Free ISC2 Certified Cloud Security Professional (CCSP) practice — 6 questions on Cloud Security Operations, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Cloud Security Operations
A cloud security team responding to a suspected compromise on a running IaaS virtual machine must collect forensic evidence. According to the order of volatility principle, which artifact should be captured FIRST, before any action that could alter system state?
RAM is the most volatile evidence source — its contents are lost on reboot or power-down — so per the order of volatility it must be captured before any less volatile artifact.
Question 2 of 6 · Cloud Security Operations
In a cloud forensic investigation, which term specifically refers to the documented, unbroken record showing who handled a piece of evidence, when, and what actions were performed on it?
Chain of custody is the specific record documenting evidence handling, transfer, and storage to preserve integrity and legal admissibility.
Question 3 of 6 · Cloud Security Operations
A cloud SOC wants its SIEM to accurately correlate privilege escalation events across a multi-cloud environment. Which configuration step is MOST critical before deploying correlation rules?
Correlation across distributed cloud log sources depends on consistent, synchronized timestamps; without a common time reference, event ordering and correlation rules produce inaccurate results.
Question 4 of 6 · Cloud Security Operations
A cloud engineering team must deploy an emergency security patch to a production Kubernetes cluster due to an actively exploited zero-day vulnerability. Following ITIL change management practices, which change record type should be used?
Emergency change process exists for urgent changes needed to resolve or prevent a major incident such as active exploitation, using an expedited approval path (e.g., an emergency CAB) instead of the full standard review cycle.
Question 5 of 6 · Cloud Security Operations
A company runs a cloud-hosted ML model for fraud detection in production. The SOC wants to detect gradual manipulation of the model's predictions caused by poisoned data entering a training feedback loop. Which monitoring approach is MOST appropriate?
Detecting data poisoning or gradual drift requires ongoing statistical monitoring of output distributions and prediction behavior compared against a known-good baseline, a core AI/ML operational security control.
Question 6 of 6 · Cloud Security Operations
During an active ransomware incident affecting a cloud-hosted customer database, the security operations team confirms customer PII was exfiltrated. Per incident communication best practices, who should be notified FIRST, before public disclosure or regulatory notification?
The predefined communication plan requires internal escalation to leadership, legal, and IR stakeholders first so that accurate, validated information drives subsequent regulatory and public notifications.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.