Certified Cloud Security Professional (CCSP)
Practice Exam 1 QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS) PLUS
RATIONALES 2025
1. Which of the following best describes the Shared Responsibility Model in
cloud security?
A) The cloud provider is solely responsible for securing everything in the cloud.
B) The cloud customer is solely responsible for securing everything in the cloud.
C) The cloud provider and customer share security responsibilities based on the
service model.
D) The cloud provider handles security for SaaS only.
Rationale: The Shared Responsibility Model divides security tasks between the
cloud provider and customer depending on whether it’s IaaS, PaaS, or SaaS. The
provider secures the infrastructure; the customer secures data, applications, and
access.
,2. Which of the following is NOT one of the six domains of the CCSP Common
Body of Knowledge (CBK)?
A) Cloud Concepts, Architecture, and Design
B) Cloud Data Security
C) Cloud Hardware Manufacturing
D) Cloud Security Operations
Rationale: The six CCSP domains are: Cloud Concepts, Architecture, and Design;
Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application
Security; Cloud Security Operations; Legal, Risk, and Compliance. Hardware
manufacturing is not part of CCSP.
3. What is the primary purpose of a Cloud Access Security Broker (CASB)?
A) To provide cloud infrastructure hosting services
B) To enforce security policies between cloud users and cloud service providers
C) To monitor network traffic for malware
D) To provide identity and access management (IAM)
Rationale: CASBs act as a security policy enforcement point between cloud users
and cloud services, enabling visibility, data security, threat protection, and
compliance.
4. In the context of cloud security, what is “data remanence”?
A) Data encryption techniques
B) Data loss prevention
, C) Residual data left on storage media after deletion
D) Backup data retention policies
Rationale: Data remanence refers to data remnants that remain on storage
devices after attempts to delete or erase, which can lead to unauthorized
recovery.
5. Which of the following cloud deployment models provides resources
exclusively for one organization?
A) Public Cloud
B) Private Cloud
C) Community Cloud
D) Hybrid Cloud
Rationale: A Private Cloud is dedicated to a single organization, offering greater
control and security compared to public clouds.
6. Which type of encryption protects data at rest in the cloud?
A) Transport Layer Security (TLS)
B) Symmetric or Asymmetric encryption applied to stored data
C) IPsec encryption
D) Hashing algorithms only
Rationale: Encryption for data at rest protects stored data using cryptographic
algorithms such as AES; TLS and IPsec protect data in transit.
Practice Exam 1 QUESTIONS AND CORRECT
ANSWERS (VERIFIED ANSWERS) PLUS
RATIONALES 2025
1. Which of the following best describes the Shared Responsibility Model in
cloud security?
A) The cloud provider is solely responsible for securing everything in the cloud.
B) The cloud customer is solely responsible for securing everything in the cloud.
C) The cloud provider and customer share security responsibilities based on the
service model.
D) The cloud provider handles security for SaaS only.
Rationale: The Shared Responsibility Model divides security tasks between the
cloud provider and customer depending on whether it’s IaaS, PaaS, or SaaS. The
provider secures the infrastructure; the customer secures data, applications, and
access.
,2. Which of the following is NOT one of the six domains of the CCSP Common
Body of Knowledge (CBK)?
A) Cloud Concepts, Architecture, and Design
B) Cloud Data Security
C) Cloud Hardware Manufacturing
D) Cloud Security Operations
Rationale: The six CCSP domains are: Cloud Concepts, Architecture, and Design;
Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application
Security; Cloud Security Operations; Legal, Risk, and Compliance. Hardware
manufacturing is not part of CCSP.
3. What is the primary purpose of a Cloud Access Security Broker (CASB)?
A) To provide cloud infrastructure hosting services
B) To enforce security policies between cloud users and cloud service providers
C) To monitor network traffic for malware
D) To provide identity and access management (IAM)
Rationale: CASBs act as a security policy enforcement point between cloud users
and cloud services, enabling visibility, data security, threat protection, and
compliance.
4. In the context of cloud security, what is “data remanence”?
A) Data encryption techniques
B) Data loss prevention
, C) Residual data left on storage media after deletion
D) Backup data retention policies
Rationale: Data remanence refers to data remnants that remain on storage
devices after attempts to delete or erase, which can lead to unauthorized
recovery.
5. Which of the following cloud deployment models provides resources
exclusively for one organization?
A) Public Cloud
B) Private Cloud
C) Community Cloud
D) Hybrid Cloud
Rationale: A Private Cloud is dedicated to a single organization, offering greater
control and security compared to public clouds.
6. Which type of encryption protects data at rest in the cloud?
A) Transport Layer Security (TLS)
B) Symmetric or Asymmetric encryption applied to stored data
C) IPsec encryption
D) Hashing algorithms only
Rationale: Encryption for data at rest protects stored data using cryptographic
algorithms such as AES; TLS and IPsec protect data in transit.