CCSKV5 Sample Questions & Answers
Twelve areas of roughly equal weight span identity and access management, governance built on cloud architecture, compliance audits and risk management, network, workload and data security, security monitoring, incident resilience, and emerging AI technologies.
Launch the full CCSKV5 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Infrastructure & Networking · Cloud Network Fundamentals
A cloud architect is designing a virtual network for a multi-tier web application. The design requires a public-facing subnet for web servers and a private subnet for database servers. The database servers must be able to initiate connections to the internet to download security patches, but they must not be directly reachable from the internet. Which combination of cloud networking components achieves this goal securely?
Show answer & explanation
Correct answer: B
This is the standard and most secure architecture for this requirement. A NAT (Network Address Translation) Gateway resides in a public subnet and has an elastic IP. Resources in a private subnet can be routed through the NAT Gateway to access the internet. This allows for outbound connections (e.g., for patches) while preventing any inbound connections from being initiated from the internet, as the private resources have no public IP address.
- Question 2Intermediate
Cloud Governance · Effective Cloud Governance
A government agency is setting up its cloud governance framework. They need to ensure that all newly created cloud storage buckets automatically block public access and have versioning enabled to comply with data retention policies. What is the most effective and scalable way to enforce these rules across the entire organization?
Show answer & explanation
Correct answer: B
Using native cloud governance tools like AWS Service Control Policies (SCPs) or Azure Policy allows the agency to define and enforce rules centrally. These policies can prevent the creation of non-compliant resources (e.g., deny creating a public bucket) or automatically remediate them. This approach is highly scalable, automated, and provides preventative control, which is far more effective than manual audits or post-creation scripts.
- Question 3Intermediate
Security Monitoring · Detection & Security Analytics
A security analyst is reviewing telemetry from a cloud environment and observes a large volume of DNS queries for known malicious domains originating from multiple virtual machines. The analyst also notes an increase in outbound network traffic to unusual IP addresses. These events, when correlated, strongly suggest a malware infection. This process of combining different telemetry sources to identify a potential threat is a core function of what type of security tool?
Show answer & explanation
Correct answer: C
A SIEM is designed specifically for this purpose. It aggregates log data and telemetry from various sources (like DNS logs, VPC flow logs, OS logs), correlates events based on predefined rules or machine learning, and generates alerts for security incidents. The scenario described—correlating DNS queries with network traffic patterns to detect malware—is a classic SIEM use case.
- Question 4Intermediate
Risk, Audit, & Compliance · Governance, Risk, & Compliance Tools & Technologies
A company is preparing for its annual SOC 2 audit. The auditors have requested evidence that the company's cloud environment adheres to its stated security policies, particularly regarding data encryption and access control. Which type of tool would be most effective for continuously monitoring the cloud environment's configuration and providing evidence of compliance?
Show answer & explanation
Correct answer: B
CSPM tools are specifically designed to automate the assessment of cloud environments against compliance frameworks (like SOC 2, PCI DSS, etc.) and security best practices. They continuously scan cloud configurations, identify misconfigurations (e.g., unencrypted storage, overly permissive IAM roles), and provide detailed reports that can be used as evidence for auditors. This directly addresses the need for compliance evidence.
- Question 5Beginner
Organization Management · Organization Hierarchy Models
A new startup is building its entire infrastructure on a public cloud provider. To manage costs and administrative overhead, they want to create a single, large account to house all company resources, from marketing websites to sensitive financial data processing. Which of the following is the primary security disadvantage of this organizational hierarchy model?
Show answer & explanation
Correct answer: B
The primary security disadvantage of a single-account model is the lack of isolation. If an attacker compromises credentials or exploits a vulnerability in a low-risk asset (like the marketing website), they could potentially move laterally to access and compromise high-risk assets (like the financial data). This is known as a large 'blast radius'. A multi-account strategy, where different workloads are segregated into separate accounts, contains the impact of a breach to a single account.
- Question 6Intermediate
Incident Response & Resilience · Detection & Analysis
Following a major security incident, a cloud forensics team needs to analyze the actions performed by a compromised IAM user account in the hours leading up to the incident detection. The company needs a definitive, immutable record of all API calls made by the user, including the source IP address, time, and specific actions taken. Which cloud service provides this essential forensic data?
Show answer & explanation
Correct answer: B
Services like AWS CloudTrail, Azure Activity Log, or Google Cloud Audit Logs are specifically designed to record every API call made against an account's resources. This creates an audit trail that answers who, what, when, and from where for all actions. For incident response and forensics, these logs are the primary source of truth for reconstructing an attacker's activities.
- Question 7Beginner
Cloud Computing Concepts & Architectures · Introduction to Cloud Computing
The NIST definition of cloud computing outlines five essential characteristics. Which characteristic refers to the ability of a consumer to unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider?
Show answer & explanation
Correct answer: D
On-demand self-service is the essential characteristic that allows users to provision resources through a web portal or API without needing to file a ticket or speak with a human at the cloud provider. This automation and empowerment of the consumer is a fundamental aspect of cloud computing.
- Question 8Advanced
Related Technologies & Strategies · Zero Trust Strategy
A large enterprise is adopting a Zero Trust security model. A security architect is tasked with implementing a key component of this model: ensuring that every request to an internal application is authenticated and authorized, regardless of where the request originates. The goal is to move away from the traditional VPN-based perimeter model. Which technology is specifically designed to enable this capability?
Show answer & explanation
Correct answer: B
ZTNA, also known as a Software-Defined Perimeter (SDP), is the technology that embodies this Zero Trust principle. Unlike a VPN which grants broad network access, a ZTNA solution creates a secure, encrypted tunnel on a per-session, per-application basis after verifying user identity and device posture. It enforces the 'never trust, always verify' mantra for every single access request, making it the ideal replacement for traditional VPNs in a Zero Trust architecture.
- Question 9Intermediate
Related Technologies & Strategies · Generative AI Security
A developer is using a generative AI coding assistant to write application code. During a security review, it is discovered that snippets of proprietary source code were included in prompts sent to the public AI model. This action creates a significant risk of intellectual property leakage. What is this type of vulnerability called in the context of Generative AI?
Show answer & explanation
Correct answer: C
This scenario is a classic example of sensitive data leakage. When users input proprietary or confidential information into prompts for public LLMs, that data can potentially be used to train future versions of the model or be exposed in other users' responses. Organizations must have clear policies and technical controls (like DLP) to prevent employees from sending sensitive data to public AI services.
- Question 10Advanced
Identity & Access Management · Identity Federation and SSO
An e-commerce company wants to implement a robust authentication system for its customer-facing application. They need to support logging in via social media providers (e.g., Google, Facebook) as well as their own user database. Which combination of open standards is best suited for handling authentication and delegated authorization in this scenario?
Show answer & explanation
Correct answer: C
This is the modern standard for this use case. OAuth 2.0 is a framework for delegated authorization, allowing an application to access resources on behalf of a user (e.g., access your Google profile). OpenID Connect (OIDC) is a thin identity layer built on top of OAuth 2.0 that provides the authentication piece, verifying the user's identity and providing a standard set of profile information (the ID Token). Together, they enable secure social logins and API access.
Ready for the real thing?
The full CCSKV5 simulator has every exam-style question, timed mode, and instant scoring.