ISC2

ISC2 Certified Cloud Security Professional (CCSP) practice questions

Cloud architecture, data security, platform and application security, operations, and legal risk for the ISC2 Certified Cloud Security Professional exam.

New to CCSP? Read the how to pass ISC2 Certified Cloud Security Professional study guide for a domain breakdown, a study plan, and exam-day tips.

Revising? The CCSP cheat sheet puts the domain weightings, key facts, and easy-to-confuse traps on one printable page.

Prefer flashcards? See a free sample of the CCSP flashcard deck, concept and misconception cards side by side.

100 to 150
Questions
180 min
Time allowed
700 / 1000
Pass mark
$599
Exam cost (USD)
291
Practice questions

Exam domains and weighting

The CCSP blueprint is split across 6 domains. See the official exam guide for the authoritative breakdown.

CCSP domains by share of the exam
DomainWeight
Cloud Concepts, Architecture and Design17%
Cloud Data Security20%
Cloud Platform and Infrastructure Security17%
Cloud Application Security16%
Cloud Security Operations17%
Legal, Risk and Compliance13%

Free sample questions

No account needed. Every question explains why every answer is right or wrong, just like the full bank.

Free sampleCloud Data Securitymedium

A cloud team must let a downstream analytics service keep processing customer card numbers in the same fixed length and character layout, while ensuring the stored values can be swapped back to the originals only by an authorised service holding a mapping. Which technique meets this requirement?

  • ATokenisation that replaces each card number with a surrogate of the same length and format, resolvable only through a protected token vault Correct
  • BFormat-preserving encryption applied with a shared symmetric key printed in the application configuration
  • COne-way salted hashing of each card number before it is written to the analytics store
  • DStatic data masking that overwrites the middle digits with a fixed character while leaving the last four visible
Distinguish tokenisation from masking, hashing, and encryption by its format-preserving surrogate and vault-controlled reversibility. Tokenisation removes the sensitive value from the processing environment by storing a format-matching surrogate with no algorithmic link to the original; reversal is possible only through the separately protected token vault, which is exactly what a controlled swap-back with preserved layout demands.

Why A is correct: Tokenisation substitutes a format-matching surrogate that carries no mathematical relationship to the original, and only the vault holding the mapping can reverse it, satisfying both the format and controlled-reversal requirements.

Why B is wrong: Format-preserving encryption does keep the layout and is reversible, but storing the key in plaintext application config defeats the protection, so this is the weaker choice the requirement does not describe.

Why C is wrong: Hashing preserves neither the format in a useful way nor reversibility, so the originals could never be recovered, which contradicts the stated need to swap values back.

Why D is wrong: Masking is deliberately irreversible for the masked characters, so although it preserves the display format it cannot be swapped back to the original value as required.

Free sampleCloud Concepts, Architecture and Designeasy

A cloud provider allows tenants to view and adjust their allocated storage and compute through a self-service portal at any time, without contacting a sales or support representative. Which essential characteristic of cloud computing does this describe?

  • ABroad network access, where capabilities are available over the network and reached through standard client platforms such as browsers and mobile devices
  • BMeasured service, where resource use is monitored, controlled, and reported to give transparency for both the provider and the consumer
  • COn-demand self-service, where a consumer can provision computing capabilities unilaterally as needed without human interaction with the provider Correct
  • DRapid elasticity, where capabilities can be scaled outward and inward automatically to match demand and appear effectively unlimited
Recognise on-demand self-service as unilateral consumer provisioning without provider interaction. On-demand self-service is defined by the consumer provisioning capabilities such as compute and storage unilaterally and automatically, without requiring any human interaction with the service provider.

Why A is wrong: Broad network access concerns reachability across varied devices; it is tempting because a portal runs over the network, but the scenario stresses provisioning without staff, not device reach.

Why B is wrong: Measured service covers metering and billing transparency; the tenant does see usage, but the defining point here is unattended self-provisioning, not metering.

Why C is correct: The portal lets the tenant provision and adjust resources unilaterally with no provider staff involved, which is exactly the on-demand self-service characteristic in the NIST definition.

Why D is wrong: Rapid elasticity is about automatic scaling to demand; a candidate may confuse manual portal adjustment with elasticity, but the scenario describes human-initiated self-service rather than automatic scaling.

Free sampleCloud Platform and Infrastructure Securitymedium

In cloud infrastructure, which statement most accurately describes the management plane and why it is treated as a high-value target?

  • AIt is the aggregation of physical network switches and routers that carry east-west traffic between virtual machines within a single host.
  • BIt is the set of orchestration and administrative interfaces used to provision, configure and control the underlying compute, storage and network resources. Correct
  • CIt is the tenant-facing application layer where end users authenticate and consume the running workloads deployed on top of the platform.
  • DIt is the encrypted data-at-rest tier where tenant volumes and object stores are persisted across availability zones.
Identify the management plane as the orchestration and control layer whose compromise yields broad authority over cloud resources. The management plane exposes the administrative and orchestration APIs and consoles that create, configure and destroy compute, storage and network resources, so control of it means control of the entire environment, which is precisely why it is guarded so heavily.

Why A is wrong: This describes elements of the underlying physical network fabric, not the management plane; the fabric moves workload traffic but does not orchestrate provisioning or configuration.

Why B is correct: The management plane provides the administrative and orchestration control over the whole environment, so compromise of it grants broad authority over provisioning and configuration, making it a prime target.

Why C is wrong: This describes the application or workload layer that consumers interact with, whereas the management plane sits beneath it and controls the resources rather than serving the application to users.

Why D is wrong: This describes storage services, not the control interface; the management plane can configure storage but is not itself the persistence tier.

More free CCSP practice questions, every answer explained

Frequently asked questions

How many questions are on the cloud security certification exam?
The ISC2 Certified Cloud Security Professional (CCSP) exam has 100 to 150 questions and runs for 180 minutes. The format is multiple choice and advanced item types.
What score do I need to pass cloud security certification?
The pass mark is 700 / 1000. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
How much does the cloud security certification exam cost?
The exam costs 599 USD to sit. Practising on Examworthy is free to start, and every answer is explained, right and wrong.
Is there a cloud security certification practice exam?
Yes. Examworthy's exam mode runs a timed cloud security certification practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand. Timed mocks are free with an account.
How does Examworthy help me prepare for cloud security certification?
Every practice question explains why the right answer is right and why each wrong one is wrong, mapped to the official blueprint domains. You learn the reasoning, not just the letter.
Is Examworthy affiliated with ISC2?
No. Examworthy is not affiliated with or endorsed by ISC2. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.

Examworthy is not affiliated with or endorsed by ISC2. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CCSP and related marks belong to their respective owners.