Mixed Deck — All CCSK Topics Flashcards
100 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCSK Topics flashcards as text
What does CCSK identify as the primary legal challenge of cloud computing related to data location?
Answer: Data may reside in multiple jurisdictions simultaneously, creating complex and potentially conflicting legal obligations
Cloud data can be distributed across multiple countries, each with different privacy and security laws, creating jurisdictional conflicts and compliance complexity.
What does CCSK say about the handling of 'personally identifiable information' (PII) in cloud audit logs?
Answer: Audit logs containing PII must be protected with the same controls as other sensitive data, and retention periods must comply with privacy regulations
Audit logs often contain PII (usernames, IP addresses, access details) and must be protected, access-controlled, and retained per applicable privacy and compliance requirements.
In the CSA Cloud Controls Matrix (CCM), what is the primary purpose of the tool?
Answer: To provide a security controls framework specifically designed for cloud environments
The CCM provides a detailed controls framework aligned to cloud security domains, helping organizations assess and implement appropriate security measures.
According to CSA, which cloud deployment model provides infrastructure exclusively for a single organization and may be managed on-premises or by a third party?
Answer: Private cloud
A private cloud is dedicated to a single organization and can be hosted on-premises or externally, offering greater control over data and security.
Which layer is the most significant for security because it is considered the basis for secure cloud operations?
Answer: Infrastructure
Infrastructure security is the foundation for functioning securely in the cloud. "Infrastructure" refers to the glue of computers and networks upon which we build everything.
What is a 'Virtual Private Cloud' (VPC) and why is it a security best practice?
Answer: An isolated virtual network within a public cloud that provides network-level segmentation
A VPC provides an isolated virtual network environment within public cloud, allowing organizations to control IP ranges, subnets, and routing for security segmentation.
What does CCSK recommend regarding cloud provider support and coordination during a security incident?
Answer: Establish provider escalation contacts and incident notification procedures in advance, before an incident occurs
Pre-establishing escalation contacts and notification procedures with providers ensures faster response and access to provider-side evidence when an incident occurs.
What is 'VM sprawl' and what security risk does it create in cloud environments?
Answer: The spread of unpatched virtual machines that are difficult to track and manage, creating unmanaged attack surfaces
VM sprawl results in orphaned, unpatched VMs that are forgotten but still running, creating entry points for attackers that are outside normal patching and monitoring.
According to CCSK, what is 'infrastructure as code' (IaC) security scanning used to detect?
Answer: Security misconfigurations and policy violations in infrastructure templates before deployment
IaC security scanning analyzes templates like Terraform or CloudFormation for misconfigurations, overly permissive policies, or compliance violations before they are deployed.
What is 'tokenization' and how does it differ from encryption in cloud data protection?
Answer: Tokenization replaces sensitive data with a non-sensitive placeholder; encryption transforms data using a mathematical algorithm and key
Tokenization substitutes sensitive data with a token that has no intrinsic value, while encryption transforms data mathematically and can be reversed with the key.
Static Application Security Testing (SAST) tools analyze an application to find vulnerabilities at which stage?
Answer: By examining source code or binaries without executing the program
SAST analyzes source code, bytecode, or binaries in a non-running state, enabling early detection of vulnerabilities before deployment.
What does the principle of 'least privilege' mean when applied to cloud application service accounts?
Answer: Service accounts should be granted only the minimum permissions necessary to perform their function
Least privilege limits a service account's permissions to only what is required for its specific task, reducing the blast radius if the account is compromised.
Which CSA guidance domain focuses on ensuring that an organization's cloud usage aligns with its legal and regulatory obligations?
Answer: Compliance and Audit Management
Compliance and Audit Management addresses aligning cloud use with legal, regulatory, and contractual requirements and managing audit processes.
What does CCSK say about the use of 'data masking' in non-production cloud environments?
Answer: Sensitive production data should be masked or anonymized before use in test or development environments
Non-production environments typically have weaker security controls, so sensitive data should be masked or synthesized to reduce exposure risk.
In CSA's guidance, what is 'data residency'?
Answer: The requirement that data must be stored and processed within specific geographic boundaries
Data residency refers to the legal and regulatory requirements mandating that certain data remain within defined geographic or national boundaries.
What is 'ISO/IEC 27017' and how does it differ from ISO/IEC 27001 in cloud security?
Answer: ISO 27017 provides cloud-specific security controls extending ISO 27001, addressing cloud-unique risks like virtual environments and shared infrastructure
ISO 27017 extends the ISO 27001 framework with additional controls specific to cloud services, covering topics like virtual machines, provider-customer responsibilities, and asset ownership.
What is 'data sovereignty' in the context of CCSK cloud security?
Answer: The legal principle that data is subject to the laws of the country where it is stored
Data sovereignty means stored data is governed by the laws and regulations of the jurisdiction where the data physically resides.
According to CSA, what is the primary security concern with 'serverless computing' architectures?
Answer: The expanded attack surface from numerous functions and increased reliance on third-party dependencies
Serverless increases the number of deployed functions and dependencies, expanding the attack surface while requiring careful input validation and least-privilege IAM policies.
What does CCSK identify as a key requirement for cloud security incident notification to affected parties?
Answer: Organizations must understand contractual and regulatory breach notification obligations and meet defined timelines
Breach notification requirements vary by regulation (GDPR, HIPAA, state laws) and contracts, requiring organizations to know their obligations and meet mandatory timelines.
In CSA's guidance, what is 'continuous compliance monitoring' in cloud environments?
Answer: Automated, real-time assessment of cloud configurations against security policies and regulatory requirements
Continuous compliance monitoring uses automated tools to constantly assess cloud resource configurations against defined policies, enabling rapid detection of drift or violations.