CCSP 2026 Flashcards: August Exam Outline Review

A 340-card, six-domain review for the CCSP outline effective August 1, 2026, including cloud AI/ML, dataset, model, and LLM application security.

Về bộ thẻ này

This 340-card deck reviews all six domains in the English CCSP exam outline effective August 1, 2026: Cloud Concepts, Architecture and Design; Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk and Compliance.

What you'll retrieve

  • Separate cloud service, deployment, architecture, data, identity, assurance, operations, risk, privacy, audit, and contract concepts that are easy to confuse.
  • Map customer, provider, security, data, privacy, audit, incident, and vendor roles to their primary responsibility boundary.
  • Choose a practical control for a short cloud scenario, then state the risk or failure mode it chiefly addresses.
  • Make focused architecture, lifecycle, recovery, testing, monitoring, service-management, and outsourcing decisions from stated requirements, including service-level management, availability management, Quality Assurance, audit planning, and provider-risk assessment.
  • Recognize revised AI and ML concerns across cloud threat detection, dataset and model privacy, data and model poisoning, provenance, model inversion and extraction, human oversight, and LLM application risks.

Selected reverse and contrast prompts are included where they improve retrieval, such as elasticity versus scalability, portability versus interoperability, RTO versus RPO, hashing versus encryption, controller versus processor, IDS versus IPS, and incident versus problem management. The deck does not mechanically reverse every fact.

Exam-format multiple choice, memorized answer patterns, dumps, vendor-console trivia, copied course wording, and legal advice are excluded. The cards do not reproduce real or simulated ISC2 exam items. They also stay outside deep cryptographic mathematics, product-specific implementation recipes, and specialist AI research that does not change a cloud-security control decision.

The order is deliberate. Each domain advances through short, coherent topic tracks from prerequisite concepts and responsibility boundaries to controls and applied decisions. The final 340-card sequence was reviewed as one topic-progressive order, with identified forward, reverse, near-duplicate, and answer-cue variants deliberately separated to reduce short-range cueing. Its topic tracks are interleaved so the sequence does not become a concept run followed by role, control, and decision runs. Domain 1 establishes cloud characteristics, actors, service and deployment models, secure design, provider evidence, and AI governance. Domain 2 follows data through flows, storage, protection, discovery, classification, rights, retention, evidence, and dataset or model risk. Domains 3 and 4 apply those foundations to infrastructure, resilience, secure development, software supply chains, APIs, LLM applications, and IAM. Domains 5 and 6 close with secure operations, monitoring, incident response, forensics, law, privacy, audit, enterprise risk, and contracts.

Reviewed for the CCSP outline effective August 1, 2026. Coverage was bounded by the official English exam outline PDF, the ISC2 outline page, and ISC2's June 2026 revision notice. NIST and OWASP primary publications were used to check standard control and AI/application-security distinctions.

Every prompt, answer, explanation, sequence choice, and metadata field was independently written from common cloud-security knowledge. The CC0 label applies to that original expression, organization, metadata, and generated cover to the extent applicable rights exist; it does not claim ownership of facts, standards, certification marks, or third-party material.

This is an independently authored, unofficial educational deck by Flashcards Open Source App. It is not affiliated with, sponsored by, or endorsed by ISC2. CCSP is a registered certification mark of ISC2. No ISC2 exam questions, answer keys, course text, outline prose, logos, badges, or trade dress were copied.

Thẻ trong bộ này

  1. Thẻ 1

    Câu hỏi

    What makes a computing environment a cloud rather than ordinary hosted infrastructure?

    Câu trả lời

    It provides shared, configurable resources on demand with rapid provisioning and minimal provider interaction. A hosted server without those operating characteristics is not automatically a cloud.

  2. Thẻ 2

    Câu hỏi

    What is the security significance of broad network access?

    Câu trả lời

    Services are reachable through standard network mechanisms from varied clients. That reach increases the need for strong identity, transport protection, and endpoint-aware access.

  3. Thẻ 3

    Câu hỏi

    How do resource pooling and multi-tenancy differ?

    Câu trả lời

    Resource pooling dynamically assigns shared capacity; multi-tenancy lets multiple customers use that shared environment with logical isolation. Pooling is the allocation model, while multi-tenancy is the customer-sharing model.

  4. Thẻ 4

    Câu hỏi

    What separates elasticity from scalability?

    Câu trả lời

    Elasticity adjusts capacity with demand; scalability is the ability to handle growth by adding or changing capacity. Elasticity stresses timely adjustment, often in both directions.

  5. Thẻ 5

    Câu hỏi

    What does measured service provide?

    Câu trả lời

    Metered visibility into resource consumption. The measurements support billing, capacity decisions, anomaly detection, and accountability.

  6. Thẻ 6

    Câu hỏi

    What does on-demand self-service let a cloud customer do?

    Câu trả lời

    Provision needed capabilities without waiting for a provider employee. Policy and quota controls can still constrain the request.

  7. Thẻ 7

    Câu hỏi

    What does virtualization contribute to cloud computing?

    Câu trả lời

    It abstracts physical resources into isolated, assignable compute, storage, or network units. Orchestration turns those units into an on-demand service.

  8. Thẻ 8

    Câu hỏi

    What remains the cloud customer's responsibility in every service category?

    Câu trả lời

    Governing its identities, data, configuration choices, and lawful use. The exact technical boundary changes, but accountability does not vanish when infrastructure is outsourced.

  9. Thẻ 9

    Câu hỏi

    What does a cloud service broker add?

    Câu trả lời

    Intermediation, aggregation, or management across cloud services. A broker may compare, combine, or govern services without owning their underlying infrastructure.

  10. Thẻ 10

    Câu hỏi

    What is a regulator's cloud-security role?

    Câu trả lời

    Set or enforce legal and regulatory obligations that apply to the service and its data. The customer must map those duties into provider selection, controls, and evidence.

  11. Thẻ 11

    Câu hỏi

    What is the cloud service provider's core responsibility?

    Câu trả lời

    Deliver the contracted cloud capabilities and secure the layers assigned to it. The service model and contract define the boundary.

  12. Thẻ 12

    Câu hỏi

    What is orchestration in a cloud environment?

    Câu trả lời

    Coordinated automation of provisioning, configuration, scaling, and lifecycle actions across resources. It applies policy consistently across many components.

  13. Thẻ 13

    Câu hỏi

    What capability does SaaS give the customer?

    Câu trả lời

    Use of a provider-run application. The customer mainly manages users, data, and allowed configuration rather than the platform beneath it.

  14. Thẻ 14

    Câu hỏi

    Which four deployment models does NIST SP 800-145 define?

    Câu trả lời

    Public, private, community, and hybrid cloud. Multi-cloud describes using more than one cloud provider or service environment; it is distinct from NIST's canonical four-model taxonomy.

  15. Thẻ 15

    Câu hỏi

    How do portability and interoperability differ?

    Câu trả lời

    Portability moves a workload or data between environments; interoperability lets different environments exchange and use information or services. One reduces switching friction, while the other supports cooperation.

  16. Thẻ 16

    Câu hỏi

    What does a cloud service partner do?

    Câu trả lời

    Supports or enhances cloud service delivery, use, or assurance. Examples include auditors, integrators, and developers acting beside the customer and provider.

  17. Thẻ 17

    Câu hỏi

    Who controls user entitlements inside a SaaS tenant?

    Câu trả lời

    The customer organization. The provider supplies the application and access mechanisms, but the customer decides which of its users need which privileges.

  18. Thẻ 18

    Câu hỏi

    When is hybrid cloud a better description than multi-cloud?

    Câu trả lời

    When the architecture deliberately combines distinct private and public environments. Multi-cloud focuses on using multiple cloud services or providers and may contain no private cloud.

  19. Thẻ 19

    Câu hỏi

    What problem does confidential computing address?

    Câu trả lời

    Protection of data while it is being processed. Hardware-backed trusted execution environments reduce exposure to the host or platform layer, but do not replace application controls.

  20. Thẻ 20

    Câu hỏi

    When does blockchain add useful assurance to a cloud workflow?

    Câu trả lời

    When multiple parties need a shared, tamper-evident record without relying on one writer. It does not make source data true, private, lawful, or immune to key and smart-contract failures.

  21. Thẻ 21

    Câu hỏi

    When does edge computing improve resilience but complicate security?

    Câu trả lời

    When local processing reduces central latency or dependency while distributing data, software, and physical exposure. The decision needs remote attestation, patching, inventory, and failure handling.

  22. Thẻ 22

    Câu hỏi

    What does reversibility require in a cloud design?

    Câu trả lời

    A practical way to exit or change providers while recovering data, configurations, dependencies, and needed evidence. A theoretical export button is not enough if the result cannot be used elsewhere.

  23. Thẻ 23

    Câu hỏi

    What is the first security question before connecting IoT devices to a cloud service?

    Câu trả lời

    Can each device be uniquely identified, updated, constrained, and monitored throughout its lifecycle? Cheap connectivity does not offset unmanaged device risk.

  24. Thẻ 24

    Câu hỏi

    What capability does PaaS give the customer?

    Câu trả lời

    Deployment of customer applications onto a provider-managed platform. The provider runs the underlying infrastructure and runtime, while the customer secures code, data, and configuration.

  25. Thẻ 25

    Câu hỏi

    What is a practical cloud decision for quantum-related cryptographic risk today?

    Câu trả lời

    Inventory cryptographic dependencies and design for algorithm agility. Replace algorithms according to authoritative migration guidance rather than adopting unreviewed schemes.

  26. Thẻ 26

    Câu hỏi

    Which SLA measure is useful only when paired with a clear measurement method and remedy?

    Câu trả lời

    Any availability or performance target. Define the service boundary, observation window, exclusions, data source, notification, and remedy before treating the number as assurance.

  27. Thẻ 27

    Câu hỏi

    How should a team use a Well-Architected pattern, SANS security principles, or CSA enterprise architecture?

    Câu trả lời

    As structured design input mapped to the workload's risks, responsibilities, and evidence. A named framework guides decisions but does not prove that the resulting architecture is secure.

  28. Thẻ 28

    Câu hỏi

    What does a FIPS 140 validation establish?

    Câu trả lời

    That a named cryptographic module was validated against the stated standard and boundary. It does not prove the surrounding application uses the module safely.

  29. Thẻ 29

    Câu hỏi

    Who normally patches the managed runtime in PaaS?

    Câu trả lời

    The cloud provider. The customer still owns secure application code, dependencies it supplies, data, identities, and configuration.

  30. Thẻ 30

    Câu hỏi

    Who should approve a cloud data classification?

    Câu trả lời

    The accountable data owner. Security and privacy teams advise, while custodians implement the handling controls.

  31. Thẻ 31

    Câu hỏi

    What should the cloud architect own in secure design?

    Câu trả lời

    The documented trust boundaries, security requirements, resilience choices, and responsibility mapping. Operations and product teams then implement and test those decisions.

  32. Thẻ 32

    Câu hỏi

    What does DevSecOps change about security ownership?

    Câu trả lời

    It makes security a shared, automated part of delivery rather than a final external gate. Product teams still need independent challenge for high-risk decisions.

  33. Thẻ 33

    Câu hỏi

    Which controls reduce container escape impact?

    Câu trả lời

    Hardened runtimes, minimal privileges, trusted images, isolation boundaries, and prompt patching. Treat a container as a process boundary, not automatically as a security boundary equal to a separate host.

  34. Thẻ 34

    Câu hỏi

    Who should own a cloud service's business recovery requirements?

    Câu trả lời

    The business or service owner. Technical teams translate the owner's impact tolerance into RTO, RPO, architecture, and tests.

  35. Thẻ 35

    Câu hỏi

    What capability does IaaS give the customer?

    Câu trả lời

    Provisioning of fundamental compute, storage, and network resources. The customer usually controls operating systems, workloads, and many network settings.

  36. Thẻ 36

    Câu hỏi

    Which key-management design limits a cloud provider compromise from exposing customer data?

    Câu trả lời

    Separate data from independently controlled encryption keys where the threat model requires it. Access policy, rotation, backup, and recovery for those keys matter as much as their location.

  37. Thẻ 37

    Câu hỏi

    What is the safer identity pattern for a cloud workload?

    Câu trả lời

    A short-lived, narrowly scoped workload identity. It avoids embedded long-lived credentials and supports rotation and traceability.

  38. Thẻ 38

    Câu hỏi

    When can cryptographic erase sanitize cloud data?

    Câu trả lời

    When destroying the correct encryption key makes all protected copies computationally unreadable and the encryption implementation is trustworthy. Key copies, snapshots, and replicas must be in scope.

  39. Thẻ 39

    Câu hỏi

    What is the first network control for limiting east-west movement between cloud workloads?

    Câu trả lời

    Explicit segmentation with deny-by-default rules. Identity-aware policy and traffic telemetry strengthen the boundary; geofencing can add a location condition but cannot replace it.

  40. Thẻ 40

    Câu hỏi

    Who normally patches a guest operating system in IaaS?

    Câu trả lời

    The cloud customer. The provider secures the underlying facilities and virtualization layer, while the customer manages the guest unless a separate managed service changes that boundary.

  41. Thẻ 41

    Câu hỏi

    What is the most important permission control for a serverless function?

    Câu trả lời

    A dedicated least-privilege execution identity. Also restrict triggers, secrets, outbound access, and runtime duration; ephemeral execution does not erase external logs, queues, or data.

  42. Thẻ 42

    Câu hỏi

    How does immutable infrastructure reduce configuration drift?

    Câu trả lời

    Replace changed instances from a controlled image instead of repairing them in place. The image pipeline, secrets, and state stores still need protection.

  43. Thẻ 43

    Câu hỏi

    What turns a security baseline into an operating control?

    Câu trả lời

    Automated assessment plus timely remediation of deviations. A baseline document alone does not prevent drift.

  44. Thẻ 44

    Câu hỏi

    What control keeps protection aligned as cloud data moves through its lifecycle?

    Câu trả lời

    Lifecycle-aware policy tied to classification and ownership. Access, encryption, retention, monitoring, and disposal should change with the data's state and purpose.

  45. Thẻ 45

    Câu hỏi

    What makes a cloud recovery plan credible?

    Câu trả lời

    Regular restore, failover, dependency, and failback tests against business targets. A provider's availability claim does not prove the customer's service can recover.

  46. Thẻ 46

    Câu hỏi

    What evidence should be checked first when evaluating a cloud provider?

    Câu trả lời

    Evidence mapped to the organization's own requirements and risk criteria. Certifications help only when their scope, period, system, and exceptions cover the intended service.

  47. Thẻ 47

    Câu hỏi

    What should drive a cloud BC/DR design before products are selected?

    Câu trả lời

    A business impact analysis. It identifies critical services, dependencies, impact over time, and acceptable recovery targets.

  48. Thẻ 48

    Câu hỏi

    Who is accountable for approving an AI model's intended cloud use?

    Câu trả lời

    The designated AI or business system owner. Model builders provide evidence, while risk, security, privacy, and legal roles challenge the use against policy.

  49. Thẻ 49

    Câu hỏi

    What should be tested before accepting a provider's portability claim?

    Câu trả lời

    Export the data and configuration, rebuild elsewhere, and measure missing features, time, cost, and dependencies. Contract wording alone cannot prove reversibility.

  50. Thẻ 50

    Câu hỏi

    What control most directly reduces hypervisor compromise risk for a customer?

    Câu trả lời

    Use a provider with strong isolation assurance, rapid patching, and evidence for the virtualization layer. The customer cannot harden a provider-managed hypervisor directly.

  51. Thẻ 51

    Câu hỏi

    How should CBA and ROI inform a cloud recovery design after the BIA?

    Câu trả lời

    CBA compares each option's lifecycle cost with expected benefit; ROI expresses the expected return relative to investment. Neither overrides mandatory duties or the BIA's approved impact tolerance.

  52. Thẻ 52

    Câu hỏi

    What control helps validate training or detection data before AI use?

    Câu trả lời

    Provenance, integrity checks, schema checks, and approval for the intended source. Statistical anomaly checks can add evidence but should not replace ownership.

  53. Thẻ 53

    Câu hỏi

    What is the human reviewer's role in AI-assisted security operations?

    Câu trả lời

    Validate consequential findings and actions before relying on them. Automation can rank and enrich signals, but the accountable human handles ambiguity and impact.

  54. Thẻ 54

    Câu hỏi

    Why read an assurance report's scope before relying on its conclusion?

    Câu trả lời

    The report may exclude the exact service, region, control, subservice, or period you need. Assurance cannot be extended beyond its stated boundary.

  55. Thẻ 55

    Câu hỏi

    Which controls make model extraction harder at a cloud API?

    Câu trả lời

    Strong access control, rate and budget limits, query monitoring, response minimization, and abuse detection. No single control removes the risk from a publicly queryable model.

  56. Thẻ 56

    Câu hỏi

    Why is high predictive accuracy insufficient for a cloud data-science or AI model?

    Câu trả lời

    The use can still create unacceptable legal, privacy, fairness, security, safety, or operational risk. Accuracy is one quality measure, not automatic authorization to deploy.

  57. Thẻ 57

    Câu hỏi

    How should SOAR handle a high-impact containment action?

    Câu trả lời

    Use explicit authorization, bounded playbooks, and human approval when impact or uncertainty is high. Automation should be reversible and fully logged.

  58. Thẻ 58

    Câu hỏi

    When is Common Criteria evidence relevant to provider evaluation?

    Câu trả lời

    When a specific evaluated product and assurance target match the component and threat being assessed. It does not certify an entire cloud service by association.

  59. Thẻ 59

    Câu hỏi

    Which data lifecycle sequence is useful for cloud control planning?

    Câu trả lời

    Create, store, use, share, archive, and destroy. Real data may move between phases, but each transition needs an owner and handling rule.

  60. Thẻ 60

    Câu hỏi

    What is data dispersion in cloud computing?

    Câu trả lời

    The distribution of data and copies across systems, regions, media, services, and providers. Replicas, caches, logs, snapshots, and backups all expand the control boundary.

  61. Thẻ 61

    Câu hỏi

    What does a cloud data flow describe?

    Câu trả lời

    Where data originates, moves, is transformed, is stored, and exits. A useful flow also names trust boundaries, actors, purposes, and protections.

  62. Thẻ 62

    Câu hỏi

    How do object and volume storage differ?

    Câu trả lời

    Object storage addresses data as objects with metadata; volume storage presents block-like storage to a host. Their access paths, sharing models, snapshots, and permission risks differ.

  63. Thẻ 63

    Câu hỏi

    How does ephemeral storage differ from long-term storage?

    Câu trả lời

    Ephemeral storage is tied to a short-lived workload or execution; long-term storage is designed to persist independently. Ephemeral does not mean automatically sanitized.

  64. Thẻ 64

    Câu hỏi

    What is raw data storage?

    Câu trả lời

    Storage of collected data before full cleaning, transformation, or enrichment. Its broad content and uncertain quality make isolation, discovery, provenance, and access control especially important.

  65. Thẻ 65

    Câu hỏi

    What makes a data-flow map useful for control design?

    Câu trả lời

    It names sources, destinations, transformations, actors, purposes, trust boundaries, and protections. Update it when architecture or processing changes.

  66. Thẻ 66

    Câu hỏi

    What should decide whether data may move to another cloud region?

    Câu trả lời

    Classification, purpose, residency and transfer rules, contract terms, threat model, and required controls. Region availability alone is not authorization.

  67. Thẻ 67

    Câu hỏi

    Which storage type fits immutable, widely shared blobs better than a mounted transactional filesystem?

    Câu trả lời

    Object storage. Use volume storage when the workload needs block-style filesystem or database access semantics.

  68. Thẻ 68

    Câu hỏi

    A short-lived AI training node is terminated. Why can data risk remain?

    Câu trả lời

    Ephemeral compute can leave snapshots, caches, logs, attached volumes, or provider-level remnants. Verify the full storage and key lifecycle, not only instance deletion.

  69. Thẻ 69

    Câu hỏi

    What control exposes unknown cloud data stores before they bypass policy?

    Câu trả lời

    Continuous asset and data discovery across accounts, regions, services, and shadow paths. Findings need ownership and remediation, not just inventory.

  70. Thẻ 70

    Câu hỏi

    What security property does encryption primarily provide?

    Câu trả lời

    Confidentiality against parties without the key. Integrity and authenticity require an appropriate authenticated mode or separate mechanism.

  71. Thẻ 71

    Câu hỏi

    What does tokenization do?

    Câu trả lời

    Replaces sensitive data with a non-sensitive token whose mapping is protected separately. The token can preserve application format while reducing where original data appears.

  72. Thẻ 72

    Câu hỏi

    How do structured, semi-structured, and unstructured data differ?

    Câu trả lời

    Structured data follows a fixed schema, semi-structured data carries flexible labels or structure, and unstructured data lacks a consistent field model. Discovery needs techniques suited to each form.

  73. Thẻ 73

    Câu hỏi

    What is data masking?

    Câu trả lời

    A transformation that hides selected data while preserving a usable shape or view. Reversible or weak masking is not anonymization.

  74. Thẻ 74

    Câu hỏi

    What does Data Loss Prevention monitor or restrict?

    Câu trả lời

    Sensitive-data movement or use across selected channels. DLP depends on discovery, classification, context, coverage, and tuned response.

  75. Thẻ 75

    Câu hỏi

    What security property does a cryptographic hash support?

    Câu trả lời

    Integrity by detecting change. A plain hash does not hide the input, prove who created it, or prevent guessing of low-entropy values.

  76. Thẻ 76

    Câu hỏi

    What does Information Rights Management add beyond storage permissions?

    Câu trả lời

    Persistent usage rules attached to protected content, such as view, print, copy, expiry, or revocation. Enforcement still depends on trusted identities, clients, and key services.

  77. Thẻ 77

    Câu hỏi

    Where should application secrets be kept?

    Câu trả lời

    In a managed secret store with narrow access, audit logs, rotation, and short-lived retrieval. Source code, images, and general configuration files are poor secret stores.

  78. Thẻ 78

    Câu hỏi

    What is anonymization trying to achieve?

    Câu trả lời

    Make data no longer reasonably linkable to an identifiable person. Re-identification risk must be assessed against auxiliary data and the release context.

  79. Thẻ 79

    Câu hỏi

    Why separate key-custodian duties from data administration?

    Câu trả lời

    To reduce the chance that one person can both reach ciphertext and independently unlock it. Separation of duties should also cover recovery and emergency access.

  80. Thẻ 80

    Câu hỏi

    What control reduces dependence on provider-held encryption keys?

    Câu trả lời

    Customer-controlled keys with independent policy and lifecycle management. The choice adds recovery, availability, rotation, and administrator risks that must be designed explicitly.

  81. Thẻ 81

    Câu hỏi

    How can tokenization reduce exposure in an application database?

    Câu trả lời

    Store tokens in routine workflows and isolate the token vault or mapping service. Access to detokenization should be rarer and more tightly logged.

  82. Thẻ 82

    Câu hỏi

    How can a hash support evidence integrity?

    Câu trả lời

    Record a strong hash at acquisition and verify it after each transfer or analysis step. Chain-of-custody records explain who handled the evidence and why.

  83. Thẻ 83

    Câu hỏi

    What is the safer source for non-production test data?

    Câu trả lời

    Synthetic or appropriately transformed data that meets the test need without exposing production identities. Validate re-identification risk before release.

  84. Thẻ 84

    Câu hỏi

    What makes DLP enforcement practical instead of noisy?

    Câu trả lời

    Accurate discovery and classification, contextual rules, staged response, tuned exceptions, and incident ownership. Blocking every pattern match can disrupt work without reducing real leakage.

  85. Thẻ 85

    Câu hỏi

    What enables IRM revocation after a file leaves its original repository?

    Câu trả lời

    A trusted client that checks current rights and can no longer obtain the needed key or license. Offline copies and screenshots remain boundary cases.

  86. Thẻ 86

    Câu hỏi

    How should cloud data discovery handle false positives?

    Câu trả lời

    Route uncertain matches for risk-based validation and tune detection with evidence. Silently discarding them hides coverage gaps; blocking them all creates operational failure.

  87. Thẻ 87

    Câu hỏi

    What keeps certificates trustworthy after issuance?

    Câu trả lời

    Inventory, protected private keys, renewal, revocation, validation, and monitored expiry. Issuing a certificate is only the start of its lifecycle.

  88. Thẻ 88

    Câu hỏi

    What is envelope encryption?

    Câu trả lời

    Encrypt data with a data-encryption key, then protect that key with a separate key-encryption key. Rotating or rewrapping the key-encryption key can protect existing data-encryption keys without re-encrypting payload data; replacing a data-encryption key may require payload re-encryption.

  89. Thẻ 89

    Câu hỏi

    What is data classification?

    Câu trả lời

    Assignment of a sensitivity or business category that drives handling requirements. The category should reflect impact, law, contract, and business need.

  90. Thẻ 90

    Câu hỏi

    When is tokenization preferable to ordinary encryption?

    Câu trả lời

    When workflows can use a surrogate while original values stay in a tightly isolated mapping service. Encryption is better when authorized systems must recover data directly with keys.

  91. Thẻ 91

    Câu hỏi

    Should a password be encrypted or hashed for verification?

    Câu trả lời

    Hash it with a password-specific salted, slow derivation function. Reversible encryption creates unnecessary recovery of the original password.

  92. Thẻ 92

    Câu hỏi

    When is masking insufficient for a public dataset release?

    Câu trả lời

    When remaining fields or external data can reasonably re-identify people. Public release needs a defensible anonymization assessment, not cosmetic redaction.

  93. Thẻ 93

    Câu hỏi

    Why should DLP not be the only control against cloud exfiltration?

    Câu trả lời

    It sees only covered channels and recognized content. Least privilege, segmentation, egress control, encryption, monitoring, and response reduce gaps.

  94. Thẻ 94

    Câu hỏi

    When is IRM more useful than a repository access control list?

    Câu trả lời

    When usage restrictions must follow a file beyond the original repository. If data never leaves a controlled service, native authorization may be simpler and stronger.

  95. Thẻ 95

    Câu hỏi

    Why perform discovery before broad classification enforcement?

    Câu trả lời

    You need to know what data exists and where it lives before applying reliable labels and controls. Enforcement on an incomplete inventory leaves blind spots.

  96. Thẻ 96

    Câu hỏi

    What should trigger data reclassification?

    Câu trả lời

    A change in content, use, law, contract, business impact, aggregation, or identifiability. Review should also occur on a defined schedule.

  97. Thẻ 97

    Câu hỏi

    Why rotate encryption keys?

    Câu trả lời

    To limit exposure, meet policy, and replace keys after age, role, algorithm, or compromise changes. Rotation must preserve authorized access to older data until it is safely reprotected or retired.

  98. Thẻ 98

    Câu hỏi

    Who sets a cloud dataset's business classification?

    Câu trả lời

    The accountable data owner. Automated tools can propose labels, but the owner resolves business context and exceptions.

  99. Thẻ 99

    Câu hỏi

    How does a data label differ from a classification policy?

    Câu trả lời

    The label marks a specific asset; the policy defines what the category means and how it must be handled. Labels without enforcement are only metadata.

  100. Thẻ 100

    Câu hỏi

    What is a data steward responsible for?

    Câu trả lời

    Day-to-day quality, definition, and policy consistency for data. A steward supports the owner but does not replace the owner's accountability.

  101. Thẻ 101

    Câu hỏi

    How do retention and archiving differ?

    Câu trả lời

    Retention states how long data must or may be kept; archiving moves data into a managed long-term state. Archived data remains subject to access, integrity, discovery, and deletion rules.

  102. Thẻ 102

    Câu hỏi

    What does a data controller decide?

    Câu trả lời

    The purposes and essential means of processing personal data. The exact legal definition depends on the applicable law.

  103. Thẻ 103

    Câu hỏi

    When should a derived dataset inherit its source classification?

    Câu trả lời

    By default, until an accountable owner proves the transformation changed sensitivity. Aggregation can reduce or increase risk depending on content and linkability.

  104. Thẻ 104

    Câu hỏi

    How should classification labels affect cloud controls?

    Câu trả lời

    Drive access, encryption, sharing, location, retention, monitoring, and deletion policy. Enforcement should follow the label across supported copies and transformations.

  105. Thẻ 105

    Câu hỏi

    What does a legal hold do?

    Câu trả lời

    Suspends normal deletion for information relevant to a legal or regulatory matter. It preserves authorized access and evidence until the hold is released.

  106. Thẻ 106

    Câu hỏi

    What should a privacy role contribute to cloud data design?

    Câu trả lời

    Purpose, minimization, transparency, rights, transfer, retention, and impact requirements. Security protects data, while privacy also asks whether processing should occur and under what conditions.

  107. Thẻ 107

    Câu hỏi

    What control turns a retention schedule into repeatable cloud behavior?

    Câu trả lời

    Policy-driven lifecycle automation with holds, approvals, exceptions, and audit evidence. Automation must cover replicas and backups where the platform supports it.

  108. Thẻ 108

    Câu hỏi

    What is a data custodian responsible for?

    Câu trả lời

    Implementing and operating the technical handling controls. Storage, backup, access, logging, and deletion are typical custody duties.

  109. Thẻ 109

    Câu hỏi

    Who should own the retention schedule?

    Câu trả lời

    The records or information-governance function with legal and business input. Technology teams implement the approved schedule and evidence.

  110. Thẻ 110

    Câu hỏi

    What does a data processor do?

    Câu trả lời

    Processes personal data for a controller under documented instructions. Using the data for its own new purpose may change the role and obligations.

  111. Thẻ 111

    Câu hỏi

    What proves a cloud deletion request was completed responsibly?

    Câu trả lời

    Provider and customer evidence tied to the asset, method, scope, time, and remaining copies. A successful API response alone may not cover backups, replicas, or exported data.

  112. Thẻ 112

    Câu hỏi

    Which controls protect a long-term cloud archive?

    Câu trả lời

    Restricted access, durable integrity checks, format and key preservation, redundancy, retention policy, and tested retrieval. An archive that cannot be read or trusted has failed its purpose.

  113. Thẻ 113

    Câu hỏi

    Who should approve a training dataset and model version for production?

    Câu trả lời

    The accountable model or system owner using evidence from data, security, privacy, and validation roles. Approval must bind the exact versions and intended use.

  114. Thẻ 114

    Câu hỏi

    Which event fields most often establish accountability for cloud data access?

    Câu trả lời

    Trusted identity, action, target, result, timestamp, source context, and relevant network or location data. Collect only attributes needed for the security, legal, and privacy purpose.

  115. Thẻ 115

    Câu hỏi

    Why synchronize clocks across cloud evidence sources?

    Câu trả lời

    To correlate events into a defensible timeline. Record time source, zone, drift, and collection context when precision matters.

  116. Thẻ 116

    Câu hỏi

    Which risk is present when model outputs reveal features of sensitive training records?

    Câu trả lời

    Model inversion or related privacy inference. Data minimization, privacy testing, output controls, and access limits reduce exposure.

  117. Thẻ 117

    Câu hỏi

    Who authorizes and scopes a legal hold?

    Câu trả lời

    An authorized legal or records function. Cloud administrators implement it without deciding the legal scope themselves.

  118. Thẻ 118

    Câu hỏi

    What must AI dataset validation check besides file integrity?

    Câu trả lời

    Source authority, consent or permitted use, representativeness, quality, labeling, poisoning indicators, and intended-use fit. A matching checksum only proves the bytes did not change after that checkpoint.

  119. Thẻ 119

    Câu hỏi

    Why is an archive not a substitute for a recovery backup?

    Câu trả lời

    An archive optimizes long-term preservation and retrieval; a backup supports restoration after loss or corruption. One system can sometimes serve both only if it meets both control sets and tests.

  120. Thẻ 120

    Câu hỏi

    What protects AI dataset and model provenance?

    Câu trả lời

    Versioned inventories, signed or hashed artifacts, controlled pipelines, approval records, and lineage from source to deployment. Bind validation results to the exact artifact versions.

  121. Thẻ 121

    Câu hỏi

    Which context should be omitted from a data event log?

    Câu trả lời

    Data that is unnecessary for the defined security, accountability, or legal purpose. More logging can create privacy, cost, and breach risk without improving evidence.

  122. Thẻ 122

    Câu hỏi

    What happens when a valid legal hold conflicts with scheduled deletion?

    Câu trả lời

    The authorized hold suspends deletion for the in-scope data. Keep access limited, document the exception, and resume policy when the hold is released.

  123. Thẻ 123

    Câu hỏi

    What adds non-repudiation evidence beyond a plain event log?

    Câu trả lời

    Strong identity binding, protected timestamps, integrity controls, and controlled custody. The strength depends on the whole evidence process, not a single hash field.

  124. Thẻ 124

    Câu hỏi

    What privacy question does a membership-inference attack answer?

    Câu trả lời

    Whether a particular record was likely part of a model's training data. Limit exposed confidence, query abuse, overfitting, and unnecessary sensitive training data.

  125. Thẻ 125

    Câu hỏi

    What is the clearest sign that training-data poisoning controls failed?

    Câu trả lời

    Untrusted or manipulated examples changed model behavior or inserted a hidden trigger. Investigate provenance, pipeline access, validation, and the exact affected versions.

  126. Thẻ 126

    Câu hỏi

    What is the strongest first step when an AI use case asks for every available customer field?

    Câu trả lời

    Reduce collection to data necessary for the approved purpose. Minimization lowers privacy, poisoning, access, retention, and breach exposure before technical controls are added.

  127. Thẻ 127

    Câu hỏi

    What is the cloud network team's primary security role?

    Câu trả lời

    Implement approved segmentation, routing, edge protection, secure connectivity, and network telemetry. Application teams still define workload access needs.

  128. Thẻ 128

    Câu hỏi

    Which layers make up a cloud infrastructure trust stack?

    Câu trả lời

    Physical facilities, network, compute, storage, virtualization, and management services. A workload inherits dependencies and failure modes from every layer beneath or beside it.

  129. Thẻ 129

    Câu hỏi

    How do the management plane and data plane differ?

    Câu trả lời

    The management plane configures and governs resources; the data plane carries or processes workload traffic and data. Compromise of the management plane can change many data-plane controls at once.

  130. Thẻ 130

    Câu hỏi

    What is a trust boundary in cloud architecture?

    Câu trả lời

    A point where identity, control, ownership, or assurance changes. Data crossing it needs an explicit policy, validation, and protected channel.

  131. Thẻ 131

    Câu hỏi

    Who owns a customer's cloud network and identity configuration?

    Câu trả lời

    The customer for the configuration choices it controls. Provider defaults and guardrails help, but do not approve the customer's architecture.

  132. Thẻ 132

    Câu hỏi

    What logical control prevents one tenant from reaching another tenant's resources?

    Câu trả lời

    Enforced tenant partitioning across identity, network, compute, storage, and management paths. Test the negative boundary, not only valid access.

  133. Thẻ 133

    Câu hỏi

    Why is the cloud management plane a high-value target?

    Câu trả lời

    It can create, modify, expose, or destroy many resources through one privileged interface. Protect it more strongly than routine workload access.

  134. Thẻ 134

    Câu hỏi

    What limits lateral movement after one cloud workload is compromised?

    Câu trả lời

    Microsegmentation with identity-aware, least-privilege communication policy. Monitor denied and unusual flows to find attempted spread.

  135. Thẻ 135

    Câu hỏi

    How does infrastructure as code improve control assurance?

    Câu trả lời

    It makes configuration reviewable, repeatable, testable, and traceable. Protect the repository, pipeline, state, modules, and deployment identity.

  136. Thẻ 136

    Câu hỏi

    How should a team verify an infrastructure control still works?

    Câu trả lời

    Test its intended outcome with current evidence and representative failure or attack conditions. Configuration presence alone does not prove effectiveness.

  137. Thẻ 137

    Câu hỏi

    What security boundary should virtualization create between tenants?

    Câu trả lời

    Strong isolation of compute, memory, storage, network, and management operations. Shared hardware still creates side-channel, escape, and noisy-neighbor considerations.

  138. Thẻ 138

    Câu hỏi

    Which controls should protect cloud management-plane access?

    Câu trả lời

    Phishing-resistant MFA, privileged access management, separate admin identities, conditional access, least privilege, and immutable logging. Restrict source networks where practical.

  139. Thẻ 139

    Câu hỏi

    How do type 1 and type 2 hypervisors differ?

    Câu trả lời

    A type 1 hypervisor runs directly on hardware; a type 2 hypervisor runs on a host operating system. The extra host layer changes attack surface and operational use.

  140. Thẻ 140

    Câu hỏi

    Who secures the public cloud facility and physical host?

    Câu trả lời

    The cloud provider. Customers still evaluate the provider's physical assurance and design their service around disclosed locations and failure domains.

  141. Thẻ 141

    Câu hỏi

    What protects a cloud AI training cluster from unrelated tenant traffic?

    Câu trả lời

    Dedicated identities, microsegmentation, controlled data paths, hardened images, and monitored management access. Accelerator scheduling and storage paths belong in the boundary.

  142. Thẻ 142

    Câu hỏi

    When is packet capture useful in cloud infrastructure?

    Câu trả lời

    When network-level detail is needed and collection is lawful, technically available, scoped, and protected. Flow logs may be safer and sufficient for many investigations.

  143. Thẻ 143

    Câu hỏi

    Which control protects detached cloud volumes and snapshots?

    Câu trả lời

    Encryption with governed keys plus explicit access policy. Inventory and delete orphaned copies because detachment does not remove their data.

  144. Thẻ 144

    Câu hỏi

    Why correlate infrastructure logs across layers?

    Câu trả lời

    To connect identity, management, network, host, and workload events into one incident path. Preserve original records and normalization context.

  145. Thẻ 145

    Câu hỏi

    What is a platform owner's responsibility for tenant isolation?

    Câu trả lời

    Configure, patch, monitor, and test the shared platform so one workload cannot cross its authorized boundary. Consumers must use the platform's isolation features correctly.

  146. Thẻ 146

    Câu hỏi

    When should an AI training cluster use stronger isolation than ordinary batch compute?

    Câu trả lời

    When valuable models, sensitive datasets, untrusted code, or high-cost accelerators raise confidentiality, integrity, or exhaustion risk. Match isolation to the workload threat model.

  147. Thẻ 147

    Câu hỏi

    What does an HSM protect in cloud infrastructure?

    Câu trả lời

    Cryptographic keys and operations inside a hardened, policy-controlled boundary. An HSM does not decide whether the requesting workload is authorized unless surrounding policy enforces it.

  148. Thẻ 148

    Câu hỏi

    What is a failure domain?

    Câu trả lời

    A set of components likely to fail together because they share a dependency. Regions, zones, racks, power feeds, control services, or software versions can define one.

  149. Thẻ 149

    Câu hỏi

    A volume is deleted but its snapshots remain. Is the data gone?

    Câu trả lời

    No. The snapshots are separate retained copies. Apply inventory, retention, hold, encryption-key, and deletion policy to every snapshot and replica.

  150. Thẻ 150

    Câu hỏi

    How should a platform reduce virtualization escape risk?

    Câu trả lời

    Minimize and patch the virtualization stack, isolate management interfaces, restrict device exposure, monitor anomalies, and contain workloads by risk. Stronger workload boundaries may be needed for hostile tenants.

  151. Thẻ 151

    Câu hỏi

    What is the first response to an internet-exposed cloud management endpoint?

    Câu trả lời

    Remove unnecessary public reachability, then enforce strong identity and monitored privileged access. A hidden URL or uncommon port is not a control.

  152. Thẻ 152

    Câu hỏi

    What is the facilities team's role in a private cloud data center?

    Câu trả lời

    Operate physical access, power, cooling, fire protection, and environmental monitoring. Security requirements should define evidence and escalation for those systems.

  153. Thẻ 153

    Câu hỏi

    Which site-location condition creates direct legal exposure for a cloud workload?

    Câu trả lời

    The jurisdictions that can reach the facility, operator, customers, or data. Cost, hazards, utilities, connectivity, workforce, and physical threats require separate location analysis.

  154. Thẻ 154

    Câu hỏi

    How does diverse pathway connectivity improve resilience?

    Câu trả lời

    It prevents one cable route, conduit, carrier handoff, or excavation from cutting every link. Verify physical diversity rather than relying on different circuit names.

  155. Thẻ 155

    Câu hỏi

    When does building a private data center make more sense than buying cloud capacity?

    Câu trả lời

    When requirements for control, latency, sovereignty, specialized hardware, or long-term economics outweigh the build and operating burden. Compare full lifecycle cost and resilience, not purchase price alone.

  156. Thẻ 156

    Câu hỏi

    Which physical controls protect cloud hardware from unauthorized handling?

    Câu trả lời

    Zoned access, least privilege, identity checks, surveillance, visitor controls, alarms, and custody records. The strength should match asset and data impact.

  157. Thẻ 157

    Câu hỏi

    What power design reduces a data center's single-point risk?

    Câu trả lời

    Independent feeds, conditioned distribution, UPS capacity, generators, fuel plans, and tested transfer. Maintenance paths must preserve the intended redundancy.

  158. Thẻ 158

    Câu hỏi

    What should environmental monitoring detect in a data center?

    Câu trả lời

    Temperature, humidity, airflow, water, smoke, power, and equipment conditions that threaten service. Alerts need thresholds, escalation, and tested response.

  159. Thẻ 159

    Câu hỏi

    How does resilience differ from simple redundancy?

    Câu trả lời

    Redundancy adds alternatives; resilience keeps or restores acceptable service despite disruption. Redundant components can still share one failure domain or bad configuration.

  160. Thẻ 160

    Câu hỏi

    Which on-premises physical control remains a customer duty when workloads move to public cloud?

    Câu trả lời

    Protection of customer-controlled offices, endpoints, network links, and any retained equipment. The provider's data-center controls do not secure the customer's physical environment.

  161. Thẻ 161

    Câu hỏi

    What are the core outputs of an infrastructure risk assessment?

    Câu trả lời

    Prioritized risks tied to assets, threats, vulnerabilities, likelihood, impact, existing controls, and owners. The output should lead to treatment and follow-up.

  162. Thẻ 162

    Câu hỏi

    Who may accept residual infrastructure risk?

    Câu trả lời

    The authorized business risk owner, not the engineer who found it. Acceptance should state scope, duration, rationale, and review trigger.

  163. Thẻ 163

    Câu hỏi

    How do a threat, vulnerability, and risk differ?

    Câu trả lời

    A threat can cause harm, a vulnerability is a weakness it may exploit, and risk combines uncertain harm with business impact. A weakness without relevant exposure may be lower priority.

  164. Thẻ 164

    Câu hỏi

    What reveals that two supposedly redundant cloud systems share fate?

    Câu trả lời

    They depend on the same control plane, account, region, identity service, network path, software defect, operator, or key. Model those dependencies before counting redundancy.

  165. Thẻ 165

    Câu hỏi

    What does a security control owner do?

    Câu trả lời

    Ensures an assigned control is designed, implemented, evidenced, monitored, and corrected. The role may coordinate several technical operators.

  166. Thẻ 166

    Câu hỏi

    Which risk treatment options should a cloud team recognize?

    Câu trả lời

    Avoid, mitigate, transfer or share, and accept. Treatment changes exposure or ownership; it does not erase accountability.

  167. Thẻ 167

    Câu hỏi

    What is a recovery service level?

    Câu trả lời

    The minimum service capacity or functionality that must be restored, often stated as a percentage of normal service. RSL defines how much service must work; RTO sets the time limit, while RPO sets the maximum data-loss interval.

  168. Thẻ 168

    Câu hỏi

    What makes a machine image trustworthy for cloud deployment?

    Câu trả lời

    Known provenance, minimal contents, current patches, signed or verified integrity, vulnerability results, and controlled promotion. Revalidate it when dependencies age.

  169. Thẻ 169

    Câu hỏi

    When do multiple availability zones materially improve resilience?

    Câu trả lời

    When the service, data, network, identities, and operations can continue after one zone and its shared dependencies fail. Merely placing instances in two zones is not a tested design.

  170. Thẻ 170

    Câu hỏi

    What should determine the strength of an infrastructure security control?

    Câu trả lời

    The asset impact, threat, vulnerability, exposure, legal duties, and risk tolerance. Use control frameworks as structured input, not as an automatic one-size baseline.

    Abstract cloud infrastructure with layered security boundaries, connected control nodes, and an AI model graph.

    340 thẻ

    CCSP 2026 Flashcards: August Exam Outline Review

    Học bộ thẻ này miễn phí

    Nibomo sẽ mở ra để bạn bắt đầu học.

  171. Thẻ 171

    Câu hỏi

    Which layered controls improve availability against cloud DDoS?

    Câu trả lời

    Provider edge absorption, rate controls, resilient scaling, caching, WAF or protocol filtering, and an exercised response plan. Scaling alone can turn attack traffic into cost exhaustion.

  172. Thẻ 172

    Câu hỏi

    A cloud contract shifts breach costs to a provider. Has the risk been removed?

    Câu trả lời

    No. Financial risk may be transferred, while operational, legal, reputational, and customer harm can remain. Retained exposure still needs mitigation and acceptance.

  173. Thẻ 173

    Câu hỏi

    Why map dependencies across compute, storage, and network services?

    Câu trả lời

    A resilient application can still fail when a shared supporting service fails. Dependency maps expose hidden single points, circular recovery steps, and shared fate.

  174. Thẻ 174

    Câu hỏi

    What does RPO constrain in an infrastructure recovery design?

    Câu trả lời

    The maximum acceptable data-loss interval measured backward from disruption. It drives backup or replication frequency and consistency choices.

  175. Thẻ 175

    Câu hỏi

    What should trigger automated failover?

    Câu trả lời

    Reliable health evidence that the primary cannot meet the service objective, with safeguards against split-brain and false triggers. Manual approval may remain appropriate for ambiguous high-impact cases.

  176. Thẻ 176

    Câu hỏi

    When is an IPS preferable to an IDS?

    Câu trả lời

    When inline blocking is justified, tested, and safe for the traffic and availability requirements. Use detection-only when false positives or inline failure would create unacceptable impact.

  177. Thẻ 177

    Câu hỏi

    What makes residual infrastructure risk ready for acceptance?

    Câu trả lời

    A clear scenario, affected assets, existing controls, likelihood and impact, owner, duration, alternatives, and review trigger. Vague acceptance is not governance.

  178. Thẻ 178

    Câu hỏi

    What makes a cloud backup resistant to account compromise?

    Câu trả lời

    Separate administration, immutable or offline retention, encryption, protected deletion, and tested restore. Keep recovery credentials outside the routine production trust path.

  179. Thẻ 179

    Câu hỏi

    What does a BC/DR coordinator own during cloud recovery planning?

    Câu trả lời

    The cross-team plan, exercises, dependencies, contacts, evidence, and follow-up. Service owners still set business priorities and targets.

  180. Thẻ 180

    Câu hỏi

    Which recovery design supports a near-zero RPO?

    Câu trả lời

    Synchronous or otherwise strongly consistent replication across independent failure domains, if latency and shared-fate limits are acceptable. Backups still protect against corruption and deletion.

  181. Thẻ 181

    Câu hỏi

    Which overlooked dependency can stop users from reaching replicated application servers after failover?

    Câu trả lời

    The identity service. Recovery planning should also cover DNS, keys, secrets, routes, data stores, quotas, and external services.

  182. Thẻ 182

    Câu hỏi

    Why test restore separately from backup completion?

    Câu trả lời

    A completed backup may be corrupt, incomplete, inaccessible, or too slow for the target. Restore testing proves usability and measures recovery performance.

  183. Thẻ 183

    Câu hỏi

    Why plan failback before declaring a DR design complete?

    Câu trả lời

    Returning to the preferred environment can create another outage, conflict, or data loss. Define authority, synchronization, validation, rollback, and communication.

  184. Thẻ 184

    Câu hỏi

    Which design choice most directly supports a short RTO?

    Câu trả lời

    Pre-provisioned or rapidly deployable recovery capacity with automated, tested orchestration. Data, identities, network, dependencies, and operators must be ready too.

  185. Thẻ 185

    Câu hỏi

    What should application-security awareness change in a cloud team?

    Câu trả lời

    Daily design and delivery decisions, not just annual quiz results. Use role-specific OWASP, ASVS, SANS Top 25, and LLM-risk examples as practical boundaries, then reinforce them with real defects.

  186. Thẻ 186

    Câu hỏi

    What makes an SDLC a secure SDLC?

    Câu trả lời

    Security requirements, design analysis, implementation controls, verification, release evidence, maintenance, and retirement are built into the lifecycle. A final penetration test alone is not a lifecycle.

  187. Thẻ 187

    Câu hỏi

    How do functional and non-functional security requirements differ?

    Câu trả lời

    Functional requirements specify security behavior; non-functional requirements set qualities such as availability, performance, resilience, or assurance. Both need measurable acceptance criteria.

  188. Thẻ 188

    Câu hỏi

    Who turns business needs into testable application security requirements?

    Câu trả lời

    The product or business owner with security, privacy, legal, and engineering input. Requirements need an accountable owner and acceptance evidence.

  189. Thẻ 189

    Câu hỏi

    How should a security requirement remain visible through delivery?

    Câu trả lời

    Trace it to design decisions, code or configuration, tests, approval, and operating evidence. Untraceable requirements are easy to drop during change.

  190. Thẻ 190

    Câu hỏi

    What is the purpose of threat modeling?

    Câu trả lời

    Identify likely abuse paths and design mitigations before or during development. Keep the model tied to assets, trust boundaries, architecture changes, and evidence.

  191. Thẻ 191

    Câu hỏi

    What makes developer security training actionable?

    Câu trả lời

    Role-specific examples, secure alternatives, practice in the delivery toolchain, and feedback from real defects. Refresh it as platforms and threats change.

  192. Thẻ 192

    Câu hỏi

    Should agile delivery remove formal security gates?

    Câu trả lời

    No. It should make them smaller, earlier, automated where reliable, and tied to risk. High-impact changes can still require independent approval.

  193. Thẻ 193

    Câu hỏi

    Which cloud-specific application risks need explicit SDLC decisions before coding?

    Câu trả lời

    Shared-technology exposure, provider insiders, limited visibility or control, and legal or jurisdiction boundaries. Record the provider boundary, evidence, data location, isolation, and compensating controls.

  194. Thẻ 194

    Câu hỏi

    How do federation and SSO differ?

    Câu trả lời

    Federation establishes trust across identity domains; SSO lets a user authenticate once for multiple services. Federation can enable SSO, but the concepts are not identical.

  195. Thẻ 195

    Câu hỏi

    What is a developer's responsibility in secure cloud delivery?

    Câu trả lời

    Use approved patterns, validate inputs and outputs, protect secrets, handle errors safely, review dependencies, and fix findings. Security tools support that judgment rather than replace it.

  196. Thẻ 196

    Câu hỏi

    What should a peer security reviewer verify?

    Câu trả lời

    That the change preserves requirements, trust boundaries, authorization, data handling, failure behavior, and evidence. Review the actual diff and deployment effect, not only style.

  197. Thẻ 197

    Câu hỏi

    What is the application security architect accountable for?

    Câu trả lời

    Security patterns, trust boundaries, threat decisions, control integration, and documented exceptions. Teams share implementation, but architecture needs coherent ownership.

  198. Thẻ 198

    Câu hỏi

    Which threat categories does STRIDE prompt a team to examine?

    Câu trả lời

    Spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. It is a coverage aid, not a risk score.

  199. Thẻ 199

    Câu hỏi

    What secure-coding rule most directly prevents broken object authorization?

    Câu trả lời

    Check the current subject's permission for the specific object on every request. ASVS or SAFECode guidance can structure assurance, but hiding identifiers or checking only authentication is insufficient.

  200. Thẻ 200

    Câu hỏi

    What should a secret-scanning gate do when it finds a real credential?

    Câu trả lời

    Block exposure, revoke or rotate the credential, remove it from reachable history, and investigate use. Deleting the latest line does not invalidate copied history.

  201. Thẻ 201

    Câu hỏi

    How does protected version control support software assurance?

    Câu trả lời

    It creates tamper-evident, access-controlled history for reviewed code and configuration changes. Protect references from unauthorized rewrite, retain audit logs, control bypass, and bind signed artifacts to approved releases; content-addressed commits alone do not make branch history immutable.

  202. Thẻ 202

    Câu hỏi

    Which threat-model method is the simplest checklist for threat categories at trust boundaries?

    Câu trả lời

    STRIDE. Use a process-centered method when business impact, attacker paths, and staged analysis need deeper treatment.

  203. Thẻ 203

    Câu hỏi

    What is an abuse case?

    Câu trả lời

    A description of how an actor could misuse a feature or violate a security goal. It turns attacker intent into testable defensive behavior.

  204. Thẻ 204

    Câu hỏi

    Why should a team avoid treating DREAD scores as objective truth?

    Câu trả lời

    Its ratings are judgment-based and can create false precision. Document evidence, assumptions, impact, and uncertainty instead of relying on one number.

  205. Thẻ 205

    Câu hỏi

    How do SAST and DAST differ?

    Câu trả lời

    SAST examines code or compiled artifacts without running the full application; DAST probes a running application from the outside. They find different classes of weakness.

  206. Thẻ 206

    Câu hỏi

    What does Software Composition Analysis examine?

    Câu trả lời

    Third-party components, versions, licenses, and known vulnerability or policy data. It does not prove that a dependency is safe in context or detect every malicious package.

  207. Thẻ 207

    Câu hỏi

    When should a cloud application's threat model be updated?

    Câu trả lời

    When trust boundaries, data, identities, dependencies, deployment, features, or threats materially change. Periodic review catches slow drift.

  208. Thẻ 208

    Câu hỏi

    How do black-box and white-box security testing differ?

    Câu trả lời

    Black-box testing uses external behavior with little internal knowledge; white-box testing uses code, design, or configuration knowledge. Gray-box testing combines partial knowledge with external interaction.

  209. Thẻ 209

    Câu hỏi

    What should a CI/CD security gate block?

    Câu trả lời

    A defined, evidence-based release condition such as an exposed secret, failed critical control, unapproved artifact, or unacceptable vulnerability. Keep exceptions explicit, owned, and time-bounded.

  210. Thẻ 210

    Câu hỏi

    When is PASTA or ATASM more useful than a short threat checklist?

    Câu trả lời

    When the team needs a structured path from business objectives and architecture to attacker behavior, attack surfaces, and mitigations. Match method depth to decision risk.

  211. Thẻ 211

    Câu hỏi

    Where does SAST provide the earliest useful feedback?

    Câu trả lời

    During coding and pull-request review, before deployment. Tune rules, confirm reachability and context, and fix root causes rather than chasing raw counts.

  212. Thẻ 212

    Câu hỏi

    When is IAST worth adding to a cloud test pipeline?

    Câu trả lời

    When representative automated tests exist and runtime path-to-code insight will improve triage. Without exercised paths, instrumentation has little to observe.

  213. Thẻ 213

    Câu hỏi

    How should an application handle LLM output before passing it to a browser, shell, database, or tool?

    Câu trả lời

    Treat it as untrusted data and validate, encode, constrain, or approve it for the destination. Model fluency is not a security guarantee.

  214. Thẻ 214

    Câu hỏi

    What should an abuse-case test assert for a sensitive workflow?

    Câu trả lời

    The application safely rejects or contains a realistic misuse path and leaves useful evidence. Test rate, sequence, privilege, data, and failure-state abuse where relevant.

  215. Thẻ 215

    Câu hỏi

    What environment makes DAST results most useful?

    Câu trả lời

    A representative running deployment with safe test data, reachable paths, and observable results. Production testing needs explicit authorization and safeguards.

  216. Thẻ 216

    Câu hỏi

    Who owns risk from a third-party software component?

    Câu trả lời

    The organization that chooses and operates it. The supplier supplies evidence and remediation, but outsourcing the component does not outsource customer accountability.

  217. Thẻ 217

    Câu hỏi

    How do an SBOM and SCA work together?

    Câu trả lời

    SCA identifies component and policy findings; an SBOM records the released component inventory. Bind both to the exact artifact and update risk when new information appears.

  218. Thẻ 218

    Câu hỏi

    What does artifact signing protect in a software supply chain?

    Câu trả lời

    Integrity and authenticated provenance of the signed artifact. Verification policy must also trust the signer, build path, and release authorization.

  219. Thẻ 219

    Câu hỏi

    What makes open-source software validated for a cloud application?

    Câu trả lời

    Its source, release, integrity, dependencies, license, maintenance, vulnerabilities, and intended use have been assessed. Open code is inspectable, not automatically safe.

  220. Thẻ 220

    Câu hỏi

    Which cloud application control validates XML message structure before processing?

    Câu trả lời

    An XML firewall. A WAF filters web traffic, an API gateway applies API-facing policy, DAM monitors database activity, and a load balancer distributes traffic.

  221. Thẻ 221

    Câu hỏi

    What authorization check belongs behind every sensitive API operation?

    Câu trả lời

    A server-side decision for the current identity, action, object, tenant, and context. Gateway authentication alone cannot decide application-level ownership.

  222. Thẻ 222

    Câu hỏi

    How should an API treat untrusted input?

    Câu trả lời

    Validate type, structure, size, range, encoding, and allowed semantics before use. Reject unexpected fields where ambiguity or mass assignment creates risk.

  223. Thẻ 223

    Câu hỏi

    What is an Identity Provider responsible for in federation?

    Câu trả lời

    Authenticating subjects and issuing trustworthy identity assertions under agreed policy. The relying application still authorizes each requested action.

  224. Thẻ 224

    Câu hỏi

    What does sandboxing add to cloud application security?

    Câu trả lời

    A constrained execution boundary for untrusted or risky code and content. Restrict identity, network, files, secrets, time, and compute outside the sandbox too.

  225. Thẻ 225

    Câu hỏi

    What should block adoption of a third-party software component?

    Câu trả lời

    Unacceptable provenance, integrity, vulnerability, maintenance, license, access, or exit risk. Popularity and a clean scan do not settle supplier risk.

  226. Thẻ 226

    Câu hỏi

    Which test perspective should verify hidden authorization logic?

    Câu trả lời

    White-box review and testing, supported by black-box attempts to cross the boundary. Internal knowledge finds code paths; external tests confirm observable enforcement.

  227. Thẻ 227

    Câu hỏi

    Which practice verifies that a cloud release consistently meets defined quality and security criteria?

    Câu trả lời

    Quality Assurance (QA). It plans and tracks repeatable reviews, tests, acceptance evidence, defect handling, and process improvement across delivery.

  228. Thẻ 228

    Câu hỏi

    Which IAM controls reduce takeover of a federated cloud account?

    Câu trả lời

    Strong MFA, trusted federation configuration, short sessions, conditional access, lifecycle automation, and monitored privilege. Secure both the IdP and relying service.

  229. Thẻ 229

    Câu hỏi

    What is the safest response when retrieved content tells an LLM to ignore system rules?

    Câu trả lời

    Treat the instruction as untrusted data, preserve higher-priority policy, and prevent unauthorized tool or data access. Input filtering alone cannot eliminate prompt injection.

  230. Thẻ 230

    Câu hỏi

    How should an LLM application reduce sensitive information disclosure?

    Câu trả lời

    Minimize prompt and training data, enforce retrieval authorization, redact where justified, constrain outputs, and test leakage. A system prompt telling the model to keep secrets is not sufficient.

  231. Thẻ 231

    Câu hỏi

    A model repository account is compromised and a backdoored model is published. Which risks overlap?

    Câu trả lời

    Supply-chain compromise and data or model poisoning. Pin trusted versions, verify provenance and signatures, scan safely, validate behavior, and control promotion.

  232. Thẻ 232

    Câu hỏi

    What identity should one microservice use to call another?

    Câu trả lời

    A distinct, short-lived workload identity with least-privilege authorization. Avoid sharing broad static credentials across services.

  233. Thẻ 233

    Câu hỏi

    How should an agentic LLM be constrained before it can delete cloud resources?

    Câu trả lời

    Give it minimal scoped tools, validate arguments, require approval for destructive actions, enforce budgets, and log every decision and result. Capability should match the smallest authorized task.

  234. Thẻ 234

    Câu hỏi

    Should a system prompt be treated as a secret control boundary?

    Câu trả lời

    No. Design as if instructions may be exposed. Keep credentials and authorization outside the prompt, minimize sensitive details, and enforce policy in trusted code.

  235. Thẻ 235

    Câu hỏi

    What is the main risk of weak authorization in a shared vector store?

    Câu trả lời

    Retrieval can cross tenant or user boundaries and expose embeddings, documents, or poisoned context. Partition, authorize, validate provenance, and monitor ingestion and queries.

  236. Thẻ 236

    Câu hỏi

    When does a CASB add value beside an IdP?

    Câu trả lời

    When the organization needs visibility or policy over cloud-service use, data movement, sessions, or unmanaged access beyond authentication. The IdP establishes identity; the CASB governs selected cloud interactions.

  237. Thẻ 237

    Câu hỏi

    How should a high-impact workflow use an LLM answer that may be plausible but false?

    Câu trả lời

    Verify it against authoritative data or require qualified human review before action. Communicate uncertainty and preserve source evidence.

  238. Thẻ 238

    Câu hỏi

    Which controls address unbounded LLM consumption?

    Câu trả lời

    Per-user and per-task quotas, rate limits, token and tool budgets, timeouts, concurrency limits, anomaly alerts, and safe cancellation. Monitor financial as well as availability impact.

  239. Thẻ 239

    Câu hỏi

    How do an HSM and a TPM differ?

    Câu trả lời

    An HSM protects shared or service cryptographic operations; a TPM anchors trust to one platform. Both protect keys, but their scope and use cases differ.

  240. Thẻ 240

    Câu hỏi

    What does secure by default mean for cloud infrastructure?

    Câu trả lời

    A new resource starts in the least exposed, least privileged, approved state. Users must make an explicit, reviewed choice to widen access or capability.

  241. Thẻ 241

    Câu hỏi

    Why do virtual CPU, memory, storage, and network settings have security impact?

    Câu trả lời

    They define resource exposure, isolation, exhaustion limits, and device access. Overbroad virtual hardware can create attack paths or noisy-neighbor risk.

  242. Thẻ 242

    Câu hỏi

    Which hypervisor type is usually preferred for production cloud hosts?

    Câu trả lời

    A type 1 hypervisor because it removes the general-purpose host OS layer. The actual choice still depends on assurance, patching, management, and workload needs.

  243. Thẻ 243

    Câu hỏi

    How can TPM-backed measured boot support cloud host assurance?

    Câu trả lời

    Measurements anchor boot components to hardware so an attestation service can compare them with approved state. The decision still depends on trusted reference values and response policy.

  244. Thẻ 244

    Câu hỏi

    How should guest OS virtualization tools be installed and maintained?

    Câu trả lời

    Use provider-authorized packages, enable only needed features, match supported versions, patch promptly, and monitor their privilege. Remove stale tools that widen the host-to-guest boundary.

  245. Thẻ 245

    Câu hỏi

    What is cloud platform operations responsible for after secure build?

    Câu trả lời

    Maintaining approved configuration, availability, patching, monitoring, backup, access, and evidence. Operations should feed recurring defects back into design.

  246. Thẻ 246

    Câu hỏi

    What does a privileged access administrator control?

    Câu trả lời

    The issuance, elevation, monitoring, review, and revocation of administrative access. Separate the access-control role from routine use where practical.

  247. Thẻ 247

    Câu hỏi

    What is the safer pattern for remote SSH administration?

    Câu trả lời

    Short-lived identity-based access through a controlled path with host verification, least privilege, session logging, and no shared keys. Disable direct root login.

  248. Thẻ 248

    Câu hỏi

    When should a cloud workload require platform attestation?

    Câu trả lời

    When access depends on proof that the host or confidential environment is in an approved measured state. Define what is measured, who verifies it, and what failure does.

  249. Thẻ 249

    Câu hỏi

    Which protocol adds origin authentication and integrity to DNS data?

    Câu trả lời

    DNSSEC. TLS protects a transport session, a VPN protects traffic across an untrusted boundary, and DHCP safeguards prevent rogue address or configuration assignment.

  250. Thẻ 250

    Câu hỏi

    What should enforce separation between cloud network zones?

    Câu trả lời

    Routing and firewall or security-group policy tied to explicit allowed flows. VLANs can organize segments but do not enforce policy by themselves.

  251. Thẻ 251

    Câu hỏi

    How do IDS and IPS differ operationally?

    Câu trả lời

    An IDS alerts on suspected activity; an IPS sits inline and can block it. Inline prevention adds availability and false-positive risk.

  252. Thẻ 252

    Câu hỏi

    What reduces RDP exposure in a cloud environment?

    Câu trả lời

    Remove direct internet access, require a hardened gateway or private path, strong MFA, current patches, device checks, and session monitoring. Limit clipboard and drive redirection by need.

  253. Thẻ 253

    Câu hỏi

    What makes a honeypot safe enough to operate?

    Câu trả lời

    Isolation, no production trust, controlled data, monitored egress, legal approval, and an incident plan. It should observe attackers without becoming their launch point.

  254. Thẻ 254

    Câu hỏi

    How do high availability and backup differ?

    Câu trả lời

    High availability keeps service running through component failure; backup restores data or state after loss or corruption. One does not replace the other.

  255. Thẻ 255

    Câu hỏi

    How should firewall, IDS, and IPS controls be layered?

    Câu trả lời

    Firewalls constrain allowed paths, IDS detects suspicious activity, and IPS may block selected attacks inline. Central telemetry and tuned ownership make the layers useful.

  256. Thẻ 256

    Câu hỏi

    When is a cloud security group insufficient as the only network control?

    Câu trả lời

    When application-aware filtering, centralized inspection, advanced threat detection, or cross-environment policy is required. Keep security groups as workload-level least-privilege boundaries.

  257. Thẻ 257

    Câu hỏi

    How should management-plane tools be installed?

    Câu trả lời

    From verified sources through a controlled, minimal, hardened build with separate privileged access and logging. Remove sample accounts, unused plugins, and default exposure.

  258. Thẻ 258

    Câu hỏi

    What is patch management?

    Câu trả lời

    A controlled lifecycle for identifying, prioritizing, testing, deploying, verifying, and documenting security and reliability updates. Asset inventory and exception ownership are prerequisites.

  259. Thẻ 259

    Câu hỏi

    How do performance and capacity monitoring differ?

    Câu trả lời

    Performance monitoring measures current service behavior; capacity monitoring forecasts whether resources can meet future demand. Both need business thresholds and trends.

  260. Thẻ 260

    Câu hỏi

    How do change, release, and deployment management differ?

    Câu trả lời

    Change management authorizes and controls modification; release management packages approved capability; deployment management moves it into an environment. One workflow may integrate all three without erasing their goals.

  261. Thẻ 261

    Câu hỏi

    What should decide whether an IPS blocks automatically?

    Câu trả lời

    Detection confidence, asset criticality, attack impact, false-positive cost, bypass behavior, and rollback. Start with observation when evidence is weak.

  262. Thẻ 262

    Câu hỏi

    Who owns a patch exception?

    Câu trả lời

    The authorized system or risk owner, with technical evidence from operations and security. The exception needs compensating controls, expiry, and review.

  263. Thẻ 263

    Câu hỏi

    What does a capacity manager protect?

    Câu trả lời

    The service's ability to meet current and forecast demand within cost and resilience constraints. The role tracks trends, thresholds, quotas, and scaling lead time.

  264. Thẻ 264

    Câu hỏi

    What is the change manager's security role?

    Câu trả lời

    Ensure risk, testing, authorization, scheduling, rollback, and communication are proportionate to the change. Emergency changes still need retrospective evidence.

  265. Thẻ 265

    Câu hỏi

    What should a backup-and-restore control verify for guest systems?

    Câu trả lời

    Required data and configuration are captured, protected, retained, and restored within targets. Include application consistency, keys, dependencies, and documented restore order.

  266. Thẻ 266

    Câu hỏi

    Which management process keeps a cloud service able to meet its agreed uptime and reliability targets?

    Câu trả lời

    Availability management. It analyzes failure patterns, resilience, maintainability, and recovery so the service can meet those targets.

  267. Thẻ 267

    Câu hỏi

    What improves patch prioritization beyond a severity score?

    Câu trả lời

    Exploitability, exposure, asset importance, compensating controls, dependency, and business impact. Verify remediation and track unsupported assets separately.

  268. Thẻ 268

    Câu hỏi

    What turns performance and capacity alerts into an availability control?

    Câu trả lời

    Thresholds tied to service objectives, trend analysis, ownership, safe scaling, and tested response. Alert volume without action is not capacity management.

  269. Thẻ 269

    Câu hỏi

    What should a configuration-management system record?

    Câu trả lời

    Approved items, owners, versions, relationships, baselines, changes, and current state. Cloud discovery should reconcile actual resources with declared configuration.

  270. Thẻ 270

    Câu hỏi

    Why place a cluster host into maintenance mode?

    Câu trả lời

    To drain or protect workloads before planned work while preserving cluster policy. Verify capacity, placement constraints, and stateful-service behavior first.

  271. Thẻ 271

    Câu hỏi

    Which management process agrees, monitors, and reviews measurable service targets with customers?

    Câu trả lời

    Service-level management. It turns business needs into agreed service objectives, tracks results, and drives action when performance misses them.

  272. Thẻ 272

    Câu hỏi

    Which hardware signals should cloud facilities monitor?

    Câu trả lời

    Disk health, CPU and memory errors, fan and temperature state, power, and vendor fault telemetry. Correlate physical signals with host and workload impact.

  273. Thẻ 273

    Câu hỏi

    How should an OS hardening baseline be maintained?

    Câu trả lời

    Version it, test it, measure compliance, remediate drift, record exceptions, and update it for new threats and platform changes. Apply separate profiles to distinct workloads.

  274. Thẻ 274

    Câu hỏi

    How do incident management and problem management differ?

    Câu trả lời

    Incident management restores service and limits harm; problem management finds and removes underlying causes. The same event can open both tracks.

  275. Thẻ 275

    Câu hỏi

    Which management process coordinates security risk and controls across cloud service operation?

    Câu trả lời

    Information security management. It aligns policy, risk treatment, control operation, evidence, incidents, and improvement with the service-management system.

  276. Thẻ 276

    Câu hỏi

    Which management process turns recurring service-control gaps into measured improvements?

    Câu trả lời

    Continual service improvement management. It prioritizes opportunities, defines a measurable target and owner, implements change, and verifies the outcome.

  277. Thẻ 277

    Câu hỏi

    How should operations choose among NIST, ISO, COBIT, CIS Controls, COSO, ITIL, or ISO/IEC 20000-1?

    Câu trả lời

    Map the applicable framework or standard to the organization's legal duties, risks, service goals, and evidence needs. The names are not interchangeable, and adoption alone does not prove control effectiveness.

  278. Thẻ 278

    Câu hỏi

    A service is restored after repeated crashes. Which process continues the root-cause work?

    Câu trả lời

    Problem management. Incident management can close after stable restoration while the underlying defect, workaround, and prevention remain tracked.

  279. Thẻ 279

    Câu hỏi

    Which management process owns tested arrangements for sustaining or restoring critical services after severe disruption?

    Câu trả lời

    Continuity management. Incident management handles the current event, while availability management focuses on meeting service uptime and reliability targets.

  280. Thẻ 280

    Câu hỏi

    What does a cloud forensic lead decide?

    Câu trả lời

    The lawful collection strategy, volatile-data priorities, tools, provider coordination, preservation, and analysis plan. The lead should understand cloud-specific evidence limits.

  281. Thẻ 281

    Câu hỏi

    What does chain of custody record?

    Câu trả lời

    Who collected, handled, transferred, stored, analyzed, and disposed of evidence, when and why. Integrity checks support the record but do not replace it.

  282. Thẻ 282

    Câu hỏi

    What does an incident commander own?

    Câu trả lời

    Priorities, roles, decisions, coordination, cadence, and safe handoffs during an incident. Technical responders investigate and act within that structure.

  283. Thẻ 283

    Câu hỏi

    What does the incident communications lead control?

    Câu trả lời

    Approved messages, audiences, channels, timing, records, and coordination with legal and leadership. Technical certainty and disclosure obligations may change during the event.

  284. Thẻ 284

    Câu hỏi

    How do a SOC, SIEM, and SOAR relate?

    Câu trả lời

    A SOC is the operating function, a SIEM centralizes and analyzes security events, and SOAR coordinates automated workflows. People, process, authority, and evidence connect the tools.

  285. Thẻ 285

    Câu hỏi

    What is an evidence custodian responsible for?

    Câu trả lời

    Controlled storage, access, transfer, integrity verification, retention, and chain-of-custody records. The custodian preserves evidence without altering its meaning.

  286. Thẻ 286

    Câu hỏi

    How should a SOC use threat intelligence?

    Câu trả lời

    Map relevant, timely indicators and adversary behavior to assets, detections, hunts, and decisions. Expire stale indicators and separate confidence from fact.

  287. Thẻ 287

    Câu hỏi

    How should AI-assisted security monitoring be governed?

    Câu trả lời

    Validate data and models, measure errors and drift, limit action authority, log reasoning inputs and outcomes, and keep human review for consequential cases. Compare against a safe manual path.

  288. Thẻ 288

    Câu hỏi

    When is a cloud snapshot suitable forensic evidence?

    Câu trả lời

    When collection is authorized, scope and timing are documented, integrity is protected, and the snapshot preserves relevant state. It may omit memory, external services, or rapidly changing logs.

  289. Thẻ 289

    Câu hỏi

    Who decides whether a regulator must be notified during a cloud incident?

    Câu trả lời

    The authorized legal or compliance owner under the incident plan. Vendor and communications owners coordinate channels; engineers supply verified facts.

  290. Thẻ 290

    Câu hỏi

    What should a forensic plan obtain from the cloud provider before an incident?

    Câu trả lời

    Available logs and APIs, retention, time sources, support contacts, legal process, evidence formats, isolation options, and responsibility boundaries. Confirm access with an exercise.

  291. Thẻ 291

    Câu hỏi

    How should vulnerability assessment and penetration testing work together?

    Câu trả lời

    Assessment finds and prioritizes likely weaknesses broadly; authorized penetration testing demonstrates selected exploit paths and impact. Both require scoped remediation and retest.

  292. Thẻ 292

    Câu hỏi

    How should a SIEM protect cloud log value?

    Câu trả lời

    Normalize without losing source evidence, control access, preserve time and integrity, correlate identities and assets, tune detections, and retain by purpose. Monitor collection gaps.

  293. Thẻ 293

    Câu hỏi

    What should SOAR do when a playbook's evidence is incomplete?

    Câu trả lời

    Pause or take only a safe reversible step, preserve context, and escalate to an authorized human. Do not let automation convert uncertainty into broad containment damage.

  294. Thẻ 294

    Câu hỏi

    When should incident communication wait?

    Câu trả lời

    Only when authorized coordination is needed to verify facts, protect response, or meet a defined legal strategy. Do not delay a mandatory notice past its trigger or deadline.

  295. Thẻ 295

    Câu hỏi

    When is penetration testing more useful than another vulnerability scan?

    Câu trả lời

    When the organization needs authorized evidence that selected weaknesses can combine into a meaningful attack path. Scanning remains better for broad, repeatable coverage.

  296. Thẻ 296

    Câu hỏi

    Which evidence should be collected first from a running cloud workload?

    Câu trả lời

    The most volatile, relevant evidence that will disappear earliest, if collection is authorized and safe. Balance volatility against service impact and contamination risk.

  297. Thẻ 297

    Câu hỏi

    Why can cloud data be subject to more than one jurisdiction?

    Câu trả lời

    Customers, providers, processing, storage, people, contracts, and affected individuals may sit in different places. Location and legal reach are related but not identical.

  298. Thẻ 298

    Câu hỏi

    Why are privacy roles contextual rather than permanent labels?

    Câu trả lời

    An organization can be controller for one processing purpose and processor for another. Determine the role from actual decisions and instructions, not the company type.

  299. Thẻ 299

    Câu hỏi

    What should legal counsel contribute to cloud design?

    Câu trả lời

    Interpret applicable law, privilege, contracts, disputes, preservation, disclosure, and legal risk. Counsel advises; accountable business owners still decide within authority.

  300. Thẻ 300

    Câu hỏi

    What is eDiscovery?

    Câu trả lời

    The identification, preservation, collection, processing, review, and production of electronically stored information for a legal matter. Cloud scale and provider control affect each step.

  301. Thẻ 301

    Câu hỏi

    How do contractual and regulated private data differ?

    Câu trả lời

    Contractual duties come from agreed terms; regulated duties come from applicable law. The same data can be subject to both, and the stricter combined obligations may govern.

  302. Thẻ 302

    Câu hỏi

    What is the controller's contract duty toward a cloud processor?

    Câu trả lời

    Give documented instructions, choose and oversee a capable processor, and define required privacy and security terms. Applicable law may add specific clauses and audit duties.

  303. Thẻ 303

    Câu hỏi

    What is a Privacy Impact Assessment?

    Câu trả lời

    A structured evaluation of how planned processing affects people and how privacy risk will be handled. Perform it early enough to change the design.

  304. Thẻ 304

    Câu hỏi

    What is an ISMS?

    Câu trả lời

    A managed system of policies, risk processes, controls, evidence, review, and continual improvement for information security. It is broader than a control checklist or toolset.

  305. Thẻ 305

    Câu hỏi

    What does a contract's choice-of-law clause do?

    Câu trả lời

    Names the law intended to govern the contract. It does not automatically override mandatory laws or every court's jurisdiction.

  306. Thẻ 306

    Câu hỏi

    What makes a legal hold operationally defensible in cloud systems?

    Câu trả lời

    Authorized scope, prompt preservation, deletion suspension, controlled collection, access logging, periodic review, and documented release. Test whether provider features cover all copies.

  307. Thẻ 307

    Câu hỏi

    Does calling a field PII or PHI settle every privacy obligation?

    Câu trả lời

    No. Applicability depends on the data, person, entity, purpose, context, and governing law or contract. Classify with qualified privacy and legal input.

  308. Thẻ 308

    Câu hỏi

    Which design control reduces privacy risk before consent screens and notices?

    Câu trả lời

    Data minimization tied to a specific approved purpose. Collecting less reduces exposure, rights handling, retention, and breach impact.

  309. Thẻ 309

    Câu hỏi

    What is a processor's core duty toward controller data?

    Câu trả lời

    Process it only under authorized instructions and required legal obligations, while applying agreed controls and assistance. Subprocessors need governed approval and flow-down terms.

  310. Thẻ 310

    Câu hỏi

    What control reveals cross-border cloud data processing before it becomes a compliance surprise?

    Câu trả lời

    A maintained data and subprocessors map tied to locations, purposes, roles, transfers, and safeguards. Reconcile contracts with actual telemetry and provider disclosures.

  311. Thẻ 311

    Câu hỏi

    How do internal and external audits differ?

    Câu trả lời

    Internal audit provides independent assurance inside the organization; external audit is performed by an outside party for a defined objective. Both require scope, criteria, evidence, and independence.

  312. Thẻ 312

    Câu hỏi

    When should a PIA be reopened?

    Câu trả lời

    When purpose, data, people, model, provider, location, sharing, retention, or risk materially changes. A one-time assessment becomes stale as processing evolves.

  313. Thẻ 313

    Câu hỏi

    How should a cloud team use GDPR, PIPEDA, India's DPDP Act, FERPA, HIPAA, ISO/IEC 27018, or GAPP?

    Câu trả lời

    First determine which laws apply, then map their obligations and any selected framework guidance to actual processing and controls. A named standard or provider region is not automatic compliance.

  314. Thẻ 314

    Câu hỏi

    Two countries impose conflicting duties on the same cloud records. What is the first move?

    Câu trả lời

    Escalate to qualified counsel with the exact data, actors, locations, contracts, orders, and timelines. Preserve evidence and avoid an irreversible technical action based on guesswork.

  315. Thẻ 315

    Câu hỏi

    What protects an internal auditor's independence?

    Câu trả lời

    Authority to assess outside the operation being audited, objective reporting, and freedom from designing or owning the control under review. Internal employment does not prevent independence if governance is sound.

  316. Thẻ 316

    Câu hỏi

    What does a privacy officer oversee?

    Câu trả lời

    Privacy governance, impact assessment, rights, transparency, lawful processing, transfers, incidents, and regulator engagement. The exact statutory role varies by jurisdiction.

  317. Thẻ 317

    Câu hỏi

    What do SOC, SSAE, and ISAE labels tell an assurance-report reader?

    Câu trả lời

    SOC identifies a service-organization report family, while SSAE and ISAE identify attestation standards used for defined engagements. The exact report type, criteria, period, scope, exceptions, and subservices determine its value.

  318. Thẻ 318

    Câu hỏi

    What must an audit plan define before cloud audit fieldwork starts?

    Câu trả lời

    The objective, criteria, scope, responsibilities, schedule, methods, evidence access, and reporting path. The plan should also name constraints and follow-up ownership.

  319. Thẻ 319

    Câu hỏi

    How do risk appetite and risk tolerance differ?

    Câu trả lời

    Risk appetite expresses the amount and type of risk an organization is willing to pursue or retain; tolerance sets acceptable variation around objectives. Both guide escalation and treatment.

  320. Thẻ 320

    Câu hỏi

    What does an enterprise risk owner decide?

    Câu trả lời

    Whether to avoid, mitigate, transfer or share, or accept a documented risk within authority. The owner tracks residual exposure and review triggers.

  321. Thẻ 321

    Câu hỏi

    How should risk metrics be designed?

    Câu trả lời

    Tie each metric to a decision, owner, threshold, reliable source, trend, and response. Separate leading indicators from lagging outcomes and guard against easy gaming.

  322. Thẻ 322

    Câu hỏi

    What is gap analysis?

    Câu trả lời

    Comparison of current control state with a required or target state. Each gap needs impact, owner, treatment, evidence, and due date.

  323. Thẻ 323

    Câu hỏi

    What makes cloud audit evidence reliable?

    Câu trả lời

    Clear criteria, complete scope, trustworthy source, protected integrity, accurate time, repeatable collection, and accountable ownership. Screenshots without context are weak evidence.

  324. Thẻ 324

    Câu hỏi

    Why does a distributed cloud model complicate audit scope?

    Câu trả lời

    Controls, evidence, people, providers, and data span locations and jurisdictions with different access and retention limits. Define boundaries and shared responsibilities before fieldwork.

  325. Thẻ 325

    Câu hỏi

    Can a clean SOC report prove compliance with a customer's specialized regulation?

    Câu trả lời

    No. Map the report's criteria, period, scope, exceptions, subservices, and customer controls to the specific requirement. NERC CIP, HIPAA, HITECH, PCI, or another regime may need additional evidence.

  326. Thẻ 326

    Câu hỏi

    What should a customer assess in a cloud provider's risk-management program?

    Câu trả lời

    Whether its policies, methods, controls, risk profile, and appetite fit the customer's requirements and exposure. Review evidence before selection and when material risk changes.

  327. Thẻ 327

    Câu hỏi

    What is a data owner's enterprise-risk role?

    Câu trả lời

    Set business value, classification, allowed use, access, retention, and acceptable risk for the data. Custodians implement the resulting controls.

  328. Thẻ 328

    Câu hỏi

    What AI evidence supports accountability and explainability without promising perfect interpretation?

    Câu trả lời

    Document intended use, data and model versions, decision roles, testing, limitations, human oversight, outputs, changes, and incident history. Match explanation depth to affected people and legal duties.

  329. Thẻ 329

    Câu hỏi

    What does a data steward add to governance?

    Câu trả lời

    Consistent definitions, quality rules, metadata, lineage, and policy application across business use. The steward connects business meaning to operational handling.

  330. Thẻ 330

    Câu hỏi

    What is procurement's security role in cloud outsourcing?

    Câu trả lời

    Make required risk, assurance, pricing, ownership, exit, and supplier terms part of selection and negotiation. Security requirements lose force if added after commercial commitment.

  331. Thẻ 331

    Câu hỏi

    When should an organization avoid a cloud risk rather than mitigate it?

    Câu trả lời

    When stopping the activity is feasible and residual exposure would remain outside appetite or legal authority. Compare the business consequence of avoidance with other treatments.

  332. Thẻ 332

    Câu hỏi

    What is an external auditor responsible for?

    Câu trả lời

    Perform the agreed independent engagement against stated criteria and report within its scope. The auditor does not own management's controls or risk decisions.

  333. Thẻ 333

    Câu hỏi

    How do an MSA, SOW, and SLA differ?

    Câu trả lời

    The MSA sets the general legal relationship, the SOW defines specific work and deliverables, and the SLA sets measurable service commitments. Read them together for the full obligation.

  334. Thẻ 334

    Câu hỏi

    What should a cloud risk register contain?

    Câu trả lời

    Scenario, assets, cause, consequence, owner, likelihood, impact, controls, treatment, residual risk, due dates, and review triggers. Link evidence and dependencies where useful.

  335. Thẻ 335

    Câu hỏi

    Who should own a cloud contract after signature?

    Câu trả lời

    A named contract or vendor manager with business, legal, security, privacy, and service stakeholders. Ownership includes obligations, evidence, changes, renewals, disputes, and exit.

  336. Thẻ 336

    Câu hỏi

    Which contract controls support a safe cloud exit?

    Câu trả lời

    Data and configuration export, assistance, timing, format, cost, continued access, verified deletion, transition support, and survival of needed duties. Exercise the exit path before a crisis.

  337. Thẻ 337

    Câu hỏi

    What makes a contractual right to audit usable?

    Câu trả lời

    Defined scope, notice, frequency, methods, evidence access, confidentiality, cost, remediation, and alternatives when direct testing is unsafe. A vague right may be impossible to exercise.

  338. Thẻ 338

    Câu hỏi

    When does source-code escrow reduce cloud vendor viability risk?

    Câu trả lời

    When usable code plus dependencies, documentation, rights, updates, and release triggers can support continuity. Escrow adds little if the customer cannot operate the service.

  339. Thẻ 339

    Câu hỏi

    What should a cloud incident-notification clause define?

    Câu trả lời

    Trigger, timing, recipient, secure channel, minimum facts, updates, cooperation, evidence, regulator support, and subcontractor flow-down. Avoid waiting for the provider's final root cause before notice.

  340. Thẻ 340

    Câu hỏi

    What should happen to customer data when a cloud contract ends?

    Câu trả lời

    Return or export it in a usable form, preserve only what is lawfully required, revoke access, and verify deletion across in-scope copies under the contract. Data ownership and transition duties should be settled before purchase.

Abstract cloud infrastructure with layered security boundaries, connected control nodes, and an AI model graph.

340 thẻ

CCSP 2026 Flashcards: August Exam Outline Review

Học bộ thẻ này miễn phí

Nibomo sẽ mở ra để bạn bắt đầu học.