CERTIFIED CLOUD SECURITY PROFESSIONAL
(CCSP) PRACTICE EXAM 2 QUESTIONS AND
CORRECT ANSWERS (VERIFIED ANSWERS)
PLUS RATIONALES 2025
1. Which of the following best describes a key characteristic of cloud
computing?
A. Dedicated infrastructure for each customer
B. On-demand self-service
C. Manual provisioning of resources
D. Fixed and limited scalability
Answer: B
Rationale: On-demand self-service is a foundational element of cloud
computing, allowing users to provision resources without requiring human
interaction with the service provider.
2. Which cloud service model provides the consumer with the most control over
the underlying infrastructure?
A. SaaS
,B. IaaS
C. PaaS
D. XaaS
Answer: B
Rationale: IaaS (Infrastructure as a Service) offers virtualized computing
resources over the internet and allows customers control over the OS, storage,
and deployed applications.
3. In a shared responsibility model, who is typically responsible for the physical
security of the data center?
A. Customer
B. Cloud service provider
C. Third-party auditor
D. Regulatory authority
Answer: B
Rationale: The cloud service provider (CSP) is responsible for the physical
security of the data centers that house the hardware.
4. What type of encryption ensures that only the sender and receiver can read
the data, even if intercepted?
A. Symmetric encryption
B. End-to-end encryption
C. Hashing
D. Tokenization
, Answer: B
Rationale: End-to-end encryption ensures that data is encrypted at the source
and only decrypted at the destination, protecting data in transit from all
intermediaries.
5. What is the main purpose of data classification in cloud security?
A. To ensure compliance with software licensing
B. To reduce costs of storage
C. To determine the sensitivity and required protection of data
D. To automate load balancing
Answer: C
Rationale: Data classification helps identify and protect sensitive data
appropriately by assigning labels that guide its handling and security controls.
6. Which security principle is violated when a user gains access to more
resources than they are authorized for?
A. Least privilege
B. Federation
C. Redundancy
D. Separation of duties
Answer: A
Rationale: The principle of least privilege restricts users to the minimal level of
access necessary to perform their jobs. Over-permissioned access violates this
principle.
(CCSP) PRACTICE EXAM 2 QUESTIONS AND
CORRECT ANSWERS (VERIFIED ANSWERS)
PLUS RATIONALES 2025
1. Which of the following best describes a key characteristic of cloud
computing?
A. Dedicated infrastructure for each customer
B. On-demand self-service
C. Manual provisioning of resources
D. Fixed and limited scalability
Answer: B
Rationale: On-demand self-service is a foundational element of cloud
computing, allowing users to provision resources without requiring human
interaction with the service provider.
2. Which cloud service model provides the consumer with the most control over
the underlying infrastructure?
A. SaaS
,B. IaaS
C. PaaS
D. XaaS
Answer: B
Rationale: IaaS (Infrastructure as a Service) offers virtualized computing
resources over the internet and allows customers control over the OS, storage,
and deployed applications.
3. In a shared responsibility model, who is typically responsible for the physical
security of the data center?
A. Customer
B. Cloud service provider
C. Third-party auditor
D. Regulatory authority
Answer: B
Rationale: The cloud service provider (CSP) is responsible for the physical
security of the data centers that house the hardware.
4. What type of encryption ensures that only the sender and receiver can read
the data, even if intercepted?
A. Symmetric encryption
B. End-to-end encryption
C. Hashing
D. Tokenization
, Answer: B
Rationale: End-to-end encryption ensures that data is encrypted at the source
and only decrypted at the destination, protecting data in transit from all
intermediaries.
5. What is the main purpose of data classification in cloud security?
A. To ensure compliance with software licensing
B. To reduce costs of storage
C. To determine the sensitivity and required protection of data
D. To automate load balancing
Answer: C
Rationale: Data classification helps identify and protect sensitive data
appropriately by assigning labels that guide its handling and security controls.
6. Which security principle is violated when a user gains access to more
resources than they are authorized for?
A. Least privilege
B. Federation
C. Redundancy
D. Separation of duties
Answer: A
Rationale: The principle of least privilege restricts users to the minimal level of
access necessary to perform their jobs. Over-permissioned access violates this
principle.