10 free, exam-style Certificate of Cloud Security Knowledge (CCSK) v5 (CCSK) practice questions with answers and
explanations. No signup required. Work through them below, then take the
full free CCSK practice test to study every exam domain.
These 10 free CCSK questions are organized by exam domain, so you can see how each part of the Certificate of Cloud Security Knowledge (CCSK) v5 blueprint is tested. Reveal the answer and explanation under each question.
Domain 1: Cloud Computing Concepts and Architectures
Question 1
A startup chooses a cloud provider where they can deploy web applications by uploading code and the provider automatically handles server provisioning, load balancing, and scaling. The startup manages only the application code and its data. This BEST describes:
- IaaS with managed services
- PaaS
- SaaS with custom extensions
- Private cloud
Show answer & explanation
Correct answer: B - PaaS
Domain 2: Cloud Governance and Strategies
Question 2
An organization's cloud registry reveals that it is using 47 different SaaS applications, 12 of which were unknown to the IT team. The MOST appropriate governance response is to:
- Immediately block all 47 applications
- Assess each application against security policies, perform risk analysis, and bring unapproved services into compliance or decommission them
- Ignore the 12 unknown applications since they are already in use
- Transfer all applications to a single cloud provider
Show answer & explanation
Correct answer: B - Assess each application against security policies, perform risk analysis, and bring unapproved services into compliance or decommission them
Domain 3: Risk, Audit, and Compliance
Question 3
During risk monitoring (Step 4), a security team discovers that a cloud provider has changed its encryption practices. The MOST appropriate response is to:
- Ignore the change since the CSP manages encryption
- Reassess the risk, evaluate the impact of the change, and determine if additional controls are needed
- Immediately terminate the contract
- Accept the change without review
Show answer & explanation
Correct answer: B - Reassess the risk, evaluate the impact of the change, and determine if additional controls are needed
Domain 4: Organization Management
Question 4
A company has three business divisions: Finance, Engineering, and Marketing. Each division runs both production and development workloads. The MOST effective hierarchy design would be:
- A single account for all divisions
- Separate OUs for each division, with sub-OUs for production and development within each
- Separate accounts only for production, with all development in a single shared account
- No organizational hierarchy, relying on resource-level permissions only
Show answer & explanation
Correct answer: B - Separate OUs for each division, with sub-OUs for production and development within each
Domain 5: Identity and Access Management
Question 5
A user wants to allow a third-party application to access their cloud storage files without sharing their password. The MOST appropriate standard is:
- SAML
- OAuth 2.0, which enables delegated authorization without sharing credentials
- LDAP
- Kerberos
Show answer & explanation
Correct answer: B - OAuth 2.0, which enables delegated authorization without sharing credentials
Domain 6: Security Monitoring
Question 6
An organization needs to manage application vulnerabilities across its CI/CD pipeline, from code to production. The MOST appropriate tool category is:
- CSPM
- CWPP
- ASPM
- SSPM
Show answer & explanation
Correct answer: C - ASPM
Domain 7: Infrastructure and Networking
Question 7
An organization needs to allow HTTP (port 80) traffic to a web server and deny all other inbound traffic at the instance level. The MOST appropriate component is:
- Network ACL
- A security group with an allow rule for port 80 inbound
- Routing table
- Load balancer
Show answer & explanation
Correct answer: B - A security group with an allow rule for port 80 inbound
Domain 8: Cloud Workload Security
Question 8
An organization discovers a VM that was launched from an unapproved image not created by the image factory. The MOST appropriate action is:
- Leave the VM running since it is functional
- Investigate and remediate - replace the VM with one launched from an approved image and investigate how the unapproved image was used
- Promote the unapproved image to approved status
- Ignore it unless there is a security incident
Show answer & explanation
Correct answer: B - Investigate and remediate - replace the VM with one launched from an approved image and investigate how the unapproved image was used
Domain 9: Data Security
Question 9
An organization wants to encrypt data at rest but maintain full control of the encryption keys without the CSP storing them. The MOST appropriate approach is:
- Provider-managed keys
- Customer-managed keys in KMS
- Customer-supplied keys (BYOK) where keys are provided for each operation but not stored by the CSP
- No encryption
Show answer & explanation
Correct answer: C - Customer-supplied keys (BYOK) where keys are provided for each operation but not stored by the CSP
Domain 10: Application Security
Question 10
An organization wants to monitor the security configuration of its SaaS applications. The MOST appropriate tool is:
- CSPM
- SSPM (SaaS Security Posture Management)
- CWPP
- CDR
Show answer & explanation
Correct answer: B - SSPM (SaaS Security Posture Management)
The rest of the CCSK blueprint
The CCSK exam also covers these domains. Drill them in the full free practice test:
- Domain 11: Incident Response and Resilience
- Domain 12: Related Technologies and Strategies