Certified Cloud Security Professional (CCSP) practice questions
200 free questions with answers and explanations.
- 51.A cloud customer is implementing a new analytics platform that processes sensitive customer data. They need to ensure that the data can be analyzed without revealing the original sensitive values, especially when shared with third-party data scientists who do not require direct access to personally identifiable information. Which data security technology is best suited for this requirement?Cloud Data Security
- 52.A cloud architect is designing a solution for a highly sensitive research dataset that needs to be processed by a third-party analytics service. The research data contains personally identifiable information (PII) that cannot be exposed to the third party, even during processing. The architect needs a method that allows computations to be performed directly on the encrypted data without decrypting it first. Which cryptographic solution should the architect recommend?Cloud Data Security
- 53.A cloud architect is designing a solution for an organization that requires maximum control over the network infrastructure, including custom routing tables, firewalls, and VPN connections, entirely isolated from other tenants. Which cloud deployment model would offer the highest level of control and isolation for these specific network requirements?Cloud Concepts, Architecture and Design
- 54.A security incident response team is investigating a potential breach involving an unauthorized highly privileged account in the cloud management plane. The team needs to quickly understand all actions performed by this account, including resource creation, modification, and deletion across various cloud services. Which of the following cloud infrastructure components provides the MOST granular and centralized record of these management plane activities?Cloud Platform and Infrastructure Security
- 55.A global enterprise uses a cloud-based document management system. They need to ensure that sensitive documents, once downloaded by authorized users, cannot be further shared or printed without explicit permission, even when offline. This control must persist regardless of where the document is stored after download. Which technology is designed to enforce such persistent control over data?Cloud Data Security
- 56.A cloud security engineer needs to implement a solution that allows multiple independent organizations (tenants) to securely share the same physical cloud infrastructure while ensuring complete logical separation of their data and applications. Each tenant must perceive that they have a dedicated environment. Which architectural concept is fundamental to achieving this in a public cloud environment?Cloud Concepts, Architecture and Design
- 57.A large enterprise is utilizing a Platform-as-a-Service (PaaS) database offering for its critical customer data. The data is highly sensitive and subject to stringent regulatory requirements for encryption at rest and in transit. The enterprise wants to ensure that they maintain full control over the encryption keys, even though the database itself is managed by the cloud provider. Which key management solution would best meet this requirement?Cloud Platform and Infrastructure Security
- 58.A software development company is considering adopting a cloud-native strategy. They want to leverage cloud services to reduce operational overhead, allowing developers to focus solely on writing code without managing the underlying infrastructure, operating systems, or even runtime environments. Which cloud service model aligns best with this goal?Cloud Concepts, Architecture and Design
- 59.A cloud security architect is designing a new multi-tenant SaaS application that will store highly sensitive customer data. The architect needs to ensure that data from one tenant cannot be accessed or influenced by another tenant, even in the event of a sophisticated attack. Which of the following security mechanisms is MOST effective in achieving strong tenant isolation within a shared compute environment?Cloud Platform and Infrastructure Security
- 60.A cloud customer is migrating a legacy on-premises application that relies on a block-level storage array to a cloud environment. The application requires high-performance, low-latency storage that can be formatted and managed like a physical disk. Which cloud storage type would be most appropriate for this migration?Cloud Data Security
- 61.A large enterprise is migrating its critical applications to an IaaS cloud environment. The security team needs to establish secure communication channels between the on-premises data center and the cloud Virtual Private Cloud (VPC) to transfer sensitive data. They require a solution that offers both strong encryption and private connectivity, without traversing the public internet. Which of the following connectivity options is MOST appropriate?Cloud Platform and Infrastructure Security
- 62.A company is using a cloud-based CRM system to manage customer interactions. They need to ensure that their customer data is continuously available, even in the event of a regional outage or disaster affecting a single data center. The recovery time objective (RTO) is near zero, and the recovery point objective (RPO) is also near zero. Which data replication strategy would best meet these stringent requirements?Cloud Data Security
- 63.A security architect is reviewing a cloud application design that uses multiple microservices, each deployed as a separate container. To enhance security, they want to ensure that each microservice has the minimum necessary privileges to perform its function and that communication between microservices is strictly controlled based on defined policies. Which security principle is being applied here?Cloud Concepts, Architecture and Design
- 64.A healthcare organization is migrating patient health records (PHR) to a cloud environment. Due to strict regulatory compliance (e.g., HIPAA), they must ensure that all PHR data is irretrievably erased after its retention period expires. Which data destruction method is most appropriate and effective for meeting this requirement in a cloud setting?Cloud Data Security
- 65.A cloud security engineer is tasked with securing a serverless application that processes sensitive financial transactions. The application consists of multiple Lambda functions. Which security challenge is most critical to address for this serverless architecture?Cloud Concepts, Architecture and Design
- 66.A cloud security architect is integrating a new third-party security tool into their cloud environment. The tool requires programmatic access to create, modify, and delete virtual machines, network configurations, and storage buckets. What is the MOST secure way to grant this tool the necessary permissions, adhering to cloud security best practices?Cloud Platform and Infrastructure Security
- 67.A global enterprise is evaluating a cloud provider for its new data analytics platform. The platform will process petabytes of sensitive customer data. The enterprise's security policy mandates that all data, regardless of its state, must be protected by encryption. For data that is actively being processed by CPU and residing in volatile memory, which encryption approach is technologically feasible and provides protection against unauthorized access from the underlying cloud infrastructure components (e.g., hypervisor, host OS)?Cloud Concepts, Architecture and Design
- 68.A cloud operations team is implementing a new virtual network for a highly sensitive application. To prevent IP address spoofing and ensure that virtual machines (VMs) only send and receive traffic using their assigned IP addresses, a specific network security feature needs to be enabled at the virtual network interface level. Which feature directly addresses this concern?Cloud Platform and Infrastructure Security
- 69.A cloud architect is designing a system for a global e-commerce platform that experiences unpredictable traffic spikes during promotional events. The platform must maintain consistent performance and availability even when demand increases tenfold within minutes. Which cloud characteristic is most crucial for enabling this system to automatically adjust its resources to meet fluctuating demand?Cloud Concepts, Architecture and Design
- 70.A cloud architect is designing a disaster recovery (DR) strategy for a critical application hosted in a single cloud region. The Recovery Time Objective (RTO) for this application is 1 hour, and the Recovery Point Objective (RPO) is 15 minutes. Which of the following DR strategies, combined with appropriate data replication, would BEST meet these objectives?Cloud Platform and Infrastructure Security
- 71.A global enterprise is migrating its legacy on-premises applications, which rely heavily on network file shares, to a cloud environment. The applications require shared access to files, strict permissions, and low-latency access for multiple virtual machines simultaneously. Which cloud storage type is best suited to meet these requirements?Cloud Data Security
- 72.An organization is migrating its legacy enterprise resource planning (ERP) system to a cloud environment. The ERP system requires significant customization at the operating system level, including specific kernel modules and low-level network configurations that are not typically exposed in a standard cloud offering. Which cloud service model would provide the necessary level of control and flexibility for this migration?Cloud Concepts, Architecture and Design
- 73.A multinational corporation is using a cloud-based email service. To comply with various global data residency and privacy regulations, they need to ensure that their email data is stored only in specific geographic regions and is not moved outside those regions without explicit authorization. Which aspect of cloud data security is primarily addressed by this requirement?Cloud Data Security
- 74.A large e-commerce company is experiencing unpredictable traffic spikes during seasonal sales events. To handle these fluctuations efficiently without over-provisioning infrastructure, they require a cloud service model that automatically scales computing resources up or down based on demand. Which cloud characteristic directly supports this requirement?Cloud Concepts, Architecture and Design
- 75.A global enterprise is migrating its legacy applications to a serverless architecture to reduce operational overhead and improve scalability. The security team is concerned about potential over-permissioning of serverless functions, which could lead to privilege escalation if a function is compromised. Which principle should be strictly applied when defining IAM roles for these serverless functions?Cloud Platform and Infrastructure Security
- 76.A software-as-a-service (SaaS) provider offers an application that stores customer data in a multi-tenant cloud database. Each customer's data must be logically separated and encrypted with a unique set of keys. The provider wants to ensure that a compromise of one customer's encryption key does not affect the confidentiality of another customer's data. Which key management principle is the provider primarily aiming to enforce?Cloud Data Security
- 77.A cloud operations team is implementing a new virtual network for a highly sensitive application. They are concerned about potential network-based attacks where malicious actors might forge source IP addresses to bypass security controls or impersonate legitimate services. Which cloud network security feature specifically protects against this type of attack within a Virtual Private Cloud (VPC)?Cloud Platform and Infrastructure Security
- 78.A cloud service customer needs to implement a data backup strategy for critical application data stored in a cloud database. The Recovery Time Objective (RTO) for this data is 4 hours, and the Recovery Point Objective (RPO) is 1 hour. Which backup and recovery approach is most likely to meet these objectives efficiently?Cloud Data Security
- 79.A software-as-a-service (SaaS) provider offers a multi-tenant application where each customer's data is stored in separate logical databases within a shared physical infrastructure. The provider needs to ensure that customer data is logically isolated and that one customer's data cannot be accessed or affected by another. Which cloud data storage model is being described?Cloud Data Security
- 80.A financial institution is migrating its on-premises virtualized infrastructure to a public cloud IaaS environment. They are concerned about the security implications of sharing physical hardware with other tenants. Which security control offered by cloud providers directly addresses this concern by preventing unauthorized data leakage or interference between different virtual machines on the same physical host?Cloud Platform and Infrastructure Security
- 81.A cloud service provider offers various data storage options. A customer needs to store infrequently accessed, non-critical log data that must be retained for 7 years for compliance but can tolerate retrieval times of several hours. Cost-efficiency is a primary concern. Which cloud storage class is most appropriate for this scenario?Cloud Data Security
- 82.A multinational corporation uses a cloud-based document management system. They need to ensure that highly confidential documents remain protected even if they are downloaded or shared with unauthorized individuals, allowing granular control over viewing, editing, and printing regardless of where the document resides. Which technology is designed to provide this persistent protection?Cloud Data Security
- 83.A global healthcare provider is designing a new cloud-based patient record system. The system must comply with diverse regional data privacy regulations (e.g., GDPR, HIPAA, local laws) that dictate where patient data can be stored and processed. The architect is particularly concerned about ensuring that patient data from specific regions never leaves those regions, even for backup or disaster recovery purposes. Which design principle is most critical to address this specific regulatory constraint?Cloud Concepts, Architecture and Design
- 84.A company is considering using a public cloud for its new customer relationship management (CRM) system. Due to regulatory compliance, all customer data must reside within the geographical borders of a specific country. Which aspect of cloud computing must be carefully evaluated to ensure compliance?Cloud Concepts, Architecture and Design
- 85.A financial institution is migrating its on-premises data centers to a public cloud environment. They require strict isolation of their compute resources, dedicated network infrastructure, and complete control over the underlying hypervisor. Which cloud service model best meets these requirements?Cloud Concepts, Architecture and Design
- 86.A cloud security engineer is tasked with securing a critical application hosted on a public cloud, which processes financial transactions. The application relies on several microservices interacting with each other. The engineer wants to ensure that even if one microservice is compromised, the attacker cannot easily pivot to other microservices or the underlying host. Which cloud security best practice, related to network segmentation, would be most effective in achieving this goal?Cloud Concepts, Architecture and Design
- 87.A multinational corporation is deploying a new application that will process highly sensitive customer data across various geographic regions. Due to strict data residency regulations in certain countries, the data generated in a specific country must remain stored and processed exclusively within that country's borders. Which cloud storage characteristic is essential for meeting this compliance requirement?Cloud Platform and Infrastructure Security
- 88.A government agency is implementing a new cloud application to handle classified information. Due to the extreme sensitivity of the data, the agency mandates that no component of the application, including development, testing, and production environments, can share physical resources with any other tenant. Furthermore, all physical access to the infrastructure must be managed and audited exclusively by agency personnel. Which cloud deployment model, combined with specific architectural choices, would be the most secure and compliant approach?Cloud Concepts, Architecture and Design
- 89.A cloud architect is designing a highly sensitive data analytics platform that requires FIPS 140-2 Level 3 validated cryptographic modules for all data encryption at rest and in transit. The organization also needs full control over the encryption key lifecycle, including key generation, storage, and destruction, without the cloud provider having access to the unencrypted keys. Which cloud service model BEST meets these stringent cryptographic and key management requirements?Cloud Platform and Infrastructure Security
- 90.A company is considering migrating its on-premises database to a cloud provider. They are concerned about the performance implications for applications that require very low latency access to the database. The cloud provider offers different storage options. Which cloud storage type generally provides the lowest latency for database workloads?Cloud Data Security
- 91.A global e-commerce company uses multiple cloud providers (AWS, Azure, GCP) for different workloads. They are struggling to maintain consistent security policies, configurations, and visibility across these disparate environments. Which cloud security best practice is most critical to address this challenge?Cloud Concepts, Architecture and Design
- 92.A company is using a public cloud provider for its entire IT infrastructure. During a recent security audit, a critical finding was identified: several virtual machines (VMs) are running vulnerable operating system versions and unpatched applications. This indicates a failure in maintaining the security posture of the compute environment. Which cloud security responsibility model aspect is primarily highlighted by this finding?Cloud Platform and Infrastructure Security
- 93.A multinational corporation uses a cloud-based Enterprise Resource Planning (ERP) system that processes highly sensitive employee data. To comply with various global privacy regulations, the corporation needs to ensure that specific fields within the database (e.g., social security numbers, bank account details) are never stored in their original, readable form in non-production environments like development or testing. However, cross-referencing and data integrity must be maintained. Which data protection technique is best suited for this requirement?Cloud Data Security
- 94.A cloud administrator is configuring a Data Loss Prevention (DLP) solution for their organization's cloud email service. The primary objective is to prevent sensitive customer data (e.g., credit card numbers, social security numbers) from being transmitted outside the organization's approved boundaries. Which DLP detection method would be most effective for identifying and blocking these specific data types?Cloud Data Security
- 95.A cloud service provider (CSP) is offering a new object storage service. A client is particularly concerned about the integrity of their archived data, ensuring that it has not been tampered with or altered over long periods. Which of the following security controls, when applied to the object storage, would BEST address the client's concern about data integrity?Cloud Platform and Infrastructure Security
- 96.A financial institution is implementing a cloud-based data lake to consolidate various data sources, including transactional data, customer demographics, and market feeds. Due to regulatory compliance requirements (e.g., GDPR, CCPA), the institution must ensure that individual customer data within the data lake cannot be directly linked back to a specific person, even if the data is compromised. However, the data must still be useful for statistical analysis and trend identification. Which data protection technique is most appropriate for this scenario?Cloud Data Security
- 97.A cloud architect is designing a key management solution for encrypted data in a multi-cloud environment. They need a system that allows them to generate, store, and manage cryptographic keys centrally, while also providing a high level of assurance for key security through hardware-backed modules. Which service type is best suited for this requirement?Cloud Data Security
- 98.A cloud administrator is configuring network security for a new application deployed on multiple virtual machines (VMs) within a Virtual Private Cloud (VPC). The application requires strict inbound and outbound traffic filtering based on IP addresses, ports, and protocols for individual VMs. Which security construct is most appropriate for this granular, stateful filtering at the VM network interface level?Cloud Platform and Infrastructure Security
- 99.A cloud platform team is implementing a custom operating system image for their virtual machines. To enhance the integrity and trustworthiness of the boot process, they want to ensure that the OS kernel and boot components have not been tampered with before the VM starts. Which security control can achieve this by verifying the integrity of the boot chain?Cloud Platform and Infrastructure Security
- 100.A large enterprise is considering a hybrid cloud strategy. They need to ensure seamless identity management across their on-premises Active Directory and multiple public cloud providers. Which security best practice should be prioritized to achieve this goal?Cloud Concepts, Architecture and Design