Skip to content

CCSKV5 Certificate of Cloud Security Knowledge v5 Practice Questions

Prepare for CCSKV5 with more than an answer.

230 questions in the full set20 sample questionsUpdated Dec 24, 2025
Exam fee
$445 USD
Level
Foundational
Valid for
No expiration
Domains covered on the exam 12
  1. Cloud Computing Concepts & Architectures8%
  2. Cloud Governance9%
  3. Risk, Audit, & Compliance9%
  4. Organization Management8%
  5. Identity & Access Management10%
  6. Security Monitoring8%
  7. Infrastructure & Networking9%
  8. Cloud Workload Security9%
  9. Data Security9%
  10. Application Security8%
  11. Incident Response & Resilience8%
  12. Related Technologies & Strategies8%
  1. 1

    A security team is securing a Kubernetes cluster. They want to prevent pods from running with unnecessary privileges, such as running as the root user or accessing the host's network namespace. Which native Kubernetes security mechanism should they use to enforce these policies at the cluster level?

    Show answer details

    Correct answer: C

    Kubernetes Pod Security Standards (which replaced PodSecurityPolicy) are the native mechanism for enforcing security constraints on pods. They define security profiles (Privileged, Baseline, Restricted) that can be applied at the namespace level. These policies control sensitive aspects of a pod's specification, such as preventing privileged containers, restricting host namespace access, and requiring non-root users, directly addressing the requirements.

  2. 2

    A developer has written an Infrastructure as Code (IaC) template to deploy a new environment. Which of the following security practices should be integrated into the CI/CD pipeline to identify potential misconfigurations, such as a publicly exposed database, before the infrastructure is provisioned?

    flowchart TD A[Code Commit] --> B{CI/CD Pipeline Triggered} B --> C[Build Artifact] C --> D{Security Scan?} D --> E[Deploy to Staging] E --> F[Deploy to Production]
    Show answer details

    Correct answer: B

    Static analysis of IaC templates (like Terraform, CloudFormation, etc.) is the correct 'shift-left' approach. Tools like Checkov, tfsec, or KICS scan the code before it is deployed to identify security misconfigurations, policy violations, and compliance issues. This is a proactive measure that prevents insecure infrastructure from ever being created, which is far more effective than detecting it post-deployment.

  3. 3

    A media company stores large volumes of video files in cloud object storage. They want to implement a data classification strategy to automatically identify and tag videos containing sensitive content. This will allow them to apply stricter access controls and retention policies to those specific files. Which type of cloud data security service is best suited for this task?

    Show answer details

    Correct answer: B

    Cloud-native services like AWS Macie are designed for this exact purpose. They use machine learning and pattern matching to automatically discover, classify, and protect sensitive data stored in cloud services like object storage. They can identify PII, financial data, and other sensitive information, and then tag the data, which can trigger automated security workflows.

  4. 4

    A company has established a formal incident response plan for its cloud environment. During a tabletop exercise simulating a ransomware attack, the team successfully identifies and contains the affected systems. What is the primary goal of the NEXT phase in the standard incident response lifecycle?

    Show answer details

    Correct answer: C

    The standard incident response lifecycle follows these phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned (Post-Incident Analysis). After an incident has been contained, the next step is Eradication, which involves removing the root cause of the incident (e.g., deleting malware, disabling compromised accounts) and then Recovery, which involves restoring systems to normal operation from clean backups.

  5. 5

    True or False: A Cloud Access Security Broker (CASB) operating in proxy mode can monitor and enforce policies on traffic from unmanaged devices accessing sanctioned cloud applications.

    Show answer details

    Correct answer: A

    This is a key capability of a CASB in forward or reverse proxy mode. By sitting in the data path between the user and the cloud service, the CASB can inspect all traffic, regardless of the device's management status. This allows it to enforce policies like preventing data exfiltration, blocking malware, and controlling access for both managed corporate laptops and unmanaged personal devices (BYOD).

  6. 6

    A financial services firm is deploying a new AI-powered fraud detection system that processes highly sensitive transaction data. The security team is concerned about adversarial attacks, specifically data poisoning, where an attacker could subtly manipulate the training data to create a backdoor in the model. Which of the following is the most effective proactive control to mitigate this specific threat?

    Show answer details

    Correct answer: B

    Data poisoning is an attack against the integrity of the training data itself. The most direct and proactive control is to secure the data supply chain. This involves implementing strong access controls (least privilege) on the training data, using cryptographic hashes to ensure data integrity, and monitoring the data ingestion pipeline for any unauthorized or anomalous modifications. While other options are good security practices for AI, they are reactive (output validation) or address different threats (model encryption, network segmentation).

  7. 7

    A DevOps team is building a CI/CD pipeline for a containerized application. To improve security, they want to integrate automated security testing. Which TWO of the following practices should be implemented in the pipeline to provide the most comprehensive security coverage before deployment? (Select TWO)

    Show answer details

    Correct answer: B, C

    SAST analyzes source code from the 'inside-out' early in the development cycle, identifying vulnerabilities before the application is even compiled. This is a core component of a secure CI/CD pipeline.

    Modern applications heavily rely on third-party libraries. SCA scans these dependencies for known vulnerabilities (CVEs) and license compliance issues, which is a critical step as these components are a major source of risk.

  8. 8

    A healthcare provider is migrating its patient records system to a PaaS database offering. To comply with HIPAA, all data must be encrypted at rest. The cloud provider's PaaS service enables encryption by default using a provider-managed key. For enhanced security and control, the organization's CISO insists on the ability to immediately revoke access to the data in case of a breach, a process often referred to as crypto-shredding. What is the most appropriate key management strategy to meet this requirement?

    Show answer details

    Correct answer: B

    Using a customer-managed key (CMK) within the provider's KMS gives the organization full control over the key's lifecycle, including the ability to disable or delete it. Deleting the key effectively renders the data it encrypted inaccessible, achieving the goal of crypto-shredding. This provides the required control without the complexity of managing a separate HSM or client-side encryption.

  9. 9

    During a security assessment of a cloud environment, an auditor finds that a team of developers is using a shared root account for a cloud provider to manage all their development, testing, and production resources. This practice centralizes access but poses a significant security risk. Which foundational security principle is being violated?

    Show answer details

    Correct answer: C

    The principle of least privilege dictates that users and services should only be granted the minimum permissions necessary to perform their tasks. Using a root account provides maximum, unrestricted permissions. Furthermore, using a shared account violates the principle of individual accountability, as it becomes impossible to trace actions back to a specific person.

  10. 10

    True or False: In a Serverless or FaaS environment, the cloud customer is responsible for patching the underlying operating system of the execution environment.

    Show answer details

    Correct answer: B

    In a Serverless/FaaS model, the cloud service provider manages the entire underlying infrastructure, including the physical hardware, hypervisor, and the operating system of the execution environment. The customer's responsibility is focused on the function code itself, its permissions (IAM role), and the security of the data it processes. This is a key benefit of the Serverless model.

Create an account to continue.