← All CCSK Flashcard Decks

Certificate of Cloud Security Knowledge Flashcards

7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Certificate of Cloud Security Knowledge flashcards as text
  1. Which CSA guidance domain focuses on ensuring that an organization's cloud usage aligns with its legal and regulatory obligations?

    Answer: Compliance and Audit Management

    Compliance and Audit Management addresses aligning cloud use with legal, regulatory, and contractual requirements and managing audit processes.

  2. In the shared responsibility model, which security control is ALWAYS the cloud customer's responsibility regardless of service model?

    Answer: Identity and access management for their users

    Customers always retain responsibility for managing their own users' identities and access permissions, regardless of whether the service is IaaS, PaaS, or SaaS.

  3. What is the primary purpose of a Cloud Access Security Broker (CASB)?

    Answer: To enforce security policies between cloud service consumers and providers

    A CASB sits between users and cloud services to enforce security policies, provide visibility, and control data movement.

  4. Which term describes the risk that a cloud provider's technical or business failure could disrupt a customer's operations?

    Answer: Provider dependency risk

    Provider dependency risk captures the exposure created when a customer relies on a cloud provider whose failure—technical or commercial—would impact the customer.

  5. In cloud security, what does the term 'elasticity' primarily refer to?

    Answer: The ability to rapidly scale resources up or down to match demand

    Elasticity is the cloud characteristic of dynamically provisioning and releasing resources to match workload demand, which has direct implications for security tooling and cost.

  6. What is 'data remanence' and why is it a concern in cloud environments?

    Answer: Residual data that persists on storage media after deletion, potentially accessible to others

    Data remanence is the residual representation of data after deletion, which is a cloud concern because customers share physical storage with others and cannot verify physical sanitization.

  7. Which cloud deployment model is MOST appropriate for an organization that requires maximum control over its infrastructure while leveraging cloud technologies?

    Answer: Private cloud

    A private cloud is dedicated to a single organization, providing maximum control over infrastructure while still delivering cloud characteristics like on-demand self-service.