CCSP Sample Questions

CCSP Sample Questions & Answers

Cloud data security carries the most weight here, alongside architecture and design, infrastructure and platform protection, the secure development life cycle for cloud apps, running cloud operations, and the legal and audit questions the cloud raises.

Launch the full CCSP simulator →

Showing 10 of 20 free samples.

  1. Question 1

    What is the only data format permitted with the SOAP API?

    Show answer & explanation

    Correct answer: D

    Explanation:
    The SOAP protocol only supports the XML data format.

  2. Question 2

    Which data formats are most commonly used with the REST API?

    Show answer & explanation

    Correct answer: B

    This is the CORRECT answer. XML and JSON (JavaScript Object Notation) are the two most commonly used data formats with REST APIs. XML provides structured data representation while JSON offers a lightweight, human-readable format that is widely preferred for web services.

  3. Question 3

    Which of the following threat types involves an application that does not validate authorization for portions of itself after the initial checks?

    Show answer & explanation

    Correct answer: D

    Explanation:
    It is imperative that an application perform checks when each function or portion of the application is accessed, to ensure that the user is properly authorized to access it. Without continual checks each time a function is accessed, an attacker could forge requests to access portions of the application where authorization has not been granted.

  4. Question 4

    Which of the following roles involves overseeing billing, purchasing, and requesting audit reports for an organization within a cloud environment?

    Show answer & explanation

    Correct answer: A

    Explanation:
    The cloud service business manager is responsible for overseeing business and billing administration, purchasing cloud services, and requesting audit reports when necessary

  5. Question 5

    What is the biggest concern with hosting a key management system outside of the cloud environment?

    Show answer & explanation

    Correct answer: A

    Explanation:
    When a key management system is outside of the cloud environment hosting the application, availability is a primary concern because any access issues with the encryption keys will render the entire application unusable.

  6. Question 6

    Which of the following approaches would NOT be considered sufficient to meet the requirements of secure data destruction within a cloud environment?

    Show answer & explanation

    Correct answer: B

    Explanation:
    Deletion merely removes the pointers to data on a system; it does nothing to actually remove and sanitize the data. As such, the data remains in a recoverable state, and more secure methods are needed to ensure it has been destroyed and is not recoverable by another party.

  7. Question 7

    Which of the following cloud aspects complicates eDiscovery?

    Show answer & explanation

    Correct answer: B

    Explanation:
    With multitenancy, eDiscovery becomes more complicated because the data collection involves extra steps to ensure that only those customers or systems that are within scope are turned over to the requesting authority.

  8. Question 8

    What does the management plane typically utilize to perform administrative functions on the hypervisors that it has access to?

    Show answer & explanation

    Correct answer: A

    Explanation:
    The functions of the management plane are typically exposed as a series of remote calls and function executions and as a set of APIs. These APIs are typically leveraged through either a client or a web portal, with the latter being the most common.

  9. Question 9

    What is a serious complication an organization faces from the perspective of compliance with international operations?

    Show answer & explanation

    Correct answer: C

    Explanation:
    When operating within a global framework, a security professional runs into a multitude of jurisdictions and requirements, and many times they might be in contention with one other or not clearly applicable. These requirements can include the location of the users and the type of data they enter into systems, the laws governing the organization that owns the application and any regulatory requirements they may have, as well as the appropriate laws and regulations for the jurisdiction housing the IT resources and where the data is actually stored, which might be multiple jurisdictions as well.

  10. Question 10

    Which networking concept in a cloud environment allows for network segregation and isolation of IP spaces?

    Show answer & explanation

    Correct answer: B

    Explanation:
    A virtual area network (VLAN) allows the logical separation and isolation of networks and IP spaces to provide enhanced security and controls.

Ready for the real thing?

The full CCSP simulator has every exam-style question, timed mode, and instant scoring.

Go to the CCSP simulator →