
Jun 27, 2024 Step by Step Guide to Prepare for CCSK Exam BrainDumps
Cloud Security Knowledge CCSK Real Exam Questions and Answers FREE Updated on 2024
To prepare for the CCSK exam, candidates can take advantage of various study resources provided by the CSA, including a comprehensive study guide, online training courses, and practice exams. These resources cover all the topics included in the exam and provide candidates with an in-depth understanding of cloud security best practices.
NEW QUESTION # 36
In a cloud environment, "unclear roles& responsibilities" and "no control over vulnerability process" on part of cloud customer can lead to:
- A. Denial of Service Attacks
- B. Lack of Disaster Recovery
- C. Loss of Governance
- D. Poor management of cloud Infrastructure
Answer: C
Explanation:
It can lead to loss of governance.
In using cloud infrastructures, the client necessarily cedes control to the cloud service provider(CSP) on several issues which may affect security.
The loss of governance and control could have a potentially severe impact on the organization's strategy and therefore on the capacity to meet its mission and goals. The loss of control and governance could lead to the impossibility of complying with the security requirements, a lack of confidentiality, integrity and availability of data, and a deterioration of performance and quality of service, not to mention the introduction of compliance challenges.
Source: ENISA- Security Risk and Benefits
NEW QUESTION # 37
How does virtualized storage help avoid data loss if a drive fails?
- A. Drives are backed up, swapped, and archived constantly
- B. Data loss is unavoidable with drive failures
- C. Incremental backups daily
- D. Multiple copies in different locations
- E. Full back ups weekly
Answer: D
NEW QUESTION # 38
Which of the following will not be provided by cloud services when requested by the customer?
- A. Details of security controls
- B. SIEM logs
- C. Geographical locations of the datacentre
- D. DLP solution results
Answer: A
Explanation:
The cloud service provider will not provide the details of security controls as it will harm the security of its infrastructure if the adversaries knows the details.
NEW QUESTION # 39
Code execution environments that run within an operating system. sharing and leveraging resources of that operating system is called :
- A. Sandbox
- B. Container
- C. Virtual Machine
- D. Instance
Answer: B
Explanation:
Containers are code execution environments that run within an operating system(for now), sharing and leveraging resources of that operating system. While a VM is a full abstraction of an operating system, a container is a constrained place to run segregated processes while still utilizing the kernel and other capabilities of the base 0S. Multiple containers can run on the same virtual machine or be implemented without the use of VMs at all and run directly on hardware.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION # 40
Which of the following can result in vendor lock-in?
- A. Proprietary data formats
- B. Favourable contract in favour of customer
- C. technology
- D. Large datasets
Answer: A
Explanation:
Proprietary data formats should be avoided. This can result in vendor lock-in.
NEW QUESTION # 41
Which of the vulnerabilities is inherited from general software development practice in PaaS environment?
- A. Backdoors
- B. Cross
- C. DDoS
- D. DNS spoofing
Answer: A
Explanation:
As a general practice of software development. Developer tend to leave backdoors so that they can come back later to fix issues.
NEW QUESTION # 42
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?
- A. Metastructure
- B. Infostructure
- C. Infrastructure
- D. Datastructure
- E. Applistructure
Answer: C
NEW QUESTION # 43
Which of the following is correct about Due Care & Due Diligence?
- A. None of the above definitions are correct.
- B. Due care is the act of investigating and understanding the risks a company faces whereas Due Diligence is the development and implementation of policies and procedures to aid in protecting the company. its assets and its people from threats.
- C. Due care is technical control whereas Due Deligence is physical control.
- D. Due diligence is the act of investigating and understanding the risks a company faces whereas Due care is the development and implementation of policies and procedures to aid in protecting the company. its assets and its people from threats.
Answer: D
Explanation:
Definitions:
Due diligence is the act of investigating and understanding the risks a company faces.
Due care is the development and implementation of policies and procedures to aid in protecting the company, its assets, and its people from threats
NEW QUESTION # 44
Which data security control is the LEAST likely to be assigned to an IaaS provider?
- A. Asset management and tracking
- B. Physical destruction
- C. Encryption solutions
- D. Application logic
- E. Access controls
Answer: D
NEW QUESTION # 45
Which of the following controls and configures the metastructure, and is also part of the metastructure itself?
- A. Network Firewall
- B. Web Application Firewall
- C. API Gateway
- D. Management Plance
Answer: D
Explanation:
The management plane controls and configures the metastructure, and is also part of the metastructure itself. As a reminder, cloud computing is the act of taking physical assets (like networks and processors) and using them to build resource pools. Meta structure is the glue and guts to create, provision, and deprovision the pools. The management plane includes the interfaces for building and managing the cloud itself, but also the interfaces for cloud users to manage their own allocated resources of the cloud.
Ref: CSA Security Guidelines v4.0
NEW QUESTION # 46
Which is the primary tool for governance in Cloud Computing environment?
- A. Contract
- B. Governance memo
- C. Service Level Agreement
- D. Operational level Agreement
Answer: D
Explanation:
Contracts: The primary tool of governance is the contract between a cloud provider and a cloud customer(this is true for public and private cloud). The contract is your only guarantee of any level of service or commitment-assuming there is no breach of contract, which tosses everything into a legal scenario. Contracts are the primary tool to extend governance into business partners and providers.
Ref: Security Guidance v4.0 Copyright2017, Cloud Security Alliance(used for educational purpose here)
NEW QUESTION # 47
The characteristics and traits of an individual that when aggregated could reveal the identity of that person. are known as:
- A. Indirect identifications
- B. Indirect indicators
- C. Indirect Identity Marks
- D. Indirect Identifiers
Answer: D
Explanation:
Indirect identifiers typically consist of demographic or socioeconomic information, dates, or events.
Although each standalone indirect identifier cannot identify the individual, the risk is that combining a number of indirect identifiers with external data can result in exposing the subject of the information.
For example, imagine a scenario in which users were able to combine search engine data, coupled with online streaming recommendations to tie back posts and recommendations to individual users on a website.
NEW QUESTION # 48
Which of the following is NOT true about CSA Cloud control metrix (CCM)?
- A. Contains security controls divided in several domains
- B. Define the Cloud Audit Methodolog
- C. Maps controls to existing standards like ISO 27001
- D. Also includes controls related to processing of personal data.
Answer: B
Explanation:
Remember that CCM is a security framework and does not include any methodology The Cloud Security Alliance Cloud Controls Matrix(CCM) is an essential and up-to-date security controls framework that is addressed to the cloud community and stakeholders. A fundamental richness of the CCM is its ability to provide mapping and cross relationships with the main industry-accepted security
NEW QUESTION # 49
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?
- A. Chaos Engineering
- B. Resiliency Planning
- C. Organized Downtime
- D. Planned Outages
- E. Expected Engineering
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 50
Which of the following processes leverages virtual network topologies to run more smaller and more isolated networks without incurring additional hardware costs?
- A. Grid networking
- B. Converged Networking
- C. VLANs
- D. Micro-segmentation
Answer: D
Explanation:
Explanation:
This type of question are asked to create confusion.
Following are the five phases of SDLC:
1. Planning and requirements analysis: Business and security requirements and standards are being determined. This phase is the main focus of the project managers and stakeholders. Meetings with managers, stakeholders, and users are held to determine requirements. The software development lifecycle calls for all business requirements(functional and nonfunctional)to be defined even before initial design begins. Planning for the quality-assurance requirements and identification of the risks associated with the project are also conducted in the planning stage. The requirements are then analyzed for their validity and the possibility of incorporating them into the system to be developed.
2. Defining: The defining phase is meant to clearly define and document the product requirements to place them in front of the customers and get them approved. This is done through a requirement specification document, which consists of all the product requirements to be designed and developed during the project lifecycle.
3. Designing: System design helps in specifying hardware and system requirements and helps in defining overall system architecture. The system design specifications serve as input for the next phase of the model. Threat modeling and secure design elements should be undertaken and discussed here.
4. Developing: Upon receiving the system design documents, work is divided into modules or units and actual coding starts. This is typically the longest phase of the software development lifecycle. Activities include code review, unit testing, and static analysis.
5. Testing: After the code is developed, it is tested against the requirements to make sure that the product is actually solving the needs gathered during the requirements phase. During this phase, unit testing, integration testing, system testing, and acceptance testing are conducted.
NEW QUESTION # 51
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
- A. Practice Integration of Duties (IOD) so that everyone is able to delete the encrypted data.
- B. Keep the keys stored on the client side so that they are secure and so that the users have the ability to delete their own data.
- C. Maintaining customer managed key management and revoking or deleting keys from the key management system to prevent the data from being accessed again.
- D. Allowing the cloud provider to manage your keys so that they have the ability to access and delete the data from the main and back-up storage.
- E. Both B and D.
Answer: C
NEW QUESTION # 52
Object storage unsuitable for data that changes frequently, Is it true?
- A. True, because data is geographically disperse and cannot be replicated
- B. True, because whenever you update a file you may have to wait until the change is propagated to all the replicas before requests return the latest version
- C. False, because change in one replica will also return latest version irrespective of its location
- D. False, Object storage is suitable for all type of data
Answer: B
Explanation:
With object storage systems, data consistency is achieved eventually. Whenever you update a file, you may have to wait until the change is propagated to all the replicas before requests return the latest version.
NEW QUESTION # 53
In ability to provide enough capacity to the cloud customer can lead to which of the following risk:
- A. Data Dispersion
- B. Resource Utilization
- C. Data Breach
- D. Resource Exhaustion
Answer: D
Explanation:
Cloud services are on-demand Therefore there is a level of calculated risk in allocating all the resources of a cloud service, because resources are allocated according to statistical projections. In accurate modelling of resources usage common resources allocation algorithms are vulnerable to distortions of fairness or inadequate resource provisioning and inadequate investments in infrastructure.
NEW QUESTION # 54
Metrics which govern the contractual obligations of cloud service are found in:
- A. Service Book
- B. Operational Level Agreement(OLA)
- C. Service Level agreements(SLA)
- D. Contract itself
Answer: C
Explanation:
The SLA is the list of defined, specific, numerical metrics that will used to determine whether the provider is sufficiently meeting the contract terms during each period of performance.
NEW QUESTION # 55
What are the encryption options available for SaaS consumers?
- A. Object encryption Volume storage encryption
- B. Any encryption option that is available for volume storage, object storage, or PaaS
- C. Provider-managed and (sometimes) proxy encryption
- D. Client/application and file/folder encryption
Answer: C
NEW QUESTION # 56
......
Ultimate Guide to Prepare CCSK Certification Exam for Cloud Security Knowledge: https://www.testpdf.com/CCSK-exam-braindumps.html
CCSK Ultimate Study Guide: https://drive.google.com/open?id=1HyI94mtM-LUIwjVYhoyA0R1tPfKBvb7l
