1 | Page
ISC2 CCSP CERTIFIED CLOUD SECURITY
PROFESSIONAL ACTUAL EXAM 2026/2027
QUESTIONS WITH VERIFIED ANSWERS &
COMPLETE RATIONALES
**1. A company stores regulated files in a cloud object storage
service. The provider secures the underlying infrastructure, but
the company configures bucket permissions and encryption
settings. A public bucket exposes files. Who is primarily
responsible for the misconfiguration?**
A. The customer, because access configuration and data
protection choices remain customer responsibilities in the
shared model.
B. The internet service provider, because the files moved
across public networks.
C. Only the cloud provider, because any cloud-hosted data is
fully provider-managed.
D. No party, because public object storage is always expected
behavior.
**Correct answer:** A
**Rationale:** Cloud providers secure many platform layers, but
customers still own data classification, permissions, identity
,2 | Page
configuration, and many encryption choices. The bucket
exposure is a customer-side configuration failure. This tests
shared responsibility, cloud data ownership, storage access
control, and customer configuration risk .
---
**2. A healthcare workload in the cloud requires encryption and
clear separation between cloud provider operations and
customer control over key use. Which design is strongest?**
A. Use one shared administrator password for the application,
database, and key-management console.
B. Turn off encryption because the cloud provider already
secures the datacenter.
C. Use customer-managed keys with strict IAM, separation of
duties, rotation policy, and logging around key use.
D. Store raw encryption keys in application source code so
developers can troubleshoot quickly.
**Correct answer:** C
**Rationale:** Customer-managed keys support stronger
control over key lifecycle and use. IAM, separation of duties,
rotation, and audit logging are the important security controls
around the key-management choice. This tests encryption
, 3 | Page
governance, customer-managed keys, key lifecycle, and
auditability .
---
**3. A cloud workload may be compromised. The incident team
needs evidence without making the attacker aware or
destroying volatile context. Which response is strongest?**
A. Delete the workload immediately and wait for users to report
whether service improves.
B. Turn off all logging to reduce cost during the incident.
C. Post credentials in the incident channel so all responders
can access the tenant quickly.
D. Preserve relevant logs, capture snapshots or forensic
images where appropriate, isolate using approved controls, and
maintain chain-of-custody records.
**Correct answer:** D
**Rationale:** Cloud incident response must preserve evidence
and control spread. Logs, snapshots, approved isolation, and
chain-of-custody documentation support investigation and
potential legal or regulatory follow-up. This tests cloud incident
response, evidence preservation, isolation, logging, and chain
of custody .
ISC2 CCSP CERTIFIED CLOUD SECURITY
PROFESSIONAL ACTUAL EXAM 2026/2027
QUESTIONS WITH VERIFIED ANSWERS &
COMPLETE RATIONALES
**1. A company stores regulated files in a cloud object storage
service. The provider secures the underlying infrastructure, but
the company configures bucket permissions and encryption
settings. A public bucket exposes files. Who is primarily
responsible for the misconfiguration?**
A. The customer, because access configuration and data
protection choices remain customer responsibilities in the
shared model.
B. The internet service provider, because the files moved
across public networks.
C. Only the cloud provider, because any cloud-hosted data is
fully provider-managed.
D. No party, because public object storage is always expected
behavior.
**Correct answer:** A
**Rationale:** Cloud providers secure many platform layers, but
customers still own data classification, permissions, identity
,2 | Page
configuration, and many encryption choices. The bucket
exposure is a customer-side configuration failure. This tests
shared responsibility, cloud data ownership, storage access
control, and customer configuration risk .
---
**2. A healthcare workload in the cloud requires encryption and
clear separation between cloud provider operations and
customer control over key use. Which design is strongest?**
A. Use one shared administrator password for the application,
database, and key-management console.
B. Turn off encryption because the cloud provider already
secures the datacenter.
C. Use customer-managed keys with strict IAM, separation of
duties, rotation policy, and logging around key use.
D. Store raw encryption keys in application source code so
developers can troubleshoot quickly.
**Correct answer:** C
**Rationale:** Customer-managed keys support stronger
control over key lifecycle and use. IAM, separation of duties,
rotation, and audit logging are the important security controls
around the key-management choice. This tests encryption
, 3 | Page
governance, customer-managed keys, key lifecycle, and
auditability .
---
**3. A cloud workload may be compromised. The incident team
needs evidence without making the attacker aware or
destroying volatile context. Which response is strongest?**
A. Delete the workload immediately and wait for users to report
whether service improves.
B. Turn off all logging to reduce cost during the incident.
C. Post credentials in the incident channel so all responders
can access the tenant quickly.
D. Preserve relevant logs, capture snapshots or forensic
images where appropriate, isolate using approved controls, and
maintain chain-of-custody records.
**Correct answer:** D
**Rationale:** Cloud incident response must preserve evidence
and control spread. Logs, snapshots, approved isolation, and
chain-of-custody documentation support investigation and
potential legal or regulatory follow-up. This tests cloud incident
response, evidence preservation, isolation, logging, and chain
of custody .