CCSP Cloud Security Operations: 255 practice questions
12 of the 255 Cloud Security Operations questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CCSP? Take the free 5-min readiness check →
1. Test and maintain authorized customer notification: Which control addresses the demonstrated failure?
- Test and maintain authorized customer notification contacts. ✓A tested contact registry directs incident notices to authorized customer personnel responsible for privacy and operational decisions.
- Require the provider to notify every affected individual directly.Individual notification authority depends on applicable roles and rules; the stated contract assigns customer-directed privacy decisions.
- Move production workloads to a separate provider region.Regional relocation does not ensure correct contacts or satisfy the contracted customer-notification coordination requirement.
- Encrypt all stored production data with customer-managed keys.Encryption may reduce exposure, but it does not correct inaccurate incident-notification routing or authorization.
Maintain and test authorized notification contacts so the provider reaches the customer’s designated decision makers.
2. Authorized approval: Which evidence best verifies compliance with the requirement?
- Authorized approval, impact assessment, testing, and rollback evidence. ✓These records demonstrate expedited authorization, evaluated impact, tested change behavior, and recoverability for the emergency modification.
- A later audit confirming the firewall rule remained active.Post-change state verifies persistence, but not emergency authorization, impact assessment, testing, or rollback planning.
- A version-controlled copy of the engineer’s configuration file.Version control establishes traceability, but does not replace approval, impact assessment, testing, or rollback evidence.
- A manager’s statement that the outage required immediate action.A retrospective statement explains urgency, but does not establish the required controlled emergency-change evidence.
Verify emergency authorization through approval, impact, testing, and rollback records.
3. Separate HSM key administration from cryptographic use: What remediation addresses the failed control?
- Use container namespaces as the sole tenant-isolation control.Namespaces organize resources but alone do not guarantee hard tenant separation or correct HSM privilege boundaries.
- Separate HSM key administration from cryptographic use. ✓Distinct privileges reduce concentration of key authority while preserving HSM protection for key material and operations.
- Require the HSM administrator to approve every TPM measurement.TPM measurements support platform attestation; assigning them to HSM administration does not separate key privileges.
- Replace TPM attestation with encrypted virtual-machine disks.Disk encryption protects stored data but does not remediate excessive HSM administrative and usage privileges.
Separate HSM key administration from cryptographic use to remediate the failed privilege-separation test.
4. Request scoped provider exports through authorized: Which approach best fits the constraint?
- Seize provider disks to obtain complete forensic coverage across the environment.Seizing shared disks risks collecting other tenants’ data and exceeds the authorized contractual collection path.
- Collect only the snapshot because its hash proves that the evidence is complete.A hash supports acquisition integrity; it does not prove completeness, and the snapshot lacks memory.
- Delay available exports until the provider can supply memory and a full physical-disk image.This risks losing available evidence and seeks artifacts beyond the stated provider capability and tenant-safe boundary.
- Request scoped provider exports through authorized channels. ✓This respects the collection boundary. The agency should preserve timestamps, hashes, acquisition details, custody, and the snapshot’s memory limitation.
Use authorized, tenant-scoped provider exports and preserve their provenance and limits.
5. The network owner approves bastion ingress and egress: Under this arrangement, which TWO decisions belong to a
Select two. More than one option is correct — every correct one is ticked below.
- The network owner approves bastion ingress and egress rules. ✓The network owner governs controlled administrative paths and their filtering rules within the customer environment.
- The bastion itself becomes accountable for continuity objectives.A bastion enforces an administrative path but cannot own business recovery objectives or service priorities.
- The cloud provider approves every customer administrator’s business need.Provider infrastructure responsibilities do not transfer the customer’s workload authorization decisions to the provider.
- The hypervisor automatically determines each tenant’s recovery priority.Recovery priority follows business impact and service-owner decisions, not automatic hypervisor classification.
- The service owner authorizes administrators for the workload. ✓The service owner remains accountable for workload access decisions despite centralized bastion administration.
Service owners authorize workload administrators; network owners approve bastion filtering and administrative-path rules.
6. The SIEM correlates evidence: Which statement correctly defines the responsibility boundary?
- SOAR determines whether collected logs are legally sufficient evidence.SOAR can coordinate actions, but legal sufficiency requires appropriate governance, context, and accountable review.
- The SIEM correlates evidence; SOAR executes approved response workflows. ✓SIEM detection and correlation differ from SOAR orchestration, which must retain calibrated thresholds and rollback controls.
- AI drift proves an attack and justifies removing approval thresholds.Drift may reflect benign change or attack; removing approvals weakens calibrated, reversible response governance.
- The SIEM isolates accounts after detecting correlated activity.Isolation is a response action generally orchestrated by SOAR or operators, not the SIEM’s correlation function.
SIEM correlates evidence; SOAR coordinates approved actions with thresholds, human oversight, and rollback.
7. Send an authorized: Which evidence package best resolves the competing requirements?
- Send an authorized, scoped package with timestamps and preservation instructions. ✓This enables prompt provider action while documenting authority, boundaries, timing, and preservation needs.
- Delete donor logs immediately and rely on a provider certification for privacy compliance.Deletion may destroy evidence, and certification does not resolve incident-specific controller or transfer obligations.
- Request unrestricted provider access to all regional tenants and their records.Unrestricted access exceeds the stated authorization and risks other tenants and jurisdictional boundaries.
- Immediately notify the provider with only the suspected application name.This is too vague to guide collection, preservation, authorization, or privacy coordination.
Use an authorized, scoped escalation with timestamps and preservation instructions.
8. Document the exception: What action evaluates this exception against policy?
- Seek retrospective approval and close the incident without problem management.Retrospective review may address authorization, but omitting problem management fails the stated policy path.
- Roll back the change immediately and defer exception review indefinitely.An unconditional rollback may harm service, and indefinite deferral leaves the policy exception unevaluated.
- Document the change, mark it emergency, and close the record after service restoration.Documentation alone does not provide the required authorized review or problem-management follow-up.
- Document the exception, obtain authorized review, and open problem management. ✓This records the deviation, restores accountability through authorized review, and addresses the underlying cause separately from service restoration.
Document the exception, obtain authorized review, and open problem management.
9. The baseline does not secure the host kernel or runtime: Which residual limitation remains?
- Image signing guarantees the application contains no exploitable dependency.Signing authenticates provenance or integrity, but does not prove dependencies are vulnerability-free or secure at runtime.
- Version control prevents all unauthorized runtime configuration changes.Version control traces intended image changes but does not automatically prevent runtime drift or privileged actions.
- Container isolation makes host hardening unnecessary.Containers share the host kernel, so host and runtime hardening remain necessary despite image controls.
- The baseline does not secure the host kernel or runtime isolation. ✓Immutable images improve provenance and drift control, but shared kernels and unenforced policies leave host and runtime exposure.
Immutable images do not secure the shared host kernel or enforce runtime network isolation.
10. Isolate, collect feasible volatile evidence, and document: The host supports a noncritical service, and logs a
- Isolate the host and rely on preserved logs instead of collecting memory.Preserved logs do not make potentially relevant volatile evidence unnecessary when collection remains feasible after isolation.
- Power off the host immediately to maximize evidence integrity and eliminate operational uncertainty.Powering off destroys volatile memory and is unnecessary when safe isolation can contain the noncritical service.
- Isolate, collect feasible volatile evidence, and document timing. ✓Safe isolation limits ongoing impact, after which feasible memory collection can preserve additional evidence while timing and tradeoffs are recorded.
- Collect memory before isolation because volatile evidence must always take priority over containment.The record supports safe prompt containment before the delayed collection; evidence priority depends on safety and impact.
Isolate safely, then collect feasible volatile evidence and document timing.
11. Perform connection-time chain and hostname validation: Before transmitting credentials, what action best addre
- Perform connection-time chain and hostname validation. ✓Validating the live chain and hostname confirms the connection is associated with the intended trusted service before credentials are sent.
- Use a VPN instead of validating the TLS peer.A VPN may protect a network path but does not replace application-layer TLS peer authentication.
- Inspect only the certificate’s key length before transmitting credentials.Key length indicates cryptographic strength but does not establish that the peer is the intended service.
- Copy the certificate into the application image and trust that copy.Bundling a certificate does not validate the live peer or ensure the presented certificate matches expectations.
Validate the live certificate chain and hostname before sending credentials.
12. Retune thresholds using validated benign and malicious: What is the most appropriate next control action?
- Disable automated response for every alert.Disabling all automation removes useful response capability and fails to address evidence-based threshold calibration.
- Retune thresholds using validated benign and malicious examples. ✓Validated examples help calibrate thresholds against changed behavior while preserving sensitivity to confirmed attacks.
- Replace the model without reviewing its training lineage.Model replacement may repeat the issue when drift, provenance, and representative validation remain unexplored.
- Expose the retailer’s real dataset to a public inference endpoint.Public inference exposure risks sensitive data and does not establish representative, authorized model validation.
Use validated examples to recalibrate thresholds while preserving detection of confirmed malicious behavior.
243 more Cloud Security Operations questions
The remaining 243 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CCSP readiness — freeOther CCSP domains
- Cloud Data Security — 300 questions →
- Cloud Concepts, Architecture and Design — 255 questions →
- Cloud Platform and Infrastructure Security — 255 questions →
- Cloud Application Security — 240 questions →
- Legal, Risk and Compliance — 195 questions →
- All 1500 CCSP questions →
- CCSP certification: requirements, cost and exam format →