CISSP CISSP Cloud Security 2 — Questions and Answers
Question 1: Which framework provides a comprehensive set of cloud security controls aligned with ISO 27001?
- CSA Cloud Controls Matrix (CCM) (Correct answer)
- COBIT
- ITIL
- SOC 2
Correct answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix maps cloud-specific controls to ISO 27001 and other frameworks to guide cloud security assessments.
Question 2: What is the primary purpose of a Cloud Access Security Broker (CASB)?
- To replace the organization's firewall
- To enforce security policies between cloud service users and providers (Correct answer)
- To encrypt cloud storage at rest
- To conduct penetration testing on cloud infrastructure
Correct answer: To enforce security policies between cloud service users and providers
A CASB sits between users and cloud services to enforce visibility, compliance, data security, and threat protection policies.
Question 3: In a SaaS model, who is responsible for patching the application software?
- The end user
- The cloud customer's IT team
- The cloud service provider (Correct answer)
- A third-party managed service
Correct answer: The cloud service provider
In SaaS, the cloud provider manages and patches the application; the customer only manages their data and user access.
Question 4: What cloud data security technique ensures that even if the provider is compromised, customer data remains unreadable?
- Data masking
- Client-side encryption with customer-managed keys (Correct answer)
- TLS in transit
- Access control lists
Correct answer: Client-side encryption with customer-managed keys
Encrypting data client-side before upload with customer-managed keys means the provider never possesses the decryption key.
Question 5: Which concept describes the risk that cloud data may be subject to the laws of the country where the data center resides?
- Data sovereignty (Correct answer)
- Data portability
- Data classification
- Data minimization
Correct answer: Data sovereignty
Data sovereignty means data stored in a foreign jurisdiction may be subject to that country's laws, including government access demands.
Question 6: What is the purpose of a right-to-audit clause in a cloud service contract?
- To allow the provider to audit customer usage
- To grant the customer the ability to inspect provider security controls (Correct answer)
- To mandate annual penetration testing by the provider
- To enforce SLA compliance penalties
Correct answer: To grant the customer the ability to inspect provider security controls
A right-to-audit clause contractually permits the customer or their agent to verify the provider's security controls and compliance.
Which framework provides a comprehensive set of cloud security controls aligned with ISO 27001?