CCSK Exam Prep Free practice test →

Free CCSK Practice Questions

10 free, exam-style Certificate of Cloud Security Knowledge (CCSK) v5 (CCSK) practice questions with answers and explanations. No signup required. Work through them below, then take the full free CCSK practice test to study every exam domain.

These 10 free CCSK questions are organized by exam domain, so you can see how each part of the Certificate of Cloud Security Knowledge (CCSK) v5 blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Cloud Computing Concepts and Architectures

Question 1

A startup chooses a cloud provider where they can deploy web applications by uploading code and the provider automatically handles server provisioning, load balancing, and scaling. The startup manages only the application code and its data. This BEST describes:

  1. IaaS with managed services
  2. PaaS
  3. SaaS with custom extensions
  4. Private cloud
Show answer & explanation

Correct answer: B - PaaS

Domain 2: Cloud Governance and Strategies

Question 2

An organization's cloud registry reveals that it is using 47 different SaaS applications, 12 of which were unknown to the IT team. The MOST appropriate governance response is to:

  1. Immediately block all 47 applications
  2. Assess each application against security policies, perform risk analysis, and bring unapproved services into compliance or decommission them
  3. Ignore the 12 unknown applications since they are already in use
  4. Transfer all applications to a single cloud provider
Show answer & explanation

Correct answer: B - Assess each application against security policies, perform risk analysis, and bring unapproved services into compliance or decommission them

Domain 3: Risk, Audit, and Compliance

Question 3

During risk monitoring (Step 4), a security team discovers that a cloud provider has changed its encryption practices. The MOST appropriate response is to:

  1. Ignore the change since the CSP manages encryption
  2. Reassess the risk, evaluate the impact of the change, and determine if additional controls are needed
  3. Immediately terminate the contract
  4. Accept the change without review
Show answer & explanation

Correct answer: B - Reassess the risk, evaluate the impact of the change, and determine if additional controls are needed

Domain 4: Organization Management

Question 4

A company has three business divisions: Finance, Engineering, and Marketing. Each division runs both production and development workloads. The MOST effective hierarchy design would be:

  1. A single account for all divisions
  2. Separate OUs for each division, with sub-OUs for production and development within each
  3. Separate accounts only for production, with all development in a single shared account
  4. No organizational hierarchy, relying on resource-level permissions only
Show answer & explanation

Correct answer: B - Separate OUs for each division, with sub-OUs for production and development within each

Domain 5: Identity and Access Management

Question 5

A user wants to allow a third-party application to access their cloud storage files without sharing their password. The MOST appropriate standard is:

  1. SAML
  2. OAuth 2.0, which enables delegated authorization without sharing credentials
  3. LDAP
  4. Kerberos
Show answer & explanation

Correct answer: B - OAuth 2.0, which enables delegated authorization without sharing credentials

Domain 6: Security Monitoring

Question 6

An organization needs to manage application vulnerabilities across its CI/CD pipeline, from code to production. The MOST appropriate tool category is:

  1. CSPM
  2. CWPP
  3. ASPM
  4. SSPM
Show answer & explanation

Correct answer: C - ASPM

Domain 7: Infrastructure and Networking

Question 7

An organization needs to allow HTTP (port 80) traffic to a web server and deny all other inbound traffic at the instance level. The MOST appropriate component is:

  1. Network ACL
  2. A security group with an allow rule for port 80 inbound
  3. Routing table
  4. Load balancer
Show answer & explanation

Correct answer: B - A security group with an allow rule for port 80 inbound

Domain 8: Cloud Workload Security

Question 8

An organization discovers a VM that was launched from an unapproved image not created by the image factory. The MOST appropriate action is:

  1. Leave the VM running since it is functional
  2. Investigate and remediate - replace the VM with one launched from an approved image and investigate how the unapproved image was used
  3. Promote the unapproved image to approved status
  4. Ignore it unless there is a security incident
Show answer & explanation

Correct answer: B - Investigate and remediate - replace the VM with one launched from an approved image and investigate how the unapproved image was used

Domain 9: Data Security

Question 9

An organization wants to encrypt data at rest but maintain full control of the encryption keys without the CSP storing them. The MOST appropriate approach is:

  1. Provider-managed keys
  2. Customer-managed keys in KMS
  3. Customer-supplied keys (BYOK) where keys are provided for each operation but not stored by the CSP
  4. No encryption
Show answer & explanation

Correct answer: C - Customer-supplied keys (BYOK) where keys are provided for each operation but not stored by the CSP

Domain 10: Application Security

Question 10

An organization wants to monitor the security configuration of its SaaS applications. The MOST appropriate tool is:

  1. CSPM
  2. SSPM (SaaS Security Posture Management)
  3. CWPP
  4. CDR
Show answer & explanation

Correct answer: B - SSPM (SaaS Security Posture Management)

The rest of the CCSK blueprint

The CCSK exam also covers these domains. Drill them in the full free practice test:

Ready for the real thing?

Practice hundreds more CCSK questions with instant scoring, weak-area drills, and full exam simulations.

Start the free practice test See pricing