Clear your concepts with CCSK Questions Before Attempting Real exam [Q28-Q48]

Share

Clear your concepts with CCSK Questions Before Attempting Real exam

Get professional help from our CCSK Dumps PDF


The benefit of obtaining the Certificate of Cloud Security Knowledge (CCSK) Exam Certification

By earning this certification, candidates will enjoy the following benefits:

  • Increase job prospects for cloud-certified professionals by filling the skills gap
  • In dealing with a wide range of responsibilities, from cloud governance to configuring technical security controls, learn to create a baseline of security best practices
  • Other credentials such as CISA, CISSP, and CCSP are complemented
  • Prove their experience with a company that specializes in cloud research on key cloud security issues
  • Display their technological expertise, experience, and abilities to use controls adapted to the cloud effectively

How to study the Certificate of Cloud Security Knowledge (CCSK) Exam

The CSA Security Guidelines for Sensitive Areas of Focus in Cloud Computing v4, English edition, ENISA Report ‘Cloud Computing: Advantages, Threats and Recommendations for Information Security' is the body of knowledge for the CCSK review.

Several resources are available for study. To get a solid understanding of the course contents, we recommend checking out the CCSK exam dumps available at the certificate-questions website that can be accessed via the link at the bottom of this document. The CSA Security Guidance can be accessed from here and is the definitive guide to keeping the cloud safe for your company. As an ever-evolving technology, the rise of cloud computing brings with it a range of opportunities and challenges. This paper offers both guidance and encouragement to support business objectives while managing and minimizing the risks associated with cloud computing technology adoption. This new edition covers developments in cloud, security, and technology support; focuses on cloud security activities in the real world; integrates the latest CSA research projects; and provides guidelines for relevant technologies.

The Cloud Controls Matrix (CCM) can be accessed from here. The CSA Cloud Controls Matrix (CCM) offers a comprehensive understanding of the concepts and values of security consistent with the domains of Security Guidelines v.4. It offers basic security concepts to direct cloud vendors as they build service offerings and assist prospective cloud customers in determining a cloud provider's overall security risk.

Cloud Security Alliance offers self-study materials, online and in person training for the exam so definitely check out and complete these training. The CCSK practice exams available have proven to be the best learning materials and have ensured unbelievable passing rates in the past years. So definitely check out the CCSK exam dumps before you appear for the exam.

 

NEW QUESTION 28
In 2015, 4 million records were stolen from telecom company, XYZ ltd, and later this information was used for scam calls to get bank information from the customers of XYZ. Which was of the following protection would have helped in minimising impact of the theft?

  • A. Use of VPN
  • B. Firewall
  • C. Repudiation
  • D. Encryption

Answer: D

Explanation:
Encryption of Data would have minimised the impact of the incident and it would have prevented data being used for scam calls.

 

NEW QUESTION 29
What item below allows disparate directory services and independent security domains to be interconnected?

  • A. Cloud
  • B. Intersection
  • C. Coalition
  • D. Union
  • E. Federation

Answer: E

 

NEW QUESTION 30
Which is the key technology that enables the sharing of resources and makes cloud computing most viable in terms of cost savings?

  • A. Content Delivery Networks(CDN)
  • B. Software Defined Networking(SDN)
  • C. Scalability
  • D. Virtualization

Answer: D

Explanation:
Virtualization is the foundational technology that underlies and makes cloud computing possible.
Virtualization is based on the use of powerful host computers to provide a shared resource pool that can be managed to maximize the number of guest operating systems(OSs) running on each host.

 

NEW QUESTION 31
An adversary uses a cloud Platform to launch a DDoS attack against XYZ company. This type of risk is termed as:

  • A. Account Hijacking
  • B. Abuse of Cloud services
  • C. Malicious Insider
  • D. Data Breaches

Answer: B

Explanation:
Malicious actors may leverage cloud computing resources to target users, Organizations or other cloud providers. Examples of misuse of cloud service-based resources include launching DDoS attacks, email spam and phishing campaigns; "mining" for digital currency; large-scale automated click fraud; brute- force compute attacks of stolen credential databases; and hosting of malicious or pirated content.

 

NEW QUESTION 32
Which of the following is correct about Due Care & Due Diligence?

  • A. Due care is technical control whereas Due Deligence is physical control.
  • B. Due diligence is the act of investigating and understanding the risks a company faces whereas Due care is the development and implementation of policies and procedures to aid in protecting the company. its assets and its people from threats.
  • C. None of the above definitions are correct.
  • D. Due care is the act of investigating and understanding the risks a company faces whereas Due Diligence is the development and implementation of policies and procedures to aid in protecting the company. its assets and its people from threats.

Answer: B

Explanation:
Definitions:
Due diligence is the act of investigating and understanding the risks a company faces.
Due care is the development and implementation of policies and procedures to aid in protecting the company, its assets, and its people from threats

 

NEW QUESTION 33
Inability of customer to leave, migrate, Or transfer to an alternate cloud service provider because of technical or nontechnical constraints. is known as:

  • A. Vendor Lock
  • B. Vendor lock-out
  • C. Vendor Limit
  • D. Vendor lock-in

Answer: D

Explanation:
Vendor lock-in is a situation in which a customer using a product or service cannot easily transition to a competitor's product or service. Vendor lock-in is usually the result of proprietary technologies that are incompatible with those of competitors.

 

NEW QUESTION 34
Under the new EU data protection rules. data destruction and corruption of personal data.

  • A. are considered forms of data breaches and require notification
  • B. does not need notification but cloud service provider is legally liable
  • C. does not attract any additional penalty
  • D. does not guarantee damages that can claimed by cloud customer.

Answer: A

Explanation:
They are considered as forms of data breached and require notification. Further cloud customer is legally liable.

 

NEW QUESTION 35
Which one of the following is the key tool of Cloud Governance?

  • A. Data classification
  • B. Contracts
  • C. Business Impact Analysis(BIA)
  • D. Auditor Selection

Answer: B

Explanation:
The primary tool of governance is the contract between a cloud provider and a cloud customer (this is true for public and private cloud). The contract is your only guarantee of any level of service or commitment Ref: CSA Security Guidance V4.0

 

NEW QUESTION 36
Which of the following processes plays a major role in managing system vulnerabilities?

  • A. Release Management
  • B. Capacity Management
  • C. Patch Management
  • D. Incident Management

Answer: C

Explanation:
Although other process are part of overall security strategy proper patch management plays key role in keeping control on system vulnerabilities.

 

NEW QUESTION 37
One of key focus of ISO 27001 standard is:

  • A. Find the data breaches in the organization
  • B. Define organizational structure
  • C. Put security controls in place
  • D. Develop ISMS (Information Security management system)

Answer: D

Explanation:
ISO/IEC 27001 is the best-known standard in the family providing requirements for an information security management system (ISMS).
An ISMS is a systematic approach to managing sensitive company information so that it remains secure.
It includes people, processes and IT systems by applying a risk management process.

 

NEW QUESTION 38
Which of the following pair represents Storage used in IaaS infra-structure?

  • A. CDN and Ephemeral
  • B. Raw and long-term storage
  • C. Volume and object storage
  • D. Structured and Unstructured Storage

Answer: C

Explanation:
IaaS uses the following storage types:
Volume storage: A virtual hard drive that can be attached to a virtual machine instance and be used to host data within a file System, Volumes attached to IaaS instances behave just like a physical drive or an array does. Examples include VMware Virtua Machine File System(VMFS), Amazon Elastic Block Store(EBS), RackSpace Redundant Array of Independent Disks (RAID), and OpenStack Cinder.
Object storage: Similar to a file share accessed via APIs or a web interface. Examples include Amazon S3 and Rackspace cloud files.

 

NEW QUESTION 39
How is encryption managed on multi-tenant storage?

  • A. One key per data owner
  • B. C for data subject to the EU Data Protection Directive; B for all others
  • C. The answer could be A, B, or C depending on the provider
  • D. Single key for all data owners
  • E. Multiple keys per data owner

Answer: A

 

NEW QUESTION 40
Which one of the following is an example of misuse or abuse of cloud services?

  • A. Honeypot
  • B. Account Hijacking
  • C. DDoS Attack
  • D. XSS attacks

Answer: C

Explanation:
Public cloud platform can be used to launch DDoS attack on other platforms.
Please note here and understand the meaning of phrase "abuse or misuse of cloud Services" This phrase means to launch attacks or campaign by using cloud as a platform. mostly. public cloud.

 

NEW QUESTION 41
Which is the set of technologies that are designed to detect conditions indicative of a security vulnerability in an application in its running state?

  • A. Static application security Testing(SAST)
  • B. Enterprise Threat Modelling
  • C. Dynamic application security testing(DAST)
  • D. STRIDE

Answer: C

Explanation:
Definitions:
SAST- Static application security testing(SAST) is a type of security testing that relies on inspecting the source code of an application. ln general, SAST involves looking at the ways the code is designed to pinpoint possible security flaws.
DAST- Dynamic application security testing(DAST) technologies are designed to detect conditions indicative of a security vulnerability in an application in its running state

 

NEW QUESTION 42
Which of the following is NOT of the essential characterstics as defined by NIST?

  • A. Resource Sharing
  • B. Resource Pooling
  • C. Rapid Elastici
  • D. On-demand self service

Answer: B

Explanation:
All others are characteristics as defined by NIST.

 

NEW QUESTION 43
Ensuring the use of data and information complies with organizational policies, standards and strategy- including regulatory, contractual, and business objectives, known as:

  • A. IT Governance
  • B. Data Governance
  • C. Corporate Governance
  • D. Enterprise Governance

Answer: B

Explanation:
It is definition of Data Governance

 

NEW QUESTION 44
Database as a Service is an example of :

  • A. Software as a Service(SaaS)
  • B. Infrastructure as a Service(IaaS)
  • C. Platform as a Service(PaaS)
  • D. Program as a Service(PaaS)

Answer: C

Explanation:
One option. frequently seen in the real world and illustrated in our model. is to build a platform on top of IaaS. A layer of integration and middleware is built on IaaS. then pooled together. orchestrated. and exposed to customers using APIs as PaaS. For example, a Database as a Service could be built by deploying modified database management system software on instances running in IaaS. The customer manages the database via API (and a web console) and accesses it either through the normal database network protocols, or, again, via API.
Ref: CSA Security Guidelines V4.0

 

NEW QUESTION 45
Cloud Service Provider and Cloud Customer are jointly responsible for ownership of the all risks in shared responsibility model for security across all service models.

  • A. False
  • B. True

Answer: A

Explanation:
This is false. This is again a tricky question and one should be careful when answering this type of question. It is the cloud customer is who is ultimately responsible for the ownership of risk in the cloud environment. Consumer just passes some of risk management responsibilities to the cloud service provider.

 

NEW QUESTION 46
The granting of right to access to a user. program or process. is called:

  • A. Entitlement
  • B. Authorization
  • C. Authentication
  • D. RBAC

Answer: B

Explanation:
Authorization is the process of granting of right to access to a user, program or process. It should not be confused with Authentication.

 

NEW QUESTION 47
ENISA: A reason for risk concerns of a cloud provider being acquired is:

  • A. Non-binding agreements put at risk
  • B. Resource isolation may fail
  • C. Arbitrary contract termination by acquiring company
  • D. Mass layoffs may occur
  • E. Provider may change physical location

Answer: A

 

NEW QUESTION 48
......


Cloud Security Alliance CCSK Foundation Exam Syllabus Topics:

SectionObjectives
Management Plane and Business Continuity-Business Continuity and Disaster Recovery in the Cloud
-Architect for Failure
-Management Plane Security
Identity, Entitlement, and Access Management-IAM Standards for Cloud Computing
-Managing Users and Identities
-Authentication and Credentials
-Entitlement and Access Management
Legal Issues, Contracts and Electronic Discovery-Legal Frameworks Governing Data Protection and Privacy
  • Cross-Border Data Transfer
  • Regional Considerations

-Contracts and Provider Selection

  • Contracts
  • Due Diligence
  • Third-Party Audits and Attestations

-Electronic Discovery

  • Data Custody
  • Data Preservation
  • Data Collection
  • Response to a Subpoena or Search Warrant
Related Technologies-Big Data
-Internet of Things
-Mobile
-Serverless Computing
Application Security-Opportunities and Challenges
-Secure Software Development Lifecycle
-How Cloud Impacts Application Design and Architectures
-The Rise and Role of DevOps
Virtualization and Containers-Mayor Virtualizations Categories
-Network
-Storage
-Containers
Infrastructure Security-Cloud Network Virtualization
-Security Changes With Cloud Networking
-Challenges of Virtual Appliances
-SDN Security Benefits
-Micro-segmentation and the Software Defined Perimeter
-Hybrid Cloud Considerations
-Cloud Compute and Workload Security
Cloud Computing Concepts and Architectures-Definitions of Cloud Computing
  • Service Models
  • Deployment Models
  • Reference and Architecture Models
  • Logical Model

-Cloud Security Scope, Responsibilities, and Models
-Areas of Critical Focus in Cloud Security


 

Achieve the CCSK Exam Best Results with Help from Cloud Security Alliance Certified Experts: https://www.testkingpdf.com/CCSK-testking-pdf-torrent.html

Give You Free Regular Updates on CCSK Exam Questions: https://drive.google.com/open?id=1Q0ot0ZstrbSyKzeDgJtjefxvUJvoQCAz