Free Certified Cloud Security Professional (CCSP) MCQ Questions and Answers — Questions and Answers
Question 1: Which of the following positions is in charge of developing cloud components as well as testing and validating services?
- Cloud service developer (Correct answer)
- Cloud service broker
- Cloud auditor
- Inter-cloud provider
Correct answer: Cloud service developer
The cloud service developer is in charge of designing and building cloud components and services, as well as testing and verifying them.
Question 2: What is the greatest source of knowledge about safeguarding a physical asset's BIOS?
- Manual pages
- Vendor documentation (Correct answer)
- Regulations
- Security policies
Correct answer: Vendor documentation
The greatest source for recommended practices for safeguarding the BIOS is vendor documentation from the maker of the actual hardware.
Question 3: Which of the following positions for a business entails testing, monitoring, and safeguarding cloud services?
- Cloud service administrator (Correct answer)
- Cloud service user
- Cloud service integrator
- Cloud service business manager
Correct answer: Cloud service administrator
The cloud service administrator is in charge of testing cloud services, monitoring services, administering service security, delivering cloud service consumption information, and responding to problem complaints.
Question 4: What is the sole data format supported by the SOAP API?
- XML (Correct answer)
- XSML
- HTML
- SAML
Correct answer: XML
Only the XML data format is supported by the SOAP protocol.
Question 5: Which data types are most typically utilized with the REST API?
- SAML and HTML
- XML and JSON (Correct answer)
- JSON and SAML
- XML and SAML
Correct answer: XML and JSON
The most often used data formats for the Representenational State Transfer (REST) API are JavaScript Object Notation (JSON) and Extensible Markup Language (XML), which are typically implemented with caching for enhanced scalability and performance.
Question 6: After the initial tests, which of the following threat types involves an application that does not validate authorization for portions of itself?
- Cross-site request forgery
- Cross-site scripting
- Injection
- Missing function-level access control (Correct answer)
Correct answer: Missing function-level access control
When each function or component of an application is accessed, an application must run checks to ensure that the user is legitimately permitted to access it. An attacker could fabricate requests to access areas of the application where authorization has not been granted if continuous checks are not performed each time a function is accessed.
Question 7: Which of the following positions is responsible for an organization's billing, purchasing, and requesting audit reports in a cloud environment?
- Cloud service business manager (Correct answer)
- Cloud service administrator
- Cloud service Integrator
- Cloud service user
Correct answer: Cloud service business manager
The cloud service business manager is in charge of supervising business and billing administration, purchasing cloud services, and obtaining audit reports as needed.
Which of the following positions is in charge of developing cloud components as well as testing and validating services?