
Get 100% Passing Success With True CCSK Exam! [Oct-2021]
Cloud Security Alliance CCSK PDF Questions - Exceptional Practice To Certificate of Cloud Security Knowledge (v4.0) Exam
NEW QUESTION 178
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document to potential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?
- A. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.
- B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
- C. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
Answer: A
NEW QUESTION 179
Which of the following is a key consideration in Data security but does not feature in Data Security Life cycle?
- A. Storage Device
- B. Storage protocol
- C. Storage Location
- D. Access Method
Answer: C
Explanation:
The lifecycle represents the phases information passes through but doesnt address its location or how it is accessed.
NEW QUESTION 180
What would you call logic/procedures running on a shared database platform as?
- A. Serverless Computing
- B. Virtual Machine
- C. Container
- D. Platform-based Workload
Answer: D
Explanation:
Platform-based workloads: This is a more complex category that covers workloads running on a shared platform that aren't virtual machines or containers, such as logic/procedures running on a shared database platform. Imagine a stored procedure running inside a multitenant database, or a machine- learning job running on a machine-learning Platform as a Service. Isolation and security are totally the responsibility of the platform provider, although the provider may expose certain security options and controls.
Reference: CSA Security GuidelinesV.4(reproduced here for the educational purpose)
NEW QUESTION 181
Single cloud assets are typically less resilient than in the case of traditional infrastructure.
- A. True
- B. False
Answer: A
Explanation:
Cloud platforms can be incredibly resilient. but single cloud assets are typically less resilient than in the case of traditional infrastructure. This is due to the inherently greater fragility of virtualized resources running in highly-complex environments.
Reference: CSA Security Guidelines V.4 (reproduced here for the educational purpose)
NEW QUESTION 182
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?
- A. Application
- B. Object storage
- C. Platform
- D. Database
- E. Volume storage
Answer: E
NEW QUESTION 183
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?
- A. Organized Downtime
- B. Planned Outages
- C. Resiliency Planning
- D. Chaos Engineering
- E. Expected Engineering
Answer: D
NEW QUESTION 184
Which of following responsibilities can never be transferred. even during cloud adoption?
- A. Application Development
- B. Infrastructure
- C. Security
- D. Governance
Answer: D
Explanation:
The primary issue to remember when governing cloud computing is that an organization can never outsource responsibility for governance, even when using external providers. This is always true, cloud or not, but is useful to keep in mind when navigating cloud computing's concepts of shared responsibility models Ref: CSA Security Guidelines V4.0
NEW QUESTION 185
Which of the following is not a common cloud service model?
- A. Infrastructure as a Service
- B. Platform as a Service
- C. Software as a Service
- D. Programming as a Service
Answer: D
Explanation:
Programming as a Service is not a common offering; the others are ubiquitous through out the industry.
NEW QUESTION 186
Which of the following decouples the network control plane from the data plane and allows to abstract networking from the tradition a limitations of a LAN?
- A. VLANS
- B. Converged Networking
- C. Traditional Networking
- D. Software defined networking
Answer: D
Explanation:
Software Defined Networking(SDN):A more complete abstraction layer on top of networking hardware, SDNs decouple the network control plane from the data plane(you can read more on SDN principles at this Wikipedia entry).This allows us to abstract networking from the traditional limitations of a LAN.
Reference: CSA Security Guidelines V4.0
NEW QUESTION 187
What is the key benefit provided to the customer in Infrastructure as a Service model?
- A. Transfer of cost of ownership
- B. Scalability
- C. Reduction of Risk
- D. Governance
Answer: A
Explanation:
Transfer of cost of ownership is the key benefit of IaaS model.
NEW QUESTION 188
Which of the following help to intermediate IAM between an organization's existing identity providers and many different cloud services used by the organization?
- A. Active Director
- B. Relying Party
- C. Cloud Access Security Broker
- D. Federated Identity Provider
Answer: D
Explanation:
One of the better-known categories heavily used in cloud security is Federated Identity Brokers. These services help intermediate IAM between an organization's existing identity providers(internal Security Guidance v4.0 Copyright2017. Cloud Security Alliance. All rights reserved or cloud-hosted directories) and the many different cloud services used by the organization. They can provide web-based Single Sign
0n(SS0). helping ease some of the complexity of connecting to a wide range of external services that use different federation configurations.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION 189
Which of the following is not one of the categories of risks as defined in, ENISA (European Network and Information Security Agency) document on Security risk and recommendation?
- A. Legal Risk
- B. Policy and organisational risk
- C. Technical Risk
- D. Environmental Risk
Answer: D
Explanation:
Environmental Risk are not defined as a category in the ENISA document however. all the other three are defined as categories.
NEW QUESTION 190
What is true of security as it relates to cloud network infrastructure?
- A. You should implement a default allow with cloud firewalls and then restrict as necessary.
- B. You should deploy your cloud firewalls identical to the existing firewalls.
- C. You should always open traffic between workloads in the same virtual subnet for better visibility.
- D. You should apply cloud firewalls on a per-network basis.
- E. You should implement a default deny with cloud firewalls.
Answer: E
Explanation:
Explanation
NEW QUESTION 191
Which of the following best describes the relationship between a cloud provider and the customer?
- A. Privacy Level Agreement
- B. Contract
- C. Operational level Agreement
- D. Service Level Agreement
Answer: B
Explanation:
Contract is the most suitable answer here. It can be argued that Service Level Agreement could also be an answer but SLA is a negotiation/agreement for minimum service-levels expected. Contract is the document that defines the relation-ship between Cloud service provider and customer
NEW QUESTION 192
In volume storage, what method is often used to support resiliency and security?
- A. hypervisor agents
- B. random placement
- C. data dispersion
- D. data rights management
- E. proxy encryption
Answer: C
NEW QUESTION 193
Which of the following is NOT part of Risk management process?
- A. Dealing
- B. Assessing
- C. Framing
- D. Responding
Answer: A
Explanation:
The risk-management process has four components
1. Framing risk
2. Assessing risk
3. Responding to risk
4. Monitoring risk
NEW QUESTION 194
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.
- A. True
- B. False
Answer: A
NEW QUESTION 195
The relationship between the shareholders (and other stakeholders) of the organisation versus the Senior Management of the organisation is governed by:
- A. Corporate Mission
- B. Corporate Governance
- C. Corporate Vision
- D. IT Governance
Answer: B
Explanation:
Corporate governance is the system of rules, practices and processes by which a company is directed and controlled. Corporate governance, essentially involves balancing the interests of a company's many stakeholders, such as shareholders, management, customers, suppliers, financiers, government and the community.
NEW QUESTION 196
......
CCSK dumps - Exams4Collection - 100% Passing Guarantee: https://www.exams4collection.com/CCSK-latest-braindumps.html
Fast, Hands-On CCSK exam: https://drive.google.com/open?id=1p5uhSV4db2REybz652ilbFpayB4RoCgE
