Free ISC2 CCSP practice questions

10 free ISC2 CCSP practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 512 questions. Work through them, then open each answer to check your reasoning.

Question 1

Which of the following roles is responsible for creating cloud components and the testing and validation of services?

  1. Cloud auditor
  2. Inter-cloud provider
  3. Cloud service broker
  4. Cloud service developer
Show answer and explanation

Correct answer: D. Cloud service developer

A cloud service developer is the role responsible for creating cloud components and performing the testing and validation of services. This role focuses on the development lifecycle and quality assurance of cloud-based solutions, including design, implementation, and validation.

Why the other options are wrong

  • A. Cloud auditors review and assess security and compliance, not create components.
  • B. Inter-cloud providers facilitate communication between different cloud providers.
  • C. Cloud service brokers manage selection, deployment, and optimization of cloud services, not development.

Question 2

What is the best source for information about securing a physical asset's BIOS?

  1. Security policies
  2. Manual pages
  3. Vendor documentation
  4. Regulations
Show answer and explanation

Correct answer: C. Vendor documentation

Vendor documentation is the best source for information about securing a physical asset's BIOS because manufacturers provide detailed, accurate guidance specific to their hardware models, including security features, configuration options, and recommended settings.

Why the other options are wrong

  • A. Security policies provide organizational guidelines but not technical BIOS-specific details.
  • B. Manual pages typically refer to software manuals, not hardware BIOS documentation.
  • D. Regulations establish compliance requirements but not technical BIOS configuration details.

Question 3

Which of the following is not a component of contractual PII?

  1. Scope of processing
  2. Value of data
  3. Location of data
  4. Use of subcontractors
Show answer and explanation

Correct answer: B. Value of data

The value of data is not a standard component of contractual PII requirements. Contractual obligations for PII typically address scope of processing, location/storage of data, use of subcontractors, data protection measures, and breach notification, but not inherent monetary value assignments.

Why the other options are wrong

  • A. Scope of processing is a core contractual PII component defining what data operations are permitted.
  • C. Location of data is essential for contractual PII, specifying where personal information is stored and processed.
  • D. Use of subcontractors is a critical contractual PII element, as it affects data handling responsibility and liability.

Question 4

Which of the following concepts refers to a cloud customer paying only for the resources and offerings they use within a cloud environment, and only for the duration that they are consuming them?

  1. Consumable service
  2. Measured service
  3. Billable service
  4. Metered service
Show answer and explanation

Correct answer: B. Measured service

Measured service is the NIST term for the cloud characteristic where usage is monitored, controlled, and reported, allowing customers to pay only for resources and services consumed during the period they use them, enabling transparent billing models.

Why the other options are wrong

  • A. Consumable service is not a standard cloud computing term.
  • C. Billable service describes the outcome of measurement but is not the official cloud computing concept.
  • D. Metered service is similar but measured service is the established NIST terminology for this characteristic.

Question 5

Which of the following roles involves testing, monitoring, and securing cloud services for an organization?

  1. Cloud service integrator
  2. Cloud service business manager
  3. Cloud service user
  4. Cloud service administrator
Show answer and explanation

Correct answer: D. Cloud service administrator

A cloud service administrator is responsible for testing, monitoring, and securing cloud services for an organization. This role manages the operational aspects of cloud services including configuration, performance monitoring, security controls, and ongoing maintenance.

Why the other options are wrong

  • A. Cloud service integrators focus on combining and integrating cloud services, not testing and securing them.
  • B. Cloud service business managers handle business aspects and strategy, not technical testing and securing.
  • C. Cloud service users consume cloud services but do not test, monitor, or secure them administratively.

Question 6

What is the only data format permitted with the SOAP API?

  1. HTML
  2. SAML
  3. XSML
  4. XML
Show answer and explanation

Correct answer: D. XML

XML is the only data format permitted with the SOAP API. SOAP uses XML exclusively for its message structure, envelope format, and protocol definitions, making it the mandatory data format for SOAP communications.

Why the other options are wrong

  • A. HTML is a markup language for web pages, not used by SOAP.
  • B. SAML is a security assertion markup language for authentication, not a SOAP data format.
  • C. XSML is not a standard data format used with SOAP APIs.

Question 7

Which data formats are most commonly used with the REST API?

  1. JSON and SAML
  2. XML and SAML
  3. XML and JSON
  4. SAML and HTML
Show answer and explanation

Correct answer: C. XML and JSON

XML and JSON are the most commonly used data formats with REST APIs. REST is flexible and supports multiple formats, but JSON and XML are the industry standards for REST API requests and responses due to their simplicity and broad support.

Why the other options are wrong

  • A. SAML is an authentication protocol, not a typical REST API data format.
  • B. SAML is not a REST API data format; while XML is correct, SAML is not paired with it here.
  • D. SAML and HTML are not the standard REST API formats; HTML is for web pages, not APIs.

Question 8

Which of the following threat types involves an application that does not validate authorization for portions of itself after the initial checks?

  1. Injection
  2. Missing function-level access control
  3. Cross-site request forgery
  4. Cross-site scripting
Show answer and explanation

Correct answer: B. Missing function-level access control

Missing function-level access control refers to applications that fail to validate authorization for specific functions after initial authentication checks. An attacker can access restricted functions by directly calling them, bypassing intended access controls at the function or method level.

Why the other options are wrong

  • A. Injection attacks involve inserting malicious code into application inputs, not authorization validation failures.
  • C. Cross-site request forgery tricks authenticated users into performing unwanted actions, but doesn't specifically involve missing function-level authorization.
  • D. Cross-site scripting involves injecting malicious scripts into web pages, not authorization validation at the function level.

Question 9

Which of the following roles involves overseeing billing, purchasing, and requesting audit reports for an organization within a cloud environment?

  1. Cloud service user
  2. Cloud service business manager
  3. Cloud service administrator
  4. Cloud service integrator
Show answer and explanation

Correct answer: B. Cloud service business manager

The Cloud Service Business Manager is responsible for overseeing business-related aspects including billing, purchasing, and requesting audit reports. This role bridges business and technical operations within cloud environments.

Why the other options are wrong

  • A. Cloud service users consume services but do not manage billing or audit processes.
  • C. Cloud service administrators focus on technical infrastructure management, not business billing and purchasing.
  • D. Cloud service integrators specialize in connecting systems and services, not financial oversight.

Question 10

What is the biggest concern with hosting a key management system outside of the cloud environment?

  1. Confidentiality
  2. Portability
  3. Availability
  4. Integrity
Show answer and explanation

Correct answer: C. Availability

Hosting a key management system outside the cloud environment creates the biggest availability concern because access to encryption keys may be delayed or interrupted if external systems experience outages, directly impacting the ability to decrypt data in the cloud.

Why the other options are wrong

  • A. While confidentiality is important, it can be protected through secure transmission protocols and authentication.
  • B. Portability is not primarily affected by external key management hosting.
  • D. Integrity of keys can be maintained through cryptographic controls and auditing regardless of location.

That was 10 of 512.

The full ISC2 CCSP pack has all 512 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack