ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A multi-tenant storage vulnerability affecting several regions is discovered by your security engineering team at 03:15 UTC. No exploitation has been observed, but successful attack paths could expose customer data. According to accepted cloud-incident communication practice, which initial action toward customers best preserves trust and meets legal or contractual requirements?
Release the complete forensic timeline and all supporting log data so customers can perform their own analysis.
Issue a concise security advisory describing the vulnerability, affected services, recommended immediate customer actions, and a schedule for follow-up updates.
Send a routine marketing newsletter highlighting overall platform availability without mentioning the vulnerability.
Wait until the patch is fully deployed across all regions, then send a single notification stating the issue is resolved.
Industry frameworks such as NIST SP 800-61 and ISO/IEC 27035 stress that cloud providers must notify customers promptly once a significant vulnerability or incident is identified. The first communication should give customers enough information to understand the risk, list services and regions affected, recommend any immediate mitigation steps, and promise periodic updates. Publishing a full forensic report at this early stage risks exposing sensitive details before validation, while marketing messages or silence until a patch is deployed both violate transparency expectations and, in many jurisdictions, breach-notification laws or contractual SLAs.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is multi-tenant storage in cloud computing?
Open an interactive chat with Bash
What are NIST SP 800-61 and ISO/IEC 27035?
Open an interactive chat with Bash
Why is prompt customer notification important in cloud security incidents?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Security Operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .