Cloud Security Compliance Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security Compliance flashcards as text
Which cloud security concept involves automatically discovering and classifying sensitive data stored across cloud services to support compliance reporting?
Answer: Data Loss Prevention (DLP)
Data Loss Prevention (DLP) tools scan cloud storage and data streams to discover, classify, and protect sensitive data based on predefined policies.
A penetration tester wants to conduct a cloud penetration test against an AWS environment. What must they do before starting the test?
Answer: Review and comply with AWS's penetration testing policy, which no longer requires prior approval for most services
AWS updated its policy to allow penetration testing of specific services without prior approval, but testers must still comply with the AWS Customer Support Policy for penetration testing.
What is the primary purpose of Cloud Security Posture Management (CSPM) tools?
Answer: Continuously monitoring cloud infrastructure configurations for compliance violations and misconfigurations
CSPM tools continuously assess cloud infrastructure configurations against security best practices and compliance standards, alerting on deviations.
An organization uses a cloud provider in a country that doesn't have an EU adequacy decision under GDPR. Which transfer mechanism provides the most flexibility for ongoing data transfers?
Answer: Standard Contractual Clauses (SCCs)
SCCs are the most practical and widely used mechanism for ongoing data transfers, as BCRs apply only within corporate groups and consent-based transfers are difficult to sustain at scale.
Which logging capability is most critical for forensic investigation after a suspected cloud security incident?
Answer: Cloud provider API activity logs (e.g., AWS CloudTrail, Azure Activity Log)
API activity logs capture every action taken in the cloud environment, including who accessed what resources and when, which is essential for incident investigation.
A company is evaluating whether to adopt a multi-cloud strategy. What is the primary compliance challenge this introduces?
Answer: Managing consistent security controls and compliance posture across providers with different tools and interfaces
Each cloud provider has different security tools, APIs, and compliance reporting mechanisms, making it difficult to maintain consistent controls and unified compliance evidence.
Which principle should guide the assignment of cloud IAM permissions to follow security best practices and compliance requirements?
Answer: Principle of least privilege
The principle of least privilege dictates granting only the minimum permissions necessary for a user or service to perform its intended function, reducing attack surface.