TechNuggets Academy
CCSK v5

Free Certificate of Cloud Security Knowledge Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$39512 exam domainsLevel Intermediate2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: Cloud Computing Concepts and Architectures
A retail company migrates its customer relationship management (CRM) system to a SaaS provider. Per the CCSK shared responsibility model, which responsibility ALWAYS remains with the customer, regardless of the service model used?
Across all service models—IaaS, PaaS, and SaaS—the customer never transfers ownership of their data or accountability for who can access it. Identity, access management, and data governance stay with the customer even in SaaS, where the provider manages nearly everything else in the stack.
Question 2 of 12 · Domain 2: Cloud Governance
A healthcare organization is negotiating a contract with a cloud provider for storing PHI. To minimize risk from potential vendor lock-in and ensure business continuity if the relationship ends, which contractual provision is MOST important to include?
A data portability and exit clause ensures the organization can retrieve its data in a usable format and confirm secure deletion by the provider, directly addressing vendor lock-in and exit strategy — a core CCSK governance concern in vendor contract negotiations.
Question 3 of 12 · Domain 3: Risk, Audit, and Compliance
A financial services firm is evaluating a large public cloud provider but cannot secure a contractual right to perform on-site audits due to the provider's multi-tenant scale. The firm still needs verifiable assurance that the provider's controls meet CCM requirements. Which approach BEST satisfies this need?
CCSK guidance recognizes that individual customer audits don't scale at cloud provider size, so CSA promotes using the CAIQ (self-assessment against CCM controls) combined with independent third-party attestations like SOC 2 Type II to gain assurance without requiring physical audits.
Question 4 of 12 · Domain 4: Organization Management
A company is expanding its cloud footprint and wants to limit the blast radius of a security incident in one business unit from affecting the resources of other business units. Which organizational strategy BEST achieves this goal?
CSA guidance recommends using separate accounts/subscriptions as the primary isolation boundary because the account itself is a hard security boundary in most cloud providers, containing IAM, billing, and resource blast radius, while still allowing centralized governance through an organizational hierarchy (e.g., management groups, organizations).
Question 5 of 12 · Domain 5: Identity and Access Management
An organization federates its workforce identities to a cloud provider using SAML-based SSO through its on-premises Identity Provider (IdP). Which statement BEST describes the security priority this architecture creates for the organization?
CCSK guidance emphasizes that federation concentrates trust in the IdP — compromise of the IdP compromises every relying party it federates to, so the IdP must be protected as critical infrastructure (hardened, monitored, and highly available).
Question 6 of 12 · Domain 6: Security Monitoring
A financial services company operates workloads across three different cloud providers and needs a unified view of security events for real-time correlation and alerting. Which approach BEST satisfies this requirement?
Centralizing normalized logs from all cloud environments into a single SIEM enables cross-provider correlation, real-time alerting, and consistent detection logic — the core goal of multi-cloud security monitoring per CSA guidance.
Question 7 of 12 · Domain 7: Infrastructure and Networking
A company is migrating a multi-tier application to the cloud. During a tabletop exercise, the security team wants to ensure that if a single compute instance is compromised, an attacker cannot easily pivot to other instances within the same subnet. Which control BEST addresses this requirement?
Micro-segmentation applies granular, identity- and workload-aware policies at the individual host or workload level, restricting lateral (east-west) movement so a compromised instance cannot freely communicate with unrelated workloads, which is exactly the scenario described.
Question 8 of 12 · Domain 8: Cloud Workload Security
A company runs containerized microservices on Kubernetes. They want to prevent a compromised container from running as root or gaining privileged access that could allow escape to the underlying host. Which control BEST addresses this requirement?
Pod Security Standards (restricted profile) is the runtime control that directly disallows privileged containers, host namespace/PID/IPC sharing, and enforces non-root execution, which is the specific mechanism that prevents container-to-host escape via privilege escalation.
Question 9 of 12 · Domain 9: Data Security
A healthcare provider stores encrypted patient records (PHI) in a cloud provider's object storage. The contract with the cloud provider is ending, and the company wants absolute assurance that no readable copies of the data remain accessible to the provider after migration, including in backups and snapshots the provider controls. Which approach BEST achieves this?
Crypto-shredding (destroying the encryption keys) is the recommended and often only practical way to guarantee data on media you don't physically control -- including provider-managed backups, snapshots, and distributed storage -- becomes permanently unrecoverable, since without the key the ciphertext is useless.
Question 10 of 12 · Domain 10: Application Security
A DevOps team's CI/CD pipeline needs database credentials and third-party API keys available to build agents during deployment. Per CCSK guidance on secrets management, which approach BEST meets this requirement?
CCSK emphasizes centralized secrets management (e.g., vault-based services) with dynamic, short-lived, auto-rotated credentials to minimize exposure window and eliminate hardcoded/static secrets scattered across systems.
Question 11 of 12 · Domain 11: Incident Response and Resilience
During an incident investigation of a suspected compromised virtual machine in an IaaS environment, the responder needs to preserve evidence for forensic analysis while limiting further attacker activity. Which action BEST meets these requirements?
Snapshotting the disk and capturing memory preserves volatile and non-volatile evidence for forensic analysis, while isolating the instance via network controls contains the threat without destroying evidence — aligning with CCSK v5 guidance to use cloud-native snapshot capabilities before termination.
Question 12 of 12 · Domain 12: Related Technologies and Strategies
A financial services company is redesigning its cloud security architecture and wants to eliminate implicit trust based on network location. Employees, contractors, and partners will access cloud applications from a variety of untrusted networks. Which approach BEST aligns with Zero Trust principles as described in CSA guidance?
Zero Trust's core tenet is 'never trust, always verify' — access decisions are based on continuously verified identity, device posture, and context, combined with least privilege, rather than on network location.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

CCSK v5 exam — quick answers

How much does the CCSK v5 exam cost?

The exam fee is approximately $395 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 12 domains: Cloud Computing Concepts and Architectures (~8%), Cloud Governance (~8%), Risk, Audit, and Compliance (~9%), Organization Management (~8%), Identity and Access Management (~9%), Security Monitoring (~8%), Infrastructure and Networking (~9%), Cloud Workload Security (~9%), Data Security (~9%), Application Security (~8%), Incident Response and Resilience (~8%), Related Technologies and Strategies (~7%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.