(CSA) Basic Flashcards
7 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 (CSA) Basic flashcards as text
In CSA's guidance on Incident Response, what is the recommended first step when a cloud security incident is detected?
Answer: Contain the incident to prevent further damage while preserving forensic evidence
Containment is the priority to limit damage, while evidence preservation ensures effective investigation and potential legal action.
What does CSA define as 'tenant isolation' in multi-tenant cloud environments?
Answer: Logical and technical controls ensuring one tenant cannot access another tenant's data or resources
Tenant isolation uses logical controls—such as virtualization, namespaces, and access policies—to ensure tenants are separated even on shared infrastructure.
According to CSA, what is the primary security concern with 'serverless computing' architectures?
Answer: The expanded attack surface from numerous functions and increased reliance on third-party dependencies
Serverless increases the number of deployed functions and dependencies, expanding the attack surface while requiring careful input validation and least-privilege IAM policies.
In CSA's framework, what is the difference between 'data masking' and 'tokenization'?
Answer: Data masking obscures data for display purposes while tokenization replaces sensitive data with a non-sensitive substitute token
Data masking hides data for display/testing, while tokenization replaces sensitive values with tokens that can be mapped back via a secure token vault.
According to CSA, what role does a Security Information and Event Management (SIEM) system play in cloud environments?
Answer: It aggregates and correlates logs and events from cloud services to detect and investigate threats
A SIEM collects, correlates, and analyzes log data from across cloud environments to identify anomalies, threats, and compliance violations.
What is the CSA-recommended strategy for 'cloud key management' to maintain customer control over data?
Answer: Use Bring Your Own Key (BYOK) or Hold Your Own Key (HYOK) to retain customer control over encryption keys
BYOK and HYOK models ensure customers control their own encryption keys, preventing providers from accessing data even when hosting the encrypted storage.
In CSA's guidance, what is 'continuous compliance monitoring' in cloud environments?
Answer: Automated, real-time assessment of cloud configurations against security policies and regulatory requirements
Continuous compliance monitoring uses automated tools to constantly assess cloud resource configurations against defined policies, enabling rapid detection of drift or violations.