ISC CCSP Certified Cloud Security Professional (CCSP) Online Training
ISC CCSP Online Training
The questions for CCSP were last updated at Apr 25,2025.
- Exam Code: CCSP
- Exam Name: Certified Cloud Security Professional (CCSP)
- Certification Provider: ISC
- Latest update: Apr 25,2025
Which of the cloud deployment models is used by popular services such as iCloud, Dropbox, and OneDrive?
- A . Hybrid
- B . Public
- C . Private
- D . Community
Why does a Type 2 hypervisor typically offer less security control than a Type 1 hypervisor?
- A . A Type 2 hypervisor runs on top of another operating system and is dependent on the security of the OS for its own security.
- B . A Type 2 hypervisor allows users to directly perform some functions with their own access.
- C . A Type 2 hypervisor is open source, so attackers can more easily find exploitable vulnerabilities with that access.
- D . A Type 2 hypervisor is always exposed to the public Internet for federated identity access.
Which is the appropriate phase of the cloud data lifecycle for determining the data’s classification?
- A . Create
- B . Use
- C . Share
- D . Store
Which of the following is the optimal temperature for a data center, per the guidelines established by the America Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE)?
- A . 69.8-86.0degF (21-30degC)
- B . 64.4-80.6degF(18-27degC)
- C . 51.8-66.2degF(11-19degC)
- D . 44.6-60-8degF(7-16degC)
Which of the following is not a risk management framework?
- A . COBIT
- B . Hex GBL
- C . ISO 31000:2009
- D . NIST SP 800-37
Which of the following threat types involves the sending of untrusted data to a user’s browser to be executed with their own credentials and access?
- A . Missing function level access control
- B . Cross-site scripting
- C . Cross-site request forgery
- D . Injection
How is an object stored within an object storage system?
- A . Key value
- B . Database
- C . LDAP
- D . Tree structure
Which of the following is NOT a regulatory system from the United States federal government?
- A . PCI DSS
- B . FISMA
- C . SOX
- D . HIPAA
Which jurisdiction lacks specific and comprehensive privacy laws at a national or top level of legal authority?
- A . European Union
- B . Germany
- C . Russia
- D . United States
Which United States law is focused on PII as it relates to the financial industry?
- A . HIPAA
- B . SOX
- C . Safe Harbor
- D . GLBA