Certificate of Cloud Security Knowledge Flashcards
7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certificate of Cloud Security Knowledge flashcards as text
Which encryption approach best protects data stored in a cloud provider's object storage from unauthorized access by the provider?
Answer: Client-side encryption with customer-managed keys before upload
Client-side encryption with customer-managed keys ensures the provider only ever sees ciphertext, preventing access even if the provider is compromised or compelled.
What is the main security implication of 'multitenancy' in cloud computing?
Answer: It creates a risk that one tenant's actions or vulnerabilities could affect others
Multitenancy means multiple customers share the same underlying infrastructure, creating risks like VM escape, noisy neighbor attacks, or data leakage across tenants.
In the context of the CSA Cloud Controls Matrix (CCM), what is the CCM's primary function?
Answer: A cybersecurity control framework specifically designed for cloud environments
The CCM is a controls framework that provides a detailed understanding of security controls applicable to cloud computing, mapped to industry standards like ISO 27001 and NIST.
What distinguishes a 'security group' in IaaS from a traditional network firewall?
Answer: Security groups are software-defined and attached per instance rather than per network boundary
Security groups are software-defined, stateful packet filters that attach to individual virtual instances or interfaces rather than guarding a fixed network perimeter.
Which risk is MOST associated with using a public cloud provider's default logging and monitoring settings?
Answer: Default settings may not capture security-relevant events needed for incident response
Cloud providers' default logging often omits key security events, so customers must explicitly configure detailed logging to support incident detection and forensics.
What is 'federation' in cloud identity management?
Answer: Establishing trust between identity domains so users authenticate once across systems
Federation links separate identity systems using standards like SAML or OIDC, allowing users to authenticate with their home identity provider and access federated cloud services.
According to CSA guidance, what is the recommended approach when a cloud provider cannot demonstrate compliance with a required regulatory standard?
Answer: Accept the risk and implement compensating controls on the customer side
When a provider lacks required certifications, the recommended approach is risk acceptance combined with compensating controls that customers implement themselves.