# CCSP interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you evaluate a cloud provider before we sign? | Independent attestations, the shared responsibility split for each service, where data sits, and an exit plan. | |
| 2 | Where do AI and machine learning workloads change your cloud security plan? | Protecting training data, controlling access to models, and knowing the outline now covers AI in 1.6 and 2.9. | |
| 3 | Where is our most sensitive data in the cloud, and how would you find out? | Discovery and classification, data flow mapping, and a named owner for each data set. | |
| 4 | How would you design encryption and key management for a SaaS app? | Encryption at rest and in transit, who holds the keys, rotation, and keeping key admins separate from data admins. | |
| 5 | How do you plan disaster recovery across regions? | Recovery time and recovery point objectives per service, a region or provider strategy, and tested failover. | |
| 6 | How do you secure the identities and APIs of a cloud-native app? | Federation, least privilege for workload identities, secrets management and API controls. | |
| 7 | How do you investigate an incident when you do not own the hardware? | Logs you control, snapshots, chain of custody, and what the contract obliges the provider to give you. | |
| 8 | What should our cloud contracts say about security? | Audit rights or reports, breach notice terms, data location, and deletion and exit terms. | |

Source: https://credentialpress.com/guides/ccsp-interview-questions
