Mixed Deck — All CCSP Topics Flashcards
100 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCSP Topics flashcards as text
What is the primary purpose of a cloud Security Operations Center (SOC)?
Answer: To continuously monitor, detect, analyze, and respond to cybersecurity incidents in the cloud environment
A SOC is a centralized function staffed with security analysts who monitor the organization's cloud environment 24/7 to detect and respond to threats.
In cloud incident response, what does the containment phase primarily involve?
Answer: Limiting the spread and impact of the incident to prevent further damage
Containment stops the attack from spreading by isolating affected systems, revoking compromised credentials, and blocking malicious traffic.
Which cloud service model places the MOST infrastructure security responsibility on the cloud customer?
Answer: Infrastructure as a Service (IaaS)
In IaaS, the customer manages the OS, middleware, runtime, and applications, making them responsible for the largest share of security controls.
Which network security control is typically used at the boundary of a cloud VPC to filter inbound and outbound traffic?
Answer: Security Group / Network Access Control List (NACL)
Security Groups and NACLs are cloud-native controls that filter traffic at the VPC or subnet level based on IP, port, and protocol rules.
Which secure development practice involves reviewing code written by another developer to identify security flaws before deployment?
Answer: Peer code review / security code review
Security-focused code review uses a second developer (or automated tool) to scrutinize code for vulnerabilities before it is merged or deployed.
What is a security group in AWS cloud infrastructure?
Answer: A virtual stateful firewall that controls inbound and outbound traffic for cloud instances
AWS Security Groups act as virtual stateful firewalls at the instance level, allowing administrators to define traffic rules based on port, protocol, and source/destination.
Automation of configuration helps in ____ from the perspective of security.
Answer: Reducing potential attack vectors
From a security perspective, automation of configuration aids in reducing potential attack vectors.
In cloud risk management, what does quantitative risk analysis produce that qualitative analysis does not?
Answer: Numerical estimates of risk in monetary terms (e.g., Annual Loss Expectancy)
Quantitative risk analysis calculates numerical values such as ALE (Annual Loss Expectancy) = ARO × SLE, enabling cost-benefit comparison of security controls.
What is the significance of the EU-US Data Privacy Framework (successor to Privacy Shield) for cloud computing?
Answer: It provides a legal mechanism for transferring personal data from the EU to certified US organizations in compliance with GDPR
The EU-US Data Privacy Framework allows US organizations that self-certify to receive EU personal data transfers lawfully under GDPR's requirements for third-country transfers.
Which technique replaces sensitive data with a non-sensitive substitute that retains the format but has no exploitable value?
Answer: Tokenization
Tokenization substitutes sensitive data values with random tokens that are meaningless to an attacker but can be reverse-mapped via a secure vault.
Which attack targets the management plane of a cloud environment to gain control over provisioning and configuration?
Answer: Cloud management plane attack / API abuse
The cloud management plane (control plane) is a high-value attack target because compromise of the API or console gives an attacker control over all cloud resources.
Which OWASP Top 10 vulnerability involves attackers manipulating SQL queries by injecting malicious input?
Answer: SQL Injection
SQL injection occurs when user-supplied input is incorporated into a SQL query without proper sanitization, allowing attackers to manipulate the database.
Which CCSP domain specifically addresses the security of data stored, processed, and transmitted in the cloud?
Answer: Cloud Data Security
Cloud Data Security is Domain 2 of the CCSP CBK and focuses on data lifecycle management, storage, retention, and protection.
Why is input validation considered insufficient as the sole defense against SQL injection?
Answer: Validation can be bypassed through encoding tricks; parameterized queries provide a stronger architectural defense
Input validation alone can be circumvented by encoding or obfuscation; parameterized queries (prepared statements) prevent injection at the architectural level by separating code from data.
What is the greatest source of knowledge about safeguarding a physical asset's BIOS?
Answer: Vendor documentation
The greatest source for recommended practices for safeguarding the BIOS is vendor documentation from the maker of the actual hardware.
Which of the following would be more restrictive when constructing a new data center in an urban setting?
Answer: Municipal codes
When building a new data center within an urban environment, municipal codes can indeed be one of the most restrictive aspects. Municipal codes refer to the regulations and requirements imposed by local government authorities to ensure compliance with zoning, building, safety, environmental, and other related standards. Municipal codes typically cover various aspects of construction and operation, including building height and size restrictions, setbacks from property lines, fire safety measures, electrical and mechanical systems, noise control, parking requirements, environmental considerations, and more. These codes are put in place to ensure the safety, sustainability, and compatibility of buildings within the urban landscape.
Which concept in cloud contracts ensures the customer retains ownership of their data and can retrieve it upon contract termination?
Answer: Data portability and right to return clause
A data portability and right to return clause contractually guarantees that the customer can export their data in a usable format and that the provider will delete it after contract termination.
What is the purpose of an API gateway in cloud application security?
Answer: To enforce authentication, rate limiting, and traffic management for API calls
An API gateway centralizes authentication, authorization, rate limiting, and logging for all API traffic, acting as a single controlled entry point.
Which of the following types of storage is most closely related to a standard file system and tree structure?
Answer: Volume
Volume storage functions as a virtual hard drive connected to a virtual machine. The volume is viewed by the operating system in the same way that a typical drive on a physical server would be.
What is the key architectural difference between containers and virtual machines (VMs)?
Answer: Containers share the host OS kernel; VMs include a complete guest OS per instance
Containers share the host OS kernel and isolate only the application and its dependencies, making them more lightweight, while VMs include a full guest OS per instance.