CISSP Cloud Security Flashcards
6 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CISSP Cloud Security flashcards as text
Which attestation report type provides a confidential SOC 2 security report shared only with customers under NDA?
Answer: SOC 2 Type II
SOC 2 Type II covers a period of time (vs. a point in time) and is restricted to customers, while SOC 3 is the public version.
What is hypervisor type 1 (bare-metal) most commonly used for in cloud environments?
Answer: Running directly on hardware to host multiple guest VMs for cloud workloads
Type 1 hypervisors run directly on physical hardware without a host OS, providing the efficient multi-tenant isolation that cloud platforms require.
What security control helps prevent unauthorized data exfiltration from cloud storage buckets?
Answer: Bucket policy with least-privilege access and public access block settings
Restricting bucket policies to least-privilege and enabling public access blocks prevents unintended public exposure of cloud storage objects.
Which cloud security principle states that workloads should be isolated so that a compromise in one does not affect others?
Answer: Blast radius reduction
Blast radius reduction limits the impact of a security incident by isolating workloads through segmentation and micro-perimeters.
What does FedRAMP require for cloud services used by US federal agencies?
Answer: Standardized security assessment, authorization, and continuous monitoring
FedRAMP establishes a standardized government-wide approach for security assessment, authorization, and continuous monitoring of cloud products.
In cloud computing, what is 'elasticity'?
Answer: The ability to automatically scale resources up or down based on demand
Elasticity enables cloud resources to scale dynamically in response to workload changes, optimizing cost and performance.