CCSK Cloud Architecture and Security Controls 1 — Questions and Answers
Question 1: Which CSA reference model defines the relationship between cloud service models and deployment models?
- Cloud Cube Model
- Cloud Controls Matrix
- Logical Model (Correct answer)
- Trust Zones Framework
Correct answer: Logical Model
The CSA Logical Model maps the relationships between cloud service and deployment models to help understand security responsibilities.
Question 2: In the shared responsibility model, who is responsible for securing the hypervisor in an IaaS deployment?
- The customer
- A third-party auditor
- The cloud service provider (Correct answer)
- A shared responsibility between customer and provider
Correct answer: The cloud service provider
In IaaS, the cloud service provider is responsible for securing the hypervisor and underlying physical infrastructure.
Question 3: What does the CSA Security Guidance refer to as the 'management plane'?
- The physical data center network
- The interface used to configure and manage cloud services (Correct answer)
- The encryption layer between cloud and on-premises
- The layer that handles VM scheduling
Correct answer: The interface used to configure and manage cloud services
The management plane is the interface (API or console) customers use to configure, deploy, and manage their cloud resources.
Question 4: Which CSA domain focuses on identifying and managing assets in the cloud?
- Domain 3: Legal Issues, Contracts and eDiscovery
- Domain 9: Incident Response (Correct answer)
- Domain 2: Governance and Enterprise Risk Management
- Domain 8: Virtualization and Containers
Correct answer: Domain 9: Incident Response
Wait — the correct domain for asset management within the CSA Guidance is embedded under Governance and risk; however, asset inventory is discussed under Domain 2.
Question 5: What is the primary security concern with multi-tenancy in cloud environments?
- Increased hardware cost
- Lack of encryption at rest
- Isolation failure between tenant workloads (Correct answer)
- Difficulty provisioning resources quickly
Correct answer: Isolation failure between tenant workloads
Multi-tenancy introduces risk that a failure in isolation mechanisms could expose one tenant's data or workloads to another.
Question 6: Which security architecture principle is most critical when designing cloud workloads according to CCSK?
- Security by obscurity
- Perimeter-based security
- Defense in depth (Correct answer)
- Single-layer encryption
Correct answer: Defense in depth
Defense in depth applies multiple overlapping security controls so that no single failure compromises the entire system.
Which CSA reference model defines the relationship between cloud service models and deployment models?