← All CCSK Flashcard Decks

(CSA) Basic Flashcards

7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 (CSA) Basic flashcards as text
  1. According to CSA, what distinguishes 'security as a service' (SecaaS) from traditional security products?

    Answer: Security capabilities are delivered via cloud subscription rather than deployed on-premises

    SecaaS delivers security functions—such as identity management, SIEM, or vulnerability scanning—as cloud-based subscription services without on-premises hardware.

  2. In CSA's Egress Monitoring guidance, what is the main goal of monitoring outbound cloud traffic?

    Answer: To detect data exfiltration and unauthorized transmission of sensitive data

    Egress monitoring focuses on detecting when sensitive data leaves cloud environments without authorization, which is a key indicator of a breach.

  3. What is the purpose of 'object storage' in cloud environments, according to CSA infrastructure guidance?

    Answer: To store unstructured data as discrete objects with associated metadata, accessed via APIs

    Object storage stores unstructured data (files, images, logs) as objects with metadata, accessed through REST APIs, making it highly scalable and durable.

  4. According to CSA, which is the most effective control for preventing unauthorized lateral movement after an initial cloud account compromise?

    Answer: Implementing micro-segmentation and least-privilege network policies

    Micro-segmentation limits blast radius by restricting east-west traffic so a compromised workload cannot freely access other resources in the environment.

  5. In CSA Guidance, what is 'immutable infrastructure'?

    Answer: Cloud resources that are replaced rather than modified when changes are needed

    Immutable infrastructure means servers and components are never modified after deployment; instead, new versions replace old ones, reducing configuration drift and attack surface.

  6. According to CSA, what is the key advantage of using 'infrastructure as code' (IaC) for cloud security?

    Answer: It enables consistent, version-controlled, and auditable provisioning of secure configurations

    IaC enables security configurations to be version-controlled, peer-reviewed, and consistently applied, reducing human error and enabling security-as-code practices.

  7. Which CSA guidance concept refers to the risk that a cloud provider's technical or business failure could disrupt a customer's operations?

    Answer: Provider dependency risk

    Provider dependency risk recognizes that reliance on a single cloud provider creates exposure to that provider's outages, insolvency, or service changes.