CCSP domain - 16% of the exam

Cloud Application Security

Cloud Application Security is 16% of the ISC2 Certified Cloud Security Professional (CCSP) exam. These are the objectives it covers, each with practice questions, with every answer explained.

Objectives in this domain

Sample question from this domain

Free sampleCloud Application Securityeasy

A team lead wants developer training to focus on the most common categories of web application security risk. Which resource is specifically designed to catalogue those widespread risks for awareness and training?

  • AThe OWASP Top 10, a consensus list of the most critical web application security risks. Correct
  • BThe shared responsibility model, which allocates security duties between the cloud provider and the customer.
  • CA service level agreement, which defines the availability and performance commitments of a cloud service.
  • DA recovery time objective, which sets the maximum tolerable duration to restore a service after disruption.
The OWASP Top 10 is the standard awareness reference for the most common web application security risks used in developer training. The OWASP Top 10 exists precisely to raise awareness of the categories of web application weakness that appear most often and cause the most harm, such as injection and broken access control. It gives training programmes a shared, prioritised vocabulary, which is why it is the resource pointed to for application security awareness rather than contractual or continuity artefacts.

Why A is correct: Correct. The OWASP Top 10 is a widely used awareness document that ranks the most common and impactful web application security risks.

Why B is wrong: Tempting because it is central to cloud security, but it divides operational responsibility rather than cataloguing common application vulnerabilities.

Why C is wrong: Tempting because it governs the provider relationship, but an SLA sets service commitments and does not list web application risks.

Why D is wrong: Tempting because it is a familiar security metric, but an RTO is a continuity target and has nothing to do with cataloguing application risks.

Other domains in this exam

See also the CCSP cert hub, the study guide, and the cheat sheet.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.