Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Cloud Security Professional

Domain 1Objective 3

Understand Security Concepts Relevant to Cloud Computing CCSP Practice Questions (Page 6)

Part of the Cloud Concepts, Architecture and Design domain, which accounts for 17% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~12–20 in this domain), expect 2–3 from this objective — we provide 56 practice questions to prepare you well beyond it. (estimate)

56questions here
12free pages
20concepts
17%of the exam

Questions 26–30

  1. 26expert · medium

    A company is designing a threat model for a new cloud-based application that will handle customer payment data. The application uses a public API, a database, and a third-party payment processor. The security team has identified the following assets: customer PII, payment card data, and the API's authentication tokens. Which threat modeling approach would be most effective in prioritizing the risks to these assets?

    Select an answer first
  2. 27application · medium

    A company is decommissioning a storage array that contains encrypted customer data. The data was encrypted using a key that is stored only in the array's local key manager. The array will be returned to the leasing company. The security team must ensure the data is unrecoverable, but the array's disks are not physically destroyed. Which method should be used?

    Select an answer first
  3. 28foundation · easy

    What is a security baseline in cloud configuration management?

    Select an answer first
  4. 29foundation · easy

    Why is regular patching important for cloud workloads?

    Select an answer first
  5. 30application · medium

    A company is moving a batch processing workload to a serverless function platform. The workload processes sensitive data and runs for a few minutes at a time. The security team is concerned about the ephemeral nature of the functions and wants to ensure that sensitive data is not left behind after execution. Which control should be implemented?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.