Certificate of Cloud Security Knowledge v5 Free Sample Questions

20 free sample questions230 in the full practice test

Try simulator

CCSKV5 Sample Questions

  1. Question 1

    A financial services firm is deploying a new AI-powered fraud detection system that processes highly sensitive transaction data. The security team is concerned about adversarial attacks, specifically data poisoning, where an attacker could subtly manipulate the training data to create a backdoor in the model. Which of the following is the most effective proactive control to mitigate this specific threat?

    Answer and explanation

    Correct answer: B

    Data poisoning is an attack against the integrity of the training data itself. The most direct and proactive control is to secure the data supply chain. This involves implementing strong access controls (least privilege) on the training data, using cryptographic hashes to ensure data integrity, and monitoring the data ingestion pipeline for any unauthorized or anomalous modifications. While other options are good security practices for AI, they are reactive (output validation) or address different threats (model encryption, network segmentation).

  2. Question 2

    Multiple answers

    A DevOps team is building a CI/CD pipeline for a containerized application. To improve security, they want to integrate automated security testing. Which TWO of the following practices should be implemented in the pipeline to provide the most comprehensive security coverage before deployment? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    SAST analyzes source code from the 'inside-out' early in the development cycle, identifying vulnerabilities before the application is even compiled. This is a core component of a secure CI/CD pipeline.

    Modern applications heavily rely on third-party libraries. SCA scans these dependencies for known vulnerabilities (CVEs) and license compliance issues, which is a critical step as these components are a major source of risk.

  3. Question 3

    A healthcare provider is migrating its patient records system to a PaaS database offering. To comply with HIPAA, all data must be encrypted at rest. The cloud provider's PaaS service enables encryption by default using a provider-managed key. For enhanced security and control, the organization's CISO insists on the ability to immediately revoke access to the data in case of a breach, a process often referred to as crypto-shredding. What is the most appropriate key management strategy to meet this requirement?

    Answer and explanation

    Correct answer: B

    Using a customer-managed key (CMK) within the provider's KMS gives the organization full control over the key's lifecycle, including the ability to disable or delete it. Deleting the key effectively renders the data it encrypted inaccessible, achieving the goal of crypto-shredding. This provides the required control without the complexity of managing a separate HSM or client-side encryption.

  4. Question 4

    During a security assessment of a cloud environment, an auditor finds that a team of developers is using a shared root account for a cloud provider to manage all their development, testing, and production resources. This practice centralizes access but poses a significant security risk. Which foundational security principle is being violated?

    Answer and explanation

    Correct answer: C

    The principle of least privilege dictates that users and services should only be granted the minimum permissions necessary to perform their tasks. Using a root account provides maximum, unrestricted permissions. Furthermore, using a shared account violates the principle of individual accountability, as it becomes impossible to trace actions back to a specific person.

  5. Question 5

    True or False: In a Serverless or FaaS environment, the cloud customer is responsible for patching the underlying operating system of the execution environment.

    Answer and explanation

    Correct answer: B

    In a Serverless/FaaS model, the cloud service provider manages the entire underlying infrastructure, including the physical hardware, hypervisor, and the operating system of the execution environment. The customer's responsibility is focused on the function code itself, its permissions (IAM role), and the security of the data it processes. This is a key benefit of the Serverless model.

  6. Question 6

    A cloud architect is designing a virtual network for a multi-tier web application. The design requires a public-facing subnet for web servers and a private subnet for database servers. The database servers must be able to initiate connections to the internet to download security patches, but they must not be directly reachable from the internet. Which combination of cloud networking components achieves this goal securely?

    Answer and explanation

    Correct answer: B

    This is the standard and most secure architecture for this requirement. A NAT (Network Address Translation) Gateway resides in a public subnet and has an elastic IP. Resources in a private subnet can be routed through the NAT Gateway to access the internet. This allows for outbound connections (e.g., for patches) while preventing any inbound connections from being initiated from the internet, as the private resources have no public IP address.

  7. Question 7

    A government agency is setting up its cloud governance framework. They need to ensure that all newly created cloud storage buckets automatically block public access and have versioning enabled to comply with data retention policies. What is the most effective and scalable way to enforce these rules across the entire organization?

    Answer and explanation

    Correct answer: B

    Using native cloud governance tools like AWS Service Control Policies (SCPs) or Azure Policy allows the agency to define and enforce rules centrally. These policies can prevent the creation of non-compliant resources (e.g., deny creating a public bucket) or automatically remediate them. This approach is highly scalable, automated, and provides preventative control, which is far more effective than manual audits or post-creation scripts.

  8. Question 8

    A security analyst is reviewing telemetry from a cloud environment and observes a large volume of DNS queries for known malicious domains originating from multiple virtual machines. The analyst also notes an increase in outbound network traffic to unusual IP addresses. These events, when correlated, strongly suggest a malware infection. This process of combining different telemetry sources to identify a potential threat is a core function of what type of security tool?

    Answer and explanation

    Correct answer: C

    A SIEM is designed specifically for this purpose. It aggregates log data and telemetry from various sources (like DNS logs, VPC flow logs, OS logs), correlates events based on predefined rules or machine learning, and generates alerts for security incidents. The scenario described—correlating DNS queries with network traffic patterns to detect malware—is a classic SIEM use case.

  9. Question 9

    A company is preparing for its annual SOC 2 audit. The auditors have requested evidence that the company's cloud environment adheres to its stated security policies, particularly regarding data encryption and access control. Which type of tool would be most effective for continuously monitoring the cloud environment's configuration and providing evidence of compliance?

    Answer and explanation

    Correct answer: B

    CSPM tools are specifically designed to automate the assessment of cloud environments against compliance frameworks (like SOC 2, PCI DSS, etc.) and security best practices. They continuously scan cloud configurations, identify misconfigurations (e.g., unencrypted storage, overly permissive IAM roles), and provide detailed reports that can be used as evidence for auditors. This directly addresses the need for compliance evidence.

  10. Question 10

    A new startup is building its entire infrastructure on a public cloud provider. To manage costs and administrative overhead, they want to create a single, large account to house all company resources, from marketing websites to sensitive financial data processing. Which of the following is the primary security disadvantage of this organizational hierarchy model?

    Answer and explanation

    Correct answer: B

    The primary security disadvantage of a single-account model is the lack of isolation. If an attacker compromises credentials or exploits a vulnerability in a low-risk asset (like the marketing website), they could potentially move laterally to access and compromise high-risk assets (like the financial data). This is known as a large 'blast radius'. A multi-account strategy, where different workloads are segregated into separate accounts, contains the impact of a breach to a single account.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 230 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon