โ† All CCSK Flashcard Decks

Cloud Architecture and Security Controls Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Architecture and Security Controls flashcards as text
  1. What is the significance of the 'trust boundary' concept in CCSK cloud security architecture?

    Answer: It marks the perimeter where security responsibilities shift between parties

    Trust boundaries define where one party's security responsibility ends and another's begins, critical for understanding the shared responsibility model.

  2. Which of the following is a key risk introduced by 'shadow IT' in cloud environments?

    Answer: Unauthorized cloud services operating outside security controls

    Shadow IT creates security blind spots because unauthorized services bypass established security policies, monitoring, and compliance controls.

  3. What does the CSA recommend as a compensating control when a cloud provider cannot supply audit logs?

    Answer: Deploy a third-party SIEM to capture available telemetry

    When provider audit logs are limited, deploying a SIEM to collect available telemetry compensates for the logging gap.

  4. In CCSK, what is meant by 'portability' as a cloud characteristic?

    Answer: The ability to move workloads or data between cloud providers without proprietary lock-in

    Portability refers to moving applications and data between cloud providers with minimal friction, reducing vendor lock-in risk.

  5. Which CSA domain covers the security implications of cloud APIs?

    Answer: Domain 10: Application Security

    Domain 10 (Application Security) covers securing cloud APIs, including authentication, input validation, and API gateway controls.

  6. What is a 'Virtual Private Cloud' (VPC) and why is it a security best practice?

    Answer: An isolated virtual network within a public cloud that provides network-level segmentation

    A VPC provides an isolated virtual network environment within public cloud, allowing organizations to control IP ranges, subnets, and routing for security segmentation.