across virtual machines running in both on-premises and public cloud environments. Which TWO components are essential for achieving this goal?

Question 16mediummulti select
Full question →

A company is negotiating a cloud contract and wants to ensure data ownership and deletion. Which TWO clauses should be included? (Select two.)

Question 17hardmulti select
Full question →

A DevSecOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and trust from build to deployment?

Question 18hardmulti select
Full question →

Which THREE are best practices for implementing secrets management in cloud applications?

Question 19mediummulti select
Full question →

A cloud security team is developing an incident response plan for a SaaS application hosted on a public cloud. During the preparation phase, which TWO steps are most critical to include?

Question 20mediummulti select
Full question →

Which THREE of the following are key considerations when designing a key management lifecycle for cloud data encryption?

These CCSP practice questions are part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style CCSP questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.