Cloud Security Compliance Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Security Compliance flashcards as text
Under the AWS Shared Responsibility Model, which security control is always the customer's responsibility regardless of the service type used?
Answer: Identity and access management for user accounts
IAM for user accounts is always the customer's responsibility across all AWS service types (IaaS, PaaS, SaaS).
Which cloud security framework specifically addresses controls for cloud service providers and was developed by the Cloud Security Alliance?
Answer: Cloud Controls Matrix (CCM)
The Cloud Security Alliance's Cloud Controls Matrix (CCM) is specifically designed for cloud environments and maps to multiple compliance frameworks.
A company stores PHI in a cloud database. Under HIPAA, which document must be executed with the cloud provider before any PHI is stored?
Answer: Business Associate Agreement (BAA)
HIPAA requires a Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity.
What is the primary purpose of a Cloud Access Security Broker (CASB)?
Answer: To enforce security policies between cloud users and cloud service providers
A CASB acts as an intermediary that enforces security, compliance, and governance policies for cloud service usage.
An organization subject to PCI DSS uses a cloud provider that has a PCI DSS AOC (Attestation of Compliance). What does this mean for the organization's compliance posture?
Answer: The cloud provider's in-scope infrastructure satisfies certain PCI DSS requirements, but the customer must still address their own controls
A provider's AOC covers only their portion of the shared responsibility; customers must still implement and validate their own controls.
Which encryption approach ensures that a cloud provider cannot decrypt customer data even when compelled by a legal order?
Answer: Client-side encryption with customer-managed keys
Client-side encryption with customer-managed keys means the provider never has access to the plaintext data or the decryption keys.
Under GDPR, if a U.S.-based company transfers EU personal data to its cloud provider's servers located in the U.S., which mechanism is commonly used to legalize the transfer?
Answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) are the most widely used legal mechanism for transferring personal data from the EU to third countries after Privacy Shield was invalidated.