
Certified Cloud Security Professional
Domain 4Objective 1
Advocate Training and Awareness for Application Security CCSP Practice Questions (Page 5)
Part of the Cloud Application Security domain, which accounts for 16% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 2–3 from this objective — we provide 27 practice questions to prepare you well beyond it. (estimate)
27questions here
6free pages
8concepts
16%of the exam
Questions 21–25
- 21
A company is developing a cloud-based API that will handle financial transactions. They want to use OWASP ASVS to verify the security of the API. Given the sensitivity of the data, they need a high level of assurance. Which ASVS verification level should they target?
Select an answer first - 22
Which security framework would be most useful for identifying the most dangerous software errors that could lead to vulnerabilities in a cloud application's source code?
Select an answer first - 23
Which OWASP Top 10 risk for Large Language Model (LLM) applications involves an attacker crafting inputs that cause the model to produce unintended or malicious outputs?
Select an answer first - 24
A company is developing a cloud application that will be publicly accessible. They want to use OWASP ASVS to guide their security testing. They need to ensure that the application meets a baseline level of security that is appropriate for a public-facing application. Which ASVS verification level should they target?
Select an answer first - 25
A cloud application's API does not enforce rate limiting, allowing an attacker to flood the API with requests and cause a denial of service. Which OWASP Top 10 risk is most directly related to this issue?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.