Step2Study
IT & TechnologyCCSP100% Free

Certified Cloud Security Professional (CCSP)

Practice bank
200 Qs
Real exam
125 Qs
Time limit
240 min
Passing
700 out of 1000 points

Exam blueprint

Cloud Concepts, Architecture and Design
17%
Cloud Data Security
20%
Cloud Platform and Infrastructure Security
17%
Cloud Application Security
17%
Cloud Security Operations
16%
Legal, Risk and Compliance
13%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 125 questions each · 240 min · pass 70% · 200 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Study with friends

Challenge a friend to beat your score.

Certified Cloud Security Professional (CCSP) practice test questions

Sample questions from the 200-question bank, with answers and explanations.

All questions
  1. 1. A cloud administrator is configuring a new cloud storage bucket for highly sensitive financial records. The organization's policy dictates that data must be encrypted both in transit and at rest, and that the encryption keys must be generated and managed by the cloud provider, but the customer retains the ability to revoke access to the keys at any time. Which key management option best meets these requirements?

    Cloud Data Security

    • A. Server-Side Encryption with Cloud-Managed Keys (SSE-KMS)
    • B. Server-Side Encryption with Customer-Managed Keys (SSE-CMK)
    • C. Server-Side Encryption with Cloud-Managed Keys (SSE-C)
    • D. Customer-Provided Encryption Keys (CPEK)
    Show answer

    A. Server-Side Encryption with Cloud-Managed Keys (SSE-KMS)

    SSE-KMS (Key Management Service) allows the cloud provider to manage the encryption keys, but the customer retains control over key usage and revocation policies. This meets the requirement for provider-managed keys with customer control.

  2. 2. A cloud customer is implementing a strategy for data destruction in their cloud environment. They have identified data classified as 'Confidential' that must be securely erased from all storage locations, including backups, within 30 days of its retention period expiring. Which data destruction method, when combined with proper key management, offers the most robust solution for ensuring irrecoverable deletion in a virtualized cloud storage environment?

    Cloud Data Security

    • A. Standard Overwriting
    • B. Secure Erase (ATA Command)
    • C. Logical Deletion
    • D. Cryptographic Erasure
    Show answer

    D. Cryptographic Erasure

    Cryptographic erasure, by destroying or revoking the encryption keys, makes the encrypted data permanently unrecoverable. In a virtualized cloud environment where direct physical access to storage media for overwriting or secure erase commands is typically not available to the customer, this is the most robust and verifiable method for irrecoverable data destruction.

  3. 3. A cloud security engineer needs to ensure that data stored in a cloud object storage bucket is protected against accidental deletion or modification for a specific retention period, even by administrators. Which feature should be enabled?

    Cloud Platform and Infrastructure Security

    • A. Server-Side Encryption
    • B. Access Control Lists (ACLs)
    • C. Versioning
    • D. Object Lock
    Show answer

    D. Object Lock

    Object Lock provides an immutable, write-once-read-many (WORM) model for objects, preventing them from being deleted or overwritten for a fixed amount of time or indefinitely.

  4. 4. An organization is deploying a new application that will store highly sensitive customer data in a cloud database. Compliance regulations require that all data, both at rest and in transit, must be encrypted. Furthermore, the organization needs to ensure that the encryption keys are managed by a dedicated, highly secure service that is FIPS 140-2 Level 3 certified. Which cloud service or technology best fulfills this specific key management requirement?

    Cloud Data Security

    • A. Client-Side Encryption with a software key store
    • B. Transparent Data Encryption (TDE) provided by the database
    • C. Hardware Security Module (HSM) as a Service
    • D. Cloud Key Management Service (KMS)
    Show answer

    C. Hardware Security Module (HSM) as a Service

    Hardware Security Module (HSM) as a Service specifically provides dedicated, FIPS 140-2 Level 3 certified hardware for key generation, storage, and cryptographic operations, meeting the stringent security and compliance requirements for encryption key management.

  5. 5. A cloud security architect is designing a secure CI/CD pipeline for containerized applications. A critical requirement is to ensure that container images used in deployment are free from known vulnerabilities and meet organizational compliance standards before being pushed to the container registry. Which security control should be integrated early in the CI/CD pipeline to address this requirement?

    Cloud Platform and Infrastructure Security

    • A. Runtime Application Self-Protection (RASP)
    • B. Network Segmentation
    • C. Web Application Firewall (WAF)
    • D. Container Image Scanning
    Show answer

    D. Container Image Scanning

    Container image scanning tools analyze container images for known vulnerabilities, misconfigurations, and compliance violations, providing a critical security gate before deployment.

  6. 6. A company is planning to migrate its on-premises database containing sensitive customer information to a public cloud environment. Before migration, they need to identify all instances of personally identifiable information (PII) and protected health information (PHI) within their existing unstructured and structured data stores across various departments. Which process is crucial for achieving this goal?

    Cloud Data Security

    • A. Data Discovery
    • B. Data Archiving
    • C. Data Retention Policy Enforcement
    • D. Data Replication
    Show answer

    A. Data Discovery

    Data discovery is the process of identifying and locating specific types of data (like PII or PHI) across an organization's various data stores, which is essential before migrating sensitive data to the cloud to understand what needs protection.

  7. 7. A company is implementing a new cloud-based data analytics platform that processes sensitive customer information. The platform utilizes multiple cloud services, including compute instances, managed databases, and object storage. To maintain regulatory compliance, the company needs to ensure that all administrative actions performed on these cloud resources are recorded, immutable, and easily auditable. Which cloud management plane security feature BEST addresses this requirement?

    Cloud Platform and Infrastructure Security

    • A. Data Loss Prevention (DLP) policies across services.
    • B. Cloud audit logging and monitoring services.
    • C. Centralized Identity and Access Management (IAM).
    • D. Cloud Access Security Broker (CASB) integration.
    Show answer

    B. Cloud audit logging and monitoring services.

    Cloud audit logging and monitoring services (e.g., AWS CloudTrail, Azure Monitor Activity Logs, GCP Cloud Audit Logs) are specifically designed to record all API calls and administrative actions taken on cloud resources. These logs are typically immutable, time-stamped, and can be integrated with analytical tools for auditing and compliance purposes, directly addressing the requirement.

  8. 8. A cloud security architect is designing a highly available and resilient application in a public cloud environment. The architect wants to ensure that if an entire cloud region becomes unavailable, the application can continue to serve users with minimal downtime and data loss. Which disaster recovery strategy BEST addresses this requirement?

    Cloud Platform and Infrastructure Security

    • A. Multi-Region Active-Active
    • B. Warm Standby
    • C. Backup and Restore
    • D. Pilot Light
    Show answer

    A. Multi-Region Active-Active

    Multi-Region Active-Active deployment ensures that the application is fully operational in multiple, geographically dispersed regions simultaneously. If one region fails, traffic is automatically routed to the other active regions, providing the highest level of availability and minimal downtime.

  9. 9. A global healthcare provider is deploying a new cloud-based electronic health record (EHR) system. Due to the highly sensitive nature of patient data and strict regulatory requirements (e.g., HIPAA, GDPR), the provider requires a solution that continuously monitors data access, identifies unusual behavior, and enforces granular access policies in real-time across multiple cloud services. Which cloud security technology is best suited to fulfill these requirements?

    Cloud Data Security

    • A. Cloud Workload Protection Platform (CWPP)
    • B. Data Loss Prevention (DLP)
    • C. Cloud Security Posture Management (CSPM)
    • D. Cloud Access Security Broker (CASB)
    Show answer

    D. Cloud Access Security Broker (CASB)

    A Cloud Access Security Broker (CASB) operates between cloud users and cloud applications, providing visibility, compliance, data security, and threat protection. It's ideal for monitoring access, detecting anomalies, and enforcing granular policies across multiple cloud services, matching the scenario's needs.

  10. 10. A cloud architect is designing a system for a global financial institution that must comply with strict data residency regulations. The institution requires that all customer data from European Union (EU) citizens must remain physically stored and processed within the EU. Which cloud deployment model is BEST suited to meet this specific data residency requirement while still leveraging cloud benefits?

    Cloud Concepts, Architecture and Design

    • A. Private Cloud
    • B. Hybrid Cloud
    • C. Public Cloud
    • D. Community Cloud
    Show answer

    D. Community Cloud

    A Community Cloud is specifically designed to meet the requirements of a specific community with shared concerns, such as regulatory compliance, which aligns perfectly with the need for data residency for EU citizens within a financial institution.

  11. 11. A financial services company is evaluating cloud providers for its new customer-facing application. The application will process sensitive personal and financial data. The company's compliance team insists on maintaining direct control over the underlying physical infrastructure, including hardware and network components, to meet stringent regulatory requirements. Which cloud deployment model would best satisfy these requirements?

    Cloud Concepts, Architecture and Design

    • A. Public Cloud
    • B. Hybrid Cloud
    • C. Community Cloud
    • D. Private Cloud
    Show answer

    D. Private Cloud

    A private cloud model provides the highest level of control over the underlying physical infrastructure, which aligns with the company's need for direct control to meet stringent regulatory requirements for sensitive data.

  12. 12. A cloud security team is implementing a strategy to protect sensitive data stored in an Amazon S3 bucket. They want to ensure that even if an attacker gains access to the S3 bucket, the data remains unreadable. Which security best practice should they prioritize?

    Cloud Concepts, Architecture and Design

    • A. Implementing strong access control lists (ACLs) on the bucket.
    • B. Applying strong encryption to the data at rest.
    • C. Configuring public access blocks for the S3 bucket.
    • D. Enabling versioning for the S3 bucket.
    Show answer

    B. Applying strong encryption to the data at rest.

    Applying strong encryption to data at rest ensures that even if an attacker gains unauthorized access to the storage location, the data itself is unreadable without the decryption key, thus achieving the goal.

  13. 13. A cloud provider offers a service that allows customers to categorize their data based on its sensitivity, compliance requirements, and business value. This categorization then automatically triggers appropriate security controls, such as encryption levels, access permissions, and retention policies. What is this service primarily facilitating?

    Cloud Data Security

    • A. Data Discovery
    • B. Digital Rights Management (DRM)
    • C. Data Loss Prevention (DLP)
    • D. Data Classification
    Show answer

    D. Data Classification

    Data classification is the process of categorizing data based on its content, context, and use, which then enables the automatic application of appropriate security controls and policies, directly matching the scenario described.

  14. 14. A company is designing a cloud-native application that requires high availability and resilience. They want to ensure that if an entire data center becomes unavailable, the application can continue to operate with minimal downtime. Which cloud architecture principle is most relevant to achieving this goal?

    Cloud Concepts, Architecture and Design

    • A. Fault Tolerance
    • B. Data Locality
    • C. Least Privilege
    • D. Defense in Depth
    Show answer

    A. Fault Tolerance

    Fault tolerance is the ability of a system to continue operating without interruption when one or more of its components fail, directly addressing the requirement for continued operation despite data center unavailability.

  15. 15. A cloud security architect is reviewing an incident where an attacker exploited a vulnerability in a web application to gain unauthorized access to an underlying virtual machine. The attacker then used escalated privileges on the VM to access other VMs on the same physical host. Which type of attack vector is described in this scenario?

    Cloud Concepts, Architecture and Design

    • A. Cross-site scripting (XSS)
    • B. Denial of service (DoS)
    • C. Virtualization escape
    • D. Side-channel attack
    Show answer

    C. Virtualization escape

    A virtualization escape occurs when an attacker breaks out of a virtual machine and gains access to the underlying hypervisor or other virtual machines on the same physical host, precisely matching the scenario described.

  16. 16. An organization relies on a cloud provider for its primary data storage. To ensure business continuity and disaster recovery, they implement a strategy where data is continuously copied to a geographically distant data center, maintained by the same cloud provider, with a recovery point objective (RPO) of minutes. Which data protection strategy is being employed?

    Cloud Data Security

    • A. Data Archiving
    • B. Data Replication
    • C. Data Backup
    • D. Data Retention
    Show answer

    B. Data Replication

    Data replication involves continuously copying data to another location to maintain a near real-time duplicate, which is essential for achieving a low RPO and supporting disaster recovery and business continuity.

  17. 17. A cloud administrator is configuring security for a new set of virtual machines (VMs) deployed in a public cloud. The administrator needs to ensure that only specific, authorized network traffic can reach these VMs, while all other inbound traffic is blocked by default. Which of the following cloud security controls should be primarily used to achieve this objective?

    Cloud Platform and Infrastructure Security

    • A. Data Loss Prevention (DLP) solutions
    • B. Host-based Intrusion Detection Systems (HIDS)
    • C. Web Application Firewalls (WAF)
    • D. Security Groups or Network Access Control Lists (NACLs)
    Show answer

    D. Security Groups or Network Access Control Lists (NACLs)

    Security Groups and Network Access Control Lists (NACLs) are fundamental cloud network security controls used to filter traffic at the virtual network level, allowing administrators to define inbound and outbound rules based on IP addresses, ports, and protocols. They effectively block unwanted traffic by default.

  18. 18. A healthcare organization is migrating patient health records (PHR) to a cloud environment. Due to strict HIPAA compliance requirements, they need to ensure that PHR data is permanently and irrevocably deleted from storage media when it is no longer needed, even in the event of hardware disposal. Which data destruction method is most effective for meeting this requirement in a cloud context?

    Cloud Data Security

    • A. Degaussing
    • B. Cryptographic Erasure
    • C. Logical Deletion
    • D. Overwriting
    Show answer

    B. Cryptographic Erasure

    Cryptographic erasure renders data unrecoverable by destroying or revoking access to the encryption keys, effectively making the encrypted data useless. This is highly effective in cloud environments where physical destruction of media isn't always feasible for the customer.

  19. 19. A cloud provider offers a service where customers can deploy their custom code without managing the underlying servers or operating systems. The customer is only billed for the actual compute time consumed by their code executions. Which cloud computing concept does this billing model align with?

    Cloud Concepts, Architecture and Design

    • A. Resource pooling
    • B. Measured service
    • C. Rapid elasticity
    • D. Broad network access
    Show answer

    B. Measured service

    Measured service is a key characteristic of cloud computing where resource usage is monitored, controlled, and reported, allowing for transparent billing based on actual consumption, precisely as described in the scenario.

  20. 20. A cloud security team is investigating a potential compromise involving a virtual machine (VM) running a critical application. The team needs to capture the VM's exact state, including its memory contents, at the time of the incident for forensic analysis. Which capability is essential for performing this type of investigation in a cloud environment?

    Cloud Platform and Infrastructure Security

    • A. Performing memory forensics on the VM
    • B. Collecting cloud provider audit logs
    • C. Snapshotting the VM's disk
    • D. Analyzing network flow logs
    Show answer

    A. Performing memory forensics on the VM

    Memory forensics involves capturing and analyzing the volatile memory (RAM) of a running system. This is crucial for incident response as it can reveal processes, network connections, loaded modules, and other artifacts that are only present in memory and not on disk.

  21. 21. A public sector organization is implementing a cloud-based data analytics platform. Due to the highly sensitive nature of the data (e.g., citizen health records), they need to ensure that the data is not only encrypted at rest and in transit but also that the integrity of the data is maintained against unauthorized modifications. Which cryptographic primitive, when used in conjunction with encryption, is primarily responsible for ensuring data integrity?

    Cloud Data Security

    • A. Symmetric Encryption
    • B. Digital Signature
    • C. Hashing
    • D. Asymmetric Encryption
    Show answer

    C. Hashing

    Hashing (specifically cryptographic hashing) is primarily used to ensure data integrity. By computing a hash of the data before transmission or storage and reverifying it later, any unauthorized modification to the data will result in a different hash, indicating tampering.

  22. 22. A cloud security architect is evaluating different cloud providers for an application that processes highly sensitive personal identifiable information (PII). The primary concern is to minimize the risk of data exposure due to a compromise of the cloud provider's underlying infrastructure or hypervisor. Which security concept or technology would offer the MOST robust protection against this specific threat vector?

    Cloud Concepts, Architecture and Design

    • A. Data Loss Prevention (DLP)
    • B. Virtualization-aware security
    • C. Confidential Computing
    • D. Homomorphic Encryption
    Show answer

    C. Confidential Computing

    Confidential Computing protects data in use by performing computation within a hardware-based trusted execution environment (TEE), making it inaccessible to the cloud provider, hypervisor, or other tenants, even if the underlying infrastructure is compromised. This directly addresses the risk of data exposure from a compromised hypervisor.

  23. 23. A healthcare provider is storing patient medical records in a cloud database. Due to strict HIPAA compliance requirements, they need to ensure that specific sensitive fields, such as patient names and diagnoses, are obscured when developers are testing new features, but the format and relationships between data elements must be preserved for application functionality. Which data security technique is best suited for this scenario?

    Cloud Data Security

    • A. Data Anonymization
    • B. Data Hashing
    • C. Data Masking
    • D. Tokenization
    Show answer

    C. Data Masking

    Data masking replaces sensitive data with realistic, yet fictitious, data while preserving the data's format and referential integrity. This allows developers to work with functional data without exposing actual patient information, which is ideal for development and testing environments.

  24. 24. A software development team is adopting a DevOps approach and needs a cloud service that allows them to quickly deploy and manage their application code without worrying about the underlying operating system, middleware, or runtime environments. They want to focus solely on writing and deploying their application logic. Which cloud service model best fits this requirement?

    Cloud Concepts, Architecture and Design

    • A. Infrastructure as a Service (IaaS)
    • B. Software as a Service (SaaS)
    • C. Platform as a Service (PaaS)
    • D. Bare Metal as a Service (BMaaS)
    Show answer

    C. Platform as a Service (PaaS)

    Platform as a Service (PaaS) abstracts away the operating system, middleware, and runtime, allowing developers to focus purely on application development and deployment, which aligns with the DevOps team's goal.

  25. 25. A cloud provider offers a platform-as-a-service (PaaS) database service. A customer wants to ensure that their data stored in this database is physically isolated from other customers' data at the storage layer. Which of the following isolation strategies would the customer MOST likely expect the CSP to implement to meet this physical isolation requirement?

    Cloud Platform and Infrastructure Security

    • A. Dedicated physical storage arrays for each customer.
    • B. Network segmentation of database instances using VLANs.
    • C. Logical separation through database schemas and user roles.
    • D. Encryption of customer data with unique customer-managed keys.
    Show answer

    A. Dedicated physical storage arrays for each customer.

    While logical separation (A), encryption (C), and network segmentation (D) are important security controls, the question specifically asks for *physical isolation at the storage layer*. Dedicated physical storage arrays or disks for each customer would be the most direct way to achieve true physical isolation of data, preventing any shared physical storage resources between tenants.

Certified Cloud Security Professional (CCSP) flashcards

Tap a card to flip it. 160 flashcards in the full deck.

  • Server-Side Encryption with Cloud-Managed Keys (SSE-KMS)

    Flip card

    A server-side encryption option where the cloud provider's Key Management Service (KMS) generates and manages the encryption keys, while allowing the customer to control key usage and revocation policies.

    • Cloud provider generates and manages keys.
    • Customer retains policy control over key usage and revocation.
    • Often integrated with other cloud services.
    Study this card →
  • Cryptographic Erasure

    Flip card

    A data destruction method that renders encrypted data permanently unrecoverable by destroying or revoking access to the encryption keys. The underlying encrypted data may persist, but it becomes unintelligible and unusable without the key.

    • Key destruction/revocation.
    • Encrypted data becomes unrecoverable.
    • Ideal for virtualized and cloud environments.
    Study this card →
  • Cloud Object Lock

    Flip card

    A feature in cloud object storage that prevents objects from being deleted or overwritten for a fixed amount of time or indefinitely, ensuring data immutability.

    • Provides Write-Once-Read-Many (WORM) capability.
    • Protects against accidental or malicious deletion/modification.
    • Can be configured with retention periods or legal holds.
    Study this card →
  • Hardware Security Module (HSM) as a Service

    Flip card

    HSM as a Service is a cloud offering that provides dedicated, FIPS 140-2 certified hardware for cryptographic key generation, storage, and operations, ensuring a high level of security and regulatory compliance for key management.

    • Provides dedicated, tamper-resistant hardware.
    • Often FIPS 140-2 Level 3 certified.
    • Keys are generated and stored within the HSM, never leaving it.
    Study this card →
  • Container Image Scanning

    Flip card

    The automated process of analyzing container images for known vulnerabilities, misconfigurations, and policy violations, typically integrated into CI/CD pipelines.

    • Identifies security risks before containers are deployed.
    • Leverages vulnerability databases (CVEs).
    • Helps enforce security policies and compliance standards.
    Study this card →
  • Data Discovery

    Flip card

    The process of identifying, locating, and mapping sensitive data across an organization's IT environment, including structured and unstructured data stores, to understand its prevalence and ensure proper protection.

    • Identifies sensitive data locations.
    • Works across structured and unstructured data.
    • Crucial first step for data protection initiatives.
    Study this card →
  • Cloud Audit Logging

    Flip card

    A cloud service feature that records API calls and administrative actions for all resources, providing an immutable audit trail for security and compliance.

    • Records all management plane activities.
    • Logs are typically immutable and time-stamped.
    • Essential for compliance, forensics, and security monitoring.
    Study this card →
  • Multi-Region Active-Active DR

    Flip card

    A disaster recovery strategy where an application is fully deployed and active in multiple, geographically separate cloud regions, processing requests concurrently.

    • Provides highest availability and lowest RTO/RPO.
    • Routes traffic automatically to active regions upon failure.
    • More complex and expensive to implement.
    Study this card →
  • Cloud Access Security Broker (CASB)

    Flip card

    A security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud-based resources are accessed. CASBs provide visibility, compliance, data security, and threat protection.

    • Intermediary between users and cloud services.
    • Provides visibility, compliance, data security, threat protection.
    • Enforces policies in real-time across multiple cloud services.
    Study this card →
  • Community Cloud

    Flip card

    A cloud infrastructure shared by several organizations with shared concerns (e.g., mission, security requirements, policy, and compliance considerations).

    • Shared by specific, related organizations.
    • Addresses common regulatory or security needs.
    • Can be managed internally or by a third party.
    Study this card →
  • Private Cloud

    Flip card

    A cloud deployment model where the cloud infrastructure is provisioned for exclusive use by a single organization.

    • Offers exclusive control over infrastructure
    • Can be managed internally or by a third party
    • Typically used for sensitive data and high compliance needs
    Study this card →
  • Encryption at Rest

    Flip card

    The practice of encrypting data when it is stored on a physical storage device, such as a hard drive, solid-state drive, or cloud storage bucket.

    • Protects data from unauthorized access even if the storage medium is compromised.
    • Can be managed by the customer (client-side) or the cloud provider (server-side).
    • Crucial for data confidentiality and compliance requirements.
    Study this card →
  • Data Classification

    Flip card

    The process of organizing data into categories based on its sensitivity, value, and regulatory requirements, which then informs the application of appropriate security controls and policies.

    • Categorizes data based on sensitivity and value.
    • Informs security controls (encryption, access).
    • Drives retention and disposal policies.
    Study this card →
  • Fault Tolerance

    Flip card

    The property that enables a system to continue operating properly in the event of the failure of some of its components.

    • Achieved through redundancy and automatic failover mechanisms.
    • Crucial for high availability and business continuity.
    • Often involves deploying across multiple availability zones or regions.
    Study this card →
  • Virtualization Escape

    Flip card

    A security vulnerability or exploit that allows an attacker to break out of a guest virtual machine and gain unauthorized access to the host operating system (hypervisor) or other virtual machines running on the same host.

    • Considered a highly severe threat in virtualized environments.
    • Can compromise the isolation between virtual machines.
    • Requires robust hypervisor security and patching.
    Study this card →
  • Data Replication

    Flip card

    The process of continuously copying data from one location to another, maintaining an up-to-date duplicate, primarily for disaster recovery, high availability, and load balancing.

    • Continuous data copying.
    • Aims for low RPO (Recovery Point Objective).
    • Supports disaster recovery and business continuity.
    Study this card →
  • Security Groups/NACLs

    Flip card

    Cloud-native virtual firewall services that control inbound and outbound network traffic for virtual machines or subnets based on rules.

    • Filter traffic based on IP, port, protocol.
    • Act as a virtual firewall.
    • Configurable at VM or subnet level.
    Study this card →
  • Measured Service

    Flip card

    A characteristic of cloud computing where resource usage is monitored, controlled, and reported, providing transparency for both the provider and consumer.

    • Enables 'pay-as-you-go' or 'pay-per-use' billing models.
    • Allows consumers to track and optimize their resource consumption.
    • Often includes metrics like compute time, data transfer, and storage used.
    Study this card →
  • Cloud VM Memory Forensics

    Flip card

    The process of capturing and analyzing the volatile memory (RAM) of a virtual machine in a cloud environment to investigate security incidents and potential compromises.

    • Captures runtime state, processes, network connections, and hidden data.
    • Essential for detecting advanced persistent threats (APTs) and malware.
    • Requires specific cloud provider capabilities or third-party tools.
    Study this card →
  • Cryptographic Hashing

    Flip card

    Cryptographic hashing is a mathematical algorithm that maps data of arbitrary size to a fixed-size bit array (hash value or message digest). It is primarily used for ensuring data integrity, as any alteration to the input data will produce a different hash value.

    • Generates a fixed-size output (hash value).
    • One-way function (computationally infeasible to reverse).
    • Collision resistant (hard to find two inputs with same hash).
    Study this card →
  • Confidential Computing

    Flip card

    A cloud security technology that protects data in use by performing computation in a hardware-based Trusted Execution Environment (TEE), shielding it from unauthorized access even from the cloud provider.

    • Protects data during processing (in use).
    • Utilizes hardware-based Trusted Execution Environments (TEEs).
    • Shields data from hypervisor, OS, and cloud administrator access.
    Study this card →
  • Data Masking

    Flip card

    A technique that replaces sensitive data with fictitious but realistic data, preserving the data's format and referential integrity, primarily used for non-production environments like development, testing, and training.

    • Replaces real data with fake, but realistic, data.
    • Preserves data format and referential integrity.
    • Used in non-production environments (dev, test, training).
    Study this card →
  • PaaS (Platform as a Service)

    Flip card

    A cloud service model where the provider delivers a computing platform and solution stack, allowing customers to develop, run, and manage applications without the complexity of building and maintaining the infrastructure.

    • Provider manages OS, middleware, runtime.
    • Customer manages applications and data.
    • Focus on application development and deployment.
    Study this card →
  • Physical Data Isolation

    Flip card

    Ensuring that one tenant's data resides on distinct physical hardware resources, preventing any sharing of underlying physical storage with other tenants.

    • Achieved through dedicated hardware (disks, servers).
    • Provides strongest form of isolation.
    • More expensive and less common in multi-tenant cloud.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.