Free ISC2 Certified Cloud Security Professional (CCSP) practice — 6 questions on Cloud Concepts, Architecture and Design, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Cloud Concepts, Architecture and Design
A consortium of five regional hospitals, all subject to the same healthcare regulatory framework, wants to jointly fund and operate a cloud environment. The infrastructure will only be accessible to the five hospitals and will be governed by a shared compliance charter that none of them could justify building alone. Which cloud deployment model BEST fits this arrangement?
Community cloud is provisioned for exclusive use by a specific group of consumers with shared concerns (compliance, mission, security requirements), often jointly owned or managed by the community members — exactly the hospitals-with-shared-regulation scenario described.
Question 2 of 6 · Cloud Concepts, Architecture and Design
According to NIST SP 800-145, which essential characteristic of cloud computing specifically refers to a consumer's ability to provision computing capabilities automatically, without requiring human interaction with each service provider?
On-demand self-service is defined by NIST as the consumer's capability to unilaterally provision compute resources as needed automatically, without requiring human interaction with the service provider.
Question 3 of 6 · Cloud Concepts, Architecture and Design
A cloud security professional is evaluating a public cloud provider that acts as a PII processor on behalf of enterprise customers. Which certification/code of practice is designed SPECIFICALLY to address the protection of personally identifiable information in public cloud environments?
ISO/IEC 27018 is the code of practice specifically addressing protection of PII in public clouds acting as PII processors, extending ISO/IEC 27002 controls with cloud-privacy-specific guidance.
Question 4 of 6 · Cloud Concepts, Architecture and Design
Under the shared responsibility model, in a Platform as a Service (PaaS) deployment, which party is responsible for patching the underlying operating system and managed runtime environment?
In PaaS, the provider manages the underlying infrastructure, OS, and runtime/middleware as part of the abstracted platform, leaving the customer responsible only for application code, data, and configuration within the platform.
Question 5 of 6 · Cloud Concepts, Architecture and Design
In the NIST cloud reference architecture, which actor is responsible for providing connectivity and transport of cloud services between cloud consumers and cloud providers, and may also provide network-level security controls such as encrypted transport?
The cloud carrier is the intermediary that provides connectivity and transport of cloud services from providers to consumers, typically via network, telecommunication, and other access devices.
Question 6 of 6 · Cloud Concepts, Architecture and Design
A cybersecurity architect negotiating a cloud contract requires a clause guaranteeing that, upon contract termination, the provider will return all customer data in a usable format and then permanently and verifiably delete any remaining copies within a defined period. Which cloud design/contractual principle does this clause primarily address?
Reversibility (formalized in ISO/IEC 27017) refers to the process for customers to retrieve their data and for all copies to be removed from the provider's systems at the end of the service relationship, exactly matching the clause described.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.