Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Cloud Security Professional

Domain 1Objective 4

Understand Design Principles of Secure Cloud Computing CCSP Practice Questions (Page 4)

Part of the Cloud Concepts, Architecture and Design domain, which accounts for 17% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 2–3 from this objective — we provide 33 practice questions to prepare you well beyond it. (estimate)

33questions here
7free pages
10concepts
17%of the exam

Questions 16–20

  1. 16foundation · easy

    In a BIA, how is the return on investment (ROI) for a security control typically calculated?

    Select an answer first
  2. 17application · medium

    A large enterprise is adopting cloud services across multiple business units. The CISO wants to ensure that cloud security controls are aligned with the organization's business goals and compliance requirements. The organization uses the CSA Enterprise Architecture reference model. Which activity best demonstrates the application of this model?

    Select an answer first
  3. 18expert · hard

    A financial services firm runs a trading application in a single cloud region. A BIA determined that the maximum tolerable downtime is 15 minutes and the maximum tolerable data loss is 5 minutes. The application is stateful and requires synchronous writes to a database. The firm is evaluating two recovery designs: (1) active-passive with a warm standby in a second region and asynchronous replication, or (2) active-active with synchronous replication across two regions. Which design should the firm choose, and why?

    Select an answer first
  4. 19application · medium

    A company uses a SaaS-based file-sharing service to collaborate with external partners. The company's security policy requires that sensitive documents be protected during the share stage of the data lifecycle. The documents contain personally identifiable information (PII). Which control is most appropriate for the share stage?

    Select an answer first
  5. 20foundation · easy

    Which security control is most critical during the 'destroy' stage of the cloud data lifecycle?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.