
Ultimate Guide to Prepare Free Cloud Security Alliance CCSK Exam Questions & Answer
Pass Cloud Security Alliance CCSK Tests Engine pdf - All Free Dumps
Cloud Security Alliance CCSK Exam Certification Details:
| Exam Code | CCSK |
| Recommended Training / Books | CCSK Course |
| Sample Questions | Cloud Security Alliance CCSK Sample Questions |
| Exam Price | $395 USD |
| Duration | 90 minutes |
NEW QUESTION 58
As with security. compliance in the cloud is a shared responsibility model.
- A. True
- B. False
Answer: A
Explanation:
As with security. compliance in the cloud is a shared responsibility model. Both the cloud provider and customer have responsibilities. But the customer is always ultimately responsible for their own compliance. These responsibilities are defined through contracts, audits/assessments. and specifics of the compliance requirements.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION 59
A health care facility has to only comply with HIPAA and do not need to comply with PCI DSS.
- A. True
- B. False
Answer: B
Explanation:
This is a tricky question. It is true that health care facility need to comply with HIPAA but if the healthcare facility is processing credit cards, they will have to comply with PCI DSS as well
NEW QUESTION 60
Which of the below hypervisors are 0S based and are more attractive to attackers?
- A. Type II
- B. Type I
- C. Type III
- D. Type V
Answer: A
Explanation:
Type II hypervisors are 0S-based and more attractive to attackers. There are lot of vulnerabilities which are found not only on 0S but also in applications residing on the 0S.
NEW QUESTION 61
Who is responsible for Application Security in Software as a Service(SaaS) service model?
- A. Cloud Customer
- B. It's a shared responsibility between Cloud Service Provider and Cloud Customer
- C. Cloud Service Provider
- D. Cloud Carrier
Answer: B
Explanation:
Its always a shared responsbility
NEW QUESTION 62
Which of the following leverages virtual network topologies to run more. smaller. and more isolated networks without incurring additional hardware costs that historically make such models prohibitive?
- A. VLANS
- B. BitVLANS
- C. Micro segmentation
- D. Micro LANs
Answer: C
Explanation:
Micro segmentation(also sometimes referred to as hyper segregation) leverages virtual network topologies to run more, smaller, and more isolated networks without incurring additional hardware costs that historically make such models prohibitive. Since the entire networks are defined in software without many of the traditional addressing issues, it is far more feasible to run these multiple, software- defined environments.
Reference: CSA Security GuidelinesV.4(reproduced here for the educational purpose)
NEW QUESTION 63
Your SLA with your cloud provider ensures continuity for all services.
- A. True
- B. False
Answer: B
NEW QUESTION 64
Which of the following is NOT true about CSA Cloud control metrix (CCM)?
- A. Maps controls to existing standards like ISO 27001
- B. Define the Cloud Audit Methodolog
- C. Also includes controls related to processing of personal data.
- D. Contains security controls divided in several domains
Answer: B
Explanation:
Remember that CCM is a security framework and does not include any methodology The Cloud Security Alliance Cloud Controls Matrix(CCM) is an essential and up-to-date security controls framework that is addressed to the cloud community and stakeholders. A fundamental richness of the CCM is its ability to provide mapping and cross relationships with the main industry-accepted security
NEW QUESTION 65
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what?
- A. An access log
- B. An entitlement matrix
- C. An entry log
- D. A validation process
- E. A support table
Answer: D
NEW QUESTION 66
ISO 27001 certification can be taken as proof to achieve Third-party assessment level in CSA star program.
- A. True
- B. False
Answer: A
Explanation:
The CSA STAR Certification is a rigorous third-party independent assessment of the security of a cloud service provider. The technology-neutral certification leverages the requirements of the ISO/IEC
27001:2013 management system standard together with the CSA Cloud Controls Matrix.
NEW QUESTION 67
One of the primary benefits of the cloud is the ability to perform dynamic allocation of physical resources when required. The most common approach is a multi-tenant environment. However, it increases risk of disclosure of customer dat a. This can happen because of which of the following?
- A. Tenancy termination
- B. Increased DDoS
- C. Isolation Failure
- D. No disaster recovery plan
Answer: C
Explanation:
All resources allocated to a particular tenant should be "isolated" and protected to avoid disclosure of information to other tenants For example, when allocated storage is no longer needed IIS Security Considerations for Cloud Computing by a client it can be freely reallocated to another enterprise. ln that case, sensitive data could be disclosed if the storage has not been scrubbed thoroughly(e.g, using forensic software).
NEW QUESTION 68
An important consideration when performing a remote vulnerability test of a cloud-based application is to
- A. Use techniques to evade cloud provider's detection systems
- B. Obtain provider permission for test
- C. Use application layer testing tools exclusively
- D. Schedule vulnerability test at night
- E. Use network layer testing tools exclusively
Answer: B
NEW QUESTION 69
Erin has a picture which he wants to store in the cloud and would like to share its URL so that his friends can see the picture. What type of cloud storage would you recommend for him?
- A. Glacier
- B. Object Storage
- C. Raw storage
- D. Block Storage
Answer: B
Explanation:
Object storage(also referred to as object-based storage) is a general term that refers to the way in which we organize and work with units of storage, called objects.
Every object contains three things:
The data itself: The data can be anything you want to store, from a family photo to a400,000-page manual for assembling an aircraft.
An expandable amount of metadata: The metadata is defined by whoever creates the object storage; it contains contextual information about what the data is, what it should be used for, its confidentiality, or anything else that is relevant to the way in which the data is used.
A globally unique identifier: The identifier is an address given to the object in order for the object to be found over a distributed system. This way, it's possible to find the data without having to know the physical location of the data(which could exist within different parts of a data center or different parts of the world).
NEW QUESTION 70
Private clouds can be hosted off-premises as well.
- A. True
- B. False
Answer: A
Explanation:
It is true. This is how Private cloud is defined.
Private Cloud: The cloud infrastructure is operated solely for a single organization. It may be managed by the organization or by a third party and may be located on-premises or off-premises.
NEW QUESTION 71
Inability of customer to leave, migrate, Or transfer to an alternate cloud service provider because of technical or nontechnical constraints. is known as:
- A. Vendor Lock
- B. Vendor lock-in
- C. Vendor lock-out
- D. Vendor Limit
Answer: B
Explanation:
Vendor lock-in is a situation in which a customer using a product or service cannot easily transition to a competitor's product or service. Vendor lock-in is usually the result of proprietary technologies that are incompatible with those of competitors.
NEW QUESTION 72
According to CSA Security Guidelines, there are four layers of Logical Model for cloud computing. Which of the following is not one of the layers as defined by Cloud Security Alliance?
- A. Softstructure
- B. Infrasturcture
- C. Metastructure
- D. Applistructure
Answer: A
Explanation:
The four layers of Logical Model for cloud computing according to Cloud Security Alliance are:
1. Infrastructure: The core components of a computing system: compute, network, and storage. The foundation that everything else is built on. The moving parts.
2. Metastructure: The protocols and mechanisms that provide the interface between the infrastructure layer and the other layers. The glue that ties the technologies and enables management and configuration.
3. Infostructure: The data and information. Content in a database, file storage, etc.
4. Applistructure: The applications deployed in the cloud and the underlying application services used to build them. For example, Platform as a Service features like message queues, artificial intelligence analysis, or notification services.
NEW QUESTION 73
Who is responsible for Data Security in Software as a Service(SaaS) service mode?
- A. It's a shared responsibility between Cloud Service Provider and Cloud Customer
- B. Cloud Service Provider
- C. Cloud Carrier
- D. Cloud Customer
Answer: D
Explanation:
Remember that data security will always remain responsibility of the cloud customer in all service models
NEW QUESTION 74
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document to potential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?
- A. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
- B. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.
- C. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
Answer: B
NEW QUESTION 75
Which of the following type of risk assessment most effectively supports cost-benefit analyses of alternative risk responses or courses of action?
- A. Quantitative Analysis
- B. Third party Risk Analysis
- C. Qualitative Analysis
- D. Outsourced risk analysis
Answer: A
Explanation:
Quantitative assessments typically employ a set of methods, principles, or rules for assessing risk based on the use of numbers This type of assessment most effectively supports cost-benefit analyses of alternative risk responses or courses of action.
NEW QUESTION 76
......
Who should take the Certificate of Cloud Security Knowledge (CCSK) Exam
For any IT professional working in cloud computing, the CCSK is planned. It’s a no-brainer for safety practitioners. As the CCSK is designed to give you a well-rounded view of cloud security, we also see non-security professionals get value from it, particularly developers, IT operations, and audit/compliance.
The exam is targeted for the following people:
- Consultant
- Security Architects
- Security Analyst
Anyone who finds the CCSk exams dumps interesting and following their interests should consider getting this certification.
Certificate of Cloud Security Knowledge (v4.0) Exam Practice Tests 2021 | Pass CCSK with confidence!: https://drive.google.com/open?id=1sDLEcxem6ahcZ0BDCV3L0NmDgUHT4ndM
Online Exam Practice Tests with detailed explanations!: https://www.testpdf.com/CCSK-exam-braindumps.html
