10 free ISC2 CCSP practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 512 questions. Work through them, then open each answer to check your reasoning.
Get all 512 questions (US$39) · Download these 10 as a PDF
Question 1
Which of the following roles is responsible for creating cloud components and the testing and validation of services?
Show answer and explanation
Correct answer: D. Cloud service developer
A cloud service developer is the role responsible for creating cloud components and performing the testing and validation of services. This role focuses on the development lifecycle and quality assurance of cloud-based solutions, including design, implementation, and validation.
Why the other options are wrong
- A. Cloud auditors review and assess security and compliance, not create components.
- B. Inter-cloud providers facilitate communication between different cloud providers.
- C. Cloud service brokers manage selection, deployment, and optimization of cloud services, not development.
Question 2
What is the best source for information about securing a physical asset's BIOS?
Show answer and explanation
Correct answer: C. Vendor documentation
Vendor documentation is the best source for information about securing a physical asset's BIOS because manufacturers provide detailed, accurate guidance specific to their hardware models, including security features, configuration options, and recommended settings.
Why the other options are wrong
- A. Security policies provide organizational guidelines but not technical BIOS-specific details.
- B. Manual pages typically refer to software manuals, not hardware BIOS documentation.
- D. Regulations establish compliance requirements but not technical BIOS configuration details.
Question 3
Which of the following is not a component of contractual PII?
Show answer and explanation
Correct answer: B. Value of data
The value of data is not a standard component of contractual PII requirements. Contractual obligations for PII typically address scope of processing, location/storage of data, use of subcontractors, data protection measures, and breach notification, but not inherent monetary value assignments.
Why the other options are wrong
- A. Scope of processing is a core contractual PII component defining what data operations are permitted.
- C. Location of data is essential for contractual PII, specifying where personal information is stored and processed.
- D. Use of subcontractors is a critical contractual PII element, as it affects data handling responsibility and liability.
Question 4
Which of the following concepts refers to a cloud customer paying only for the resources and offerings they use within a cloud environment, and only for the duration that they are consuming them?
Show answer and explanation
Correct answer: B. Measured service
Measured service is the NIST term for the cloud characteristic where usage is monitored, controlled, and reported, allowing customers to pay only for resources and services consumed during the period they use them, enabling transparent billing models.
Why the other options are wrong
- A. Consumable service is not a standard cloud computing term.
- C. Billable service describes the outcome of measurement but is not the official cloud computing concept.
- D. Metered service is similar but measured service is the established NIST terminology for this characteristic.
Question 5
Which of the following roles involves testing, monitoring, and securing cloud services for an organization?
Show answer and explanation
Correct answer: D. Cloud service administrator
A cloud service administrator is responsible for testing, monitoring, and securing cloud services for an organization. This role manages the operational aspects of cloud services including configuration, performance monitoring, security controls, and ongoing maintenance.
Why the other options are wrong
- A. Cloud service integrators focus on combining and integrating cloud services, not testing and securing them.
- B. Cloud service business managers handle business aspects and strategy, not technical testing and securing.
- C. Cloud service users consume cloud services but do not test, monitor, or secure them administratively.
Question 6
What is the only data format permitted with the SOAP API?
Show answer and explanation
Correct answer: D. XML
XML is the only data format permitted with the SOAP API. SOAP uses XML exclusively for its message structure, envelope format, and protocol definitions, making it the mandatory data format for SOAP communications.
Why the other options are wrong
- A. HTML is a markup language for web pages, not used by SOAP.
- B. SAML is a security assertion markup language for authentication, not a SOAP data format.
- C. XSML is not a standard data format used with SOAP APIs.
Question 7
Which data formats are most commonly used with the REST API?
Show answer and explanation
Correct answer: C. XML and JSON
XML and JSON are the most commonly used data formats with REST APIs. REST is flexible and supports multiple formats, but JSON and XML are the industry standards for REST API requests and responses due to their simplicity and broad support.
Why the other options are wrong
- A. SAML is an authentication protocol, not a typical REST API data format.
- B. SAML is not a REST API data format; while XML is correct, SAML is not paired with it here.
- D. SAML and HTML are not the standard REST API formats; HTML is for web pages, not APIs.
Question 8
Which of the following threat types involves an application that does not validate authorization for portions of itself after the initial checks?
Show answer and explanation
Correct answer: B. Missing function-level access control
Missing function-level access control refers to applications that fail to validate authorization for specific functions after initial authentication checks. An attacker can access restricted functions by directly calling them, bypassing intended access controls at the function or method level.
Why the other options are wrong
- A. Injection attacks involve inserting malicious code into application inputs, not authorization validation failures.
- C. Cross-site request forgery tricks authenticated users into performing unwanted actions, but doesn't specifically involve missing function-level authorization.
- D. Cross-site scripting involves injecting malicious scripts into web pages, not authorization validation at the function level.
Question 9
Which of the following roles involves overseeing billing, purchasing, and requesting audit reports for an organization within a cloud environment?
Show answer and explanation
Correct answer: B. Cloud service business manager
The Cloud Service Business Manager is responsible for overseeing business-related aspects including billing, purchasing, and requesting audit reports. This role bridges business and technical operations within cloud environments.
Why the other options are wrong
- A. Cloud service users consume services but do not manage billing or audit processes.
- C. Cloud service administrators focus on technical infrastructure management, not business billing and purchasing.
- D. Cloud service integrators specialize in connecting systems and services, not financial oversight.
Question 10
What is the biggest concern with hosting a key management system outside of the cloud environment?
Show answer and explanation
Correct answer: C. Availability
Hosting a key management system outside the cloud environment creates the biggest availability concern because access to encryption keys may be delayed or interrupted if external systems experience outages, directly impacting the ability to decrypt data in the cloud.
Why the other options are wrong
- A. While confidentiality is important, it can be protected through secure transmission protocols and authentication.
- B. Portability is not primarily affected by external key management hosting.
- D. Integrity of keys can be maintained through cryptographic controls and auditing regardless of location.
That was 10 of 512.
The full ISC2 CCSP pack has all 512 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
