Certified Cloud Security Professional (CCSP) practice questions
200 free questions with answers and explanations.
- 1.A cloud administrator is configuring a new cloud storage bucket for highly sensitive financial records. The organization's policy dictates that data must be encrypted both in transit and at rest, and that the encryption keys must be generated and managed by the cloud provider, but the customer retains the ability to revoke access to the keys at any time. Which key management option best meets these requirements?Cloud Data Security
- 2.A cloud security engineer needs to ensure that data stored in a cloud object storage bucket is protected against accidental deletion or modification for a specific retention period, even by administrators. Which feature should be enabled?Cloud Platform and Infrastructure Security
- 3.An organization is deploying a new application that will store highly sensitive customer data in a cloud database. Compliance regulations require that all data, both at rest and in transit, must be encrypted. Furthermore, the organization needs to ensure that the encryption keys are managed by a dedicated, highly secure service that is FIPS 140-2 Level 3 certified. Which cloud service or technology best fulfills this specific key management requirement?Cloud Data Security
- 4.A cloud customer is implementing a strategy for data destruction in their cloud environment. They have identified data classified as 'Confidential' that must be securely erased from all storage locations, including backups, within 30 days of its retention period expiring. Which data destruction method, when combined with proper key management, offers the most robust solution for ensuring irrecoverable deletion in a virtualized cloud storage environment?Cloud Data Security
- 5.A company is planning to migrate its on-premises database containing sensitive customer information to a public cloud environment. Before migration, they need to identify all instances of personally identifiable information (PII) and protected health information (PHI) within their existing unstructured and structured data stores across various departments. Which process is crucial for achieving this goal?Cloud Data Security
- 6.A company is implementing a new cloud-based data analytics platform that processes sensitive customer information. The platform utilizes multiple cloud services, including compute instances, managed databases, and object storage. To maintain regulatory compliance, the company needs to ensure that all administrative actions performed on these cloud resources are recorded, immutable, and easily auditable. Which cloud management plane security feature BEST addresses this requirement?Cloud Platform and Infrastructure Security
- 7.A cloud security architect is designing a highly available and resilient application in a public cloud environment. The architect wants to ensure that if an entire cloud region becomes unavailable, the application can continue to serve users with minimal downtime and data loss. Which disaster recovery strategy BEST addresses this requirement?Cloud Platform and Infrastructure Security
- 8.A global healthcare provider is deploying a new cloud-based electronic health record (EHR) system. Due to the highly sensitive nature of patient data and strict regulatory requirements (e.g., HIPAA, GDPR), the provider requires a solution that continuously monitors data access, identifies unusual behavior, and enforces granular access policies in real-time across multiple cloud services. Which cloud security technology is best suited to fulfill these requirements?Cloud Data Security
- 9.A cloud architect is designing a system for a global financial institution that must comply with strict data residency regulations. The institution requires that all customer data from European Union (EU) citizens must remain physically stored and processed within the EU. Which cloud deployment model is BEST suited to meet this specific data residency requirement while still leveraging cloud benefits?Cloud Concepts, Architecture and Design
- 10.A cloud security architect is designing a secure CI/CD pipeline for containerized applications. A critical requirement is to ensure that container images used in deployment are free from known vulnerabilities and meet organizational compliance standards before being pushed to the container registry. Which security control should be integrated early in the CI/CD pipeline to address this requirement?Cloud Platform and Infrastructure Security
- 11.A cloud security team is implementing a strategy to protect sensitive data stored in an Amazon S3 bucket. They want to ensure that even if an attacker gains access to the S3 bucket, the data remains unreadable. Which security best practice should they prioritize?Cloud Concepts, Architecture and Design
- 12.A cloud provider offers a service that allows customers to categorize their data based on its sensitivity, compliance requirements, and business value. This categorization then automatically triggers appropriate security controls, such as encryption levels, access permissions, and retention policies. What is this service primarily facilitating?Cloud Data Security
- 13.A company is designing a cloud-native application that requires high availability and resilience. They want to ensure that if an entire data center becomes unavailable, the application can continue to operate with minimal downtime. Which cloud architecture principle is most relevant to achieving this goal?Cloud Concepts, Architecture and Design
- 14.A cloud security architect is reviewing an incident where an attacker exploited a vulnerability in a web application to gain unauthorized access to an underlying virtual machine. The attacker then used escalated privileges on the VM to access other VMs on the same physical host. Which type of attack vector is described in this scenario?Cloud Concepts, Architecture and Design
- 15.An organization relies on a cloud provider for its primary data storage. To ensure business continuity and disaster recovery, they implement a strategy where data is continuously copied to a geographically distant data center, maintained by the same cloud provider, with a recovery point objective (RPO) of minutes. Which data protection strategy is being employed?Cloud Data Security
- 16.A cloud administrator is configuring security for a new set of virtual machines (VMs) deployed in a public cloud. The administrator needs to ensure that only specific, authorized network traffic can reach these VMs, while all other inbound traffic is blocked by default. Which of the following cloud security controls should be primarily used to achieve this objective?Cloud Platform and Infrastructure Security
- 17.A healthcare organization is migrating patient health records (PHR) to a cloud environment. Due to strict HIPAA compliance requirements, they need to ensure that PHR data is permanently and irrevocably deleted from storage media when it is no longer needed, even in the event of hardware disposal. Which data destruction method is most effective for meeting this requirement in a cloud context?Cloud Data Security
- 18.A cloud provider offers a service where customers can deploy their custom code without managing the underlying servers or operating systems. The customer is only billed for the actual compute time consumed by their code executions. Which cloud computing concept does this billing model align with?Cloud Concepts, Architecture and Design
- 19.A cloud security team is investigating a potential compromise involving a virtual machine (VM) running a critical application. The team needs to capture the VM's exact state, including its memory contents, at the time of the incident for forensic analysis. Which capability is essential for performing this type of investigation in a cloud environment?Cloud Platform and Infrastructure Security
- 20.A public sector organization is implementing a cloud-based data analytics platform. Due to the highly sensitive nature of the data (e.g., citizen health records), they need to ensure that the data is not only encrypted at rest and in transit but also that the integrity of the data is maintained against unauthorized modifications. Which cryptographic primitive, when used in conjunction with encryption, is primarily responsible for ensuring data integrity?Cloud Data Security
- 21.A cloud security architect is evaluating different cloud providers for an application that processes highly sensitive personal identifiable information (PII). The primary concern is to minimize the risk of data exposure due to a compromise of the cloud provider's underlying infrastructure or hypervisor. Which security concept or technology would offer the MOST robust protection against this specific threat vector?Cloud Concepts, Architecture and Design
- 22.A financial services company is evaluating cloud providers for its new customer-facing application. The application will process sensitive personal and financial data. The company's compliance team insists on maintaining direct control over the underlying physical infrastructure, including hardware and network components, to meet stringent regulatory requirements. Which cloud deployment model would best satisfy these requirements?Cloud Concepts, Architecture and Design
- 23.A healthcare provider is storing patient medical records in a cloud database. Due to strict HIPAA compliance requirements, they need to ensure that specific sensitive fields, such as patient names and diagnoses, are obscured when developers are testing new features, but the format and relationships between data elements must be preserved for application functionality. Which data security technique is best suited for this scenario?Cloud Data Security
- 24.A software development team is adopting a DevOps approach and needs a cloud service that allows them to quickly deploy and manage their application code without worrying about the underlying operating system, middleware, or runtime environments. They want to focus solely on writing and deploying their application logic. Which cloud service model best fits this requirement?Cloud Concepts, Architecture and Design
- 25.A cloud provider offers a platform-as-a-service (PaaS) database service. A customer wants to ensure that their data stored in this database is physically isolated from other customers' data at the storage layer. Which of the following isolation strategies would the customer MOST likely expect the CSP to implement to meet this physical isolation requirement?Cloud Platform and Infrastructure Security
- 26.A cloud security architect is designing a highly available and resilient application in a public cloud. The application uses multiple virtual machines (VMs) and a database. To ensure business continuity, the architect must implement a strategy where the application can automatically fail over to a geographically separate location with minimal data loss and recovery time. Which disaster recovery (DR) strategy best fits these requirements?Cloud Platform and Infrastructure Security
- 27.A development team is deploying a new microservices application using serverless functions. They need to ensure that each function execution is isolated from others and that the underlying infrastructure is automatically managed and scaled without direct server provisioning. Which characteristic of serverless computing directly provides this isolation and management benefit?Cloud Platform and Infrastructure Security
- 28.A global enterprise is migrating its legacy applications to a serverless architecture to reduce operational overhead and improve scalability. The security team is concerned about potential over-privileging of serverless functions. Which security principle is most critical to apply when defining permissions for these functions?Cloud Platform and Infrastructure Security
- 29.A healthcare organization is migrating patient health records to a cloud environment. Due to the highly sensitive nature of the data and stringent regulatory requirements (e.g., HIPAA), they need to ensure that the underlying infrastructure is isolated and dedicated to their use, without sharing physical hardware resources with other tenants. Which cloud characteristic is MOST critical for this requirement?Cloud Concepts, Architecture and Design
- 30.A cloud customer is implementing a new data storage solution in a multi-tenant cloud environment. Due to strict regulatory requirements, they need to ensure that their sensitive data is cryptographically separated from other tenants' data and that the encryption keys are never exposed to the cloud provider. Which cryptographic solution best meets these requirements?Cloud Data Security
- 31.A security auditor is reviewing a cloud environment for compliance with data residency regulations. The organization stores sensitive customer data in a regional cloud storage service. The auditor needs to confirm that the data never leaves the specified geographic region, even for backup or disaster recovery purposes. Which cloud storage configuration ensures this strict data residency requirement?Cloud Platform and Infrastructure Security
- 32.A security architect is reviewing a proposed cloud deployment for a new application that will store highly sensitive customer data, including personally identifiable information (PII) and protected health information (PHI). The architect is particularly concerned about the risk of data compromise due to a misconfiguration in the cloud environment. Which design principle should be most heavily emphasized to minimize this risk?Cloud Concepts, Architecture and Design
- 33.A cloud security engineer is tasked with securing the management plane of their cloud environment. They need to implement a control that ensures all administrative actions, such as creating new VMs, modifying network configurations, or deleting storage buckets, are scrutinized and potentially blocked if they deviate from established policies or indicate malicious behavior. Which control is most effective for real-time policy enforcement and threat detection within the management plane?Cloud Platform and Infrastructure Security
- 34.A company is required by law to delete all customer data related to a specific service 90 days after the customer terminates their subscription. To ensure compliance, they need a robust method to permanently destroy this data across all cloud storage locations, including backups and archives, making it irrecoverable. Which data destruction method is most appropriate for this requirement?Cloud Data Security
- 35.A cloud security architect is designing a solution for a highly sensitive research dataset. The requirement is that the data must be encrypted in such a way that it can be searched and queried without ever being decrypted. This would allow researchers to perform statistical analysis on sensitive data while ensuring its confidentiality. Which advanced cryptographic technique is designed to enable this functionality?Cloud Data Security
- 36.A cloud customer is storing sensitive customer data in a database. They want to prevent sensitive fields (e.g., credit card numbers, social security numbers) from appearing in plain text in database logs, even if the application processes them in cleartext temporarily. The solution must not significantly impact application performance or require extensive code changes. Which data protection technique is most appropriate for this scenario?Cloud Data Security
- 37.A cloud customer is concerned about unauthorized access to sensitive data stored in a public cloud. They want to implement a solution where the encryption keys are never exposed to the cloud provider, even during key usage for encryption and decryption operations. Which key management approach would best satisfy this stringent requirement?Cloud Data Security
- 38.A large enterprise is migrating its legacy data warehouse to a public cloud. The data warehouse contains petabytes of historical customer transaction data. The enterprise's compliance team requires that all data, regardless of its age or access frequency, must be encrypted with customer-managed keys and that the encryption keys must be stored in a FIPS 140-2 Level 3 certified hardware security module (HSM). Which cloud security challenge does this requirement primarily address?Cloud Concepts, Architecture and Design
- 39.A global enterprise is utilizing a multi-cloud strategy and needs to ensure that sensitive customer data stored in various cloud environments is protected against unauthorized access and modification, regardless of its location. They require a solution that can enforce consistent security policies across different cloud providers and on-premises systems. Which cloud data security technology would be most effective for this purpose?Cloud Data Security
- 40.An organization is migrating its on-premises virtualized environment to an Infrastructure as a Service (IaaS) cloud provider. The security team is concerned about the potential for 'hypervisor escape' attacks, where an attacker gains unauthorized access from a guest virtual machine to the underlying hypervisor or other guest virtual machines. Which fundamental cloud security challenge does this concern directly relate to?Cloud Concepts, Architecture and Design
- 41.A cloud security engineer needs to establish a secure, private network connection between an on-premises data center and a Virtual Private Cloud (VPC) in a public cloud environment. The connection must offer high throughput and low latency, bypassing the public internet. Which cloud networking service should the engineer choose?Cloud Platform and Infrastructure Security
- 42.A cloud security team is investigating a potential compromise involving a virtual machine (VM) in their IaaS environment. They suspect unauthorized access to the VM's operating system. To perform a forensic analysis without altering the running system, they need to acquire a complete, forensically sound copy of the VM's memory. Which cloud capability would best facilitate this process?Cloud Platform and Infrastructure Security
- 43.A cloud platform team is implementing a custom operating system image for their virtual machines (VMs) to ensure a standardized and secure baseline. Before deploying these VMs, they need to verify that the OS kernel and boot process have not been tampered with and are cryptographically verified. Which virtualization security mechanism provides this assurance?Cloud Platform and Infrastructure Security
- 44.A financial institution is migrating highly sensitive customer records to a cloud data warehouse. To comply with privacy regulations and minimize the risk of data exposure in case of a breach, they decide to replace actual credit card numbers and personally identifiable information (PII) with unique, non-sensitive surrogate values. The original sensitive data needs to be recoverable for specific authorized processes. Which data security technique is being applied?Cloud Data Security
- 45.A cloud service provider (CSP) offers a service where customers can deploy their custom code without managing underlying servers, operating systems, or even the runtime environment. The customers are billed based on the number of requests and the execution time of their code. Which cloud computing concept is best illustrated by this billing model?Cloud Concepts, Architecture and Design
- 46.A cloud security architect is designing a system that uses serverless functions (FaaS) to process real-time data streams. The organization requires a high degree of assurance that the code executed within these functions has not been tampered with and originates from a trusted source. Additionally, the execution environment itself must be verified for integrity before code execution. Which advanced security concept is most relevant for meeting these requirements?Cloud Concepts, Architecture and Design
- 47.A company is using a cloud-based video conferencing platform. They store recordings of meetings, some of which contain sensitive business discussions. To meet legal and regulatory obligations, these recordings must be retained for exactly 5 years and then securely deleted. Which cloud data security concept directly addresses the '5 years and then securely deleted' aspect?Cloud Data Security
- 48.A financial institution is migrating its legacy applications to a serverless architecture in the cloud. The security team is particularly concerned about the potential for code injection vulnerabilities and excessive permissions granted to the serverless functions. Which of the following strategies BEST mitigates these two specific risks?Cloud Platform and Infrastructure Security
- 49.A cloud customer is implementing a new application that will process highly sensitive personal identifiable information (PII). They require a solution that ensures data remains encrypted both at rest and in transit, and also prevents the cloud provider from accessing the unencrypted data, even when it is being processed. Which cryptographic solution best addresses these requirements?Cloud Data Security
- 50.A cloud customer is evaluating different storage options for a large volume of sensor data that is rarely accessed after an initial processing period but must be retained for seven years for regulatory compliance. The customer prioritizes cost-effectiveness for long-term storage and accepts higher retrieval latency and costs when access is eventually needed. Which cloud storage class is most suitable for this use case?Cloud Data Security