Certified Cloud Security Professional
Demonstrates advanced technical skills and knowledge to design, manage, and secure data, applications, and infrastructure in cloud environments using best practices, policies, and procedures. Covers six domains including cloud architecture, data security, platform security, application security, operations, and legal compliance. Requires five years of IT work experience with three years in information security and one year in a CCSP domain. Accredited under ISO/IEC 17024 and approved by the U.S. DoD.
Sample questions
A free preview of 15 source-grounded questions from this exam — answers and explanations included.
- Q1Cloud Data Securitymedium
A federal agency is preparing to release a public statistical dataset, and the privacy officer is evaluating how to break the link between each record and the individual it describes while still supporting analysis. Which NIST SP 800-188 process applies?
- A.Media sanitization, rendering access to data on retired media infeasible for a given level of effort
- B.Tokenization of primary keys so the records can later be re-linked to individuals on demand by analysts
- C.Dynamic data masking that hides fields only inside live query results for nonprivileged database users
- D.De-identification, the process of removing the association between a set of identifying data and the data subjectCorrect answer
Sources
Questions are grounded in 150 references from official and authoritative materials.
- SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations | CSRC
- SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations | CSRC
- Shared responsibility in the cloud - Microsoft Azure | Microsoft Learn
- SP 800-145, The NIST Definition of Cloud Computing | CSRC