CCSK - V4 and ENISA Exam 2026
Questions and Answers
What is the standard cloud computing model used here? - Correct answer-NIST
(National Institute of Standards and Technology, a US federal agency); the ISO
definition is similar.
What are the five essential characteristics that NIST uses to define cloud
computing? - Correct answer-1) broad network access 2) rapid elasticity 3)
measured service 4) on-demand self service 5) resource pooling
What are the four cloud deployment models defined by NIST? - Correct answer-1)
Public 2) Private 3) Hybrid 4) Community
What is a cloud broker? - Correct answer-Entity that manages the use,
performance, and delivery of cloud services (and negotiates relationship with
customer)
What is the Jericho Cloud Cube Model? - Correct answer-Four dimensions to
differentiate cloud (or IT) formations:
1) External/Internal (physical location)
©COPYRIGHT 2025, ALL RIGHTS RESERVED 1
,2) Proprietary/Open (technology)
3) Perimiterized/De-perimiterized (within firewall)
4) Outsourced/Insourced
What is the CSA Cloud Reference Model? - Correct answer-The service models fit
in an architectural framework (where APIs are an important access mechanism)
What is Multi-tenancy (in the ISO definition) - Correct answer-The characteristic
of multiple independent consumers sharing resources, which implies a need for
certain controls.
What are SLAs for? - Correct answer-Important control to allocate responsibility
between consumer and provider. Shared responsibility model.
How do characteristics introduce risk? - Correct answer-Broad network access
introduces the client device and the network as new sources of risk. Rapid
Elasticity brings availability risks. Measured service can bring licensing risk.
Resource pooling brings isolation related risks. On-demand self service introduces
risks around who can control what.
What are Security concerns for hypervisor architecture? - Correct answer-VM
hosts and guests need to be hardened; Hypervisor software and provenance is
highest risk area.
©COPYRIGHT 2025, ALL RIGHTS RESERVED 2
, What do you need to know about AV? - Correct answer-Don't run AV scan inside
VM; use hypervisor aware products.
What are blind spots? - Correct answer-Inter VM communication may not be
visible in the physical network (i.e. through virtual switch or side channel) leading
to blind spots.
What are VM isolation (compartmentalization) techniques? - Correct answer-
LANs, IDS/IPS, Firewalls, zoning (combinations may be required for compliance)
How can VM persistent storage leak risk (safe destruction) be countered? - Correct
answer-Storage level encryption
What is VM image risk? - Correct answer-Too many different images (sprawl) and
images that are not up to date (staleness).
What is Commingling? - Correct answer-Sensitive data may be in non compliant
zones.
Why is asset management more complicated? - Correct answer-Asset management
for audit/monitoring is complicated by the extra need need to track hosts as well as
guests and images.
What is OVF? - Correct answer-Open Virtualization Format (helps ensure
interoperability)
©COPYRIGHT 2025, ALL RIGHTS RESERVED 3
Questions and Answers
What is the standard cloud computing model used here? - Correct answer-NIST
(National Institute of Standards and Technology, a US federal agency); the ISO
definition is similar.
What are the five essential characteristics that NIST uses to define cloud
computing? - Correct answer-1) broad network access 2) rapid elasticity 3)
measured service 4) on-demand self service 5) resource pooling
What are the four cloud deployment models defined by NIST? - Correct answer-1)
Public 2) Private 3) Hybrid 4) Community
What is a cloud broker? - Correct answer-Entity that manages the use,
performance, and delivery of cloud services (and negotiates relationship with
customer)
What is the Jericho Cloud Cube Model? - Correct answer-Four dimensions to
differentiate cloud (or IT) formations:
1) External/Internal (physical location)
©COPYRIGHT 2025, ALL RIGHTS RESERVED 1
,2) Proprietary/Open (technology)
3) Perimiterized/De-perimiterized (within firewall)
4) Outsourced/Insourced
What is the CSA Cloud Reference Model? - Correct answer-The service models fit
in an architectural framework (where APIs are an important access mechanism)
What is Multi-tenancy (in the ISO definition) - Correct answer-The characteristic
of multiple independent consumers sharing resources, which implies a need for
certain controls.
What are SLAs for? - Correct answer-Important control to allocate responsibility
between consumer and provider. Shared responsibility model.
How do characteristics introduce risk? - Correct answer-Broad network access
introduces the client device and the network as new sources of risk. Rapid
Elasticity brings availability risks. Measured service can bring licensing risk.
Resource pooling brings isolation related risks. On-demand self service introduces
risks around who can control what.
What are Security concerns for hypervisor architecture? - Correct answer-VM
hosts and guests need to be hardened; Hypervisor software and provenance is
highest risk area.
©COPYRIGHT 2025, ALL RIGHTS RESERVED 2
, What do you need to know about AV? - Correct answer-Don't run AV scan inside
VM; use hypervisor aware products.
What are blind spots? - Correct answer-Inter VM communication may not be
visible in the physical network (i.e. through virtual switch or side channel) leading
to blind spots.
What are VM isolation (compartmentalization) techniques? - Correct answer-
LANs, IDS/IPS, Firewalls, zoning (combinations may be required for compliance)
How can VM persistent storage leak risk (safe destruction) be countered? - Correct
answer-Storage level encryption
What is VM image risk? - Correct answer-Too many different images (sprawl) and
images that are not up to date (staleness).
What is Commingling? - Correct answer-Sensitive data may be in non compliant
zones.
Why is asset management more complicated? - Correct answer-Asset management
for audit/monitoring is complicated by the extra need need to track hosts as well as
guests and images.
What is OVF? - Correct answer-Open Virtualization Format (helps ensure
interoperability)
©COPYRIGHT 2025, ALL RIGHTS RESERVED 3