[2021] Pass CCSK Exam - Real Questions & Answers [Q98-Q115]

Share

[2021] Pass CCSK Exam - Real Questions & Answers

CCSK Exam Questions Get Updated [2021] with Correct Answers


How much Certificate of Cloud Security Knowledge (CCSK) Exam Cost

The Certificate of Cloud Security Knowledge (CCSK) Exam costs USD 395 which includes two attempts for the candidates. In case of failure, each further attempt will cost USD 395. Candidates may incur other costs during the preparation phase of the exam like purchasing the CCSk dumps pdf and then practicing for the exam via the CCSK practice test.

 

NEW QUESTION 98
Which of the following processes leverages virtual network topologies to run more smaller and more isolated networks without incurring additional hardware costs?

  • A. VLANs
  • B. Converged Networking
  • C. Micro-segmentation
  • D. Grid networking

Answer: C

Explanation:
Explanation:
This type of question are asked to create confusion.
Following are the five phases of SDLC:
1. Planning and requirements analysis: Business and security requirements and standards are being determined. This phase is the main focus of the project managers and stakeholders. Meetings with managers, stakeholders, and users are held to determine requirements. The software development lifecycle calls for all business requirements(functional and nonfunctional)to be defined even before initial design begins. Planning for the quality-assurance requirements and identification of the risks associated with the project are also conducted in the planning stage. The requirements are then analyzed for their validity and the possibility of incorporating them into the system to be developed.
2. Defining: The defining phase is meant to clearly define and document the product requirements to place them in front of the customers and get them approved. This is done through a requirement specification document, which consists of all the product requirements to be designed and developed during the project lifecycle.
3. Designing: System design helps in specifying hardware and system requirements and helps in defining overall system architecture. The system design specifications serve as input for the next phase of the model. Threat modeling and secure design elements should be undertaken and discussed here.
4. Developing: Upon receiving the system design documents, work is divided into modules or units and actual coding starts. This is typically the longest phase of the software development lifecycle. Activities include code review, unit testing, and static analysis.
5. Testing: After the code is developed, it is tested against the requirements to make sure that the product is actually solving the needs gathered during the requirements phase. During this phase, unit testing, integration testing, system testing, and acceptance testing are conducted.

 

NEW QUESTION 99
Which of the following uses security and encryption as means to prevent unauthorized copying and limitations on distribution to only those who pay?

  • A. Data Dispersion
  • B. Data Encryption
  • C. Digital Rights Management(DRM)
  • D. IPSEC

Answer: C

Explanation:
Digital rights management(DRM)was designed to focus on security and encryption as a means of preventing unauthorized copying and limitations on distribution of content to only those authorized(purchasers).

 

NEW QUESTION 100
Who is responsible for Governance, Risk & Compliance in Software as a Service(SaaS) service model?

  • A. Cloud Service Provider
  • B. Cloud Customer
  • C. It's a shared responsibility between Cloud Service Provider and Cloud Customer
  • D. Cloud Carrier

Answer: B

Explanation:
Remember, GRC will always remain responsibility of the cloud customer in all service models

 

NEW QUESTION 101
Which attack surfaces, if any, does virtualization technology introduce?

  • A. The hypervisor
  • B. All of the above
  • C. Configuration and VM sprawl issues
  • D. Virtualization management components apart from the hypervisor

Answer: B

 

NEW QUESTION 102
What defines easiness to move and reuse application components regardless of the provider, platform,
0S, infrastructure, location, storage, format of data or APIs, how well applications work together, and how well new applications work with other solutions present in the business, organization, or provider's existing architecture?

  • A. Portability
  • B. Interoperability
  • C. Scalability
  • D. Elasticity

Answer: B

Explanation:
Interoperability is an important characteristic.
Definition: Interoperability
Interoperability is the ability of a system or a product to work with other systems or products without special effort on the part of the customer.

 

NEW QUESTION 103
Cloud architectures necessitate certain roles which are extremely high-risk. Examples of such roles include CP system administrators and auditors and managed security service providers dealing with intrusion detection reports and incident response. They are known as high-risk because their malicious activities can lead to abuse of high privilege roles and can impact confidentiality, integrity and availability of data.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 104
"Cloud provider acquisition" as a risk fall under which of the following categories?

  • A. Legal Risk
  • B. Technical risk
  • C. Policy and Organizational Risk
  • D. Environmental Risk

Answer: C

Explanation:
Cloud provider acquisition comes under Policy and Organizational Risk and can be categorised as follows.
As in any new IT market, competitive pressure, an inadequate business strategy, lack of financial support, etc, could lead some providers to go out of business or at least to force them to restructure their service portfolio offering. In other words, it is possible that in the short or medium term some cloud computing services could be terminated.

 

NEW QUESTION 105
Object storage unsuitable for data that changes frequently, Is it true?

  • A. True, because whenever you update a file you may have to wait until the change is propagated to all the replicas before requests return the latest version
  • B. False, because change in one replica will also return latest version irrespective of its location
  • C. True, because data is geographically disperse and cannot be replicated
  • D. False, Object storage is suitable for all type of data

Answer: A

Explanation:
With object storage systems, data consistency is achieved eventually. Whenever you update a file, you may have to wait until the change is propagated to all the replicas before requests return the latest version.

 

NEW QUESTION 106
How is encryption managed on multi-tenant storage?

  • A. C for data subject to the EU Data Protection Directive; B for all others
  • B. Multiple keys per data owner
  • C. Single key for all data owners
  • D. One key per data owner
  • E. The answer could be A, B, or C depending on the provider

Answer: D

 

NEW QUESTION 107
Who is responsible for infrastructure Security in Software as a Service(SaaS) service model?

  • A. Cloud Customer
  • B. Cloud Service Provider
  • C. It's a shared responsibility between Cloud Service Provider and Cloud Customer
  • D. Cloud Carrier

Answer: B

Explanation:
Cloud service Provider is responsible for infrastructure in Software as a service(SaaS) service Model

 

NEW QUESTION 108
No policy on resource capping can lead to:

  • A. Resource Exhaustion
  • B. Data disclosure
  • C. Resource manipulation
  • D. Data manipulation

Answer: A

Explanation:
It can lead to resource exhaustion if you do not put upper limit on resource allocation.
Cloud services are on-demand Therefore there is a level of calculated risk in allocating all the resources of a cloud service, because resources are allocated according to statistical projections. In accurate modelling of resources usage- common resources allocation algorithms are vulnerable to distortions of fairness

 

NEW QUESTION 109
Which of the following reports is of most interest to the customer but may not be provided by Cloud Service Provider?

  • A. SOC1 Type I
  • B. SOC2 Type I
  • C. SOC3
  • D. SOC2 Type II

Answer: D

Explanation:
SOC2 Type II is the report which will be of lot of interest to the customers but it will not be provided by the cloud service provider as it may release lot of information about security controls put in place which can harm cloud service providers infrastructure adversely.
SOC2 Type II is a report on management's description of the service organisation's system and the suitability of the design and operating effectiveness of the controls

 

NEW QUESTION 110
ISO 27001 certification can be taken as proof to achieve Third-party assessment level in CSA star program.

  • A. False
  • B. True

Answer: B

Explanation:
The CSA STAR Certification is a rigorous third-party independent assessment of the security of a cloud service provider. The technology-neutral certification leverages the requirements of the ISO/IEC
27001:2013 management system standard together with the CSA Cloud Controls Matrix.

 

NEW QUESTION 111
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07 - Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework

  • A. Governance and Risk Management
  • B. Governance and Retention Management
  • C. Governing and Risk Metrics

Answer: A

 

NEW QUESTION 112
"Standards like the SSAE16 have a defined scope. which includes both what is assessed (e.g. which of the provider's services) as well as which controls are assessed. A provider can thus "pass" an audit that doesn't include any security controls. which isn't overly useful for security and risk managers. " True or False?

  • A. False
  • B. True

Answer: B

Explanation:
This is true, When cloud assessment is done, it is very important to understand the scope of the audit and the standard used. In statement above, we can see that, audit scope ofSSAE16 is decided by cloud provider and can be very limited and one may not be get full visilibility into the security of the cloud service provider.

 

NEW QUESTION 113
Which of the following is not a common cloud service model?

  • A. Software as a Service
  • B. Infrastructure as a Service
  • C. Programming as a Service
  • D. Platform as a Service

Answer: C

Explanation:
Programming as a Service is not a common offering; the others are ubiquitous through out the industry.

 

NEW QUESTION 114
A unit of processing, which can be in a virtual machine, a container, or other abstraction and always run somewhere on a processor and consume memory is called:

  • A. Controller
  • B. Workload
  • C. Host
  • D. Device

Answer: B

Explanation:
A workload is a unit of processing, which can be in a virtual machine, a container, or other abstraction.
Workloads always run somewhere on a processor and consume memory. Workloads include a very diverse range of processing tasks, which range from traditional applications running in a virtual machine on a standard operating system, to GPU- or FPGA-based specialized tasks Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)

 

NEW QUESTION 115
......

Practice CCSK Questions With Certification guide Q&A from Training Expert Pass4sureCert: https://www.pass4surecert.com/Cloud-Security-Alliance/CCSK-practice-exam-dumps.html

Free Cloud Security Alliance CCSK Test Practice Test Questions Exam Dumps: https://drive.google.com/open?id=1FV92Rdm1ellkhQZ9ARd9DlQ5-PX3lYWz