CCSP Practice Questions
Prepare for CCSP with more than an answer.
- Exam fee
- $749 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- Cloud Concepts, Architecture and Design17%
- Cloud Data Security20%
- Cloud Platform & Infrastructure Security17%
- Cloud Application Security17%
- Cloud Security Operations16%
- Legal, Risk and Compliance13%
- 1
What is a serious complication an organization faces from the perspective of compliance with international operations?
Show answer details
Correct answer: C
Explanation:
When operating within a global framework, a security professional runs into a multitude of jurisdictions and requirements, and many times they might be in contention with one other or not clearly applicable. These requirements can include the location of the users and the type of data they enter into systems, the laws governing the organization that owns the application and any regulatory requirements they may have, as well as the appropriate laws and regulations for the jurisdiction housing the IT resources and where the data is actually stored, which might be multiple jurisdictions as well. - 2
Which networking concept in a cloud environment allows for network segregation and isolation of IP spaces?
Show answer details
Correct answer: B
Explanation:
A virtual area network (VLAN) allows the logical separation and isolation of networks and IP spaces to provide enhanced security and controls. - 3
Which of the following standards primarily pertains to cabling designs and setups in a data center?
Show answer details
Correct answer: A
Explanation:
The standards put out by Building Industry Consulting Service International (BICSI) primarily cover complex cabling designs and setups for data centers, but also include specifications on power, energy efficiency, and hot/cold aisle setups. - 4
Which of the following publishes the most commonly used standard for data center design in regard to tiers and topologies?
Show answer details
Correct answer: C
Explanation:
The Uptime Institute publishes the most commonly used and widely known standard on data center tiers and topologies. It is based on a series of four tiers, with each progressive increase in number representing more stringent, reliable, and redundant systems for security, connectivity, fault tolerance, redundancy, and cooling. - 5
What type of segregation and separation of resources is needed within a cloud environment for multitenancy purposes versus a traditional data center model?
Show answer details
Correct answer: B
Explanation:
Cloud environments lack the ability to physically separate resources like a traditional data center can. To compensate, cloud computing logical segregation concepts are employed. These include VLANs, sandboxing, and the use of virtual network devices such as firewalls. - 6
Which United States law is focused on data related to health records and privacy?
Show answer details
Correct answer: D
Explanation:
The Health Insurance Portability and Accountability Act (HIPAA) requires the U.S. Federal Department of Health and Human Services to publish and enforce regulations pertaining to electronic health records and identifiers between patients, providers, and insurance companies. It is focused on the security controls and confidentiality of medical records, rather than the specific technologies used, so long as they meet the requirements of the regulations. - 7
A healthcare organization is using an IaaS provider to host an application that processes electronic protected health information (ePHI). To comply with HIPAA, they must ensure that all data at rest is encrypted. The organization's security team wants to maintain full control over the lifecycle of the encryption keys. Which approach should they use?
graph TD subgraph Customer Premise KMS[On-Premise KMS/HSM] end subgraph Cloud Provider subgraph VPC VM[Virtual Machine] Storage[(Encrypted Volume)] end end KMS -- Manages Keys --> Storage VM -- Reads/Writes Data --> StorageShow answer details
Correct answer: D
To maintain full control over the key lifecycle, the organization should use their own on-premises Hardware Security Module (HSM) or a highly controlled KMS. By integrating their on-premise HSM with the cloud services, they can manage key generation, rotation, and destruction entirely within their own environment, ensuring the cloud provider has no access to the keys. BYOK gives more control than provider-managed keys, but still involves trusting the provider's KMS. A CASB can help manage policies but doesn't solve the core key custody issue. Provider-managed keys offer the least control.
- 8
Which of the following roles is responsible for creating cloud components and the testing and validation of services?
Show answer details
Correct answer: C
Explanation:
The cloud service developer is responsible for developing and creating cloud components and services, as well as for testing and validating services. - 9
What is the best source for information about securing a physical asset's BIOS?
Show answer details
Correct answer: C
Explanation:
Vendor documentation from the manufacturer of the physical hardware is the best source of best practices for securing the BIOS. - 10
Which of the following is not a component of contractual PII?
Show answer details
Correct answer: C
This is the CORRECT answer. Value of data is not a standard component of contractual PII arrangements. Contractual PII focuses on processing scope, location, security requirements, and compliance obligations rather than data valuation.
