Free CCSK Braindumps Download Updated on Nov 18, 2021 with 300 Questions [Q26-Q51]

Share

Free CCSK Braindumps Download Updated on Nov 18, 2021 with 300 Questions

Cloud Security Alliance CCSK Exam Practice Test Questions


Cloud Security Alliance CCSK Exam Syllabus Topics:

TopicDetails
Topic 1
  • Management Plan E and Business Continuity
  • Virtualization and Containers
Topic 2
  • Cloud Security Standards and Certifications
  • Information Governance
Topic 3
  • Cloud Security Lexicon
  • Governance and Enterprise Risk Management
Topic 4
  • Compliance and Audit Management
  • Cloud Computing Concepts and Architectures
Topic 5
  • Identity, Entitlement, and Access Management
  • Sample Cloud Policy
Topic 6
  • ENISA Cloud Computing: Benefits, Risks and Recommendations for Information Security
Topic 7
  • Infrastructure Security
  • Security as a Service
Topic 8
  • Application Security
  • Incident Response
  • Related Technologies
Topic 9
  • Data Security and Encryption
  • Legal Issues, Contracts, and Electronic Discovery

 

NEW QUESTION 26
ANF and ONF are referred in which of the following ISO standards?

  • A. ISO 27034-1
  • B. ISO 27001
  • C. ISO 27005
  • D. ISO 27032

Answer: A

Explanation:
ISO/ IEC 27034-1, "Information Technology - Security Techniques - Application Security," provides one of the most widely accepted set of standards and guidelines for secure application development. IS0/ IEC27034-1 is a comprehensive set of standards that cover many aspects of application development. A few of the key elements include the organizational normative framework (ONF), the application normative framework (ANF), and the application security management process (APSM).

 

NEW QUESTION 27
Security Governance, Risk and Compliance(GRC) is, generally, responsibility of which of the following across all the platforms (IaaS, PaaS and SaaS)?

  • A. Joint Responsibility
  • B. Customer
  • C. Cloud Service Provider
  • D. Shared responsibility

Answer: B

Explanation:
GRC is responsibility of the customer across all service models.

 

NEW QUESTION 28
Who is responsible for Governance, Risk & Compliance in Software as a Service(SaaS) service model?

  • A. Cloud Customer
  • B. It's a shared responsibility between Cloud Service Provider and Cloud Customer
  • C. Cloud Service Provider
  • D. Cloud Carrier

Answer: A

Explanation:
Remember, GRC will always remain responsibility of the cloud customer in all service models

 

NEW QUESTION 29
What factors should you understand about the data specifically due to legal, regulatory, and jurisdictional factors?

  • A. The actual size of the data and the storage format
  • B. The language of the data and how it affects the user
  • C. The fragmentation and encryption algorithms employed
  • D. The implications of storing complex information on simple storage systems
  • E. The physical location of the data and how it is accessed

Answer: D

 

NEW QUESTION 30
Which of the following very important consideration when securing access to the Management Plane?

  • A. Service Administrator
  • B. Remote Access VPN
  • C. Least Privilege
  • D. Super Administrator

Answer: C

Explanation:
Both providers and consumers should consistently only allow the least privilege required for users.
applications. and other management plane usage.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)

 

NEW QUESTION 31
Which one of the following is the key tool of Cloud Governance?

  • A. Business Impact Analysis(BIA)
  • B. Contracts
  • C. Data classification
  • D. Auditor Selection

Answer: B

Explanation:
The primary tool of governance is the contract between a cloud provider and a cloud customer (this is true for public and private cloud). The contract is your only guarantee of any level of service or commitment Ref: CSA Security Guidance V4.0

 

NEW QUESTION 32
Which of the following help to intermediate IAM between an organization's existing identity providers and many different cloud services used by the organization?

  • A. Cloud Access Security Broker
  • B. Active Director
  • C. Federated Identity Provider
  • D. Relying Party

Answer: C

Explanation:
One of the better-known categories heavily used in cloud security is Federated Identity Brokers. These services help intermediate IAM between an organization's existing identity providers(internal Security Guidance v4.0 Copyright2017. Cloud Security Alliance. All rights reserved or cloud-hosted directories) and the many different cloud services used by the organization. They can provide web-based Single Sign
0n(SS0). helping ease some of the complexity of connecting to a wide range of external services that use different federation configurations.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)

 

NEW QUESTION 33
No policy on resource capping can lead to:

  • A. Resource manipulation
  • B. Resource Exhaustion
  • C. Data disclosure
  • D. Data manipulation

Answer: B

Explanation:
It can lead to resource exhaustion if you do not put upper limit on resource allocation.
Cloud services are on-demand Therefore there is a level of calculated risk in allocating all the resources of a cloud service, because resources are allocated according to statistical projections. In accurate modelling of resources usage- common resources allocation algorithms are vulnerable to distortions of fairness

 

NEW QUESTION 34
Which attack surfaces, if any, does virtualization technology introduce?

  • A. All of the above
  • B. The hypervisor
  • C. Configuration and VM sprawl issues
  • D. Virtualization management components apart from the hypervisor

Answer: A

 

NEW QUESTION 35
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?

  • A. Platform
  • B. Object storage
  • C. Application
  • D. Volume storage
  • E. Database

Answer: D

 

NEW QUESTION 36
APIs and web services require extensive hardening and must assume attacks from authenticated and unauthenticated adversaries.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 37
ENISA: A reason for risk concerns of a cloud provider being acquired is:

  • A. Resource isolation may fail
  • B. Non-binding agreements put at risk
  • C. Arbitrary contract termination by acquiring company
  • D. Provider may change physical location
  • E. Mass layoffs may occur

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 38
ENISA: "VM hopping" is:

  • A. Lack of vulnerability management standards.
  • B. Instability in VM patch management causing VM routing errors.
  • C. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
  • D. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.
  • E. Looping within virtualized routing systems.

Answer: D

 

NEW QUESTION 39
Which of the following is a key tool for enabling and enforcing separation and isolation in multitenancy?

  • A. Control Plane
  • B. Networking
  • C. Management Plane
  • D. Processors

Answer: C

Explanation:
The management plane is a key tool for enabling and enforcing separation and isolation in multitenancy.
Limiting who can do what with the APIs is one important means for segregating out customers, or different users within a single tenant. Resources are in the pool, out of the pool, and where they are allocated Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)

 

NEW QUESTION 40
Which governance domain deals with evaluating how cloud computing affects compliance with internal security policies and various legal requirements, such as regulatory and legislative?

  • A. Infrastructure Security
  • B. Legal Issues: Contracts and Electronic Discovery
  • C. Information Governance
  • D. Governance and Enterprise Risk Management
  • E. Compliance and Audit Management

Answer: E

 

NEW QUESTION 41
What is the newer application development methodology and philosophy focused on automation of application development and deployment?

  • A. BusOps
  • B. SecDevOps
  • C. Agile
  • D. DevOps
  • E. Scrum

Answer: D

 

NEW QUESTION 42
When your bank or credit card company sends you a notification of changes in how it collects or shares data, it is sending that notification in compliance with:

  • A. GDPR
  • B. ISO 27001
  • C. HIPAA
  • D. FERPA

Answer: A

Explanation:
Under GDPR. it is mandatory to notify consumers how their data will be used

 

NEW QUESTION 43
Which is the document used by Cloud Service Provider to declare the level of personal data protection and security that it sustains for the relevant data processing?

  • A. Privacy Level Agreement(PLA)
  • B. Contract
  • C. Privacy Charter
  • D. Service Level Agreement(SLA)

Answer: A

Explanation:
The PLA, as defined by the CSA, does the following Provides a clear and effective way to communicate the level of personal data protection offered by a service provider.
Works as a tool to assess the level of a service provider's compliance with data protection legislative requirements and leading practices Provides a way to offer contractual protection against possible financial damages due to lack of compliance

 

NEW QUESTION 44
Which one of the following is the key techniques to create cloud infrastructure?

  • A. Abstraction
  • B. Authentication
  • C. Orientation
  • D. Classification

Answer: A

Explanation:
The key techniques to create a cloud are abstraction and orchestration. We abstract the resources from the underlying physical infrastructure to create our pools, and use orchestration (and automation) to coordinate carving out and delivering a set of resources from the pools to the consumers. As you will see, these two techniques create all the essential characteristics we use to define something as a
"cloud."
Ref: CSA Security Guidelines V4.0

 

NEW QUESTION 45
Exploitable bugs in programs that attackers can use to infiltrate a computer system for the purpose of stealing data, taking control of the system or disrupting service operations, are called:

  • A. Threat Agents
  • B. Threats
  • C. Vulnerbilities
  • D. Honepots

Answer: C

Explanation:
It's a definition of System Vulnerability.

 

NEW QUESTION 46
Exploitable bugs in programs that attackers can use to infiltrate a computer system for the purpose of stealing data, taking control of the system or disrupting service operations, are called:

  • A. Threat Agents
  • B. Threats
  • C. Vulnerbilities
  • D. Honepots

Answer: C

 

NEW QUESTION 47
Which communication methods within a cloud environment must be exposed for partners or consumers to access database information using a web application?

  • A. Resource Description Framework (RDF)
  • B. Software Development Kits (SDKs)
  • C. Application Binary Interface (ABI)
  • D. Application Programming Interface (API)
  • E. Extensible Markup Language (XML)

Answer: D

 

NEW QUESTION 48
What is the key difference between Business Continuity and Business Continuity Management?

  • A. Business Continuity is the capability of the organization whereas Business Continuity Management is the holistic process.
  • B. None of the above
  • C. Business Continuity is the holistic process whereas Business Continuity Management is the capability of the organization
  • D. They are same concepts used interchangeably

Answer: A

Explanation:
Definitions:
Business continuity: The capability of the organisation to continue delivery of products or services at acceptable predefined levels following a loss of service.
Business continuity management: A holistic management process that identifies potential threats to an organisation and the impacts to business operations those threats, if realised, might cause. It provides a framework for building organisational resilience with the capability of an effective response that safeguards the interests of its key stakeholders, reputation, brand, and value-creating activities

 

NEW QUESTION 49
The individual's right to have data(PII) removed from a entity/ provider at anytime per their request. is known as:

  • A. Right to claim
  • B. Right to be forgotten
  • C. Right to disclosure
  • D. Right of erasure

Answer: B

Explanation:
Under this principle of "Right to be forgotten", any individual can notify any entity that has PII fort hat individual and instruct that entity to delete and destroy all of that individual's PII in that entity's control.
This is a very serious and powerful individual right, and compliance can be extremely difficult.

 

NEW QUESTION 50
The basis for deciding which laws are most appropriate in a situation where conflicting laws exist. refers to:

  • A. Criminal law
  • B. Doctrine of proper law
  • C. Tort law
  • D. The Restatement(Second) Conflict of Law

Answer: D

Explanation:
The Restatement(Second) Conflict of Law refers to a collation of developments in common law that help the courts stay up with changes. Many states have conflicting laws. and judges use these restatements to assist them in determining which laws should apply when conflicts occur.

 

NEW QUESTION 51
......


Who should take the Certificate of Cloud Security Knowledge (CCSK) Exam

For any IT professional working in cloud computing, the CCSK is planned. It’s a no-brainer for safety practitioners. As the CCSK is designed to give you a well-rounded view of cloud security, we also see non-security professionals get value from it, particularly developers, IT operations, and audit/compliance.

The exam is targeted for the following people:

  • Information Security
  • Solutions Architect
  • Security Analyst
  • Security Architects
  • Consultant
  • Manager

Anyone who finds the CCSk exams dumps interesting and following their interests should consider getting this certification.

 

Updated Verified CCSK dumps Q&As - Pass Guarantee or Full Refund: https://www.braindumpspass.com/Cloud-Security-Alliance/CCSK-practice-exam-dumps.html

Updated Certification Exam CCSK Dumps - Practice Test Questions: https://drive.google.com/open?id=1EUiqnUlAAG1HMDNUpqjjdQmTTVQywGkf