CCSP Cloud Security Operations: 255 practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

CCSP Cloud Security Operations: 255 practice questions

CCSP 255 questions 12 shown free

12 of the 255 Cloud Security Operations questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for CCSP? Take the free 5-min readiness check →

1. Test and maintain authorized customer notification: Which control addresses the demonstrated failure?

Medium
An industrial manufacturer’s cloud provider detected unauthorized access to production data but notified an obsolete contact. The contract names the manufacturer as controller and provider as processor, requiring customer-directed privacy decisions. Which control addresses the demonstrated failure?
  1. Test and maintain authorized customer notification contacts. ✓
    A tested contact registry directs incident notices to authorized customer personnel responsible for privacy and operational decisions.
  2. Require the provider to notify every affected individual directly.
    Individual notification authority depends on applicable roles and rules; the stated contract assigns customer-directed privacy decisions.
  3. Move production workloads to a separate provider region.
    Regional relocation does not ensure correct contacts or satisfy the contracted customer-notification coordination requirement.
  4. Encrypt all stored production data with customer-managed keys.
    Encryption may reduce exposure, but it does not correct inaccurate incident-notification routing or authorization.
The trap
Protects data, not notification accuracy or routing. Bypasses the customer’s stated notification decision role. Changes location without fixing escalation governance.

Maintain and test authorized notification contacts so the provider reaches the customer’s designated decision makers.

2. Authorized approval: Which evidence best verifies compliance with the requirement?

Hard
A legal services firm permits emergency production changes only through an expedited authorized procedure. During an outage, an engineer changed a firewall rule, but the review record contains only a ticket number. Which evidence best verifies compliance with the requirement?
  1. Authorized approval, impact assessment, testing, and rollback evidence. ✓
    These records demonstrate expedited authorization, evaluated impact, tested change behavior, and recoverability for the emergency modification.
  2. A later audit confirming the firewall rule remained active.
    Post-change state verifies persistence, but not emergency authorization, impact assessment, testing, or rollback planning.
  3. A version-controlled copy of the engineer’s configuration file.
    Version control establishes traceability, but does not replace approval, impact assessment, testing, or rollback evidence.
  4. A manager’s statement that the outage required immediate action.
    A retrospective statement explains urgency, but does not establish the required controlled emergency-change evidence.
The trap
Urgency does not substitute for documented control evidence. Traceability alone cannot prove authorized emergency handling. Shows outcome, not the required authorization evidence.

Verify emergency authorization through approval, impact, testing, and rollback records.

3. Separate HSM key administration from cryptographic use: What remediation addresses the failed control?

Medium
A distributed engineering team failed a control test because one administrator could both operate an HSM and administer its keys. The team uses virtual machines and requires tenant separation. TPM attestation is separately required for host boot. What remediation addresses the failed control?
  1. Use container namespaces as the sole tenant-isolation control.
    Namespaces organize resources but alone do not guarantee hard tenant separation or correct HSM privilege boundaries.
  2. Separate HSM key administration from cryptographic use. ✓
    Distinct privileges reduce concentration of key authority while preserving HSM protection for key material and operations.
  3. Require the HSM administrator to approve every TPM measurement.
    TPM measurements support platform attestation; assigning them to HSM administration does not separate key privileges.
  4. Replace TPM attestation with encrypted virtual-machine disks.
    Disk encryption protects stored data but does not remediate excessive HSM administrative and usage privileges.
The trap
Addresses storage confidentiality, not key-role separation. Combines unrelated assurance responsibilities instead of separating them. Resource organization is not sufficient isolation.

Separate HSM key administration from cryptographic use to remediate the failed privilege-separation test.

4. Request scoped provider exports through authorized: Which approach best fits the constraint?

Hard
A public agency investigates suspected cloud misuse. Policy permits provider-held evidence collection only through authorized contractual channels and forbids collecting other tenants’ data. The provider can export tenant logs, snapshots, and audit records; exports include UTC timestamps and hashes, but snapshots omit memory. Which approach best fits the constraint?
  1. Seize provider disks to obtain complete forensic coverage across the environment.
    Seizing shared disks risks collecting other tenants’ data and exceeds the authorized contractual collection path.
  2. Collect only the snapshot because its hash proves that the evidence is complete.
    A hash supports acquisition integrity; it does not prove completeness, and the snapshot lacks memory.
  3. Delay available exports until the provider can supply memory and a full physical-disk image.
    This risks losing available evidence and seeks artifacts beyond the stated provider capability and tenant-safe boundary.
  4. Request scoped provider exports through authorized channels. ✓
    This respects the collection boundary. The agency should preserve timestamps, hashes, acquisition details, custody, and the snapshot’s memory limitation.
The trap
Violates tenant boundaries and the stated authorization. Confuses integrity with completeness. Pursues theoretical completeness instead of preserving available scoped evidence.

Use authorized, tenant-scoped provider exports and preserve their provenance and limits.

5. The network owner approves bastion ingress and egress: Under this arrangement, which TWO decisions belong to a

Easy
A telecommunications operator requires all privileged administration to enter through a bastion host. The bastion mediates access to virtualized workloads, while continuity planning assigns recovery priorities to service owners. Under this arrangement, which TWO decisions belong to accountable customer owners? Select TWO.

Select two. More than one option is correct — every correct one is ticked below.

  1. The network owner approves bastion ingress and egress rules. ✓
    The network owner governs controlled administrative paths and their filtering rules within the customer environment.
  2. The bastion itself becomes accountable for continuity objectives.
    A bastion enforces an administrative path but cannot own business recovery objectives or service priorities.
  3. The cloud provider approves every customer administrator’s business need.
    Provider infrastructure responsibilities do not transfer the customer’s workload authorization decisions to the provider.
  4. The hypervisor automatically determines each tenant’s recovery priority.
    Recovery priority follows business impact and service-owner decisions, not automatic hypervisor classification.
  5. The service owner authorizes administrators for the workload. ✓
    The service owner remains accountable for workload access decisions despite centralized bastion administration.
The trap
A control component cannot own business continuity outcomes. Confuses provider infrastructure duties with customer access accountability. Technical placement does not establish business recovery priority.

Service owners authorize workload administrators; network owners approve bastion filtering and administrative-path rules.

6. The SIEM correlates evidence: Which statement correctly defines the responsibility boundary?

Medium
A regional hospital group sends identity, endpoint, and cloud logs to a SIEM. It is considering an AI-assisted SOAR workflow that isolates accounts automatically. The workflow has approval thresholds and rollback steps, but recent benign staffing changes altered alert patterns. Which statement correctly defines the responsibility boundary?
  1. SOAR determines whether collected logs are legally sufficient evidence.
    SOAR can coordinate actions, but legal sufficiency requires appropriate governance, context, and accountable review.
  2. The SIEM correlates evidence; SOAR executes approved response workflows. ✓
    SIEM detection and correlation differ from SOAR orchestration, which must retain calibrated thresholds and rollback controls.
  3. AI drift proves an attack and justifies removing approval thresholds.
    Drift may reflect benign change or attack; removing approvals weakens calibrated, reversible response governance.
  4. The SIEM isolates accounts after detecting correlated activity.
    Isolation is a response action generally orchestrated by SOAR or operators, not the SIEM’s correlation function.
The trap
Assigns response execution to the correlation platform. Treats ambiguous drift as conclusive malicious activity. Automation cannot independently establish legal evidentiary sufficiency.

SIEM correlates evidence; SOAR coordinates approved actions with thresholds, human oversight, and rollback.

7. Send an authorized: Which evidence package best resolves the competing requirements?

Hard
An international nonprofit suspects compromise of a cloud-hosted donor application. The provider contract requires customer authorization before provider collection. Privacy counsel must assess controller obligations and transfer implications, while operations wants immediate escalation. Which evidence package best resolves the competing requirements?
  1. Send an authorized, scoped package with timestamps and preservation instructions. ✓
    This enables prompt provider action while documenting authority, boundaries, timing, and preservation needs.
  2. Delete donor logs immediately and rely on a provider certification for privacy compliance.
    Deletion may destroy evidence, and certification does not resolve incident-specific controller or transfer obligations.
  3. Request unrestricted provider access to all regional tenants and their records.
    Unrestricted access exceeds the stated authorization and risks other tenants and jurisdictional boundaries.
  4. Immediately notify the provider with only the suspected application name.
    This is too vague to guide collection, preservation, authorization, or privacy coordination.
The trap
Prioritizes speed while omitting essential scope and governance details. Conflicts with authorization, tenant separation, and privacy scope. Combines evidence destruction with an unsupported legal conclusion.

Use an authorized, scoped escalation with timestamps and preservation instructions.

8. Document the exception: What action evaluates this exception against policy?

Easy
A training company permits emergency incident changes through an approved expedited path, followed by documentation and problem management. An instructor-facing service was restored by bypassing normal review, but the change has no approval record. What action evaluates this exception against policy?
  1. Seek retrospective approval and close the incident without problem management.
    Retrospective review may address authorization, but omitting problem management fails the stated policy path.
  2. Roll back the change immediately and defer exception review indefinitely.
    An unconditional rollback may harm service, and indefinite deferral leaves the policy exception unevaluated.
  3. Document the change, mark it emergency, and close the record after service restoration.
    Documentation alone does not provide the required authorized review or problem-management follow-up.
  4. Document the exception, obtain authorized review, and open problem management. ✓
    This records the deviation, restores accountability through authorized review, and addresses the underlying cause separately from service restoration.
The trap
Treats restoration and documentation as sufficient governance. Addresses approval while ignoring recurring-cause management. Substitutes uncontrolled reversal for assessed recovery and governance.

Document the exception, obtain authorized review, and open problem management.

9. The baseline does not secure the host kernel or runtime: Which residual limitation remains?

Easy
A university research consortium provisions workloads only from signed, version-controlled immutable images. A review confirms image provenance and patching, but containers share the host kernel and runtime network policies are not enforced. Which residual limitation remains?
  1. Image signing guarantees the application contains no exploitable dependency.
    Signing authenticates provenance or integrity, but does not prove dependencies are vulnerability-free or secure at runtime.
  2. Version control prevents all unauthorized runtime configuration changes.
    Version control traces intended image changes but does not automatically prevent runtime drift or privileged actions.
  3. Container isolation makes host hardening unnecessary.
    Containers share the host kernel, so host and runtime hardening remain necessary despite image controls.
  4. The baseline does not secure the host kernel or runtime isolation. ✓
    Immutable images improve provenance and drift control, but shared kernels and unenforced policies leave host and runtime exposure.
The trap
Misunderstands shared-kernel exposure. Authenticity does not establish absence of vulnerabilities. Configuration history is not runtime enforcement.

Immutable images do not secure the shared host kernel or enforce runtime network isolation.

10. Isolate, collect feasible volatile evidence, and document: The host supports a noncritical service, and logs a

Medium
An energy company’s incident record states: “At 14:02 UTC, suspicious process activity was observed. Operations could isolate the host safely by 14:06; memory collection would require twelve minutes. The host supports a noncritical service, and logs are already preserved.” What evidence decision is most appropriate?
  1. Isolate the host and rely on preserved logs instead of collecting memory.
    Preserved logs do not make potentially relevant volatile evidence unnecessary when collection remains feasible after isolation.
  2. Power off the host immediately to maximize evidence integrity and eliminate operational uncertainty.
    Powering off destroys volatile memory and is unnecessary when safe isolation can contain the noncritical service.
  3. Isolate, collect feasible volatile evidence, and document timing. ✓
    Safe isolation limits ongoing impact, after which feasible memory collection can preserve additional evidence while timing and tradeoffs are recorded.
  4. Collect memory before isolation because volatile evidence must always take priority over containment.
    The record supports safe prompt containment before the delayed collection; evidence priority depends on safety and impact.
The trap
Confuses shutdown with preservation and ignores available containment. Applies an absolute priority rule despite the scenario’s facts. Treats one evidence source as complete.

Isolate safely, then collect feasible volatile evidence and document timing.

11. Perform connection-time chain and hostname validation: Before transmitting credentials, what action best addre

Medium
A cloud migration team has confirmed that a service certificate chains to an approved trust anchor, matches the intended hostname, and is unexpired. Before transmitting credentials, what action best addresses TLS peer validation?
  1. Perform connection-time chain and hostname validation. ✓
    Validating the live chain and hostname confirms the connection is associated with the intended trusted service before credentials are sent.
  2. Use a VPN instead of validating the TLS peer.
    A VPN may protect a network path but does not replace application-layer TLS peer authentication.
  3. Inspect only the certificate’s key length before transmitting credentials.
    Key length indicates cryptographic strength but does not establish that the peer is the intended service.
  4. Copy the certificate into the application image and trust that copy.
    Bundling a certificate does not validate the live peer or ensure the presented certificate matches expectations.
The trap
Substitutes tunnel protection for endpoint authentication. Treats certificate distribution as live peer authentication. Confuses cryptographic strength with peer identity validation.

Validate the live certificate chain and hostname before sending credentials.

12. Retune thresholds using validated benign and malicious: What is the most appropriate next control action?

Medium
An online retailer’s AI-driven response workflow flags legitimate bulk orders as account compromise. Reviewers find that recent seasonal purchasing patterns changed, while confirmed attacks still appear in the data. The retailer wants fewer false positives without hiding genuine attacks. What is the most appropriate next control action?
  1. Disable automated response for every alert.
    Disabling all automation removes useful response capability and fails to address evidence-based threshold calibration.
  2. Retune thresholds using validated benign and malicious examples. ✓
    Validated examples help calibrate thresholds against changed behavior while preserving sensitivity to confirmed attacks.
  3. Replace the model without reviewing its training lineage.
    Model replacement may repeat the issue when drift, provenance, and representative validation remain unexplored.
  4. Expose the retailer’s real dataset to a public inference endpoint.
    Public inference exposure risks sensitive data and does not establish representative, authorized model validation.
The trap
Eliminates detection rather than correcting its calibration. Introduces unnecessary disclosure and weak validation evidence. Changes technology without diagnosing the observed control gap.

Use validated examples to recalibrate thresholds while preserving detection of confirmed malicious behavior.

243 more Cloud Security Operations questions

The remaining 243 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your CCSP readiness — free

Other CCSP domains

Part of the Certsqill CCSP question bank · Cloud Security Operations · Every answer, right and wrong, comes with its own explanation.