Cloud Security Compliance Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cloud Security Compliance flashcards as text
A security auditor is reviewing a multi-cloud environment. Which document helps map a cloud provider's security controls to multiple compliance frameworks simultaneously?
Answer: CSA STAR registry entry
The CSA STAR (Security Trust Assurance and Risk) registry provides a public repository of cloud provider security controls mapped to the CCM and multiple compliance frameworks.
What distinguishes a SOC 2 Type I report from a SOC 2 Type II report?
Answer: Type I assesses control design at a point in time; Type II tests operational effectiveness over a period
SOC 2 Type I evaluates whether controls are suitably designed at a specific date, while Type II tests whether those controls operated effectively over a review period (typically 6–12 months).
Which FedRAMP authorization level is required for cloud systems that process Controlled Unclassified Information (CUI) with moderate potential impact?
Answer: FedRAMP Moderate
FedRAMP Moderate is required for systems where compromise would have serious adverse effects, covering most federal civilian data including standard CUI.
An organization discovers that its cloud provider subcontracted data processing to a fourth-party vendor without notification. Which compliance principle does this most directly violate?
Answer: Sub-processor notification requirements
GDPR and many frameworks require processors to notify controllers before engaging sub-processors, giving controllers the right to object.
What is the primary security concern addressed by implementing a Zero Trust Architecture in cloud environments?
Answer: Ensuring that no user or device is inherently trusted, requiring continuous verification
Zero Trust eliminates implicit trust based on network location, requiring every access request to be authenticated, authorized, and continuously validated.
Which cloud storage misconfiguration has been the most common cause of large-scale data breaches in public cloud environments?
Answer: Publicly accessible storage buckets without authentication
Misconfigured S3 buckets and equivalent public cloud storage containers set to public access have been responsible for numerous high-profile data breaches.
Under the NIST Cloud Computing definition, which deployment model offers infrastructure exclusively for use by a single organization but may be managed by a third party?
Answer: Private cloud
A private cloud is provisioned for exclusive use by a single organization and can be owned, managed, and operated by the organization, a third party, or a combination.