[Dec-2023] Check your preparation for Cloud Security Alliance CCSK On-Demand Exam [Q30-Q46]

Share

[Dec-2023] Check your preparation for Cloud Security Alliance CCSK On-Demand Exam

Practice Exam CCSK Realistic Dumps Verified Questions


The CCSK exam is an online, web-based test that is administered by the Cloud Security Alliance. CCSK exam consists of 60 multiple-choice questions that test the knowledge and skills of the candidate in cloud security. The questions are divided into 13 domains, including architecture, governance and risk management, data security, and compliance. CCSK exam is timed and must be completed within 90 minutes.

 

NEW QUESTION # 30
According to Cloud Security Alliance logical model of cloud computing, which of the following defines the protocols and mechanisms that provide the interface between the infrastructure layer and the other layers.

  • A. Applistructure
  • B. Metastructure
  • C. Infostructure
  • D. Infrastructure

Answer: B

Explanation:
According to CSA Securityguidelines4.0. Metastucture is defined as the protocols and mechanisms that provide the interface between the infrastructure layer and the other layers. The glue that ties the technologies and enables management and configuration.


NEW QUESTION # 31
Which of the following is NOT one of the common networks underlying in Cloud Infrastructure?

  • A. Management Network
  • B. Service Network
  • C. Security Network
  • D. Storage Network

Answer: C

Explanation:
If you are a cloud provider (including managing a private cloud), physical segregation of networks composing your cloud is important for both operational and security reasons. We most commonly see at least three different networks which are isolated onto dedicated hardware since there is no functional or traffic overlap:
1. The service network for communications between virtual machines and the Internet. This builds the network resource pool for the cloud users.
2. The storage network to connect virtual storage to virtual machines.
3. A management network for management and API traffic.
Ref: Reference: CSA Security GuidelinesV.4 (reproduced here for the educational purpose)


NEW QUESTION # 32
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?

  • A. Cloud Access and Security Brokers (CASB)
  • B. Intrusion Prevention System
  • C. Database Activity Monitoring
  • D. URL filters
  • E. Data Loss Prevention

Answer: B


NEW QUESTION # 33
ln which of the following cloud service models is the customer required to maintain the operating system?

  • A. SaaS
  • B. Public Cloud
  • C. IaaS
  • D. PaaS

Answer: C

Explanation:
According to "The NIST Definition of Cloud Computing," in IaaS, "the capability provided to the consumer is to provision processing, storage, networks, and other fundamental computing resources where the consumer is able to deploy and run arbitrary software, which can include OSs and applications. The consumer does not manage or control the underlying cloud infrastructure but has control over OSs, storage, and deployed applications; and possibly limited control of select networking components (e.g, host firewalls)."


NEW QUESTION # 34
Where does the private cloud reside?

  • A. Off-premise
  • B. On-premise
  • C. On-premise or off-premise
  • D. Remote

Answer: C

Explanation:
According to CSA security guide lines. although. private cloud is for organisation's own use. it can reside on-site or off-premise as well.


NEW QUESTION # 35
On Demand Shelf Service is one of the key characteristics as defined by NIST.

  • A. True
  • B. False

Answer: B

Explanation:
This is false. Please read the question carefully.
Question: is asking
On Demand "Shelf" Service where the correct characteristic is "0n Demand Self Service"


NEW QUESTION # 36
Which one of the following is NOT a level of CSA star program?

  • A. Third-party attestation
  • B. Continuous-monitoring program
  • C. Self-assessment
  • D. Technology Audit program

Answer: D

Explanation:
"Technology Audit Program" is not one of the levels of CSA star program The three levels of CSA Star program are
1) Self Assessment
2) Third-party Attestment
3) Continuous Monitoring program


NEW QUESTION # 37
In which service model, cloud consumer is responsible to manage authorizations and entitlements only?

  • A. All of them
  • B. Software as a Service (SaaS)
  • C. Infrastructure as a Service (IaaS)
  • D. Platform as a Service (PaaS)

Answer: B

Explanation:
It is important to read the question carefully and then choose the best answer. Although cloud consumer is responsible for authorizations and entitlements across all service models but questions uses
"only''. Therefore, answer is Software as a Service (SaaS) and a SaaS provider is responsible for perimeter security, logging/ monitoring/auditing, and application security.


NEW QUESTION # 38
Which of the following processes plays a major role in managing system vulnerabilities?

  • A. Release Management
  • B. Patch Management
  • C. Incident Management
  • D. Capacity Management

Answer: B

Explanation:
Although other process are part of overall security strategy proper patch management plays key role in keeping control on system vulnerabilities.


NEW QUESTION # 39
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document to potential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?

  • A. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
  • B. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
  • C. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.

Answer: C


NEW QUESTION # 40
Which of the following uses security and encryption as means to prevent unauthorized copying and limitations on distribution to only those who pay?

  • A. Data Dispersion
  • B. Data Encryption
  • C. Digital Rights Management(DRM)
  • D. IPSEC

Answer: C

Explanation:
Digital rights management(DRM)was designed to focus on security and encryption as a means of preventing unauthorized copying and limitations on distribution of content to only those authorized(purchasers).


NEW QUESTION # 41
Private clouds can be hosted off-premises as well.

  • A. False
  • B. True

Answer: B

Explanation:
It is true. This is how Private cloud is defined.
Private Cloud: The cloud infrastructure is operated solely for a single organization. It may be managed by the organization or by a third party and may be located on-premises or off-premises.


NEW QUESTION # 42
Which of the following decouples the network control plane from the data plane and allows to abstract networking from the tradition a limitations of a LAN?

  • A. Traditional Networking
  • B. Software defined networking
  • C. VLANS
  • D. Converged Networking

Answer: B

Explanation:
Software Defined Networking(SDN):A more complete abstraction layer on top of networking hardware, SDNs decouple the network control plane from the data plane(you can read more on SDN principles at this Wikipedia entry).This allows us to abstract networking from the traditional limitations of a LAN.
Reference: CSA Security Guidelines V4.0


NEW QUESTION # 43
What refers refer the model that allows customers to scale their computer and/ or storage needs with little or no intervention from or prior communication with the provider. The services happen in real time?

  • A. Broad network access
  • B. Resource pooling
  • C. Rapid elasticity
  • D. On-demand self-service

Answer: D

Explanation:
It is the characteristic of 0n-demand self-service that allows customers to scale their computer and/ or storage needs with little or no intervention from or prior communication with the provider


NEW QUESTION # 44
Object storage unsuitable for data that changes frequently, Is it true?

  • A. False, because change in one replica will also return latest version irrespective of its location
  • B. False, Object storage is suitable for all type of data
  • C. True, because data is geographically disperse and cannot be replicated
  • D. True, because whenever you update a file you may have to wait until the change is propagated to all the replicas before requests return the latest version

Answer: D

Explanation:
With object storage systems, data consistency is achieved eventually. Whenever you update a file, you may have to wait until the change is propagated to all the replicas before requests return the latest version.


NEW QUESTION # 45
Which is the most important trust mechanism between cloud service provider and cloud customer?

  • A. Meeting SLA requirements
  • B. Contract
  • C. Audit reports
  • D. Logging and Monitoring reports

Answer: B

Explanation:
Contract is the most important document which defines trust and relationship between cloud service provider and the customer.


NEW QUESTION # 46
......

Valid CCSK Dumps for Helping Passing Cloud Security Alliance Exam: https://www.testkingpdf.com/CCSK-testking-pdf-torrent.html

Download Free Cloud Security Alliance CCSK Exam Questions & Answer: https://drive.google.com/open?id=1sybxvvT8HcknH20Sl4W39AM6XOeLUrZd