Certified Cloud Security Professional (CCSP) — Questions and Answers
Question 1: What is the main purpose of a Cloud Access Security Broker (CASB)?
- To encrypt data before it reaches the cloud provider
- To provide multi-factor authentication to cloud portals
- To replace the cloud provider's built-in firewall
- To act as an intermediary that enforces security policies between cloud users and cloud services (Correct answer)
Correct answer: To act as an intermediary that enforces security policies between cloud users and cloud services
A CASB sits between cloud service consumers and providers to enforce visibility, compliance, data security, and threat protection policies.
Question 2: Which cloud security practice involves regularly reviewing and removing unused IAM accounts, roles, and permissions?
- Penetration testing
- Security awareness training
- Threat intelligence integration
- Access entitlement review (access recertification) (Correct answer)
Correct answer: Access entitlement review (access recertification)
Access entitlement reviews (also called access recertification or user access reviews) periodically verify that all IAM grants are still needed and remove those that are not.
Question 3: What is the primary security concern introduced by multitenancy in cloud computing environments?
- Inability to enforce encryption for individual tenants
- Potential for data leakage or unauthorized access between co-located tenant workloads (Correct answer)
- Increased latency due to shared network bandwidth
- Difficulty in deploying applications across multiple instances
Correct answer: Potential for data leakage or unauthorized access between co-located tenant workloads
Multitenancy introduces the risk that tenant data or workloads could be exposed to other tenants through misconfigurations, virtualization vulnerabilities, or side-channel attacks on shared infrastructure.
Question 4: Which cloud infrastructure component acts as a logical boundary to isolate resources between different tenants or business units?
- Content Delivery Network (CDN)
- Load Balancer
- Virtual Private Cloud (VPC) (Correct answer)
- API Gateway
Correct answer: Virtual Private Cloud (VPC)
A Virtual Private Cloud (VPC) creates an isolated network segment within the cloud provider's infrastructure to separate tenant resources.
Question 5: What is the sole data format supported by the SOAP API?
- HTML
- SAML
- XSML
- XML (Correct answer)
Correct answer: XML
Only the XML data format is supported by the SOAP protocol.
Question 6: Which NIST cloud computing characteristic describes the ability of cloud resources to be provisioned and released rapidly to scale elastically with demand?
- Rapid elasticity (Correct answer)
- Broad network access
- Measured service
- Resource pooling
Correct answer: Rapid elasticity
Rapid elasticity allows cloud resources to be provisioned and released quickly—automatically in some cases—to scale with demand, appearing unlimited to the consumer.
Question 7: What is the key difference between vulnerability scanning and penetration testing?
- Vulnerability scanning identifies potential weaknesses automatically; penetration testing actively exploits vulnerabilities to determine real impact (Correct answer)
- Penetration testing is automated; vulnerability scanning is manual
- Vulnerability scanning is illegal; penetration testing is not
- Vulnerability scanning requires physical access; penetration testing is remote only
Correct answer: Vulnerability scanning identifies potential weaknesses automatically; penetration testing actively exploits vulnerabilities to determine real impact
Vulnerability scanners produce lists of potential issues without confirming exploitability, while penetration testers actively attempt to exploit vulnerabilities to assess real-world risk.
Question 8: Which technique helps detect unauthorized changes to cloud infrastructure configurations?
- Penetration testing
- Multi-factor authentication
- Employee awareness training
- Continuous configuration monitoring and drift detection (Correct answer)
Correct answer: Continuous configuration monitoring and drift detection
Continuous configuration monitoring compares the running infrastructure state against a known-good baseline to detect and alert on unauthorized changes (drift).
Question 9: What does a runtime application self-protection (RASP) solution do?
- Performs static analysis of container images
- Monitors network traffic outside the application
- Scans source code before compilation
- Instruments the application to detect and block attacks in real time from within the running process (Correct answer)
Correct answer: Instruments the application to detect and block attacks in real time from within the running process
RASP integrates into the application runtime to monitor execution, detect attack patterns, and block malicious actions from within the application itself.
Question 10: Which cloud deployment model is operated solely for a group of organizations with shared missions, security requirements, or compliance objectives?
- Public cloud
- Hybrid cloud
- Community cloud (Correct answer)
- Private cloud
Correct answer: Community cloud
A community cloud is provisioned for a specific community of consumers with common concerns such as shared mission, security requirements, policy, or compliance considerations.
Question 11: What is the primary purpose of identity federation in cloud computing environments?
- To encrypt user credentials stored across cloud identity providers
- To enable users to authenticate once and access resources across multiple cloud services using a single identity (Correct answer)
- To duplicate user accounts across multiple cloud platforms for redundancy
- To restrict each user to accessing only a single cloud provider
Correct answer: To enable users to authenticate once and access resources across multiple cloud services using a single identity
Identity federation enables single sign-on (SSO) across multiple cloud services by establishing trust between identity providers, reducing authentication complexity and credential sprawl.
Question 12: Which cloud storage type is best suited for unstructured data such as images, videos, and backups?
- Object storage (Correct answer)
- In-memory storage
- File storage
- Block storage
Correct answer: Object storage
Object storage is designed for unstructured data, storing items as objects with metadata and a unique identifier rather than in a hierarchical file system.
Question 13: Which data security technique ensures that data remains protected even if the storage medium is stolen?
- Encryption at rest (Correct answer)
- Data tokenization
- Data classification
- Data masking
Correct answer: Encryption at rest
Encryption at rest protects data stored on physical media by rendering it unreadable without the correct decryption key.
Question 14: In cloud security, what does UEBA (User and Entity Behavior Analytics) do?
- Enforces access control policies across cloud services
- Automates compliance report generation
- Establishes behavioral baselines and alerts on anomalous deviations that may indicate insider threats or compromised accounts (Correct answer)
- Manages user passwords and MFA enrollment
Correct answer: Establishes behavioral baselines and alerts on anomalous deviations that may indicate insider threats or compromised accounts
UEBA uses machine learning to model normal behavior for users and entities, then flags deviations (e.g., data exfiltration patterns, unusual login times) as potential threats.
Question 15: Which cloud application security component validates the identity of API consumers using client credentials before granting access?
- DNS resolver
- API Key / OAuth 2.0 Client Credentials flow (Correct answer)
- Content Delivery Network (CDN)
- Load balancer health check
Correct answer: API Key / OAuth 2.0 Client Credentials flow
API keys or the OAuth 2.0 client credentials grant are used to authenticate machine-to-machine API consumers, ensuring only authorized clients can call the API.
Question 16: In cloud data security, what does IRM (Information Rights Management) primarily protect?
- Network packets in transit
- Documents and files after they leave the organization (Correct answer)
- Physical hardware in the data center
- Database connection strings
Correct answer: Documents and files after they leave the organization
IRM enforces usage policies on documents and files so that access controls follow the content even outside the organization's perimeter.
Question 17: What does the term 'cloud bursting' describe in a hybrid cloud architecture?
- A failure condition where cloud resource quotas become exhausted
- A DDoS attack targeting cloud infrastructure resources
- The automatic overflow of workloads from a private cloud to a public cloud during demand spikes (Correct answer)
- The process of permanently migrating all workloads to a public cloud
Correct answer: The automatic overflow of workloads from a private cloud to a public cloud during demand spikes
Cloud bursting allows applications to run in a private cloud and automatically extend to public cloud resources when demand exceeds private cloud capacity, enabling cost-effective scalability.
Question 18: What is the OWASP Secure Coding Practices guideline's primary recommendation for handling user input?
- Log all input but do not validate it
- Validate and sanitize all input from untrusted sources (Correct answer)
- Trust all input from authenticated users
- Reject all input longer than 50 characters
Correct answer: Validate and sanitize all input from untrusted sources
OWASP recommends treating all input from external sources as untrusted and applying validation, sanitization, and encoding to prevent injection and other attacks.
Question 19: What is the primary security concern with a hypervisor in a multi-tenant cloud environment?
- Hypervisors prevent the use of firewalls
- A compromised hypervisor can expose all guest VMs running on that host (Correct answer)
- Hypervisors increase network latency significantly
- Hypervisors cannot support encrypted VMs
Correct answer: A compromised hypervisor can expose all guest VMs running on that host
Because the hypervisor controls all VMs on a host, a vulnerability in it can allow an attacker to break out of one VM and access others on the same physical host.
Question 20: What is the purpose of a bastion host (jump server) in cloud infrastructure security?
- To store encryption keys for cloud resources
- To load balance traffic across multiple servers
- To provide a hardened, monitored single entry point for administrative access to private network resources (Correct answer)
- To encrypt all traffic within the VPC
Correct answer: To provide a hardened, monitored single entry point for administrative access to private network resources
A bastion host is a specially secured server that serves as the sole access point for SSH/RDP into private cloud networks, reducing the attack surface.
Question 21: The following capabilities, with the exception of ______, should all be guaranteed by the options included in cloud application designs.
- Encryption of data at rest
- Hashing database fields (Correct answer)
- Data masking
- Encryption of data in transit
Correct answer: Hashing database fields
Software developers designing applications for the cloud should expect to include options to ensure all of the following capabilities except for hashing database fields.
Question 22: What is the primary purpose of data classification in a cloud environment?
- To assign appropriate security controls based on sensitivity (Correct answer)
- To compress data for transmission
- To reduce storage costs
- To enable faster data retrieval
Correct answer: To assign appropriate security controls based on sensitivity
Data classification categorizes data by sensitivity so that the appropriate security controls can be applied to each category.
Question 23: In the context of cloud eDiscovery, what is the primary challenge compared to on-premises environments?
- Cloud providers have too much storage
- eDiscovery tools do not work on cloud data
- Data may be distributed across multiple jurisdictions and commingled with other tenants' data, complicating legal hold and collection (Correct answer)
- Cloud systems cannot produce logs
Correct answer: Data may be distributed across multiple jurisdictions and commingled with other tenants' data, complicating legal hold and collection
Cloud eDiscovery challenges include multi-jurisdictional data storage, commingling of data across tenants, and limited customer access to enforce legal holds on provider-managed infrastructure.
Question 24: What is the primary purpose of a Business Associate Agreement (BAA) in the context of HIPAA compliance in the cloud?
- To legally obligate a cloud vendor handling PHI to comply with HIPAA security and privacy requirements (Correct answer)
- To establish pricing between a company and its cloud provider
- To authorize the cloud provider to share medical data with third parties
- To certify that a cloud provider has passed a HIPAA audit
Correct answer: To legally obligate a cloud vendor handling PHI to comply with HIPAA security and privacy requirements
A BAA is a legally binding contract required by HIPAA whenever a covered entity shares protected health information (PHI) with a third-party service provider.
Question 25: What is the purpose of threat intelligence sharing in cloud security operations?
- To enable cloud providers to monitor customer data
- To allow organizations to collectively improve defenses by sharing indicators of compromise and attacker tactics across the community (Correct answer)
- To automate software patching
- To reduce cloud storage costs
Correct answer: To allow organizations to collectively improve defenses by sharing indicators of compromise and attacker tactics across the community
Threat intelligence sharing (via ISACs, STIX/TAXII, or commercial feeds) allows organizations to benefit from others' detection and response experiences to defend against known threats faster.
Question 26: In a Software as a Service (SaaS) deployment, which area does the cloud customer retain primary responsibility for?
- Network and server infrastructure
- Application code and features
- User identity, access management, and data stored in the application (Correct answer)
- Underlying database configuration
Correct answer: User identity, access management, and data stored in the application
In SaaS, the customer's responsibility is primarily limited to managing user access, identity provisioning, and the data they input and store in the application.
Question 27: What is the primary risk of storing sensitive data in JWT (JSON Web Token) payloads?
- JWTs cannot be transmitted over HTTPS
- JWTs expire too quickly for production use
- JWT payloads are base64-encoded but not encrypted by default, making the data readable if intercepted (Correct answer)
- JWTs are limited to 256 bytes
Correct answer: JWT payloads are base64-encoded but not encrypted by default, making the data readable if intercepted
JWT payloads are only base64url-encoded, not encrypted, so anyone who intercepts or decodes the token can read the claims within it.
Question 28: In cloud risk assessment, what is the formula for calculating Annual Loss Expectancy (ALE)?
- ALE = Control Cost Ă— Risk Level
- ALE = Single Loss Expectancy (SLE) Ă— Annual Rate of Occurrence (ARO) (Correct answer)
- ALE = Vulnerability Score Ă— Impact Score
- ALE = Asset Value Ă— Threat Frequency
Correct answer: ALE = Single Loss Expectancy (SLE) Ă— Annual Rate of Occurrence (ARO)
ALE is calculated by multiplying the Single Loss Expectancy (the dollar loss from one incident) by the Annual Rate of Occurrence (how often the incident is expected per year).
Question 29: Which OWASP Top 10 vulnerability involves attackers manipulating SQL queries by injecting malicious input?
- Security Misconfiguration
- Broken Access Control
- SQL Injection (Correct answer)
- Insecure Deserialization
Correct answer: SQL Injection
SQL injection occurs when user-supplied input is incorporated into a SQL query without proper sanitization, allowing attackers to manipulate the database.
Question 30: In secure software development for cloud applications, what does SAST (Static Application Security Testing) analyze?
- Network traffic between microservices
- Running application behavior in production
- Container image vulnerabilities
- Source code or compiled binaries without executing the program (Correct answer)
Correct answer: Source code or compiled binaries without executing the program
SAST tools analyze source code, bytecode, or binaries statically to identify security vulnerabilities early in the development lifecycle before the code runs.
Question 31: Which regulation requires organizations that handle payment card data to comply with a set of security standards?
- HIPAA
- FERPA
- SOX
- PCI DSS (Correct answer)
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for all organizations that store, process, or transmit cardholder data.
Certified Cloud Security Professional (CCSP)
The CCSP certification validates advanced technical skills to design, manage, and secure data, applications, and infrastructure in the cloud using best practices, policies, and procedures. It covers six domains spanning cloud concepts, data security, platform security, application security, security operations, and legal/compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds