← All CSC Flashcard Decks

Cloud Security Compliance Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cloud Security Compliance flashcards as text
  1. A company using IaaS must patch its operating systems. Under the shared responsibility model, which party is responsible for this task?

    Answer: The customer, because IaaS shifts OS management to the tenant

    In IaaS, the customer is responsible for the operating system, middleware, runtime, and applications — the provider manages only the underlying physical infrastructure.

  2. Which compliance framework requires cloud environments processing federal government data to receive a formal Authorization to Operate (ATO)?

    Answer: FedRAMP

    FedRAMP (Federal Risk and Authorization Management Program) requires cloud service providers to obtain an ATO before federal agencies can use their services.

  3. What is 'data residency' in the context of cloud compliance?

    Answer: The legal and regulatory requirement that data must be stored within specific geographic boundaries

    Data residency requirements mandate that certain types of data must physically reside within specified countries or regions to comply with local laws.

  4. An organization wants to verify a cloud provider's security controls without conducting a full on-site audit. Which document provides the most comprehensive third-party assurance?

    Answer: SOC 2 Type II report from an independent auditor

    A SOC 2 Type II report from an independent CPA firm provides tested evidence that security controls operated effectively over an audit period.

  5. Which technique allows an organization to use cloud resources for sensitive workloads while ensuring the cloud provider cannot access plaintext data during processing?

    Answer: Homomorphic encryption

    Homomorphic encryption allows computations to be performed on encrypted data without decrypting it, so the provider never sees plaintext.

  6. A SaaS provider stores customer data commingled with other customers' data in a shared database. What security control is most critical to prevent cross-tenant data exposure?

    Answer: Strong tenant isolation and logical data segregation controls

    In multi-tenant SaaS environments, robust tenant isolation ensures one customer cannot access another customer's data within the shared infrastructure.

  7. Under GDPR's right to erasure ('right to be forgotten'), which scenario presents the greatest technical challenge in cloud environments?

    Answer: Ensuring data is erased from all backups, replicas, and geographically distributed copies

    Cloud environments often replicate data across multiple regions and retain backups; ensuring complete erasure from all copies is technically complex.