Isc

CCSP practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 499-question bank.

Provider
Isc
Question bank
499
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CCSP, a certification listed under Isc. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isc. The certification credential is issued by Isc, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Which of the following roles is responsible for creating cloud components and the testing and validation of services?

    Choose one answer.

    • Cloud auditor
    • Inter-cloud provider
    • Cloud service broker
    • Cloud service developer
  2. Question 2 · 1

    What is the biggest concern with hosting a key management system outside of the cloud environment?

    Choose one answer.

    • Confidentiality
    • Portability
    • Availability
    • Integrity
  3. Question 3 · 1

    What type of PII is controlled based on laws and carries legal penalties for noncompliance with requirements?

    Choose one answer.

    • Contractual
    • Regulated
    • Specific
    • Jurisdictional
    Read explanation

    Regulated PII involves those requirements put forth by specific laws or regulations, and unlike contractual PII, where a violation can lead to contractual penalties, a violation of regulated PII can lead to fines or even criminal charges in some jurisdictions. PII regulations can depend on either the jurisdiction that applies to the hosting location or application or specific legislation based on the industry or type of data used.

  4. Question 4 · 1

    Which if the following is NOT one of the three components of a federated identity system transaction?

    Choose one answer.

    • Relying party
    • Identity provider
    • User
    • Proxy relay
  5. Question 5 · 1

    Which value refers to the amount of time it takes to recover operations in a BCDR situation to meet management's objectives?

    Choose one answer.

    • RSL
    • RPO
    • SRE
    • RTO
    Read explanation

    The recovery time objective (RTO) is a measure of the amount of time it would take to recover operations in the event of a disaster to the point where management's objectives are met for BCDR.

  6. Question 6 · 1

    Which of the cloud deployment models requires the cloud customer to be part of a specific group or organization in order to host cloud services within it?

    Choose one answer.

    • Community
    • Hybrid
    • Private
    • Public
    Read explanation

    A community cloud model is where customers that share a certain common bond or group membership come together to offer cloud services to their members, focused on common goals and interests.

  7. Question 7 · 1

    What provides the information to an application to make decisions about the authorization level appropriate when granting access?

    Choose one answer.

    • User
    • Relying party
    • Federation
    • Identity Provider
  8. Question 8 · 1

    What is a standard configuration and policy set that is applied to systems and virtual machines called?

    Choose one answer.

    • Standardization
    • Baseline
    • Hardening
    • Redline
    Read explanation

    The most common and efficient manner of securing operating systems is through the use of baselines. A baseline is a standardized and understood set of base configurations and settings. When a new system is built or a new virtual machine is established, baselines will be applied to a new image to ensure the base configuration meets organizational policy and regulatory requirements.

  9. Question 9 · 1

    Which entity requires all collection and storing of data on their citizens to be done on hardware that resides within their borders?

    Choose one answer.

    • Russia
    • France
    • Germany
    • United States
  10. Question 10 · 1

    Which of the cloud cross-cutting aspects relates to the ability to easily move services and applications between different cloud providers?

    Choose one answer.

    • Reversibility
    • Availability
    • Portability
    • Interoperability
  11. Question 11 · 1

    Which type of audit report is considered a "restricted use" report for its intended audience?

    Choose one answer.

    • SAS-70
    • SSAE-16
    • SOC Type 1
    • SOC Type 2
  12. Question 12 · 1

    What is the concept of segregating information or processes, within the same system or application, for security reasons?

    Choose one answer.

    • fencing
    • Sandboxing
    • Cellblocking
    • Pooling
    Read explanation

    Sandboxing involves segregating and isolating information or processes from others within the same system or application, typically for security concerns. This is generally used for data isolation (for example, keeping different communities and populations of users isolated from other similar data).

  13. Question 13 · 1

    Which of the following approaches would NOT be considered sufficient to meet the requirements of secure data destruction within a cloud environment?

    Choose one answer.

    • Cryptographic erasure
    • Zeroing
    • Overwriting
    • Deletion
  14. Question 14 · 1

    The European Union passed the first major regulation declaring data privacy to be a human right. In what year did it go into effect?

    Choose one answer.

    • 2010
    • 2000
    • 1995
    • 1990
  15. Question 15 · 1

    Which of the following is NOT a key area for performance monitoring as far as an SLA is concerned?

    Choose one answer.

    • CPU
    • Users
    • Memory
    • Network
    Read explanation

    An SLA requires performance monitoring of CPU, memory, storage, and networking. The number of users active on a system would not be part of an SLA specifically, other than in regard to the impact on the other four variables.

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free