Certified Cloud Security Officer Exam Prep
Free practice questions

Free C)CSO Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The C)CSO exam has 100 questions and runs 2 hours.

These 10 free C)CSO questions are organized by exam domain, so you can see how each part of the Certified Cloud Security Officer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Cloud Computing and Architectural Concepts

Question 1

A payroll team replaces its self-managed virtual machines with a SaaS application. The supplier operates the application and its supporting infrastructure; the customer administers its own tenant. When revising the security responsibility matrix, which task should remain assigned to the customer?

Show answer & explanation

Correct answer: D - Reviewing tenant administrator privileges and external sharing permissions.

Domain 2: Fundamental Technologies to Cloud Computing

Question 2

A hosting company runs mutually untrusted customer workloads as ordinary Linux containers on one host. A new isolation requirement prohibits different customers from sharing an operating-system kernel. The workloads must remain available. Which redesign satisfies that requirement?

Show answer & explanation

Correct answer: A - Place each customer's containers in a separate virtual machine with its own guest kernel.

Domain 3: Enterprise Risk Management and Governance

Question 3

A proposed control would reduce the expected loss per cloud data-exposure incident from $240,000 to $80,000. The estimated frequency remains 0.25 incidents per year. Operating the control would cost $25,000 annually, with no separate implementation cost. No legal mandate or additional benefit applies. The approved funding rule requires a positive net annual benefit. What recommendation follows from these estimates?

Show answer & explanation

Correct answer: D - Fund the control; its estimated net annual benefit is $15,000.

Domain 4: Cloud Risks

Question 4

CVSS v4.0 Base: 8.3. EPSS score: 0.20. EPSS percentile: 0.97. These values appear together in a vulnerability report. A manager reads the percentile as a 97% chance that the company's application will be attacked. Which interpretation should replace that statement?

Show answer & explanation

Correct answer: C - High severity; a 20% forecast of exploitation in the wild over the next 30 days.

Domain 5: Design Fundamentals

Question 5

Repeated timeouts have opened the circuit breaker protecting a checkout service's calls to its fraud-screening provider. The recovery delay has elapsed. Orders may wait, but they must not bypass screening. How should the breaker test whether the dependency can recover without being overwhelmed?

Show answer & explanation

Correct answer: D - Enter half-open and admit limited trial calls before restoring normal traffic.

Domain 6: Encryption Capabilities and Key Management

Question 6

An autoscaling storage service uses AES-256-GCM. Every worker starts its nonce counter at zero, and all workers use the same encryption key. Testing finds different objects encrypted with an identical key-and-nonce pair, although their authentication tags verify successfully. The review should require this change:

Show answer & explanation

Correct answer: B - Ensure nonce uniqueness across all workers sharing the key, including after restarts.

Domain 8: Identity, Entitlement and Access Management

Question 7

A phishing exercise uses a lookalike sign-in site that relays employees' passwords and current time-based one-time passwords to the real cloud identity provider. The provider accepts the relayed credentials. Which replacement most directly prevents this verifier-impersonation technique?

Show answer & explanation

Correct answer: C - Use WebAuthn authentication bound to the legitimate service's relying-party identifier.

Domain 9: Application Security

Question 8

During an authorized test, a cloud document-preview service accepts a customer-supplied URL. The preview worker follows a redirect to a private administrative endpoint and returns that endpoint's response. Network captures show the connection originates from the worker, not the customer's browser. No script executes in the browser. Which vulnerability accounts for these findings?

Show answer & explanation

Correct answer: B - Server-side request forgery through the preview worker's URL-fetching function.

Domain 11: Business Continuity, Disaster Recovery and Incident Response

Question 9

An incident responder confirms that a stolen service credential is actively downloading a hospital's confidential cloud records. The credential belongs exclusively to a paused analytics job; clinical applications use separate identities. Audit logs are already preserved in a protected account. The responder has containment authority, and the platform supports immediate session revocation. What should happen first to stop the disclosure while preserving clinical service?

Show answer & explanation

Correct answer: A - Revoke the affected identity's access and invalidate its active sessions.

Domain 12: Legal, Auditing and Compliance Responsibilities

Question 10

'The add-on uses our corporate security policies, so our SOC 2 Type 2 report covers it,' says a SaaS supplier. The report's system description expressly excludes the analytics add-on; it covers only the core service. The customer wants to purchase both. What is the appropriate assurance decision?

Show answer & explanation

Correct answer: A - Request control evidence for the add-on; the existing opinion does not cover its excluded scope.

The rest of the C)CSO blueprint

The C)CSO exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more C)CSO questions with explanations.

Continue in the free practice test →

View plans