Certificate of Cloud Security Knowledge (CCSK) — Questions and Answers
Question 1: What does CCSK say about the use of 'data masking' in non-production cloud environments?
- Production data should be used as-is in test environments for accuracy
- Data masking is only required for financial data
- Sensitive production data should be masked or anonymized before use in test or development environments (Correct answer)
- Data masking is only needed for data stored in public cloud
Correct answer: Sensitive production data should be masked or anonymized before use in test or development environments
Non-production environments typically have weaker security controls, so sensitive data should be masked or synthesized to reduce exposure risk.
Question 2: In CCSK, what is meant by 'portability' as a cloud characteristic?
- The ability to scale workloads globally in real time
- The ability to carry physical servers between data centers
- The ability to move workloads or data between cloud providers without proprietary lock-in (Correct answer)
- The ability to encrypt data in transit across clouds
Correct answer: The ability to move workloads or data between cloud providers without proprietary lock-in
Portability refers to moving applications and data between cloud providers with minimal friction, reducing vendor lock-in risk.
Question 3: What is the primary challenge of cloud incident response compared to on-premises incident response?
- Cloud environments produce too much data for incident investigation
- Limited physical access and reliance on provider-supplied logs reduce investigative control (Correct answer)
- Cloud incidents are always less severe than on-premises incidents
- Cloud providers handle all incident response on behalf of customers
Correct answer: Limited physical access and reliance on provider-supplied logs reduce investigative control
In cloud environments, customers cannot access physical media and depend on provider-provided logs and APIs for forensic investigation, limiting their control.
Question 4: What does CCSK recommend for 'containment' of a compromised cloud workload?
- Isolate the workload by modifying security groups and network ACLs while preserving forensic state (Correct answer)
- Transfer the workload to a different cloud region
- Immediately delete the compromised instance to stop the attack
- Notify all users of the incident before taking containment action
Correct answer: Isolate the workload by modifying security groups and network ACLs while preserving forensic state
Containment in cloud involves isolating the workload through network controls while preserving its state for forensic investigation before remediation.
Question 5: What is 'identity sprawl' in cloud environments and why is it a security concern?
- The growth of cloud storage capacity over time
- The expansion of network access rules across cloud regions
- The spread of encryption keys across multiple providers
- The proliferation of unmanaged identities across multiple cloud services, creating governance blind spots (Correct answer)
Correct answer: The proliferation of unmanaged identities across multiple cloud services, creating governance blind spots
Identity sprawl occurs when identities multiply across cloud services without central governance, making it difficult to track, manage, and revoke access.
Question 6: What is 'egress filtering' and why is it important for cloud data security?
- Filtering incoming traffic to detect malware
- Blocking all outbound traffic from cloud workloads
- Filtering API calls from cloud management consoles
- Monitoring and restricting outbound data flows to prevent unauthorized data exfiltration (Correct answer)
Correct answer: Monitoring and restricting outbound data flows to prevent unauthorized data exfiltration
Egress filtering monitors and controls outbound network traffic to prevent sensitive data from leaving the environment without authorization.
Question 7: Which encryption approach does CCSK recommend to maintain control of data even when stored in a cloud provider's infrastructure?
- Provider-managed encryption with default keys
- Customer-managed encryption keys (CMEK) where the customer holds the keys (Correct answer)
- No encryption for publicly accessible data
- Encryption only during transmission
Correct answer: Customer-managed encryption keys (CMEK) where the customer holds the keys
Using customer-managed encryption keys ensures the customer retains control of data access even if the provider's environment is compromised.
Question 8: What does the CSA Security Guidance refer to as the 'management plane'?
- The encryption layer between cloud and on-premises
- The layer that handles VM scheduling
- The interface used to configure and manage cloud services (Correct answer)
- The physical data center network
Correct answer: The interface used to configure and manage cloud services
The management plane is the interface (API or console) customers use to configure, deploy, and manage their cloud resources.
Question 9: According to CCSK, what should organizations do before terminating a cloud provider contract to address data security?
- Ensure all data is exported, verify deletion by the provider, and obtain written confirmation (Correct answer)
- Archive all data locally and leave copies with the provider
- Notify the provider 90 days in advance and request a full audit
- Transfer all data to another cloud provider without notifying the current provider
Correct answer: Ensure all data is exported, verify deletion by the provider, and obtain written confirmation
Before contract termination, organizations should export all data, confirm its deletion from provider systems, and obtain written assurance of secure disposal.
Question 10: According to CCSK, what should organizations test to validate their cloud business continuity plans?
- Only the backup and restore capabilities
- Only the network connectivity between primary and DR regions
- Full failover scenarios including switching to DR environments, validating RTOs, and testing personnel procedures (Correct answer)
- Only the cloud provider's SLA compliance
Correct answer: Full failover scenarios including switching to DR environments, validating RTOs, and testing personnel procedures
BCP validation requires testing complete failover scenarios, verifying that RTO/RPO objectives are met, and ensuring personnel can execute procedures under real conditions.
Question 11: What is a 'cloud access security broker' (CASB) primarily used for?
- Scanning cloud provider networks for vulnerabilities
- Enforcing security policies between cloud users and cloud services (Correct answer)
- Managing cloud provider contracts and SLAs
- Hosting encryption keys for cloud workloads
Correct answer: Enforcing security policies between cloud users and cloud services
A CASB sits between users and cloud services to enforce security policies including visibility, compliance, data security, and threat protection.
Question 12: What does CCSK say about 'recovery time objective' (RTO) in cloud business continuity planning?
- RTO applies only to physical data center recovery, not cloud services
- RTO is determined solely by the cloud provider's SLA
- RTO is not relevant to cloud environments because recovery is automatic
- RTO defines the maximum acceptable time to restore services after an incident, which cloud architectures should be designed to meet (Correct answer)
Correct answer: RTO defines the maximum acceptable time to restore services after an incident, which cloud architectures should be designed to meet
RTO defines how quickly services must be restored; cloud architectures should be designed with automation, multi-region failover, and runbooks to meet defined RTO targets.
Question 13: What does CCSK recommend as a key control for data stored in object storage (e.g., S3 buckets)?
- Leave buckets public by default for performance
- Grant all IAM users read/write access by default
- Enable versioning and enforce bucket policies restricting public access (Correct answer)
- Store all objects without encryption for faster retrieval
Correct answer: Enable versioning and enforce bucket policies restricting public access
Object storage should have public access blocked, versioning enabled, and bucket policies enforcing least-privilege access to prevent data exposure.
Question 14: In CCSK, what is 'volume storage encryption' primarily used to protect against?
- Insider threats from cloud administrators accessing running instances
- Application-layer data breaches from SQL injection
- Unauthorized access to data if physical storage media is removed or accessed outside the system (Correct answer)
- Network interception of data in transit
Correct answer: Unauthorized access to data if physical storage media is removed or accessed outside the system
Volume storage encryption protects data at rest so that raw access to the storage media yields no readable data without the encryption key.
Question 15: What is a 'SOC 2 Type II' report and why is it relevant to CCSK cloud security assessments?
- A report that certifies cloud providers have zero security vulnerabilities
- A financial audit of cloud provider billing practices
- An independent auditor's report verifying a cloud provider's security controls operated effectively over a defined period (typically 12 months) (Correct answer)
- A one-time snapshot audit of a provider's security configuration
Correct answer: An independent auditor's report verifying a cloud provider's security controls operated effectively over a defined period (typically 12 months)
SOC 2 Type II covers operational effectiveness of controls over time (vs. Type I which is point-in-time), providing stronger assurance of consistent security practices.
Question 16: What is 'ISO/IEC 27017' and how does it differ from ISO/IEC 27001 in cloud security?
- They are identical standards with different numbering
- ISO 27017 is for network security; ISO 27001 is for cloud security
- ISO 27017 provides cloud-specific security controls extending ISO 27001, addressing cloud-unique risks like virtual environments and shared infrastructure (Correct answer)
- ISO 27017 replaces ISO 27001 for cloud service providers
Correct answer: ISO 27017 provides cloud-specific security controls extending ISO 27001, addressing cloud-unique risks like virtual environments and shared infrastructure
ISO 27017 extends the ISO 27001 framework with additional controls specific to cloud services, covering topics like virtual machines, provider-customer responsibilities, and asset ownership.
Question 17: According to CSA, which technique best protects against SQL injection attacks in cloud-hosted applications?
- Deploying a WAF without application-level code changes
- Restricting database access to a single subnet
- Encrypting the database at rest using AES-256
- Using parameterized queries and input validation (Correct answer)
Correct answer: Using parameterized queries and input validation
Parameterized queries prevent attackers from injecting malicious SQL by treating user input as data rather than executable code.
Question 18: In the shared responsibility model, who is responsible for securing the hypervisor in an IaaS deployment?
- A shared responsibility between customer and provider
- The customer
- A third-party auditor
- The cloud service provider (Correct answer)
Correct answer: The cloud service provider
In IaaS, the cloud service provider is responsible for securing the hypervisor and underlying physical infrastructure.
Question 19: Which CCSK concept describes ensuring data integrity throughout its lifecycle in the cloud?
- Data lineage (Correct answer)
- Immutable logging
- Chain of custody
- Non-repudiation controls
Correct answer: Data lineage
Data lineage tracks how data moves, transforms, and is used throughout its lifecycle, ensuring accountability and integrity verification.
Question 20: What is 'cloud forensics' and what unique challenges does the cloud environment present?
- Network traffic analysis for cloud performance issues
- Analyzing cloud provider audit reports for compliance
- Digital forensic investigation in cloud environments, challenged by multi-tenancy, ephemeral resources, and limited physical access (Correct answer)
- Financial forensics for cloud billing disputes
Correct answer: Digital forensic investigation in cloud environments, challenged by multi-tenancy, ephemeral resources, and limited physical access
Cloud forensics faces unique challenges including inability to access physical media, evidence volatility in ephemeral environments, and jurisdictional issues with multi-tenant data.
Question 21: According to CCSK, what is the recommended approach for classifying data before moving it to the cloud?
- Classify data based on cost to store
- Classify data after migration is complete
- Classify data by file size and format only
- Classify data by its sensitivity level and regulatory requirements before migration (Correct answer)
Correct answer: Classify data by its sensitivity level and regulatory requirements before migration
Data should be classified by sensitivity and regulatory requirements before cloud migration to ensure appropriate controls are applied.
Question 22: What is a 'hypervisor escape' attack and why is it particularly dangerous in cloud environments?
- An attack that exploits weak encryption on virtual disks
- An attack that overloads the cloud management console
- An attack where malicious code breaks out of a VM to access the hypervisor and other VMs on the same host (Correct answer)
- An attack targeting container orchestration platforms
Correct answer: An attack where malicious code breaks out of a VM to access the hypervisor and other VMs on the same host
Hypervisor escape allows malware from one tenant's VM to break through to the hypervisor layer, potentially accessing other tenants' VMs on the same physical host.
Question 23: Which approach does CCSK recommend for managing encryption keys in a multi-cloud environment?
- Use a centralized, customer-controlled key management system (KMS) or HSM (Correct answer)
- Rotate keys only when a breach is suspected
- Store keys in the same location as the encrypted data
- Use each provider's native key management with default settings
Correct answer: Use a centralized, customer-controlled key management system (KMS) or HSM
A centralized customer-controlled KMS or hardware security module (HSM) ensures consistent key governance across multiple cloud providers.
Question 24: What does CCSK say about the use of 'bastion hosts' (jump servers) for cloud infrastructure access?
- Bastion hosts eliminate the need for MFA on cloud management access
- Bastion hosts are outdated and should not be used in cloud environments
- Bastion hosts provide a controlled, audited, single entry point for administrative access to cloud infrastructure (Correct answer)
- Bastion hosts should be publicly accessible without authentication for convenience
Correct answer: Bastion hosts provide a controlled, audited, single entry point for administrative access to cloud infrastructure
A bastion host channels all administrative access through a single hardened, monitored entry point, reducing attack surface and creating an audit trail.
Question 25: According to CSA, what is the primary security concern with 'serverless computing' architectures?
- The expanded attack surface from numerous functions and increased reliance on third-party dependencies (Correct answer)
- Serverless platforms do not support encryption of function execution environments
- Functions cannot be monitored because the provider controls the runtime environment
- Serverless functions always run as root, increasing privilege escalation risk
Correct answer: The expanded attack surface from numerous functions and increased reliance on third-party dependencies
Serverless increases the number of deployed functions and dependencies, expanding the attack surface while requiring careful input validation and least-privilege IAM policies.
Question 26: Which CSA domain focuses on identifying and managing assets in the cloud?
- Domain 9: Incident Response (Correct answer)
- Domain 8: Virtualization and Containers
- Domain 3: Legal Issues, Contracts and eDiscovery
- Domain 2: Governance and Enterprise Risk Management
Correct answer: Domain 9: Incident Response
Wait — the correct domain for asset management within the CSA Guidance is embedded under Governance and risk; however, asset inventory is discussed under Domain 2.
Question 27: What is the significance of the 'trust boundary' concept in CCSK cloud security architecture?
- It marks the perimeter where security responsibilities shift between parties (Correct answer)
- It identifies regions where data sovereignty laws apply
- It sets latency thresholds for cloud applications
- It defines the pricing boundary between on-premises and cloud
Correct answer: It marks the perimeter where security responsibilities shift between parties
Trust boundaries define where one party's security responsibility ends and another's begins, critical for understanding the shared responsibility model.
Question 28: Which of the following is a key risk introduced by 'shadow IT' in cloud environments?
- Reduced application performance
- Unauthorized cloud services operating outside security controls (Correct answer)
- Increased software licensing costs
- Slower deployment pipelines
Correct answer: Unauthorized cloud services operating outside security controls
Shadow IT creates security blind spots because unauthorized services bypass established security policies, monitoring, and compliance controls.
Question 29: According to CSA, what role does a Security Information and Event Management (SIEM) system play in cloud environments?
- It acts as a cloud firewall by blocking malicious traffic in real time
- It manages user provisioning and de-provisioning across cloud platforms
- It aggregates and correlates logs and events from cloud services to detect and investigate threats (Correct answer)
- It enforces encryption policies across all cloud storage services automatically
Correct answer: It aggregates and correlates logs and events from cloud services to detect and investigate threats
A SIEM collects, correlates, and analyzes log data from across cloud environments to identify anomalies, threats, and compliance violations.
Question 30: Which CSA domain covers the security implications of cloud APIs?
- Domain 12: Identity, Entitlement and Access Management
- Domain 7: Infrastructure Security
- Domain 10: Application Security (Correct answer)
- Domain 4: Compliance and Audit Management
Correct answer: Domain 10: Application Security
Domain 10 (Application Security) covers securing cloud APIs, including authentication, input validation, and API gateway controls.
Question 31: What does CCSK identify as the primary legal challenge of cloud computing related to data location?
- Legal jurisdiction only applies to on-premises data storage
- Data may reside in multiple jurisdictions simultaneously, creating complex and potentially conflicting legal obligations (Correct answer)
- Cloud data is exempt from national laws because it resides in a virtual environment
- Cloud providers charge more for data stored in regulated jurisdictions
Correct answer: Data may reside in multiple jurisdictions simultaneously, creating complex and potentially conflicting legal obligations
Cloud data can be distributed across multiple countries, each with different privacy and security laws, creating jurisdictional conflicts and compliance complexity.
Question 32: What is the role of metadata in cloud data governance according to CCSK?
- Metadata contains the actual sensitive data in encrypted form
- Metadata describes data attributes enabling classification, discovery, and access control decisions (Correct answer)
- Metadata is only used for billing and cost allocation
- Metadata is irrelevant to security and governance
Correct answer: Metadata describes data attributes enabling classification, discovery, and access control decisions
Metadata describes data characteristics (type, owner, sensitivity) and enables automated classification, discovery, and enforcement of governance policies.
Question 33: What is 'data sovereignty' in the context of CCSK cloud security?
- A customer's right to delete their data at any time
- The ability to encrypt data across international borders
- The legal principle that data is subject to the laws of the country where it is stored (Correct answer)
- A cloud provider's right to use customer data for analytics
Correct answer: The legal principle that data is subject to the laws of the country where it is stored
Data sovereignty means stored data is governed by the laws and regulations of the jurisdiction where the data physically resides.
Question 34: What does 'geo-residency' or 'data sovereignty' mean for cloud customers?
- Restrictions on which countries can access the cloud management portal
- The cloud provider's ability to replicate data globally to improve performance
- Legal requirements mandating that data be stored and processed within specific geographic boundaries (Correct answer)
- The requirement that cloud data be accessible from any geographic location at all times
Correct answer: Legal requirements mandating that data be stored and processed within specific geographic boundaries
Data sovereignty laws in many jurisdictions require that certain types of data remain physically within national borders, which customers must verify their cloud provider can guarantee.
Question 35: Scoping and review activities can be sped up by:
- Relying on certifications instead of audits
- Obtaining a letter of attestation
- Outsourcing audits to a "Big 5" auditing shop
- Engaging auditors with experience in the cloud space. (Correct answer)
Correct answer: Engaging auditors with experience in the cloud space.
There is no need to pay for the auditor to be taught on the issue by hiring auditors with experience in the cloud domain. It should be noted that this is mentioned in domain 4 of the guideline (V4) with the phrase "Attempt to select auditors with experience in cloud computing," but does not explain why, as it did in the previous version of the guidance.
Question 36: What is 'tokenization' and how does it differ from encryption in cloud data protection?
- Tokenization replaces sensitive data with a non-sensitive placeholder; encryption transforms data using a mathematical algorithm and key (Correct answer)
- Tokenization and encryption are identical techniques
- Tokenization is used only for network traffic; encryption is used only for storage
- Tokenization scrambles data; encryption replaces it with a token
Correct answer: Tokenization replaces sensitive data with a non-sensitive placeholder; encryption transforms data using a mathematical algorithm and key
Tokenization substitutes sensitive data with a token that has no intrinsic value, while encryption transforms data mathematically and can be reversed with the key.
Question 37: Which architectural pattern is recommended by CCSK to reduce the attack surface of cloud workloads?
- Flat network topology
- Micro-segmentation (Correct answer)
- Monolithic deployments
- Single availability zone deployments
Correct answer: Micro-segmentation
Micro-segmentation divides the network into small zones to limit lateral movement if one workload is compromised.
Question 38: What is the CSA phrase for something assigned to an object within a specific namespace?
- Persona
- Authorizer
- Identity (Correct answer)
- Identifier
Correct answer: Identity
An Identifier is the means through which one's identity is declared. Persona is identity plus contextual characteristics. The CSA does not use the name Authorizer as SAML is a federation standard.
Question 39: Who is in charge of the physical infrastructure and virtualization platform's security?
- The cloud consumer
- The cloud provider (Correct answer)
- It depends on the agreement
- The responsibility is split equally
Correct answer: The cloud provider
The cloud provider is in charge of securing the underlying infrastructure and virtualization technologies from external attack or internal misuse. This entails employing patched and up-to-date hypervisors that are appropriately setup and supported with processes to keep them safe over time.
Question 40: In cloud security architecture, what is the function of a 'security group'?
- A virtual firewall controlling inbound and outbound traffic to instances (Correct answer)
- A team responsible for cloud security policy
- A logging mechanism for cloud API calls
- A certificate authority for cloud services
Correct answer: A virtual firewall controlling inbound and outbound traffic to instances
Security groups act as virtual firewalls that control network traffic at the instance level in cloud environments like AWS and Azure.
Question 41: What does the CSA recommend as a compensating control when a cloud provider cannot supply audit logs?
- Encrypt all data and assume logs are sufficient
- Terminate the cloud contract immediately
- Deploy a third-party SIEM to capture available telemetry (Correct answer)
- Rely solely on the provider's SLA commitments
Correct answer: Deploy a third-party SIEM to capture available telemetry
When provider audit logs are limited, deploying a SIEM to collect available telemetry compensates for the logging gap.
Question 42: What is a 'warm standby' disaster recovery pattern in cloud environments?
- A backup that requires manual restoration of all data before use
- A fully idle backup environment with no running resources
- A scaled-down but running replica of the production environment that can be quickly scaled up for failover (Correct answer)
- A complete production-scale duplicate running in parallel at all times
Correct answer: A scaled-down but running replica of the production environment that can be quickly scaled up for failover
Warm standby maintains a minimally scaled running environment that mirrors production, enabling faster recovery than cold standby but at lower cost than hot standby.
Question 43: What is 'data remanence' and why is it a concern in cloud environments?
- Data that is replicated across multiple cloud regions
- Data that is retained for compliance archiving
- Data that remains encrypted during processing
- Data that persists on storage media after deletion, potentially exposing residual information (Correct answer)
Correct answer: Data that persists on storage media after deletion, potentially exposing residual information
Data remanence refers to residual data left on storage after deletion, which is a concern in cloud because customers often cannot verify physical media sanitization.
Question 44: Which CSA reference model defines the relationship between cloud service models and deployment models?
- Logical Model (Correct answer)
- Cloud Cube Model
- Trust Zones Framework
- Cloud Controls Matrix
Correct answer: Logical Model
The CSA Logical Model maps the relationships between cloud service and deployment models to help understand security responsibilities.
Question 45: Which of the following best describes a 'cloud broker' in the NIST cloud computing model?
- An entity that physically hosts cloud infrastructure
- An entity that audits cloud provider compliance
- An entity that certifies cloud security standards
- An entity that manages use, performance, and delivery of cloud services between providers and consumers (Correct answer)
Correct answer: An entity that manages use, performance, and delivery of cloud services between providers and consumers
A cloud broker acts as an intermediary who negotiates relationships and manages cloud services between providers and consumers.
Question 46: What is 'eDiscovery' in the context of CCSK and what cloud challenges does it present?
- The legal process of identifying, collecting, and producing electronically stored information for legal proceedings, complicated in cloud by data distribution and provider access limits (Correct answer)
- A tool for discovering shadow IT cloud usage
- A compliance framework for electronic health records in cloud
- A cloud provider's process for discovering security vulnerabilities
Correct answer: The legal process of identifying, collecting, and producing electronically stored information for legal proceedings, complicated in cloud by data distribution and provider access limits
Cloud eDiscovery is complicated because data may be distributed across jurisdictions, commingled with other tenants, and require provider assistance to collect.
Question 47: What is the primary security concern with multi-tenancy in cloud environments?
- Difficulty provisioning resources quickly
- Lack of encryption at rest
- Isolation failure between tenant workloads (Correct answer)
- Increased hardware cost
Correct answer: Isolation failure between tenant workloads
Multi-tenancy introduces risk that a failure in isolation mechanisms could expose one tenant's data or workloads to another.
Question 48: What is 'cloud bursting' and what security challenge does it introduce?
- Migrating all data to cloud at once; it causes access control gaps
- Dynamically extending workloads from private to public cloud; it creates data spillage risk (Correct answer)
- Encrypting data across cloud regions; it introduces key management complexity
- A DDoS attack targeting cloud APIs; it introduces availability risk
Correct answer: Dynamically extending workloads from private to public cloud; it creates data spillage risk
Cloud bursting moves workloads to public cloud under peak load, creating risk that sensitive data may leave the private environment without proper controls.
Question 49: What distinguishes a 'security group' in IaaS from a traditional network firewall?
- Security groups are software-defined and attached per instance rather than per network boundary (Correct answer)
- Security groups cannot block inbound traffic, only outbound
- Security groups operate at Layer 7 while firewalls operate at Layer 3
- Security groups require physical hardware appliances to function
Correct answer: Security groups are software-defined and attached per instance rather than per network boundary
Security groups are software-defined, stateful packet filters that attach to individual virtual instances or interfaces rather than guarding a fixed network perimeter.
Question 50: Which security concern is most critical when exposing microservices through a public API in a cloud environment?
- Using HTTP instead of HTTPS for internal service communication
- Lack of proper authentication and authorization controls on API endpoints (Correct answer)
- Excessive logging of non-sensitive events
- Deploying microservices in a single availability zone
Correct answer: Lack of proper authentication and authorization controls on API endpoints
Without strong authentication and authorization controls, unauthorized actors can access or abuse API endpoints, making this the most critical security concern for public APIs.
Question 51: What is the primary security concern with 'live migration' of virtual machines in cloud environments?
- Live migration increases latency for all cloud services
- Live migration requires rebooting all VMs on the source host
- VM memory contents, potentially including sensitive data and keys, are transmitted between hosts during migration (Correct answer)
- Live migration permanently deletes the source VM image
Correct answer: VM memory contents, potentially including sensitive data and keys, are transmitted between hosts during migration
During live migration, VM memory (which may contain encryption keys, passwords, or sensitive data) is transmitted between physical hosts, creating an interception risk.
Question 52: In the CSA Cloud Controls Matrix (CCM), what is the primary purpose of the control domains?
- To define SLA requirements for cloud contracts
- To list cloud vendors and their certifications
- To outline data sovereignty regulations by country
- To provide security controls mapped to industry standards and cloud service models (Correct answer)
Correct answer: To provide security controls mapped to industry standards and cloud service models
The CCM provides a framework of security controls aligned to cloud service models and mapped to standards like ISO 27001, NIST, and PCI DSS.
Question 53: According to CCSK, how does 'auto-scaling' in cloud environments complicate incident response?
- Auto-scaling interferes with encryption key rotation during incidents
- Auto-scaling reduces the number of instances available for forensic analysis
- New instances spin up and old ones terminate automatically, potentially destroying forensic evidence and confusing attack timelines (Correct answer)
- Auto-scaling makes it harder to provision new resources for response activities
Correct answer: New instances spin up and old ones terminate automatically, potentially destroying forensic evidence and confusing attack timelines
Auto-scaling terminates instances based on load, destroying forensic artifacts; investigators must ensure logging is centralized before instances disappear.
Question 54: What does the CSA define as the 'control plane' in cloud computing?
- The physical network switches that route traffic
- The encryption module protecting data in transit
- The management layer that allows users to configure and control cloud resources (Correct answer)
- The billing interface for tracking cloud expenditure
Correct answer: The management layer that allows users to configure and control cloud resources
The control plane is the management layer through which users provision, configure, and orchestrate cloud resources and services.
Question 55: What is 'post-incident review' (PIR) and what value does it provide after a cloud security incident?
- A structured analysis of what happened, why, and how to prevent recurrence — improving future detection and response (Correct answer)
- A review of cloud costs incurred during the incident
- A compliance audit triggered automatically after every incident
- A legal review determining cloud provider liability for the incident
Correct answer: A structured analysis of what happened, why, and how to prevent recurrence — improving future detection and response
PIR (also called a post-mortem or lessons-learned review) systematically analyzes incident causes and response gaps to drive improvements in controls and procedures.
Question 56: In CSA's Egress Monitoring guidance, what is the main goal of monitoring outbound cloud traffic?
- To reduce bandwidth costs by throttling non-essential transfers
- To detect data exfiltration and unauthorized transmission of sensitive data (Correct answer)
- To ensure compliance with cloud provider SLA uptime commitments
- To enforce routing policies for multi-cloud architectures
Correct answer: To detect data exfiltration and unauthorized transmission of sensitive data
Egress monitoring focuses on detecting when sensitive data leaves cloud environments without authorization, which is a key indicator of a breach.
Question 57: According to the CSA CCSK guidance, which phase of the Secure Software Development Lifecycle (SSDLC) should threat modeling occur?
- Operations
- Design (Correct answer)
- Deployment
- Testing
Correct answer: Design
Threat modeling should be performed during the Design phase so that security requirements and mitigations are built into the architecture before code is written.
Question 58: What is 'data remanence' and why is it a concern in cloud environments?
- The latency introduced when retrieving archived cloud data
- Data that remains accessible after a user logs out of a cloud portal
- Residual data that persists on storage media after deletion, potentially accessible to others (Correct answer)
- Data that is replicated across multiple cloud regions automatically
Correct answer: Residual data that persists on storage media after deletion, potentially accessible to others
Data remanence is the residual representation of data after deletion, which is a cloud concern because customers share physical storage with others and cannot verify physical sanitization.
Question 59: What does CCSK recommend regarding cloud provider support and coordination during a security incident?
- Contact the provider only after completing internal investigation
- Avoid contacting the cloud provider to prevent contractual complications
- Rely entirely on the cloud provider to manage all aspects of the incident
- Establish provider escalation contacts and incident notification procedures in advance, before an incident occurs (Correct answer)
Correct answer: Establish provider escalation contacts and incident notification procedures in advance, before an incident occurs
Pre-establishing escalation contacts and notification procedures with providers ensures faster response and access to provider-side evidence when an incident occurs.
Question 60: According to CCSK, what is a key challenge of applying traditional DRM (Digital Rights Management) in cloud environments?
- DRM eliminates the need for encryption in cloud
- DRM tools are too expensive for cloud use
- DRM only works with on-premises storage systems
- DRM requires persistent connectivity to rights servers which can conflict with cloud availability patterns (Correct answer)
Correct answer: DRM requires persistent connectivity to rights servers which can conflict with cloud availability patterns
Traditional DRM requires connection to rights servers to validate access, which can create availability and latency issues in distributed cloud environments.
Certificate of Cloud Security Knowledge (CCSK)
The CCSK is a vendor-neutral cloud security certification by the Cloud Security Alliance (CSA) that validates knowledge across 12 domains covering cloud architecture, governance, risk, IAM, infrastructure, data security, workload security, application security, monitoring, and incident response in cloud environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds