CISSP Cloud Security Flashcards
6 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CISSP Cloud Security flashcards as text
Which framework provides a comprehensive set of cloud security controls aligned with ISO 27001?
Answer: CSA Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix maps cloud-specific controls to ISO 27001 and other frameworks to guide cloud security assessments.
What is the primary purpose of a Cloud Access Security Broker (CASB)?
Answer: To enforce security policies between cloud service users and providers
A CASB sits between users and cloud services to enforce visibility, compliance, data security, and threat protection policies.
In a SaaS model, who is responsible for patching the application software?
Answer: The cloud service provider
In SaaS, the cloud provider manages and patches the application; the customer only manages their data and user access.
What cloud data security technique ensures that even if the provider is compromised, customer data remains unreadable?
Answer: Client-side encryption with customer-managed keys
Encrypting data client-side before upload with customer-managed keys means the provider never possesses the decryption key.
Which concept describes the risk that cloud data may be subject to the laws of the country where the data center resides?
Answer: Data sovereignty
Data sovereignty means data stored in a foreign jurisdiction may be subject to that country's laws, including government access demands.
What is the purpose of a right-to-audit clause in a cloud service contract?
Answer: To grant the customer the ability to inspect provider security controls
A right-to-audit clause contractually permits the customer or their agent to verify the provider's security controls and compliance.