โ† All CCSP Flashcard Decks

Cloud Security Operations Flashcards

6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Security Operations flashcards as text
  1. What is the primary purpose of a cloud Security Operations Center (SOC)?

    Answer: To continuously monitor, detect, analyze, and respond to cybersecurity incidents in the cloud environment

    A SOC is a centralized function staffed with security analysts who monitor the organization's cloud environment 24/7 to detect and respond to threats.

  2. Which concept describes the minimum level of access rights a user or system should be granted to perform their required functions?

    Answer: Principle of least privilege

    The principle of least privilege limits access rights to only what is necessary for the user's role, minimizing the potential damage from accidents or compromised credentials.

  3. In cloud forensics, why is evidence collection challenging compared to traditional on-premises forensics?

    Answer: Evidence may be distributed across multiple jurisdictions, shared infrastructure makes isolation difficult, and data may be volatile or ephemeral

    Cloud forensics is complicated by data being spread across multiple countries, shared hardware making chain of custody complex, and auto-scaling that may destroy evidence by terminating instances.

  4. What is the purpose of chaos engineering in cloud security operations?

    Answer: To intentionally introduce failures to test system resilience and identify weaknesses before real incidents occur

    Chaos engineering deliberately injects failures (e.g., terminating instances, dropping network packets) to validate that security and resilience controls work as expected under real failure conditions.

  5. What is the difference between an RTO and an RPO in cloud disaster recovery planning?

    Answer: RTO is the maximum acceptable downtime; RPO is the maximum acceptable data loss measured in time

    RTO (Recovery Time Objective) defines how long the system can be down, while RPO (Recovery Point Objective) defines how much data loss (measured in time) is acceptable.

  6. Which cloud security practice involves regularly reviewing and removing unused IAM accounts, roles, and permissions?

    Answer: Access entitlement review (access recertification)

    Access entitlement reviews (also called access recertification or user access reviews) periodically verify that all IAM grants are still needed and remove those that are not.