โ† All CCSK Flashcard Decks

(CSA) Basic Flashcards

7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 (CSA) Basic flashcards as text
  1. According to CSA, what is the primary purpose of a Cloud Access Security Broker (CASB)?

    Answer: To act as an intermediary enforcing security policies between cloud users and cloud services

    A CASB sits between cloud consumers and providers to enforce security policies such as visibility, compliance, data security, and threat protection.

  2. What does CSA identify as a key risk of 'vendor lock-in' in cloud computing?

    Answer: Difficulty migrating workloads due to proprietary technologies and data formats

    Vendor lock-in risk arises when proprietary APIs, data formats, or services make it costly or technically challenging to move to another provider.

  3. In the CSA Cloud Controls Matrix (CCM), what is the primary purpose of the tool?

    Answer: To provide a security controls framework specifically designed for cloud environments

    The CCM provides a detailed controls framework aligned to cloud security domains, helping organizations assess and implement appropriate security measures.

  4. According to CSA, which technique best protects against SQL injection attacks in cloud-hosted applications?

    Answer: Using parameterized queries and input validation

    Parameterized queries prevent attackers from injecting malicious SQL by treating user input as data rather than executable code.

  5. What is the CSA-recommended approach for managing secrets (API keys, passwords) in cloud-native applications?

    Answer: Store secrets in a dedicated secrets management service with strict access controls

    Secrets management services (such as HashiCorp Vault or cloud-native equivalents) centralize secret storage with auditing, rotation, and least-privilege access.

  6. In CSA's guidance, what is 'data residency'?

    Answer: The requirement that data must be stored and processed within specific geographic boundaries

    Data residency refers to the legal and regulatory requirements mandating that certain data remain within defined geographic or national boundaries.

  7. Which CSA Guidance domain specifically addresses the security considerations for cloud-based application development?

    Answer: Application Security

    The Application Security domain in CSA Guidance covers secure SDLC, DevSecOps, testing, and cloud-specific application security challenges.