Get New 2021 Cloud Security Alliance CCSK Exam Dumps Bundle On flat Updated Dumps! [Q153-Q174]

Share

Get New 2021 Cloud Security Alliance exam CCSK Dumps Bundle On flat Updated Dumps!

Full CCSK Practice Test and 300 unique questions with explanations waiting just for you, get it now!

NEW QUESTION 153
Who is responsible for the security of the physical infrastructure and virtualization platform?

  • A. The cloud provider
  • B. It depends on the agreement
  • C. The responsibility is split equally
  • D. The majority is covered by the consumer
  • E. The cloud consumer

Answer: A

 

NEW QUESTION 154
Which is the set of technologies that are designed to detect conditions indicative of a security vulnerability in an application in its running state?

  • A. Enterprise Threat Modelling
  • B. STRIDE
  • C. Dynamic application security testing(DAST)
  • D. Static application security Testing(SAST)

Answer: C

Explanation:
Definitions:
SAST- Static application security testing(SAST) is a type of security testing that relies on inspecting the source code of an application. ln general, SAST involves looking at the ways the code is designed to pinpoint possible security flaws.
DAST- Dynamic application security testing(DAST) technologies are designed to detect conditions indicative of a security vulnerability in an application in its running state

 

NEW QUESTION 155
Which of the following document defines the roles and responsibilities for risk management between a cloud provider and a cloud customer?

  • A. Contract
  • B. Operational level Agreement
  • C. Service Level Agreement
  • D. Risk Management Agreement

Answer: A

Explanation:
Contract defines defines the roles and responsibilities for risk management between a cloud provider and a cloud customer

 

NEW QUESTION 156
What is the key difference between Business Continuity and Business Continuity Management?

  • A. They are same concepts used interchangeably
  • B. Business Continuity is the capability of the organization whereas Business Continuity Management is the holistic process.
  • C. None of the above
  • D. Business Continuity is the holistic process whereas Business Continuity Management is the capability of the organization

Answer: B

Explanation:
Definitions:
Business continuity: The capability of the organisation to continue delivery of products or services at acceptable predefined levels following a loss of service.
Business continuity management: A holistic management process that identifies potential threats to an organisation and the impacts to business operations those threats, if realised, might cause. It provides a framework for building organisational resilience with the capability of an effective response that safeguards the interests of its key stakeholders, reputation, brand, and value-creating activities

 

NEW QUESTION 157
Logs, documentation, and other materials needed for audits and compliance and often serve as evidence of compliance activities are known as:

  • A. Documented Evidence
  • B. Artifacts
  • C. Proof of Audit
  • D. Log Trail

Answer: B

Explanation:
Artifacts are the logs, documentation, and other materials needed for audits and compliance; they are the evidence to support compliance activities. Both providers and customers have responsibilities for producing and managing their respective artifacts.
Reference: CSA Security GuidelinesV.4(reproduced here for the educational purpose)

 

NEW QUESTION 158
The individual's right to have data(PII) removed from a entity/ provider at anytime per their request. is known as:

  • A. Right to disclosure
  • B. Right to claim
  • C. Right to be forgotten
  • D. Right of erasure

Answer: C

Explanation:
Under this principle of "Right to be forgotten", any individual can notify any entity that has PII fort hat individual and instruct that entity to delete and destroy all of that individual's PII in that entity's control.
This is a very serious and powerful individual right, and compliance can be extremely difficult.

 

NEW QUESTION 159
"Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms" Which of the following characterstics defines this

  • A. 0n-demand self-service
  • B. Broad network access
  • C. Resource pooling
  • D. Rapid elasticity

Answer: A

 

NEW QUESTION 160
The risk left in any system after all countermeasures and strategies have been applied is called:

  • A. Annualised Risk
  • B. Residual Risk
  • C. Leftover risk
  • D. Mitigated Risk

Answer: B

Explanation:
Thats the definition of residual risk

 

NEW QUESTION 161
CCM: In the CCM tool, a _____________________ is a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.

  • A. Control Specification
  • B. Domain
  • C. Risk Impact

Answer: A

 

NEW QUESTION 162
Which of the following is not one of the essential characteristics as defined by NIST 800-145?

  • A. On-demand Shelf service
  • B. Rapid Elasticity
  • C. Resource Pooling
  • D. Broad Network Access

Answer: A

Explanation:
The key characteristic is on-demand self-service and not shelf" service.

 

NEW QUESTION 163
One of the primary benefits of the cloud is the ability to perform dynamic allocation of physical resources when required. The most common approach is a multi-tenant environment. However, it increases risk of disclosure of customer dat a. This can happen because of which of the following?

  • A. Isolation Failure
  • B. Tenancy termination
  • C. Increased DDoS
  • D. No disaster recovery plan

Answer: A

Explanation:
All resources allocated to a particular tenant should be "isolated" and protected to avoid disclosure of information to other tenants For example, when allocated storage is no longer needed IIS Security Considerations for Cloud Computing by a client it can be freely reallocated to another enterprise. ln that case, sensitive data could be disclosed if the storage has not been scrubbed thoroughly(e.g, using forensic software).

 

NEW QUESTION 164
CCM: In the CCM tool, a is a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.

  • A. Control Specification
  • B. Domain
  • C. Risk Impact

Answer: A

 

NEW QUESTION 165
What is true of companies considering a cloud computing business relationship?

  • A. The laws protecting customer data are based on the cloud provider and customer location only.
  • B. The confidentiality agreements between companies using cloud computing services is limited legally to the company, not the provider.
  • C. The cloud computing companies are absolved of all data security and associated risks through contracts and data laws.
  • D. The companies using the cloud providers are the custodians of the data entrusted to them.
  • E. The cloud computing companies own all customer data.

Answer: D

 

NEW QUESTION 166
Which is the key technology that enables the sharing of resources and makes cloud computing most viable in terms of cost savings?

  • A. Content Delivery Networks(CDN)
  • B. Virtualization
  • C. Software Defined Networking(SDN)
  • D. Scalability

Answer: B

Explanation:
Virtualization is the foundational technology that underlies and makes cloud computing possible.
Virtualization is based on the use of powerful host computers to provide a shared resource pool that can be managed to maximize the number of guest operating systems(OSs) running on each host.

 

NEW QUESTION 167
GRC is responsibility of ______ in the all cloud services models

  • A. Customer
  • B. Reseller
  • C. Cloud Access Security Broker(CASB)
  • D. Service Provider

Answer: A

Explanation:
GRC and data is responsibility of the customer in all service models according to shared responsibility model.

 

NEW QUESTION 168
CCM: In the CCM tool, a is a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.

  • A. Control Specification
  • B. Domain
  • C. Risk Impact

Answer: A

 

NEW QUESTION 169
Which of the following is most commonly used to program Application Programming Interface(API)?

  • A. JSON
  • B. HTTP
  • C. SOAP
  • D. REST

Answer: D

Explanation:
APIs are typically REST for cloud services, since REST is easy to implement across the Internet. REST APIs have become the standard for web-based services since they run over Hl'-P/S and thus work well across diverse environments.
Reference: CSA Security GuidelinesV.4 (reproduced here for the educational purpose)

 

NEW QUESTION 170
A health care facility has to only comply with HIPAA and do not need to comply with PCI DSS.

  • A. False
  • B. True

Answer: A

Explanation:
This is a tricky question. It is true that health care facility need to comply with HIPAA but if the healthcare facility is processing credit cards, they will have to comply with PCI DSS as well

 

NEW QUESTION 171
Which of the following is true after your organization migrates the data to the cloud?

  • A. Breaches will be termed as loss of Intellectual property.
  • B. In case of data breach, you as a customer, will be still legally liable.
  • C. Cloud service provider will be legally liable for any data breach.
  • D. It is totally secure because cloud service providers have more security.

Answer: B

Explanation:
Even after cloud migration. cloud customer is responsible for the data and ultimately liable for any data loss or breaches.

 

NEW QUESTION 172
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what?

  • A. An access log
  • B. An entitlement matrix
  • C. A validation process
  • D. A support table
  • E. An entry log

Answer: C

 

NEW QUESTION 173
The amount of risk that the leadership and stakeholders of an organization are willing to accept is know as:

  • A. Residual Risk
  • B. Risk Residual
  • C. Risk Tolerance
  • D. Risk Acceptance

Answer: C

Explanation:
Risk tolerance is the amount of risk that the leadership and stakeholders of an organization are willing to accept. It varies based on asset and you shouldn't make a blanket risk decision about a particular provider; rather, assessments should align with the value and requirements of the assets Ref: Security Guidance v4.0 Copyright2017, Cloud Security Alliance(used for educational purpose here)

 

NEW QUESTION 174
......

[Sep-2021] Pass Cloud Security Alliance CCSK Exam in First Attempt Guaranteed: https://drive.google.com/open?id=1jQwmO_VF2gt-jwKiUK9z026bY4-bNaRW

Reduce Your Chance of Failure in CCSK Exam: https://www.braindumpspass.com/Cloud-Security-Alliance/CCSK-practice-exam-dumps.html