(CSA) Basic Flashcards
7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 (CSA) Basic flashcards as text
According to CSA, what distinguishes 'security as a service' (SecaaS) from traditional security products?
Answer: Security capabilities are delivered via cloud subscription rather than deployed on-premises
SecaaS delivers security functions—such as identity management, SIEM, or vulnerability scanning—as cloud-based subscription services without on-premises hardware.
In CSA's Egress Monitoring guidance, what is the main goal of monitoring outbound cloud traffic?
Answer: To detect data exfiltration and unauthorized transmission of sensitive data
Egress monitoring focuses on detecting when sensitive data leaves cloud environments without authorization, which is a key indicator of a breach.
What is the purpose of 'object storage' in cloud environments, according to CSA infrastructure guidance?
Answer: To store unstructured data as discrete objects with associated metadata, accessed via APIs
Object storage stores unstructured data (files, images, logs) as objects with metadata, accessed through REST APIs, making it highly scalable and durable.
According to CSA, which is the most effective control for preventing unauthorized lateral movement after an initial cloud account compromise?
Answer: Implementing micro-segmentation and least-privilege network policies
Micro-segmentation limits blast radius by restricting east-west traffic so a compromised workload cannot freely access other resources in the environment.
In CSA Guidance, what is 'immutable infrastructure'?
Answer: Cloud resources that are replaced rather than modified when changes are needed
Immutable infrastructure means servers and components are never modified after deployment; instead, new versions replace old ones, reducing configuration drift and attack surface.
According to CSA, what is the key advantage of using 'infrastructure as code' (IaC) for cloud security?
Answer: It enables consistent, version-controlled, and auditable provisioning of secure configurations
IaC enables security configurations to be version-controlled, peer-reviewed, and consistently applied, reducing human error and enabling security-as-code practices.
Which CSA guidance concept refers to the risk that a cloud provider's technical or business failure could disrupt a customer's operations?
Answer: Provider dependency risk
Provider dependency risk recognizes that reliance on a single cloud provider creates exposure to that provider's outages, insolvency, or service changes.