Sample questions
Certified Cloud Security Professional CCSP practice questions
A company receives an erasure request under GDPR. The cloud provider can delete from active storage within 24 hours but requires 90 days to delete from archives. The company has a…
Which TWO of the following are valid considerations when performing forensic imaging of virtual machines in a public cloud? (Choose two.)
A multinational corporation operates in a country where data sovereignty laws require that all customer data remain within the country's borders. The company uses a global public c…
A cloud customer wants to ensure that their data is encrypted during transmission between their on-premises data center and the cloud provider's service. Which protocol should they…
An organization wants to prevent secrets from being exposed in source code. Which two practices should they adopt? (Choose TWO.)
Which of the following is the best way to protect a web application from cross-site scripting (XSS) attacks?
Which TWO best practices help secure a cloud application's runtime environment?
A cloud application uses a service mesh for inter-service communication. The security team wants to enforce mutual TLS (mTLS) between all services and ensure that service identitie…
A cloud security analyst is investigating a potential data breach. They discover that an employee's credentials were used to access a cloud storage bucket containing sensitive file…
A security architect is designing network segmentation for a multi-tier application in the cloud. Which TWO configurations help enforce micro-segmentation? (Choose two.)
An organization uses a CI/CD pipeline that automatically builds and deploys container images to a Kubernetes cluster. A security scanner flags that the base image contains a critic…
Which TWO of the following are considered best practices for securing containerized applications in a cloud environment?
A medium-sized e-commerce company uses a cloud provider's container orchestration service (e.g., Amazon ECS or Google Kubernetes Engine). They have a security requirement to ensure…
A software company develops an API for third-party integrations. They want to ensure that only authorized partners can access the API. Which authentication mechanism is most approp…
An organization uses a multi-cloud architecture with applications running on both AWS and Azure. They need to implement a secrets management solution that works across both platfor…
A security team is reviewing a cloud application's CI/CD pipeline. They want to ensure that only approved open-source libraries are used in production builds. Which approach best a…
Refer to the exhibit. A security analyst sees this alert. According to the shared responsibility model, who is primarily responsible for ensuring that the IAM policy correctly rest…
A multinational corporation uses a SaaS application that stores data in multiple jurisdictions. The company's legal team is concerned about cross-border data transfers under the GD…
A company uses a cloud provider's managed database service. The security team is concerned about the shared responsibility model for patching the operating system and database engi…
Which TWO of the following are key elements of a cloud service agreement (CSA) for legal compliance?
A security auditor is reviewing a cloud provider's virtualisation infrastructure. Which TWO mechanisms ensure VM isolation at the hardware level to prevent one tenant from accessin…
Cloud Platform and Infrastructure SecurityhardSee the answer and why each option is right or wrong →A cloud security architect is implementing a CI/CD pipeline for a containerized application on AWS. Which TWO practices should be integrated to enforce container image security?
A security team is investigating a potential data exfiltration incident where a large volume of data was downloaded from a cloud storage bucket. Which log source would provide the…
A company uses a cloud KMS with HSM-backed keys for regulatory compliance. They need to allow a cloud service to use a key for encryption while retaining the ability to revoke acce…