
Certified Cloud Security Professional
Domain 1Objective 5
Evaluate Cloud Service Providers (CSP) CCSP Practice Questions (Page 5)
Part of the Cloud Concepts, Architecture and Design domain, which accounts for 17% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 2–3 from this objective — we provide 34 practice questions to prepare you well beyond it. (estimate)
34questions here
7free pages
8concepts
17%of the exam
Questions 21–25
- 21
A defense contractor is evaluating a cloud-based virtual machine monitor (hypervisor) for a classified workload. The contractor requires a product certification that provides assurance that the hypervisor's security functions are correctly implemented and that the product has been evaluated against a specific Protection Profile. The contractor also needs to compare the level of assurance between two products. Which framework and concept should the contractor use?
Select an answer first - 22
Which method is used to verify a cloud service provider's compliance with security standards?
Select an answer first - 23
A cloud provider is designing a new key management service (KMS) for a government customer. The customer requires that the cryptographic module protecting the master keys be validated at FIPS 140-2 Level 3 or higher. The provider is considering two modules: Module A is validated at Level 3, and Module B is validated at Level 2. The provider also has a Common Criteria EAL4 certificate for the KMS software. Which module should the provider use to meet the customer's requirement?
Select an answer first - 24
A company is evaluating a cloud provider that has a SOC 2 Type II report with a qualified opinion. The qualification is due to a control deficiency in the area of access management. The company's application will handle sensitive customer data, and the company requires strong access controls. What should the company do?
Select an answer first - 25
A cloud provider has obtained a FedRAMP authorization at the Moderate impact level. A prospective customer, a federal agency, is considering using the provider for a system that will process data at the High impact level. What should the agency do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.