Courseiva
← Back to Certified Cloud Security Professional CCSP questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Certified Cloud Security Professional CCSP practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

13
scenario questions
CCSP
exam code
ISC2
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related CCSP topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

A security engineer reviews the S3 bucket policy shown in the exhibit. Which security concern should be addressed immediately?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "10.0.0.0/8"
        }
      }
    },
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*"
    }
  ]
}
Question 2hardmultiple choice
Full question →

Refer to the exhibit. A cloud security administrator is reviewing the following network firewall rule configuration associated with a web server instance. What security best practice is being violated?

Exhibit

{
  "SecurityGroup": {
    "GroupName": "sg-web",
    "IngressRules": [
      { "Protocol": "TCP", "PortRange": "443", "SourceCIDR": "10.0.0.0/8" },
      { "Protocol": "TCP", "PortRange": "22", "SourceCIDR": "0.0.0.0/0" }
    ],
    "EgressRules": [
      { "Protocol": "TCP", "PortRange": "443", "DestinationCIDR": "0.0.0.0/0" }
    ]
  }
}
Question 3mediummultiple choice
Full question →

Refer to the exhibit. An IAM policy is attached to a user. Which action is the user allowed to perform?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:ListBucket"
      ],
      "Resource": [
        "arn:aws:s3:::example-bucket",
        "arn:aws:s3:::example-bucket/*"
      ]
    },
    {
      "Effect": "Deny",
      "Action": [
        "s3:DeleteObject"
      ],
      "Resource": "arn:aws:s3:::example-bucket/*"
    }
  ]
}
Question 4mediummultiple choice
Full question →

Refer to the exhibit. A cloud administrator sees this error log from AWS CloudTrail. The user [email protected] is a member of the 'Analysts' group. Which of the following is the most likely cause of the AccessDenied error?

Exhibit

Refer to the exhibit.
Error Log Entry:
Timestamp: 2024-08-15T14:23:10Z
User: [email protected]
Action: PutObject
Resource: s3://finance-reports/quarterly.xlsx
Status: AccessDenied
Source IP: 203.0.113.45
UserAgent: [ConsoleLogin]
Additional: The user does not have permissions to write to this bucket.
Question 5easymultiple choice
Full question →

The exhibit shows the versioning configuration for an S3 bucket. What effect does enabling MFADelete have on data protection?

Network Topology
$ aws s3api get-bucket-versioningbucket my-bucketRefer to the exhibit.```"Status": "Enabled","MFADelete": "Enabled"
Question 6easymultiple choice
Full question →

Refer to the exhibit. A log entry shows a suspected SQL injection attack. Which security control would have prevented this attack?

Exhibit

Refer to the exhibit.

```
[ERROR] 2025-03-01 12:34:56,789 - myapp - CRITICAL - SQL Injection detected on endpoint /api/login
Input: ' OR '1'='1
```
Question 7hardmultiple choice
Full question →

A company has multiple VPCs in different cloud accounts that need to communicate with each other. They also need to enforce centralized security policies and simplify network management. Which cloud networking service should they use to create a hub-and-spoke topology?

Question 8hardmultiple choice
Full question →

Refer to the exhibit. A cloud security analyst reviews the bucket policy for example-bucket. Based on the policy, which of the following is true?

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "192.0.2.0/24"
        }
      }
    },
    {
      "Effect": "Deny",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": "arn:aws:s3:::example-bucket/*",
      "Condition": {
        "Bool": {
          "aws:SecureTransport": "false"
        }
      }
    }
  ]
}
```
Question 9mediummultiple choice
Full question →

Refer to the exhibit. A security analyst is investigating a potential unauthorized key pair creation. The CloudTrail log shows a successful CreateKeyPair event for an admin user. What additional step should the analyst take to determine if this was an authorized action?

Network Topology
$ aws cloudtrail lookup-eventslookup-attributes AttributeKey=EventNamequery 'Events[?ErrorCode==`nil`]'output textRefer to the exhibit.```Events:- EventId: abc123EventName: CreateKeyPairEventTime: 2023-10-01T10:00:00ZUserIdentity: {"type":"IAMUser","arn":"arn:aws:iam::123456789012:user/admin"}Resources: [{"resourceType":"AWS::EC2::KeyPair","resourceName":"mykey"}]SourceIPAddress: 203.0.113.50UserAgent: console.amazonaws.com
Question 10mediummultiple choice
Full question →

Refer to the exhibit. A security auditor is reviewing the security group configuration for a web server. Which change would improve the security posture without breaking the application functionality?

Exhibit

Security Group Rule Analysis:
Rule 1: Inbound | TCP | Port 22 | 0.0.0.0/0 | Allow
Rule 2: Inbound | TCP | Port 443 | 0.0.0.0/0 | Allow
Rule 3: Inbound | TCP | Port 3389 | 192.168.1.0/24 | Allow
Rule 4: Outbound | All Traffic | 0.0.0.0/0 | Allow
Question 11easymultiple choice
Full question →

Refer to the exhibit. A cloud administrator ran the Azure CLI command to list virtual machines. One VM shows a ProvisioningState of 'Failed'. What is the most likely cause of this state?

Network Topology
$ az vm listoutput tableRefer to the exhibit.```Name ResourceGroup Location ProvisioningStatevm-prod-1 rg-prod eastus Succeededvm-prod-2 rg-prod eastus Succeededvm-dev-1 rg-dev eastus Failed
Question 12mediummultiple choice
Full question →

A cloud administrator applies the bucket policy shown in the exhibit to an S3 bucket. What is the expected outcome?

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::my-bucket/*",
      "Condition": {
        "StringNotEquals": {
          "s3:x-amz-server-side-encryption": "AES256"
        }
      }
    }
  ]
}
```
Question 13hardmultiple choice
Full question →

An AWS S3 bucket policy is configured as shown in the exhibit. The security team wants to ensure that only requests from the corporate IP range (203.0.113.0/24) can read objects in the bucket. However, they notice that a CloudFront distribution configured to serve content from this bucket is returning 403 Forbidden errors. What is the MOST likely cause?

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::my-secure-bucket/*",
      "Condition": {
        "IpAddress": {
          "aws:SourceIp": "203.0.113.0/24"
        }
      }
    }
  ]
}
```

These CCSP practice questions are part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style CCSP questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.