CSS Certified Security Sentinel — Questions and Answers
Question 1: Which security concern is MOST unique to multi-tenant cloud environments?
- Data isolation and tenant separation failures (Correct answer)
- Password complexity and rotation requirements
- Phishing attacks targeting end users
- Antivirus software management across endpoints
Correct answer: Data isolation and tenant separation failures
Multi-tenancy creates the risk of data leaking between co-located tenants, making proper logical isolation the defining security concern.
Question 2: Which principle best describes 'zero trust' architecture as applied to cloud environments?
- Never implicitly trusting any user, device, or network segment regardless of location (Correct answer)
- Allowing unrestricted traffic between cloud services within the same account
- Trusting all users and devices connected to the internal corporate network
- Completely delegating all security decisions to the cloud provider
Correct answer: Never implicitly trusting any user, device, or network segment regardless of location
Zero trust assumes no entity is inherently trustworthy and requires continuous verification of identity, device health, and authorization for every access request.
Question 3: What does tokenization do to protect sensitive data such as payment card numbers?
- Hashes the data irreversibly
- Encrypts data using AES-256
- Compresses data to reduce storage size
- Replaces sensitive data with a non-sensitive surrogate value that maps back to the original in a secure vault (Correct answer)
Correct answer: Replaces sensitive data with a non-sensitive surrogate value that maps back to the original in a secure vault
Tokenization substitutes sensitive data with a random token; the original value is stored in a secure token vault and can only be retrieved by authorized systems.
Question 4: Which IAM concept involves automatically removing access rights when they are no longer needed?
- Role explosion
- Credential harvesting
- User self-service enrollment
- Access certification and deprovisioning (Correct answer)
Correct answer: Access certification and deprovisioning
Regular access reviews (certifications) and automated deprovisioning ensure that users who change roles or leave the organization do not retain unnecessary access.
Question 5: Which attack targets authentication systems by using previously captured valid authentication tokens?
- Pass-the-ticket / pass-the-hash attack (Correct answer)
- Password spraying
- Phishing attack
- SQL injection
Correct answer: Pass-the-ticket / pass-the-hash attack
Pass-the-hash and pass-the-ticket attacks use stolen authentication tokens to authenticate as a victim without knowing the actual password.
Question 6: Which security mechanism prevents a compromised VLAN from accessing other VLANs through switch exploitation?
- Increasing VLAN ID numbers
- Enabling spanning tree protocol
- Using dynamic ARP inspection only
- Disabling trunk negotiation and using dedicated native VLANs (Correct answer)
Correct answer: Disabling trunk negotiation and using dedicated native VLANs
Disabling Dynamic Trunking Protocol and setting a dedicated unused native VLAN prevents VLAN hopping attacks.
Question 7: What security vulnerability is MOST associated with serverless (Function as a Service) architectures?
- Unauthorized physical access to the servers running the functions
- Event-data injection attacks via malicious data passed through function triggers (Correct answer)
- Inability to apply encryption to data processed by serverless functions
- Complete loss of network connectivity due to ephemeral compute nodes
Correct answer: Event-data injection attacks via malicious data passed through function triggers
Serverless functions are triggered by events that can carry attacker-controlled data, making input validation against injection attacks a critical security concern.
Question 8: What is the security purpose of just-in-time (JIT) privileged access?
- Requires manual approval for every login attempt
- Grants elevated privileges only for the duration needed, then automatically revokes them (Correct answer)
- Provides persistent admin access to all systems
- Replaces the need for multi-factor authentication
Correct answer: Grants elevated privileges only for the duration needed, then automatically revokes them
JIT access reduces the standing privilege attack surface by provisioning elevated rights only when requested and revoking them immediately after the task is complete.
Question 9: Which concept in risk assessment describes the point at which the cost of a control exceeds the value of the asset it protects?
- Maximum tolerable downtime
- Risk threshold
- Control obsolescence
- Cost-benefit analysis breakeven (Correct answer)
Correct answer: Cost-benefit analysis breakeven
A cost-benefit analysis breakeven point occurs when control expenditure equals the risk reduction value, beyond which spending is economically unjustified.
Question 10: From a security perspective, what does a Service Level Agreement (SLA) with a cloud provider typically address?
- Guaranteed uptime commitments, incident response timelines, and division of security responsibilities (Correct answer)
- The number of certified security staff the provider is required to employ
- The specific encryption algorithms the provider will use to protect customer data
- The maximum number of concurrent users permitted on the platform
Correct answer: Guaranteed uptime commitments, incident response timelines, and division of security responsibilities
SLAs establish measurable commitments for availability, incident notification windows, and clarify the boundary of security responsibilities between provider and customer.
Question 11: A risk register entry states: 'Risk Owner: CISO; Risk Response: Mitigate; Control: MFA deployment; Review Date: Q3.' What is the primary purpose of assigning a risk owner?
- To designate accountability for monitoring and managing the risk (Correct answer)
- To document who discovered the risk during the assessment
- To ensure the CISO is liable for any financial losses
- To grant the owner authority to override security controls
Correct answer: To designate accountability for monitoring and managing the risk
A risk owner is accountable for ensuring the risk is appropriately monitored, treated, and reported, creating clear governance and follow-through.
Question 12: Which concept describes the minimum acceptable backup age that an organization can tolerate losing in a recovery scenario?
- Mean Time to Recover (MTTR)
- Recovery Time Objective (RTO)
- Maximum Tolerable Downtime (MTD)
- Recovery Point Objective (RPO) (Correct answer)
Correct answer: Recovery Point Objective (RPO)
RPO defines the maximum tolerable data loss measured in time, dictating how frequently backups must be created to meet business requirements.
Question 13: What is the purpose of a privileged access workstation (PAW)?
- A remote desktop server for multiple users
- A virtual machine for testing malware
- A hardened, dedicated workstation used exclusively for privileged administrative tasks (Correct answer)
- A shared workstation for general office use
Correct answer: A hardened, dedicated workstation used exclusively for privileged administrative tasks
A PAW is a dedicated, highly secured device used only for admin tasks, reducing exposure to phishing and malware that could compromise privileged credentials.
Question 14: What is the main vulnerability addressed by salting a password hash?
- Replaces the need for password complexity requirements
- Prevents rainbow table and precomputed hash lookup attacks (Correct answer)
- Prevents brute-force attacks entirely
- Speeds up authentication
Correct answer: Prevents rainbow table and precomputed hash lookup attacks
A salt is a random value added to a password before hashing, ensuring that identical passwords produce different hashes and defeating precomputed lookup tables.
Question 15: A security team implements egress filtering on the perimeter firewall. Which threat does this PRIMARILY help prevent?
- Brute force attacks against internet-facing login portals
- Inbound phishing emails reaching users
- Exploitation of unpatched vulnerabilities in web servers
- Unauthorized outbound data exfiltration and C2 communications from compromised internal hosts (Correct answer)
Correct answer: Unauthorized outbound data exfiltration and C2 communications from compromised internal hosts
Egress filtering controls outbound traffic, limiting what compromised internal systems can communicate with externally, which disrupts exfiltration and C2 channels.
Question 16: Which attack floods a target server with half-open TCP connections to exhaust its resources?
- Ping of death
- Smurf attack
- SYN flood (Correct answer)
- Teardrop attack
Correct answer: SYN flood
A SYN flood sends massive numbers of TCP SYN packets without completing the handshake, consuming server connection table resources.
Question 17: Which US regulatory framework mandates encryption of cardholder data at rest and in transit?
- SOX Section 404
- FISMA
- PCI DSS (Payment Card Industry Data Security Standard) (Correct answer)
- HIPAA Security Rule
Correct answer: PCI DSS (Payment Card Industry Data Security Standard)
PCI DSS Requirement 3 mandates protection of stored cardholder data and Requirement 4 mandates encryption of cardholder data in transit.
Question 18: What type of encryption is used in TLS handshakes to securely exchange session keys?
- Symmetric AES encryption
- One-time pad encryption
- Homomorphic encryption
- Asymmetric encryption (e.g., RSA or ECDH) (Correct answer)
Correct answer: Asymmetric encryption (e.g., RSA or ECDH)
TLS uses asymmetric cryptography during the handshake to securely establish a shared symmetric session key for bulk data encryption.
Question 19: What does single sign-on (SSO) provide to enterprise users?
- Access to multiple applications using one set of credentials authenticated once (Correct answer)
- Automatic privilege escalation for all users
- Elimination of all password requirements
- A single password shared across all users
Correct answer: Access to multiple applications using one set of credentials authenticated once
SSO allows users to authenticate once with an identity provider and gain access to multiple connected applications without re-entering credentials.
Question 20: What is the difference between authentication and authorization in IAM?
- Authorization verifies identity; authentication assigns permissions
- Authentication verifies identity; authorization determines what an authenticated identity is permitted to do (Correct answer)
- Authentication assigns roles; authorization validates passwords
- They are the same process
Correct answer: Authentication verifies identity; authorization determines what an authenticated identity is permitted to do
Authentication confirms who you are, while authorization determines what resources and actions you are permitted to access once your identity is confirmed.
Question 21: Which cloud deployment model provides an organization with the highest level of control over its infrastructure?
- Community cloud
- Public cloud
- Private cloud (Correct answer)
- Hybrid cloud
Correct answer: Private cloud
A private cloud is dedicated exclusively to one organization, granting the greatest control over security configurations and infrastructure.
Question 22: A healthcare organization's security policy must comply with HIPAA. This is an example of which type of policy driver?
- Regulatory/compliance driver (Correct answer)
- Risk-based driver
- Technology refresh driver
- Operational efficiency driver
Correct answer: Regulatory/compliance driver
HIPAA is a federal regulation that mandates specific security requirements, making regulatory compliance the primary policy driver for covered entities.
Question 23: What is the role of a certificate revocation list (CRL) in PKI?
- Lists certificates that have been invalidated before their expiration date (Correct answer)
- Contains public keys of trusted root CAs
- Lists all valid certificates issued by the CA
- Stores encrypted private keys for recovery
Correct answer: Lists certificates that have been invalidated before their expiration date
A CRL is a signed list published by a Certificate Authority of certificates that have been revoked due to compromise, policy violation, or other reasons.
Question 24: What is the primary function of a privileged access management (PAM) solution?
- Provides antivirus protection for servers
- Manages network firewall rules
- Securely manages, monitors, and audits access to privileged accounts and credentials (Correct answer)
- Encrypts all database records
Correct answer: Securely manages, monitors, and audits access to privileged accounts and credentials
PAM solutions vault privileged credentials, enforce access workflows, and record privileged sessions to prevent misuse and support forensic investigation.
Question 25: What is the recommended approach for managing privileged access in cloud environments?
- Storing privileged credentials directly in application environment variables
- Granting all administrators full access to simplify permissions management
- Implementing just-in-time (JIT) access with least privilege principles (Correct answer)
- Using shared administrator accounts to improve operational efficiency
Correct answer: Implementing just-in-time (JIT) access with least privilege principles
JIT access grants elevated permissions only when operationally required and for a limited duration, minimizing the attack surface while adhering to least privilege.
Question 26: What is the difference between an Incident Response Plan (IRP) and a Business Continuity Plan (BCP)?
- IRP is for physical incidents; BCP is for cyber incidents only
- IRP and BCP are identical documents with different names
- IRP focuses on restoring IT systems; BCP focuses on security event investigation
- IRP addresses security event response; BCP ensures critical business functions continue during disruptions (Correct answer)
Correct answer: IRP addresses security event response; BCP ensures critical business functions continue during disruptions
An IRP governs how to respond to and recover from security incidents, while a BCP ensures essential business operations continue under any disruptive condition.
Question 27: What is a key security consideration when cloud services process data belonging to EU citizens?
- Cloud providers must obtain annual security certification directly from the European Commission
- The data must be encrypted using only EU government-approved cryptographic algorithms
- The data must be stored exclusively on U.S.-based servers to meet export controls
- GDPR compliance requirements including data subject rights and cross-border transfer restrictions (Correct answer)
Correct answer: GDPR compliance requirements including data subject rights and cross-border transfer restrictions
GDPR imposes obligations on any organization handling EU citizen data, including honoring data subject rights and restricting transfers of that data outside the European Economic Area.
Question 28: What is end-to-end encryption (E2EE) designed to prevent?
- Privilege escalation on endpoints
- SQL injection in database systems
- Interception and decryption of data by intermediaries, including service providers (Correct answer)
- Unauthorized physical access to devices
Correct answer: Interception and decryption of data by intermediaries, including service providers
E2EE ensures that only the communicating endpoints can decrypt the data, preventing even the service provider from reading message content.
Question 29: Which framework was specifically designed to address cloud computing security controls?
- NIST SP 800-53
- PCI-DSS v4.0
- HIPAA Security Rule
- CSA Cloud Controls Matrix (CCM) (Correct answer)
Correct answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix is a cybersecurity control framework developed by the Cloud Security Alliance specifically for cloud computing environments.
Question 30: What is credential stuffing and how does it differ from brute-force attacks?
- Both attacks use the same technique
- Credential stuffing uses stolen username/password pairs from breaches, while brute-force tries all possible combinations (Correct answer)
- Brute force uses breached credentials; credential stuffing generates random passwords
- Credential stuffing is slower than brute force
Correct answer: Credential stuffing uses stolen username/password pairs from breaches, while brute-force tries all possible combinations
Credential stuffing relies on real credentials from previous data breaches, making it more effective than random brute-force guessing.
Question 31: What is the purpose of a Public Key Infrastructure (PKI) in enterprise environments?
- Monitors endpoint behavior
- Manages the lifecycle of digital certificates to enable trusted encrypted communications (Correct answer)
- Stores plaintext passwords securely
- Provides network access control
Correct answer: Manages the lifecycle of digital certificates to enable trusted encrypted communications
PKI provides the framework for issuing, managing, distributing, and revoking digital certificates used for authentication and encryption.
Question 32: Which cryptographic concept ensures that a party cannot deny having performed an action?
- Integrity
- Availability
- Non-repudiation (Correct answer)
- Confidentiality
Correct answer: Non-repudiation
Non-repudiation, typically achieved through digital signatures, provides proof of origin so that a sender cannot later deny sending a message.
CSS Certified Security Sentinel
The Certified Security Sentinel (CSS) is a vendor-neutral, entry-level cybersecurity certification by Mile2 that validates foundational knowledge in network security, data protection, identity management, cloud security, cryptography, and regulatory compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds