CCSP Cloud Concepts, Architecture and Design: 255 practice questions
12 of the 255 Cloud Concepts, Architecture and Design questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CCSP? Take the free 5-min readiness check →
1. Conduct a business impact analysis before finalizing: Which control addresses the demonstrated failure?
- Deploy active processing in multiple regions with automated traffic redirection and synchronized storage.This may improve availability, but it presupposes recovery requirements instead of addressing the absent business impact analysis.
- Conduct a business impact analysis before finalizing recovery capabilities. ✓A business impact analysis identifies critical processes, dependencies, and time-dependent impacts before recovery priorities and capabilities are selected.
- Run a disaster-recovery failover exercise against the proposed second-region architecture.A failover exercise tests an implemented design, but cannot establish whether recovery priorities and dependencies were correctly identified.
- Increase backup frequency to meet the stated fifteen-minute data-loss tolerance.More frequent backups address potential recovery-point performance, not the missing business impact analysis and dependency prioritization.
A business impact analysis must identify priorities and dependencies before recovery architecture is finalized.
2. Team-linked audit logs of portal/API provisioning: Which evidence best verifies on-demand self-service?
- A provider statement describing availability in several countries.Geographic availability concerns broad network access or deployment reach, not self-service provisioning.
- Team-linked audit logs of portal/API provisioning. ✓These logs directly show teams independently provisioning resources without provider personnel.
- Monthly project invoices for compute, storage, and network use.Invoices demonstrate measured service, not who provisioned the resources or whether self-service was available.
- A capacity report showing resources can expand quickly during campaigns.Rapid elasticity concerns scaling capacity, not independent customer provisioning through authorized interfaces.
Team-linked provisioning logs directly verify customer self-service.
3. Strengthen the customer’s guest operating-system patch: What remediation should the company select?
- Request that the provider assume responsibility for customer operating-system patch approval and deployment.The stated contract assigns guest operating-system administration to the customer, so provider takeover is not the selected remediation.
- Replace the IaaS service with SaaS so the provider manages more infrastructure.Changing service models may alter responsibilities, but does not remediate the current failed guest-patching control.
- Strengthen the customer’s guest operating-system patch process and verify remediation. ✓The customer controls guest operating systems in IaaS, so it must correct patching and verify closure of the failed control.
- Require the provider to patch the physical hosts more frequently.Provider host maintenance does not remediate missing patches inside customer-controlled guest operating systems.
The customer owns guest operating-system patching in this IaaS arrangement and must correct the failed process.
4. Use the detailed report matching the service: Which approach best satisfies the stated constraint?
- Prefer the point-in-time report because design evidence proves controls operated throughout the year.Point-in-time design evidence does not demonstrate operating effectiveness across the required twelve-month period.
- Use the detailed report matching the service, period, exceptions, and customer responsibilities. ✓A scoped operating-effectiveness report provides evidence aligned with the purchased service, assessment period, exceptions, and responsibilities.
- Rely on the vendor’s certification statement without reviewing report boundaries or exceptions.Certification or attestation alone cannot demonstrate that evidence matches the consortium’s service and responsibility boundaries.
- Accept the general-use report because its broad audience makes scope verification unnecessary.General-use presentation does not remove the need to verify service scope, period, exceptions, and customer responsibilities.
Use evidence whose service, period, exceptions, and customer responsibilities match the contracted scope.
5. The key administrator performs rotation: Its policy states: “The data owner approves which business data may b
Select two. More than one option is correct — every correct one is ticked below.
- The storage virtualization administrator decides which business data requires encryption.Infrastructure administration does not establish business ownership of data protection decisions under the stated policy.
- The key administrator performs rotation, recovery, and other key lifecycle operations. ✓The key administrator manages lifecycle operations while remaining separate from application cryptographic usage privileges.
- The data owner approves authorized business use of protected data and keys. ✓The data owner decides which business data and access purposes are authorized under the stated policy.
- The application operator independently grants its service account permission to administer keys.Application operators may use approved keys, but the policy expressly withholds key administration authority from them.
- The external auditor selects production key versions and approves application access.Auditors evaluate evidence and controls; they do not normally operate production key lifecycles or approve business access.
The data owner decides authorized protection use, while the key administrator controls lifecycle operations.
6. Establish lineage and integrity checks for training data: Select TWO actions that address the stated responsib
Select two. More than one option is correct — every correct one is ticked below.
- Publish the model behind an unrestricted inference endpoint for broader validation.Unrestricted endpoints can expose sensitive behavior or data and do not repair missing lineage or operational oversight.
- Treat observed drift as proof that an attacker poisoned the training set.Drift can reflect benign change or attack, so evidence is required before attributing malicious training-data manipulation.
- Allow the model to disable controls automatically whenever its confidence score is high.High confidence does not establish correctness and could permit harmful automated actions without accountable human oversight.
- Establish lineage and integrity checks for training data and model versions. ✓Lineage and integrity evidence helps distinguish benign drift, unauthorized changes, and poisoning affecting model behavior.
- Require human validation of alerts, calibrated thresholds, and documented rollback authority. ✓Human oversight, calibrated thresholds, and rollback reduce unsafe automated response when model behavior or workload conditions change.
AI security operations require accountable human response plus trustworthy data and model provenance.
7. Test alternate processing for a 30-minute RTO and 5-minute: Which recovery design best satisfies all stated re
- Test alternate processing for a 30-minute RTO and 5-minute RPO; require commander approval. ✓This provides tested alternate capability, meets both recovery objectives, and preserves the required approval before production switching.
- Restore from daily backups after approval.Approval addresses authorization, but daily backups cannot meet the five-minute data-loss tolerance or reliably establish a 30-minute recovery.
- Conduct weekly exercises, document recovery measurements, and permit production switching only after incident-commander approval.Exercises and approval are useful controls, but this design does not require a five-minute RPO or establish tested alternate processing that meets the 30-minute RTO.
- Replicate orders every five minutes and approve failover within 30 minutes, without testing the alternate service.Replication and approval address data loss and authorization, but untested alternate processing does not demonstrate that service can resume within 30 minutes.
Use tested alternate processing that meets both objectives and requires approval before failover.
8. Record and allocate the temporary environment’s measured: What should management decide?
- Permit exclusion because temporary environments cannot materially affect accountability.Short duration does not eliminate measurable consumption or the policy’s stated chargeback and capacity-planning purpose.
- Replace chargeback with a fixed development fee for all temporary environments.A fixed fee changes the policy approach instead of evaluating the requested exception against the stated measured-service requirement.
- Record and allocate the temporary environment’s measured consumption under the existing policy. ✓The environment remains within measured-service accountability because the policy has no duration exception and consumption is measurable.
- Ask the provider to estimate usage manually after the environment is deleted.Manual estimation weakens the available measured-service evidence and occurs after potentially unrecoverable environment activity.
The temporary environment remains subject to measured-service accountability because no policy exception applies.
9. The company must implement server-side authorization: Which residual limitation remains the company’s responsi
- The company must implement server-side authorization for each requested invoice object. ✓The customer controls application code and must verify authorization for each object and action on the server side.
- The provider must harden the physical hosts supporting the managed runtime.Physical-host hardening belongs to the provider’s infrastructure responsibility and does not correct application object authorization.
- The provider must redesign tenant isolation so application identifiers cannot be manipulated.Provider isolation controls do not replace customer responsibility for object-level authorization within application requests.
- The provider must patch the platform runtime according to its maintenance process.Platform maintenance is provider-managed, while the demonstrated flaw exists in the customer application’s authorization logic.
The customer must enforce server-side object authorization because PaaS does not transfer application-code responsibilities.
10. The record does not establish validation for the deployed: What conclusion is supported by this record?
- The application’s entire cryptographic implementation is validated automatically.Validation of one module configuration does not establish assurance for the application’s broader cryptographic implementation.
- Validation proves the application cannot expose plaintext during processing.Module validation does not prove application behavior or eliminate plaintext exposure during permitted cryptographic processing.
- The record does not establish validation for the deployed module configuration. ✓The deployed version and configuration differ from the specifically validated module version and mode identified in the record.
- The application is validated because both module versions belong to the same product family.Validation status applies to exact module versions and configurations, not merely related product families.
Cryptographic validation is bounded by the exact module version and configuration assessed.
11. Replace the key with a scoped federated workload identity: What should the security architect do next?
- Store the static key in a managed secrets vault and review access.Vaulting improves secret storage, but the workload still depends on a long-lived key rather than federated identity.
- Grant administrator access temporarily and review activity afterward.Administrative access violates least privilege and defers authorization control until after deployment activity.
- Rotate the static key more often.Rotation reduces exposure duration but leaves a persistent workload credential in use.
- Replace the key with a scoped federated workload identity. ✓This uses the available short-lived credential mechanism and limits access to the repository actions already defined by its owner.
Replace the static key with a narrowly scoped federated workload identity.
12. Document dataset and artifact lineage: Which control gap most directly explains the inability to assess traini
- Apply differential privacy to every training record and document the selected privacy budget.Differential privacy can limit designed privacy loss, but it does not document source, transformation, authorization, or representativeness.
- Encrypt model outputs.Output encryption protects data but does not establish how training data or artifacts were produced.
- Document dataset and artifact lineage, authorization, and representativeness validation. ✓These records and checks directly support provenance, authorized use, integrity assessment, and representativeness evaluation.
- Apply stronger runtime prompt filtering across the model interface.Prompt filtering addresses runtime instructions, not missing records about training sources and transformations.
The gap is missing lineage, authorization, and representativeness evidence.
243 more Cloud Concepts, Architecture and Design questions
The remaining 243 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CCSP readiness — freeOther CCSP domains
- Cloud Data Security — 300 questions →
- Cloud Platform and Infrastructure Security — 255 questions →
- Cloud Security Operations — 255 questions →
- Cloud Application Security — 240 questions →
- Legal, Risk and Compliance — 195 questions →
- All 1500 CCSP questions →
- CCSP certification: requirements, cost and exam format →