CCSP Cloud Concepts, Architecture practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

CCSP Cloud Concepts, Architecture and Design: 255 practice questions

CCSP 255 questions 12 shown free

12 of the 255 Cloud Concepts, Architecture and Design questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for CCSP? Take the free 5-min readiness check →

1. Conduct a business impact analysis before finalizing: Which control addresses the demonstrated failure?

Hard
A financial services firm’s exhibit states: “Critical payment processing must resume within 2 hours; transactions may lose 15 minutes; dependencies include identity, network, and settlement.” The architecture team immediately proposes a second region and hourly backups, but has not documented business priorities or dependency impacts. Which control addresses the demonstrated failure?
  1. Deploy active processing in multiple regions with automated traffic redirection and synchronized storage.
    This may improve availability, but it presupposes recovery requirements instead of addressing the absent business impact analysis.
  2. Conduct a business impact analysis before finalizing recovery capabilities. ✓
    A business impact analysis identifies critical processes, dependencies, and time-dependent impacts before recovery priorities and capabilities are selected.
  3. Run a disaster-recovery failover exercise against the proposed second-region architecture.
    A failover exercise tests an implemented design, but cannot establish whether recovery priorities and dependencies were correctly identified.
  4. Increase backup frequency to meet the stated fifteen-minute data-loss tolerance.
    More frequent backups address potential recovery-point performance, not the missing business impact analysis and dependency prioritization.
The trap
Testing an unvalidated design leaves business priorities unresolved. Improving backups does not define critical business dependencies. Architecture expansion cannot substitute for impact-based prioritization.

A business impact analysis must identify priorities and dependencies before recovery architecture is finalized.

2. Team-linked audit logs of portal/API provisioning: Which evidence best verifies on-demand self-service?

Medium
An international nonprofit requires project teams to create isolated computing resources without submitting provider tickets. The contract permits portal and API use and records each request under the requesting team’s identity. Which evidence best verifies on-demand self-service?
  1. A provider statement describing availability in several countries.
    Geographic availability concerns broad network access or deployment reach, not self-service provisioning.
  2. Team-linked audit logs of portal/API provisioning. ✓
    These logs directly show teams independently provisioning resources without provider personnel.
  3. Monthly project invoices for compute, storage, and network use.
    Invoices demonstrate measured service, not who provisioned the resources or whether self-service was available.
  4. A capacity report showing resources can expand quickly during campaigns.
    Rapid elasticity concerns scaling capacity, not independent customer provisioning through authorized interfaces.
The trap
Usage records do not prove customer-controlled provisioning. Regional availability is not self-service evidence. Elasticity and self-service are different cloud characteristics.

Team-linked provisioning logs directly verify customer self-service.

3. Strengthen the customer’s guest operating-system patch: What remediation should the company select?

Medium
A training company runs virtual machines under an IaaS agreement. A control test finds several guest operating systems missing critical patches, while the provider’s report confirms the hypervisor and physical hosts are maintained. The contract assigns guest operating-system administration to the customer. What remediation should the company select?
  1. Request that the provider assume responsibility for customer operating-system patch approval and deployment.
    The stated contract assigns guest operating-system administration to the customer, so provider takeover is not the selected remediation.
  2. Replace the IaaS service with SaaS so the provider manages more infrastructure.
    Changing service models may alter responsibilities, but does not remediate the current failed guest-patching control.
  3. Strengthen the customer’s guest operating-system patch process and verify remediation. ✓
    The customer controls guest operating systems in IaaS, so it must correct patching and verify closure of the failed control.
  4. Require the provider to patch the physical hosts more frequently.
    Provider host maintenance does not remediate missing patches inside customer-controlled guest operating systems.
The trap
Contractual responsibility remains with the customer here. Service replacement avoids rather than corrects the tested failure. Host patching does not fix guest operating-system exposure.

The customer owns guest operating-system patching in this IaaS arrangement and must correct the failed process.

4. Use the detailed report matching the service: Which approach best satisfies the stated constraint?

Medium
A university research consortium may use only evidence covering its purchased analytics service, the relevant assessment period, and customer responsibilities. A vendor offers a general-use report, a point-in-time design report, and a detailed operating-effectiveness report covering the contracted service for twelve months. Which approach best satisfies the stated constraint?
  1. Prefer the point-in-time report because design evidence proves controls operated throughout the year.
    Point-in-time design evidence does not demonstrate operating effectiveness across the required twelve-month period.
  2. Use the detailed report matching the service, period, exceptions, and customer responsibilities. ✓
    A scoped operating-effectiveness report provides evidence aligned with the purchased service, assessment period, exceptions, and responsibilities.
  3. Rely on the vendor’s certification statement without reviewing report boundaries or exceptions.
    Certification or attestation alone cannot demonstrate that evidence matches the consortium’s service and responsibility boundaries.
  4. Accept the general-use report because its broad audience makes scope verification unnecessary.
    General-use presentation does not remove the need to verify service scope, period, exceptions, and customer responsibilities.
The trap
Design at one date cannot prove yearlong operation. Broad distribution does not establish relevant assessment scope. A certification label cannot replace scope examination.

Use evidence whose service, period, exceptions, and customer responsibilities match the contracted scope.

5. The key administrator performs rotation: Its policy states: “The data owner approves which business data may b

Easy
An energy company separates cryptographic administration from application use. Its policy states: “The data owner approves which business data may be encrypted and accessed; the key administrator controls key lifecycle operations; application operators may use approved keys but may not administer them.” Select TWO accountable decision owners for these activities.

Select two. More than one option is correct — every correct one is ticked below.

  1. The storage virtualization administrator decides which business data requires encryption.
    Infrastructure administration does not establish business ownership of data protection decisions under the stated policy.
  2. The key administrator performs rotation, recovery, and other key lifecycle operations. ✓
    The key administrator manages lifecycle operations while remaining separate from application cryptographic usage privileges.
  3. The data owner approves authorized business use of protected data and keys. ✓
    The data owner decides which business data and access purposes are authorized under the stated policy.
  4. The application operator independently grants its service account permission to administer keys.
    Application operators may use approved keys, but the policy expressly withholds key administration authority from them.
  5. The external auditor selects production key versions and approves application access.
    Auditors evaluate evidence and controls; they do not normally operate production key lifecycles or approve business access.
The trap
Platform administration is not data ownership. Usage permission does not include key administration. Assurance reviewers should not operate production cryptography.

The data owner decides authorized protection use, while the key administrator controls lifecycle operations.

6. Establish lineage and integrity checks for training data: Select TWO actions that address the stated responsib

Medium
A cloud migration team deploys an AI-driven security-orchestration system. The system automatically raises incidents when model scores exceed a threshold. The team discovers benign workload drift and cannot show training-data lineage for the current model. Select TWO actions that address the stated responsibility boundary.

Select two. More than one option is correct — every correct one is ticked below.

  1. Publish the model behind an unrestricted inference endpoint for broader validation.
    Unrestricted endpoints can expose sensitive behavior or data and do not repair missing lineage or operational oversight.
  2. Treat observed drift as proof that an attacker poisoned the training set.
    Drift can reflect benign change or attack, so evidence is required before attributing malicious training-data manipulation.
  3. Allow the model to disable controls automatically whenever its confidence score is high.
    High confidence does not establish correctness and could permit harmful automated actions without accountable human oversight.
  4. Establish lineage and integrity checks for training data and model versions. ✓
    Lineage and integrity evidence helps distinguish benign drift, unauthorized changes, and poisoning affecting model behavior.
  5. Require human validation of alerts, calibrated thresholds, and documented rollback authority. ✓
    Human oversight, calibrated thresholds, and rollback reduce unsafe automated response when model behavior or workload conditions change.
The trap
Confidence scores do not eliminate response accountability. Drift alone cannot establish poisoning. Public exposure increases risk without validating provenance.

AI security operations require accountable human response plus trustworthy data and model provenance.

7. Test alternate processing for a 30-minute RTO and 5-minute: Which recovery design best satisfies all stated re

Hard
A logistics operator’s business impact analysis requires order processing to resume within 30 minutes after a regional outage, while no more than 5 minutes of accepted orders may be lost. Security policy prohibits production failover until an authorized incident commander approves the change. Which recovery design best satisfies all stated requirements?
  1. Test alternate processing for a 30-minute RTO and 5-minute RPO; require commander approval. ✓
    This provides tested alternate capability, meets both recovery objectives, and preserves the required approval before production switching.
  2. Restore from daily backups after approval.
    Approval addresses authorization, but daily backups cannot meet the five-minute data-loss tolerance or reliably establish a 30-minute recovery.
  3. Conduct weekly exercises, document recovery measurements, and permit production switching only after incident-commander approval.
    Exercises and approval are useful controls, but this design does not require a five-minute RPO or establish tested alternate processing that meets the 30-minute RTO.
  4. Replicate orders every five minutes and approve failover within 30 minutes, without testing the alternate service.
    Replication and approval address data loss and authorization, but untested alternate processing does not demonstrate that service can resume within 30 minutes.
The trap
Authorization cannot correct an inadequate recovery point. Replication alone does not validate recovery capability. Testing frequency does not substitute for specified recovery capability.

Use tested alternate processing that meets both objectives and requires approval before failover.

8. Record and allocate the temporary environment’s measured: What should management decide?

Medium
A media platform’s policy requires measured service records for chargeback and capacity planning. A development team asks to exclude its temporary cloud environment because it runs for less than one day. The provider can meter compute, storage, and network consumption for that environment, and the policy contains no short-duration exception. What should management decide?
  1. Permit exclusion because temporary environments cannot materially affect accountability.
    Short duration does not eliminate measurable consumption or the policy’s stated chargeback and capacity-planning purpose.
  2. Replace chargeback with a fixed development fee for all temporary environments.
    A fixed fee changes the policy approach instead of evaluating the requested exception against the stated measured-service requirement.
  3. Record and allocate the temporary environment’s measured consumption under the existing policy. ✓
    The environment remains within measured-service accountability because the policy has no duration exception and consumption is measurable.
  4. Ask the provider to estimate usage manually after the environment is deleted.
    Manual estimation weakens the available measured-service evidence and occurs after potentially unrecoverable environment activity.
The trap
Post-deletion estimates reduce measurement reliability. Brief use remains measurable and accountable. Pricing substitution does not address policy compliance.

The temporary environment remains subject to measured-service accountability because no policy exception applies.

9. The company must implement server-side authorization: Which residual limitation remains the company’s responsi

Hard
A digital payments company deploys its application on a managed PaaS service. The provider manages the platform runtime and underlying infrastructure. During review, the application permits a user to retrieve another customer’s invoice by changing an identifier in the request. Which residual limitation remains the company’s responsibility?
  1. The company must implement server-side authorization for each requested invoice object. ✓
    The customer controls application code and must verify authorization for each object and action on the server side.
  2. The provider must harden the physical hosts supporting the managed runtime.
    Physical-host hardening belongs to the provider’s infrastructure responsibility and does not correct application object authorization.
  3. The provider must redesign tenant isolation so application identifiers cannot be manipulated.
    Provider isolation controls do not replace customer responsibility for object-level authorization within application requests.
  4. The provider must patch the platform runtime according to its maintenance process.
    Platform maintenance is provider-managed, while the demonstrated flaw exists in the customer application’s authorization logic.
The trap
Runtime patching does not fix application access control. Infrastructure hardening does not enforce invoice ownership. Platform isolation cannot substitute for application authorization.

The customer must enforce server-side object authorization because PaaS does not transfer application-code responsibilities.

10. The record does not establish validation for the deployed: What conclusion is supported by this record?

Easy
An industrial manufacturer receives a validation record stating: “Module X, version 4.2, configured mode Y, validated on the assessment date.” Its application uses Module X version 4.3 in mode Z. What conclusion is supported by this record?
  1. The application’s entire cryptographic implementation is validated automatically.
    Validation of one module configuration does not establish assurance for the application’s broader cryptographic implementation.
  2. Validation proves the application cannot expose plaintext during processing.
    Module validation does not prove application behavior or eliminate plaintext exposure during permitted cryptographic processing.
  3. The record does not establish validation for the deployed module configuration. ✓
    The deployed version and configuration differ from the specifically validated module version and mode identified in the record.
  4. The application is validated because both module versions belong to the same product family.
    Validation status applies to exact module versions and configurations, not merely related product families.
The trap
Module validation is not application-wide security proof. Product-family similarity cannot extend validation scope. Validation does not guarantee plaintext confidentiality in use.

Cryptographic validation is bounded by the exact module version and configuration assessed.

11. Replace the key with a scoped federated workload identity: What should the security architect do next?

Medium
A legal services firm approved federation for its document-processing workload. The provider supports short-lived workload credentials, the repository owner defined required actions, and logging is enabled. The deployment still uses a long-lived static cloud key. What should the security architect do next?
  1. Store the static key in a managed secrets vault and review access.
    Vaulting improves secret storage, but the workload still depends on a long-lived key rather than federated identity.
  2. Grant administrator access temporarily and review activity afterward.
    Administrative access violates least privilege and defers authorization control until after deployment activity.
  3. Rotate the static key more often.
    Rotation reduces exposure duration but leaves a persistent workload credential in use.
  4. Replace the key with a scoped federated workload identity. ✓
    This uses the available short-lived credential mechanism and limits access to the repository actions already defined by its owner.
The trap
Rotation does not eliminate static credentials. Secure storage is not workload federation. Temporary broad privilege still exceeds the approved boundary.

Replace the static key with a narrowly scoped federated workload identity.

12. Document dataset and artifact lineage: Which control gap most directly explains the inability to assess traini

Medium
A distributed engineering team uses an internal model to prioritize defects. Access controls protect the training repository, and engineers can reproduce the published model version. However, records do not identify source datasets, transformations, annotators, or representativeness checks. Which control gap most directly explains the inability to assess training-data provenance?
  1. Apply differential privacy to every training record and document the selected privacy budget.
    Differential privacy can limit designed privacy loss, but it does not document source, transformation, authorization, or representativeness.
  2. Encrypt model outputs.
    Output encryption protects data but does not establish how training data or artifacts were produced.
  3. Document dataset and artifact lineage, authorization, and representativeness validation. ✓
    These records and checks directly support provenance, authorized use, integrity assessment, and representativeness evaluation.
  4. Apply stronger runtime prompt filtering across the model interface.
    Prompt filtering addresses runtime instructions, not missing records about training sources and transformations.
The trap
Encryption cannot reconstruct lineage. Runtime prompt controls do not establish training provenance. Privacy protection is not lineage evidence.

The gap is missing lineage, authorization, and representativeness evidence.

243 more Cloud Concepts, Architecture and Design questions

The remaining 243 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your CCSP readiness — free

Other CCSP domains

Part of the Certsqill CCSP question bank · Cloud Concepts, Architecture and Design · Every answer, right and wrong, comes with its own explanation.