Certified Cloud Security Engineer Exam Prep
Free practice questions

Free CCSE Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The CCSE exam has 125 questions and runs 4 hours.

These 10 free CCSE questions are organized by exam domain, so you can see how each part of the Certified Cloud Security Engineer blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Introduction to Cloud Security 8% of exam

Question 1

An insurer moves a database from a customer-managed Azure VM to Azure SQL Database without changing the application that queries it. In the revised responsibility matrix, how should database-engine patching, application query security, and database permissions be assigned?

Show answer & explanation

Correct answer: A - Microsoft handles engine patching; the customer handles application query security and database permissions.

Domain 2: Platform and Infrastructure Security in Cloud 12% of exam

Question 2

An external client at 203.0.113.24 uses TCP source port 52144 to connect to port 443 on an EC2 instance in subnet 10.20.1.0/24. The security group permits the connection. The subnet network ACL allows inbound destination port 443 and outbound destination port 443, then denies all other traffic. A packet capture on the instance shows an arriving SYN and a departing SYN-ACK, but the client receives no reply. What additional network ACL rule is needed for this connection?

Show answer & explanation

Correct answer: D - Permit outbound TCP destination port 52144 to 203.0.113.24/32 before the deny rule.

Question 3

An engineer needs Compute Viewer access to Google Cloud project North, but none to project South. Both projects inherit the engineer's Compute Viewer grant from the same parent folder. A duplicate grant directly on South has already been removed. There are no other grants or group memberships. Which permission arrangement achieves the required access?

Show answer & explanation

Correct answer: C - Remove the folder grant and assign Compute Viewer directly to the engineer on North.

Domain 3: Application Security in Cloud 12% of exam

Question 4

A billing API correctly validates each access token's signature, issuer, audience, and expiration. A user from one customer company can nevertheless retrieve another company's invoice by changing the invoice identifier in the request. Users must retain access to invoices belonging to their own company. Which change closes the demonstrated vulnerability?

Show answer & explanation

Correct answer: B - Authorize each invoice request against the authenticated user and the requested invoice on the server.

Domain 4: Data Security in Cloud 12% of exam

Question 5

An application encrypts each object with a data-encryption key (DEK), then wraps that DEK with a Cloud KMS key-encryption key (KEK). During a rotation rehearsal, a new KEK version becomes primary. New objects remain readable, but older objects become unreadable when the previous KEK version is disabled. The previous version must eventually be retired without rewriting the object payloads. How should the rotation procedure be corrected?

Show answer & explanation

Correct answer: A - Unwrap the existing DEKs, rewrap them with the new KEK version, and verify reads before retiring the old version.

Question 6

An S3 object version has compliance-mode retention until December 31, 2030, and a separate legal hold. Counsel authorizes removal of the legal hold on March 1, 2029. The account remains active. An administrator then requests permanent deletion of that specific version. Which statement describes the remaining protection?

Show answer & explanation

Correct answer: C - The unexpired compliance retention still prevents deletion, including a deletion request by the account root user.

Domain 5: Security Operations in Cloud 8% of exam

Question 7

A vulnerability report lists a CVSS v4.0 Base score of 9.4, an EPSS probability of 0.08, and an EPSS percentile of 0.93. Which statement interprets the finding without confusing severity, probability, and rank?

Show answer & explanation

Correct answer: C - Critical severity; an estimated 8% probability of exploitation in the wild during the next 30 days.

Domain 6: Penetration Testing in Cloud 8% of exam

Question 8

Written authorization covers a company's application in its own cloud account, and the planned techniques comply with the cloud provider's testing policy. During reconnaissance, the tester identifies an external payment API operated by another company; it is absent from the authorized target list. The remaining approved tests do not send test traffic to that API. How should the engagement proceed?

Show answer & explanation

Correct answer: D - Continue approved tests; obtain separate written authorization before testing the external API.

Domain 7: Incident Response in Cloud 8% of exam

Question 9

An incident responder confirms that a compromised VM is actively uploading customer records to an unauthorized destination. The approved endpoint quarantine function can block this transfer immediately while preserving a forensic management channel. The responder has authority to use it, and there is no evidence of control-plane compromise. What should happen before a lengthy memory acquisition begins?

Show answer & explanation

Correct answer: A - Quarantine the running VM, verify containment, then collect memory through the preserved management channel.

Domain 9: Business Continuity and Disaster Recovery in Cloud 8% of exam

Question 10

A payment service has a recovery point objective (RPO) of 10 minutes and a recovery time objective (RTO) of 45 minutes. Its recovery plan measures RTO from service interruption until an end-to-end payment succeeds. In a drill, the service stops at 14:00, and the recovered database is complete through 13:54, with no later transactions available. Traffic switches at 14:20, but the first successful end-to-end payment occurs at 14:52. How should the drill be assessed?

Show answer & explanation

Correct answer: B - Only the RPO was met: a 6-minute recovery-point gap and a 52-minute recovery time.

The rest of the CCSE blueprint

The CCSE exam also covers these domains. Drill them in the full free practice test:

That's 10 of 1,030

The full bank has 1,020 more CCSE questions with explanations.

Continue in the free practice test →

View plans