Certificate of Cloud Security Knowledge Flashcards
7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certificate of Cloud Security Knowledge flashcards as text
Which cloud service model gives customers the LEAST control over the underlying infrastructure security?
Answer: SaaS (Software as a Service)
In SaaS, the provider manages everything from infrastructure to the application layer, leaving customers to control only their data and user access.
What is the purpose of a 'Virtual Private Cloud' (VPC)?
Answer: To create an isolated, logically defined network segment within a public cloud
A VPC provides logical network isolation within a public cloud, letting customers define IP ranges, subnets, routing, and access controls in a private network environment.
In cloud incident response, what challenge is MOST unique compared to traditional on-premises incident response?
Answer: Customers may have limited forensic access to underlying infrastructure and logs controlled by the provider
Cloud customers often cannot access physical hardware, hypervisor logs, or provider-side evidence, making forensic investigation dependent on what the provider exposes through APIs.
What is 'infrastructure as code' (IaC) and what is its primary security benefit?
Answer: Defining infrastructure through machine-readable files enabling consistent, auditable, and repeatable deployments
IaC allows infrastructure to be defined in version-controlled code, enabling security review of configurations before deployment and ensuring consistent, drift-free environments.
Which attack is MOST specific to cloud and virtualized environments, where a malicious workload escapes its isolated container to affect the host or neighboring workloads?
Answer: VM/container escape
VM or container escape exploits vulnerabilities in the hypervisor or container runtime to break isolation boundaries and access the host system or other tenants.
What is the CSA STAR program primarily used for?
Answer: Providing a registry where cloud providers document their security controls and compliance
CSA STAR (Security, Trust, Assurance, and Risk) is a publicly accessible registry where cloud providers self-document or have third-party audited their security controls using the CCM.
What does 'right to audit' mean in a cloud services contract?
Answer: The customer's contractual right to assess the cloud provider's security controls and practices
Right to audit gives customers (or their designated third parties) the contractual ability to verify that the cloud provider's security controls meet agreed standards.