ISO 27017:2015 - Cloud Security Foundation Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

Consider a scenario where a cloud service customer (CSC) is utilizing a Platform as a Service (PaaS) offering from a cloud service provider (CSP). A security audit reveals that sensitive customer data stored within the PaaS application has been inadvertently exposed due to overly permissive access controls configured within the CSC\'s application deployment. According to the principles outlined in ISO 27017:2015, which party bears the primary responsibility for rectifying this specific security lapse?

The cloud service customer, for misconfiguring the access controls within their deployed application.
The cloud service provider, for failing to enforce stricter default access control policies on the PaaS platform.
Both the cloud service provider and the cloud service customer, sharing equal responsibility for the misconfiguration.
A joint incident response team comprising representatives from both the cloud service provider and the cloud service customer, to determine the root cause.

About the ISO 27017:2015 - Cloud Security Foundation Certification

These free practice questions are designed to help you assess your readiness for the ISO 27017:2015 - Cloud Security Foundation exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.