CCSK (CSA) Basic 2 — Questions and Answers
Question 1: According to CSA, which cloud deployment model provides infrastructure exclusively for a single organization and may be managed on-premises or by a third party?
- Public cloud
- Community cloud
- Private cloud (Correct answer)
- Hybrid cloud
Correct answer: Private cloud
A private cloud is dedicated to a single organization and can be hosted on-premises or externally, offering greater control over data and security.
Question 2: In the CSA Shared Responsibility Model, which security responsibility does the cloud customer always retain regardless of service model?
- Hypervisor patching
- Physical data center security
- Data classification and accountability (Correct answer)
- Network infrastructure management
Correct answer: Data classification and accountability
Customers always retain responsibility for data classification and accountability regardless of whether they use IaaS, PaaS, or SaaS.
Question 3: What does the CSA define as the 'control plane' in cloud computing?
- The physical network switches that route traffic
- The management layer that allows users to configure and control cloud resources (Correct answer)
- The encryption module protecting data in transit
- The billing interface for tracking cloud expenditure
Correct answer: The management layer that allows users to configure and control cloud resources
The control plane is the management layer through which users provision, configure, and orchestrate cloud resources and services.
Question 4: Which CSA Guidance domain focuses on how organizations plan and manage the processes, procedures, and governance of cloud security?
- Infrastructure Security
- Governance and Enterprise Risk Management (Correct answer)
- Data Security and Encryption
- Identity and Access Management
Correct answer: Governance and Enterprise Risk Management
The Governance and Enterprise Risk Management domain covers organizational policies, risk management frameworks, and cloud security strategy.
Question 5: According to CSA, what is 'cloud bursting'?
- A DDoS attack that overwhelms cloud resources
- Automatically scaling workloads from a private cloud into a public cloud during peak demand (Correct answer)
- Migrating all on-premises data to cloud storage at once
- A technique for encrypting burst data transfers
Correct answer: Automatically scaling workloads from a private cloud into a public cloud during peak demand
Cloud bursting is a hybrid cloud configuration that allows workloads to move from private cloud to public cloud when demand exceeds private capacity.
Question 6: In CSA terminology, what is a 'metastructure'?
- The physical hardware layer of a cloud data center
- The protocols and mechanisms that provide the interface between the infrastructure and other layers (Correct answer)
- A schema defining structured metadata for cloud objects
- A security framework for multi-cloud environments
Correct answer: The protocols and mechanisms that provide the interface between the infrastructure and other layers
The metastructure is the layer of protocols and mechanisms—like APIs—that bridges cloud infrastructure with the services built on top of it.
Question 7: Which statement best describes the CSA concept of 'segregation of duties' in cloud IAM?
- Requiring all cloud admins to share a single privileged account for auditability
- Dividing critical tasks among multiple individuals so no single person controls an entire process (Correct answer)
- Storing encryption keys separately from encrypted data
- Isolating cloud tenants through hypervisor controls
Correct answer: Dividing critical tasks among multiple individuals so no single person controls an entire process
Segregation of duties divides responsibilities across multiple individuals to reduce fraud risk and prevent any single person from having unchecked control.
According to CSA, which cloud deployment model provides infrastructure exclusively for a single organization and may be managed on-premises or by a third party?