[Oct 06, 2022] CCSK Dumps Full Questions - Exam Study Guide [Q34-Q51]

Share

[Oct 06, 2022] CCSK Dumps Full Questions - Exam Study Guide

Cloud Security Knowledge Free Certification Exam Material from ActualTestsIT with 60 Questions

NEW QUESTION 34
NIST defines five characteristics of cloud computing- Rapid Elasticity, Broad Network Access, 0n demand self-service, Metered Usage & Resource pooling. However, IS0/lEC17788 mentions one more characteristic in addition is those 5. Which of the following is that characterstic?

  • A. Multitenancy
  • B. Segregation
  • C. Isolation
  • D. Automation

Answer: A

Explanation:
IS0/lEC17788 lists six key characteristics. the first five of which are identical to the NIST characteristics.
The only addition is multitenancy. which is distinct from resource pooling.
Ref: CSA Security Guidelines V4.0

 

NEW QUESTION 35
Who is responsible for the safe custody, transport, data storage. and implementation of business rules in relation to the privacy?

  • A. Data owner
  • B. Data controller
  • C. Data custodian
  • D. Data processor

Answer: C

Explanation:
Data custodians are responsible for the safe custody. transport. data storage. and implementation of business rules

 

NEW QUESTION 36
When the data is transferred to third party. who is ultimately responsible for security of data?

  • A. Cloud Processor
  • B. Cloud Controller
  • C. Cloud Security Broker
  • D. Cloud Service Provider

Answer: B

Explanation:
Whatever will be the scenario. Data controller will be responsible for security of data in cloud

 

NEW QUESTION 37
Which ISO standards addresses Privacy in the cloud environment?

  • A. ISO 27018
  • B. ISO 27017
  • C. ISO 27032
  • D. ISO 27034

Answer: A

Explanation:
ISO/IEC 27018:2014 establishes commonly accepted control objectives, controls and guidelines for implementing measures to protect Personally Identifiable Information (PII) in accordance with the privacy principles in ISO/IEC 29100 for the public cloud computing environment.

 

NEW QUESTION 38
Term which defined acquired IT Technologies without the knowledge of IT Department is:

  • A. Shadow IT
  • B. Shadow devices
  • C. Shadow servers
  • D. Shadow application

Answer: A

Explanation:
Shadow IT is a term often used to describe information-technology systems and solutions built and used inside organizations without explicit organizational approval.

 

NEW QUESTION 39
What is true of security as it relates to cloud network infrastructure?

  • A. You should always open traffic between workloads in the same virtual subnet for better visibility.
  • B. You should apply cloud firewalls on a per-network basis.
  • C. You should implement a default deny with cloud firewalls.
  • D. You should implement a default allow with cloud firewalls and then restrict as necessary.
  • E. You should deploy your cloud firewalls identical to the existing firewalls.

Answer: C

 

NEW QUESTION 40
Which of the following describes the cloud security reference architecture?

  • A. ISO 17789
  • B. ISO 27032
  • C. ISO 17788
  • D. ISO 27001

Answer: C

Explanation:
ISO 17788 has a cloud reference architecture

 

NEW QUESTION 41
Which of the following is key component of regulated PII components?

  • A. E-discovery
  • B. Mandatory Breach Reporting
  • C. Data disclosure
  • D. Cloud Service Provider Consent

Answer: B

Explanation:
The key component and differentiator related to regulated PII is mandatory breach reporting requirements. At present. 47 states and territories within the United States, including the District of Columbia. Puerto Rico. and the Virgin Islands, have legislation in place that requires both private and government entities to notify and inform individuals of any security breaches involving PII.

 

NEW QUESTION 42
Which of the following will not be provided by cloud services when requested by the customer?

  • A. Details of security controls
  • B. DLP solution results
  • C. Geographical locations of the datacentre
  • D. SIEM logs

Answer: A

Explanation:
The cloud service provider will not provide the details of security controls as it will harm the security of its infrastructure if the adversaries knows the details.

 

NEW QUESTION 43
What is a type of computing comparable to grid computing that relies on sharing computing resources rather than having local servers or personal devices to handle applications?

  • A. Cloud computing
  • B. Server hosting
  • C. Vertical computing
  • D. Traditional computing

Answer: A

Explanation:
Thats the definition of cloud computing

 

NEW QUESTION 44
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?

  • A. Cloud Access and Security Brokers (CASB)
  • B. Data Loss Prevention
  • C. Database Activity Monitoring
  • D. Intrusion Prevention System
  • E. URL filters

Answer: D

 

NEW QUESTION 45
Why is a service type of network typically isolated on different hardware?

  • A. It requires unique security
  • B. It requires distinct access controls
  • C. It manages resource pools for cloud consumers
  • D. It has distinct functions from other networks
  • E. It manages the traffic between other networks

Answer: E

 

NEW QUESTION 46
Which one of the following is the key techniques to create cloud infrastructure?

  • A. Classification
  • B. Orientation
  • C. Abstraction
  • D. Authentication

Answer: C

Explanation:
The key techniques to create a cloud are abstraction and orchestration. We abstract the resources from the underlying physical infrastructure to create our pools, and use orchestration (and automation) to coordinate carving out and delivering a set of resources from the pools to the consumers. As you will see, these two techniques create all the essential characteristics we use to define something as a
"cloud."
Ref: CSA Security Guidelines V4.0

 

NEW QUESTION 47
Which of following responsibilities can never be transferred. even during cloud adoption?

  • A. Governance
  • B. Application Development
  • C. Infrastructure
  • D. Security

Answer: A

Explanation:
The primary issue to remember when governing cloud computing is that an organization can never outsource responsibility for governance, even when using external providers. This is always true, cloud or not, but is useful to keep in mind when navigating cloud computing's concepts of shared responsibility models Ref: CSA Security Guidelines V4.0

 

NEW QUESTION 48
Which of the following is correct about Due Care & Due Diligence?

  • A. Due care is the act of investigating and understanding the risks a company faces whereas Due Diligence is the development and implementation of policies and procedures to aid in protecting the company. its assets and its people from threats.
  • B. None of the above definitions are correct.
  • C. Due care is technical control whereas Due Deligence is physical control.
  • D. Due diligence is the act of investigating and understanding the risks a company faces whereas Due care is the development and implementation of policies and procedures to aid in protecting the company. its assets and its people from threats.

Answer: D

Explanation:
Definitions:
Due diligence is the act of investigating and understanding the risks a company faces.
Due care is the development and implementation of policies and procedures to aid in protecting the company, its assets, and its people from threats

 

NEW QUESTION 49
In Platform as a Service (PaaS), platform security is a responsibility of:

  • A. It's a shared responsibility
  • B. Neither of them
  • C. Customer
  • D. Cloud service provider

Answer: A

Explanation:
This is a very confusing question and we need to understand that its a shared responsibility between cloud service provider and customer.

 

NEW QUESTION 50
Which is the leading industry leading standard you will recommend to a web developer when designing web application or an API for a cloud solution?

  • A. SOC2
  • B. OWASP
  • C. FIPS 140
  • D. ISO 27001

Answer: B

Explanation:
OWASP is an open project and is leading industry standard for designing web applications and its security.

 

NEW QUESTION 51
......


What is the duration, language, and format of the Certificate of Cloud Security Knowledge (CCSK) Exam

  • Passing score: 80%
  • Number of questions: 60
  • Time Allowed: 90 minutes
  • Language of Exam: English, Spanish
  • Format: Multiple Choice Questions

Who should take the Certificate of Cloud Security Knowledge (CCSK) Exam

For any IT professional working in cloud computing, the CCSK is planned. It's a no-brainer for safety practitioners. As the CCSK is designed to give you a well-rounded view of cloud security, we also see non-security professionals get value from it, particularly developers, IT operations, and audit/compliance.

The exam is targeted for the following people:

  • Consultant
  • Security Analyst
  • Security Architects
  • Manager
  • Solutions Architect

Anyone who finds the CCSk exams exam dumps interesting and following their interests should consider getting this certification.

 

Dumps Brief Outline Of The CCSK Exam: https://www.actualtestsit.com/Cloud-Security-Alliance/CCSK-exam-prep-dumps.html

Use Real CCSK - 100% Cover Real Exam Questions: https://drive.google.com/open?id=1l9MQbsZR30HBu6tY2EwsDUWWVZwVqMWN