โ† All CCSK Flashcard Decks

Cloud Application Security Flashcards

7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Cloud Application Security flashcards as text
  1. In the CSA Cloud Controls Matrix (CCM), which domain specifically addresses application and interface security for cloud services?

    Answer: Application & Interface Security (AIS)

    The CCM's Application & Interface Security (AIS) domain covers controls for secure application development, testing, and integrity of customer-facing interfaces.

  2. What is the purpose of a Content Security Policy (CSP) HTTP response header in web application security?

    Answer: It restricts the sources from which a browser can load resources, mitigating XSS attacks

    CSP instructs the browser to only load resources (scripts, styles, images) from trusted origins, significantly reducing the risk of Cross-Site Scripting (XSS) attacks.

  3. When performing penetration testing on a cloud application, which action MUST be taken before starting to avoid violating the cloud provider's terms of service?

    Answer: Obtain prior written authorization from the cloud provider and the application owner

    Cloud providers require customers to request explicit authorization before conducting penetration tests; failure to do so may violate terms of service and result in account suspension.

  4. Which secure coding practice specifically prevents SQL Injection attacks in cloud-hosted database-backed applications?

    Answer: Parameterized queries (prepared statements)

    Parameterized queries separate SQL code from user-supplied data, ensuring that user input is always treated as a data value and never interpreted as executable SQL.

  5. In a serverless cloud application, which security consideration is unique compared to traditional application hosting?

    Answer: Overly permissive function-level IAM roles and event injection via triggers

    Serverless functions often inherit overly permissive IAM roles, and their many event-based triggers (S3, SQS, API Gateway) can be exploited for injection attacks if inputs are not validated.

  6. What does the principle of 'least privilege' mean when applied to cloud application service accounts?

    Answer: Service accounts should be granted only the minimum permissions necessary to perform their function

    Least privilege limits a service account's permissions to only what is required for its specific task, reducing the blast radius if the account is compromised.

  7. Which approach best supports continuous security validation of cloud application deployments in a CI/CD pipeline?

    Answer: Integrating automated SAST, DAST, and dependency scanning into every pipeline build and blocking on critical findings

    Embedding automated security scanning (SAST, DAST, SCA) into every CI/CD pipeline build ensures continuous validation and allows teams to catch and remediate vulnerabilities before code reaches production.