
2021 Realistic Verified Free Cloud Security Alliance CCSK Exam Questions
CCSK Real Exam Questions and Answers FREE
Topics of Certificate of Cloud Security Knowledge (CCSK) Exam
This syllabus outline for the Certificate of Cloud Security Knowledge (CCSK) Exam can be found in the CCSk dumps pdf and focuses on the critical areas of the exam. Below, the main sections along with their subsections are listed:
1. Cloud Computing Concepts and Architectures
Objectives covered by this section:
- Logical Model
- Areas of Critical Focus in Cloud Security
- Cloud Security Scope, Responsibilities, and Models
- Definitions of Cloud Computing
- Deployment Models
- Reference and Architecture Models
- Service Models
2. Governance and Enterprise Risk Management
Objectives covered by this section:
- Tools of Cloud Governance
- Enterprise Risk Management in the Cloud
- Effects of various Service and Deployment Models
- Cloud Risk Trade-offs and Tools
3. Legal Issues, Contracts, and Electronic Discovery
Objectives covered by this section:
- Regional Considerations
- Third-Party Audits and Attestations
- Due Diligence
- Cross-Border Data Transfer
- Contracts and Provider Selection
- Data Preservation
- Response to a Subpoena or Search Warrant
- Contracts
- Data Collection
- Data Custody
- Electronic Discovery
- Legal Frameworks Governing Data Protection and Privacy
4. Compliance and Audit Management
Objectives covered by this section:
- Audit Management in the Cloud
- Audit scope
- Auditor requirements
- Compliance in the Cloud
- Compliance scope
- Right to audit
- Compliance impact on cloud contracts
- Compliance analysis requirements
5. Information Governance
Objectives covered by this section:
- Six phases of the Data Security Lifecycle and their key elements
- Data Security Functions, Actors and Controls
- Governance Domains
6. Management Plane and Business Continuity
Objectives covered by this section:
- Business Continuity and Disaster Recovery in the Cloud
- Architect for Failure
- Management Plane Security
7. Infrastructure Security
Objectives covered by this section:
- Challenges of Virtual Appliances
- Cloud Network Virtualization
- SDN Security Benefits
- Security Changes With Cloud Networking
- Hybrid Cloud Considerations
- Cloud Compute and Workload Security
- Micro-segmentation and the Software-Defined Perimeter
8. Virtualization and Containers
Objectives covered by this section:
- Containers
- Network
- Mayor Virtualizations Categories
- Storage
9. Incident Response
Objectives covered by this section:
- How the Cloud Impacts IR
- Incident Response Lifecycle
10. Application Security
Objectives covered by this section:
- Secure Software Development Lifecycle
- Opportunities and Challenges
- The Rise and Role of DevOps
- How Cloud Impacts Application Design and Architectures
11. Data Security and Encryption
Objectives covered by this section:
- Data Security Controls
- Managing Data Migrations to the Cloud
- Securing Data in the Cloud
- Cloud Data Storage Types
12. Identity, Entitlement, and Access Management
Objectives covered by this section:
- Authentication and Credentials
- Entitlement and Access Management
- Managing Users and Identities
- IAM Standards for Cloud Computing
13. Security as a Service
Objectives covered by this section:
- Potential Benefits and Concerns of SecaaS
- Major Categories of Security as a Service Offerings
14. Related Technologies
Objectives covered by this section:
- Internet of Things
- Mobile
- Big Data
- Serverless Computing
15. ENISA Cloud Computing: Benefits, Risks, and Recommendations for Information Security
Objectives covered by this section:
- VM hopping
- User provisioning vulnerability
- Isolation failure
- In Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring
- Economic Denial of Service
- Top security risks in ENISA research
- Underlying vulnerability in Loss of Governance
- Security benefits of cloud
- Five key legal issues common across all scenarios
- OVF
- Licensing Risks
- Data controller versus data processor definitions
- Risk concerns of a cloud provider being acquired
- Risks R.1 â R.35 and underlying vulnerabilities
16. Cloud Security Alliance - Cloud Controls Matrix
Objectives covered by this section:
- Scope Applicability
- CCM Domains
- CCM Controls
- Mapped Standards and Frameworks
- Delivery Model Applicability
- Architectural Relevance
NEW QUESTION 42
Ensuring the use of data and information complies with organizational policies, standards and strategy- including regulatory, contractual, and business objectives, known as:
- A. Enterprise Governance
- B. IT Governance
- C. Corporate Governance
- D. Data Governance
Answer: D
Explanation:
It is definition of Data Governance
NEW QUESTION 43
Private clouds can be hosted off-premises as well.
- A. False
- B. True
Answer: B
Explanation:
It is true. This is how Private cloud is defined.
Private Cloud: The cloud infrastructure is operated solely for a single organization. It may be managed by the organization or by a third party and may be located on-premises or off-premises.
NEW QUESTION 44
To understand their compliance alignments and gaps with a cloud provider, what must cloud customers rely on?
- A. Provider documentation
- B. Provider run audits and reports
- C. Third-party attestations
- D. EDiscovery tools
- E. Provider and consumer contracts
Answer: C
NEW QUESTION 45
Who decides the risk appetite of the organization?
- A. CEO
- B. Senior Management
- C. Risk Officer
- D. CIO
Answer: B
Explanation:
It is the Senior Management who decides the appetite of the organization
NEW QUESTION 46
All of the following are type of access controls except:
- A. Administrative
- B. Natural
- C. Physical
- D. Technical
Answer: B
Explanation:
There is no control as such for Natural control.
There are three types of controls
1. Physical
2. Technical
3. Administrative
NEW QUESTION 47
Which concept provides the abstraction needed for resource pools?
- A. Metastructure
- B. Hypervisor
- C. Orchestration
- D. Applistructure
- E. Virtualization
Answer: E
NEW QUESTION 48
Operating System management is done by customer in which service model of cloud computing?
- A. XaaS
- B. SaaS
- C. IaaS
- D. PaaS
Answer: C
Explanation:
In IaaS model. operating system is managed by the customer
NEW QUESTION 49
Which of the following document defines the roles and responsibilities for risk management between a cloud provider and a cloud customer?
- A. Service Level Agreement
- B. Risk Management Agreement
- C. Operational level Agreement
- D. Contract
Answer: D
Explanation:
Contract defines defines the roles and responsibilities for risk management between a cloud provider and a cloud customer
NEW QUESTION 50
An important consideration when performing a remote vulnerability test of a cloud-based application is to
- A. Obtain provider permission for test
- B. Use techniques to evade cloud provider's detection systems
- C. Use network layer testing tools exclusively
- D. Use application layer testing tools exclusively
- E. Schedule vulnerability test at night
Answer: A
NEW QUESTION 51
Which of the following can result in vendor lock-in?
- A. Proprietary data formats
- B. Favourable contract in favour of customer
- C. Large datasets
- D. technology
Answer: A
Explanation:
Proprietary data formats should be avoided. This can result in vendor lock-in.
NEW QUESTION 52
An agreed-upon description of the attributes of a product. at a point in time that serves as a basis for defining change is called:
- A. Baseline
- B. Trusted Module
- C. Secured Server
- D. Standardization
Answer: A
Explanation:
A baseline is an agreed-upon description of the attributes of a product. at a point in time that serves as a basis for defining change.
NEW QUESTION 53
Multi-tenancy and shared resources are defining characteristics of cloud computing. However, mechanisms separating storage, memory, routing may fail due to several reasons. What risk are we talking about?
- A. Isolation Failure
- B. Separation of Duties
- C. Route poisoning
- D. Isolation Escalation
Answer: A
Explanation:
According to ENISA (European Network and Information Security Agency) document on Security risk and recommendation, Isolation failure is considered as one of the top risk and is defined as follows Multi- tenancy and shared resources are defining characteristics of cloud computing. This risk category covers the failure of mechanisms separating storage, memory, routing and even reputation between different tenants (e.g, so-called guest-hopping attacks). However it should be considered that attacks on resource isolation mechanisms (e.g. against hypervisors) are still less numerous and much more difficult for an attacker to put in practice compared to attacks on traditional Oss.
NEW QUESTION 54
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
- A. Inspect and account for risks inherited from other members of the cloud supply chain and take active measures to mitigate and contain risks through operational resiliency.
- B. Provide transparency to stakeholders and shareholders demonstrating fiscal solvency and organizational transparency.
- C. Negotiate long-term contracts with companies who use well-vetted software application to avoid the transient nature of the cloud environment.
- D. Respect the interdependency of the risks inherent in the cloud supply chain and communicate the corporate risk posture and readiness to consumers and dependent parties.
- E. Both B and C.
Answer: C
NEW QUESTION 55
An inherent weakness in an information system. security procedures. internal controls, or implementation that could be exploited by a threat source.
- A. ARO
- B. Threat
- C. Risk
- D. Vulnerbility
Answer: D
Explanation:
Thats the definition of vulnerbility
NEW QUESTION 56
Which of the following is NOT a characteristic of Object Storage?
- A. Accessed through web interface
- B. Has additional Metadata
- C. Stored in cloud
- D. Cannot be accessed through web interface
Answer: D
Explanation:
Object storage: Similar to a file share accessed via APIs or a web interface. Examples include Amazon S3 and Rackspace cloud files.
NEW QUESTION 57
Which one of the following is not one the cloud deployment models?
- A. Community
- B. Joint
- C. Public
- D. Private
Answer: B
Explanation:
The four cloud deployment models are
1. Public
2. Private
3. Hybrid
4. Community
NEW QUESTION 58
Which of the following is key component of regulated PII components?
- A. Cloud Service Provider Consent
- B. E-discovery
- C. Data disclosure
- D. Mandatory Breach Reporting
Answer: D
Explanation:
The key component and differentiator related to regulated PII is mandatory breach reporting requirements. At present. 47 states and territories within the United States, including the District of Columbia. Puerto Rico. and the Virgin Islands, have legislation in place that requires both private and government entities to notify and inform individuals of any security breaches involving PII.
NEW QUESTION 59
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
- A. Allowing the cloud provider to manage your keys so that they have the ability to access and delete the data from the main and back-up storage.
- B. Keep the keys stored on the client side so that they are secure and so that the users have the ability to delete their own data.
- C. Maintaining customer managed key management and revoking or deleting keys from the key management system to prevent the data from being accessed again.
- D. Practice Integration of Duties (IOD) so that everyone is able to delete the encrypted data.
- E. Both B and D.
Answer: C
NEW QUESTION 60
On Demand Shelf Service is one of the key characteristics as defined by NIST.
- A. False
- B. True
Answer: A
Explanation:
This is false. Please read the question carefully.
Question: is asking
On Demand "Shelf" Service where the correct characteristic is "0n Demand Self Service"
NEW QUESTION 61
......
Exam Dumps CCSK Practice Free Latest Cloud Security Alliance Practice Tests: https://www.examprepaway.com/Cloud-Security-Alliance/braindumps.CCSK.ete.file.html
CCSK Exam Questions | Real CCSK Practice Dumps: https://drive.google.com/open?id=1B3n79padizJLxW_XmCLpF39WpNmn-Ebd