198 184
199 185
200 186
201 187
202 188
203 189
204 190
205 191
206 192
207 193
208 194
209 195
210 196
211 197
212 198
213 199
214 200
215 201
216 202
217 203
218 204
219 205
220 206
221 207
222 208
223 209
224 210
225 211
226 212
227 213
228 214
229 215
230 216
231 217
232 218
233 219
234 220
235 221
236 222
237 223
238 224
239 225
240 226
241 227
242 228
243 229
244 230
245 231
246 232
247 233
248 234
249 235
250 236
251 237
252 238
253 239
254 240
255 241
256 242
257 243
258 244
259 245
260 246
261 247
262 248
263 249
264 250
265 251
266 252
267 253
268 254
269 255
270 256
271 257
272 258
273 259
274 260
275 261
276 262
277 263
278 264
279 265
280 266
281 267
282 268
283 269
284 270
285 271
286 272
287 273
288 274
289 275
290 276
291 277
292 278
293 279
294 280
295 281
296 282
297 283
298 284
299 285
300 286
301 287
302 288
303 289
304 290
305 291
306 292
307 293
308 294
309 295
310 296
311 297
312 298
313 299
314 300
315 301
316 302
317 303
318 304
319 305
320 306
321 307
322 308
323 309
324 310
325 311
326 312
327 313
328 314
329 315
330 316
331 317
332 318
333 319
334 320
335 321
336 322
337 323
338 324
339 325
340 326
341 327
342 328
343 329
344 330
345 331
346 332
347 333
348 334
349 335
350 336
351 337
352 338
353 339
354 340
355 341
356 342
357 343
358 344
359 345
360 346
361 347
362 348
363 349
364 350
365 351
366 352
367 353
368 354
369 355
370 356
371 357
372 358
373 359
374 360
375 361
376 362
377 363
378 364
379 365
380 366
381 367
382 368
383 369
384 370
385 371
386 372
387 373
388 374
389 375
There is no magic formula for passing the Certified Cloud Security Professional (CCSP) certification exam, just as there is no single source that will prepare you sufficiently to pass the actual test. You can, however, prepare yourself for the challenge. This book is all about preparation.
We’ve included more than 1,000 questions related to the CCSP material in this book, which also includes access to the online databank (the same questions but in a point-and-click format). They were created in accordance with the (ISC) 2CCSP Common Body of Knowledge (CBK), the CCSP Training Guide, the Official CCSP Study Guide , Second Edition, and the CCSP Exam Outline, which is also referred to as the CCSP Exam Outline ( www.isc2.org/-/media/ISC2/Certifications/Exam-Outlines/ CCSP-Exam-Outline.ashx), which lists all the elements of practice that the candidate is expected to know for the certification.
The questions in this book are not necessarily indicative of what you’ll see on the actual CCSP exam. Instead, these questions are intended for study purposes, to help you review and understand the concepts that you may be tested on when you take the certification exam. Be aware that some of these questions may be easier, and some may be harder, than what you’ll be faced with if you try to become a CCSP.
How This Book Is Organized
The questions have been arranged in the order of the CBK, with varying amounts in proportion to the (ISC) 2published matrix describing how the exam is constructed, as shown in Table I.1.
Table I.1 How the exam is constructed
Domains |
Weight |
1. Cloud Concepts, Architecture, and Design |
17% |
2. Cloud Data Security |
19% |
3. Cloud Platform and Infrastructure Security |
17% |
4. Cloud Application Security |
17% |
5. Cloud Security Operations |
17% |
6. Legal, Risk, and Compliance |
13% |
There are six chapters, one for each of the CBK domains; each chapter contains a fraction of the hundreds of practice questions, reflecting the questions from the respective domain on the exam (for example, Chapter 1reflects Domain 1 of the CBK and has over 100 questions). There are also two full-length practice exams, 125 questions each, at the end of the book ( Chapters 7and 8).
Who Should Read This Book
This book is intended for CCSP candidates. To earn the CCSP, you are expected to have professional experience in the field of information security/IT security, particularly experience related to cloud computing. Candidates will also need to provide evidence of their professional experience to (ISC) 2in the event of passing the exam.
The author has drawn on his own experience studying for and passing the exam as well as years of teaching the Certified Information Systems Security Professional (CISSP) and CCSP preparation courses for (ISC) 2. He also solicited feedback from colleagues and former students who have taken the prep course and the exam. The book should reflect the breadth and depth of question content you are likely to see on the exam. Some of the questions in this book are easier than what you will see on the exam; some of them may be harder. Hopefully, the book will prepare you for what you might encounter when you take the test.
The one thing I chose not to simulate in the book is the “interactive” questions; (ISC) 2has stated that the current tests may go beyond the regular multiple-choice format and could include “matching” questions (a list of multiple answers and multiple terms, where the candidate has to arrange them all in order), drag-and-drop questions (where the candidate uses the mouse to arrange items on the screen), and “hot spot” questions (where the candidate uses the mouse to point at specific areas of the screen to indicate an answer). There will probably not be many of these on the exam you take, but they are weighted more in your score than the multiple-choice questions, so pay attention and be extra careful answering those.
In addition to this book, I recommend the CCSP (ISC) 2 Certified Cloud Security Professional Official Study Guide, Second Edition , also from Wiley (2019). There is, as stated in this introduction, no magic formula for passing the exam. No single particular book or source with all the answers to the exam exists. If someone claims to be able to provide you with such a product, realize that they are mistaken or, worse, misleading you.
However, you can augment your studying by reviewing a significant portion of the likely sources used by the professionals who created the test. The following is a just a sampling of the possible professional resources the cloud practitioner should be familiar with:
The Cloud Security Alliance’s Notorious Nine https://downloads.cloudsecurityalliance.org/initiatives/top_threats/ The_Notorious_Nine_Cloud_Computing_Top_Threats_in_2013.pdf
The OWASP’s Top 10 www.owasp.org/index.php/Top_10_2013-Top_10
Читать дальше