Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 130 pages
Exam (elaborations)

CERTIFIED CLOUD SECURITY PROFESSIONAL (CCSP) –QUESTIONS AND CORRECT ANSWERS (VERIFIED ANSWERS) PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF.

Document preview thumbnail
Preview 4 out of 130 pages

CERTIFIED CLOUD SECURITY PROFESSIONAL (CCSP) –QUESTIONS AND CORRECT ANSWERS (VERIFIED ANSWERS) PLUS RATIONALES 2026 Q&A | INSTANT DOWNLOAD PDF.

Content preview

CERTIFIED CLOUD SECURITY PROFESSIONAL (CCSP) –QUESTIONS AND
CORRECT ANSWERS (VERIFIED ANSWERS) PLUS RATIONALES 2026 Q&A |
INSTANT DOWNLOAD PDF.

Core Domains:
• Cloud Concepts, Architecture and Design
• Cloud Data Security
• Cloud Platform and Infrastructure Security
• Cloud Application Security
• Cloud Security Operations
• Legal, Risk and Compliance

Introduction
The Certified Cloud Security Professional (CCSP) assessment is designed to validate
the advanced knowledge and skills required to design, manage, and secure data,
applications, and infrastructure in cloud environments. This comprehensive exam
evaluates a candidate's understanding of cloud security architecture, compliance
standards, risk management, and operational best practices. Comprising a mix of
foundational multiple-choice questions and complex, scenario-based items, this
assessment emphasizes real-world application, critical thinking, and strategic decision-
making. Candidates must demonstrate the ability to evaluate threats, implement robust
controls, and ensure legal and regulatory compliance across diverse cloud deployment
models, reflecting the highest standards of professional competence in cloud security.

,Section One: Questions 1–100
Question 1
An organization is migrating its highly sensitive financial applications to a public cloud
environment. The security architect needs to ensure that data remains protected not only
at rest and in transit but also while it is actively being processed in memory by the CPU.
Which of the following technologies provides this specific capability?

A. Homomorphic encryption
B. Transport Layer Security
C. Confidential Computing
D. Advanced Encryption Standard

🟢 C. Confidential Computing
🔴 RATIONALE: Confidential Computing protects data in use by performing computation
in a hardware-based, isolated Trusted Execution Environment (TEE). This prevents
unauthorized access or modification of applications and data while they are being
processed, which fulfills the requirement of protecting data in use/memory.

Question 2
A cloud security engineer is designing a disaster recovery plan for an enterprise
operating in a multi-tenant public cloud environment. The primary objective is to minimize

,data loss in the event of a catastrophic failure. Which metric must the engineer define to
specify the maximum acceptable age of data that can be restored?

A. Recovery Time Objective (RTO)
B. Recovery Point Objective (RPO)
C. Maximum Tolerable Downtime (MTD)
D. Work Recovery Time (WRT)

🟢 B. Recovery Point Objective (RPO)
🔴 RATIONALE: Recovery Point Objective (RPO) defines the maximum targeted period
in which data might be lost from an IT service due to a major incident. It directly dictates
the backup frequency required to minimize data loss.

Question 3
During a legal dispute involving a cloud customer and a third party, a cloud provider
receives a judicially sanctioned demand to preserve and hand over all relevant data logs.
This legal mechanism used to command the production of evidence is known as what?

A. Interrogatory
B. Subpoena
C. Deposition
D. Spoliation

, 🟢 B. Subpoena
🔴 RATIONALE: A subpoena is a legal document issued by a court or administrative
agency that commands a person or entity to testify or produce specific documents,
records, or evidence for a legal proceeding.

Question 4
A SaaS provider wants to establish a rigorous framework for continuous risk monitoring
and compliance reporting to satisfy federal government clients. Which risk management
framework specifically outlines the security and privacy controls required for US federal
information systems and organizations?

A. ISO/IEC 27001
B. NIST SP 800-53
C. COBIT
D. PCI DSS

🟢 B. NIST SP 800-53
🔴 RATIONALE: NIST Special Publication 800-53 provides a catalog of security and
privacy controls for federal information systems and organizations, making it the primary
standard for compliance in US federal cloud migrations.

Question 5
An organization is deploying a new web application on an Infrastructure as a Service
(IaaS) platform. The application must dynamically scale based on traffic. Who is

Document information

Uploaded on
May 22, 2026
Number of pages
130
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$25.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
tutorwalter
1.0
(1)
Sold
9
Followers
0
Items
1002
Last sold
2 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions