Cloud Security Alliance CCSK Sample Questions:

01. What is a potential concern of using Security-as-a-Service (SecaaS)?
a) Lack of visibility
b) Deployment flexibility
c) Scaling and costs
d) Intelligence sharing
e) Insulation of clients
02. How many documents are officially part of the CCSK version 4 body of knowledge?
a) 1
b) 2
c) 3
d) 4
03. When creating business strategies for cloud migration. which is the most important aspect?
a) Due Diligence when inspecting technologies and choosing cloud provider
b) Choosing the right auditor
c) Hiring a cloud broker
d) Valuating current staff for their capabilities
04. Audits should be robustly designed to reflect best practice, appropriate resources, and tested protocols and standards. They should also use what type of auditors?
a) Auditors working in the interest of the cloud customer
b) Independent auditors
c) Certified by CSA
d) Auditors working in the interest of the cloud provider
e) None of the above
05. Who is responsible for infrastructure Security in Software as a Service(SaaS) service model?
a) Cloud Customer
b) Cloud Carrier
c) Cloud Service Provider
d) It's a shared responsibility between Cloud Service Provider and Cloud Customer
06. CCM: The Cloud Service Delivery Model Applicability column in the CCM indicates the applicability of the cloud security control to which of the following elements?
a) Mappings to well-known standards and frameworks
b) SaaS, PaaS or IaaS
c) Physical, Network, Compute, Storage, Application or Data
d) Service Provider or Tenant/Consumer
07. Which of the following is the correct pair of risk management standards?
a) ISO27002 & ISO27005
b) ISO27001 & ISO27018
c) ISO31000 & ISO27017
d) ISO27005 & ISO31000
08. What type of information is contained in the Cloud Security Alliance's Cloud Control Matrix?
a) Network traffic rules for cloud environments
b) A number of requirements to be implemented, based upon numerous standards and regulatory requirements
c) Federal legal business requirem
d) A list of cloud configurations including traffic logic and efficient routes
e) The command and control management hierarchy of typical cloud company
09. Which of the following are two most effective ways of protection against data breaches in the cloud environment?
a) Contracts and SLAs
b) Data Loss Prevention techniques and Web Application Firewall
c) Encryption and Honeypot
d) Multifactor Authentication and Encryption
10. Operating System management is done by customer in which service model of cloud computing?
a) IaaS
b) PaaS
c) SaaS
d) XaaS


Question: 01
Answer: a
Question: 02
Answer: c
Question: 03
Answer: a
Question: 04
Answer: b
Question: 05
Answer: c
Question: 06
Answer: b
Question: 07
Answer: d
Question: 08
Answer: b
Question: 09
Answer: d
Question: 10
Answer: a

