
New 2021 Realistic Free Cloud Security Alliance CCSK Exam Dump Questions & Answer
CCSK Practice Test Engine: Try These 300 Exam Questions
Cloud Security Alliance CCSK Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
NEW QUESTION 43
A unit of processing, which can be in a virtual machine, a container, or other abstraction and always run somewhere on a processor and consume memory is called:
- A. Controller
- B. Host
- C. Device
- D. Workload
Answer: D
Explanation:
A workload is a unit of processing, which can be in a virtual machine, a container, or other abstraction.
Workloads always run somewhere on a processor and consume memory. Workloads include a very diverse range of processing tasks, which range from traditional applications running in a virtual machine on a standard operating system, to GPU- or FPGA-based specialized tasks Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION 44
The risk left in any system after all countermeasures and strategies have been applied is called:
- A. Annualised Risk
- B. Mitigated Risk
- C. Leftover risk
- D. Residual Risk
Answer: D
Explanation:
Thats the definition of residual risk
NEW QUESTION 45
When Database as a Service is offered on Platform as a Service(PaaS) model, who is responsible for security features that needs to applied to the Databases?
- A. Cloud Access Security Broker (CASB)
- B. Cloud Consumer
- C. Cloud Service Provider
- D. Cloud Carrier
Answer: B
Explanation:
This is a tricky question.
When using a Database as a Service, the provider manages fundamental security, patching, and core configuration, while the cloud user is responsible for everything else, including which security features of the database to use, managing accounts, or even authentication methods.
Ref: CSA Security Guidelines v4.0
NEW QUESTION 46
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07 - Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework
- A. Governing and Risk Metrics
- B. Governance and Risk Management
- C. Governance and Retention Management
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 47
Which of the following is a responsibility of Cloud customer?
- A. Image Asset Management
- B. Meta Structure
- C. Secure Virtualization Infrastructure
- D. Isolation
Answer: A
Explanation:
Image asset management. Cloud compute deployments are based on master images-be it a virtual machine, container, or other code-that are then run in the cloud. This is often highly automated and results in a larger number of images to base assets on, compared to traditional computing master images. Managing these-including which meet security requirements, where they can be deployed, and who has access to them-is an important security responsibility.
Reference: CSA Security GuidelinesV.4(reproduced here for the educational purpose)
NEW QUESTION 48
Which of the following type of risk assessment most effectively supports cost-benefit analyses of alternative risk responses or courses of action?
- A. Quantitative Analysis
- B. Third party Risk Analysis
- C. Qualitative Analysis
- D. Outsourced risk analysis
Answer: A
Explanation:
Quantitative assessments typically employ a set of methods, principles, or rules for assessing risk based on the use of numbers This type of assessment most effectively supports cost-benefit analyses of alternative risk responses or courses of action.
NEW QUESTION 49
What is the process to determine any weaknesses in the application and the potential ingress, egress, and actors involved before the weakness is introduced to production?
- A. Threat Modelling
- B. Threat Detection
- C. Vulnerability Assessment
- D. STRIDE
Answer: A
Explanation:
Threat modelling is performed once an application design is created. The goal of threat modelling is to determine any weaknesses in the application and the potential ingress, egress, and actors involved before the weakness is introduced to production. It is the overall attack surface that is amplified by the cloud, and the threat model has to take that into account.
NEW QUESTION 50
Application security is a shared responsibility between cloud service provider between cloud service provider and cloud customer Platform as a Service(PaaS) model.
- A. True
- B. False
Answer: B
Explanation:
It is false.
This type of question is there to confuse students. Although, we do develop applications on platform provided, its security is total responsibility of the cloud customer.
NEW QUESTION 51
To understand their compliance alignments and gaps with a cloud provider, what must cloud customers rely on?
- A. Provider documentation
- B. Provider run audits and reports
- C. EDiscovery tools
- D. Provider and consumer contracts
- E. Third-party attestations
Answer: E
NEW QUESTION 52
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?
- A. Domain
- B. Control Specification
- C. Risk Impact
Answer: A
NEW QUESTION 53
CCM: In the CCM tool, a _____________________ is a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.
- A. Risk Impact
- B. Control Specification
- C. Domain
Answer: B
NEW QUESTION 54
Which of the following is NOT true about CSA Cloud control metrix (CCM)?
- A. Maps controls to existing standards like ISO 27001
- B. Define the Cloud Audit Methodolog
- C. Also includes controls related to processing of personal data.
- D. Contains security controls divided in several domains
Answer: B
Explanation:
Remember that CCM is a security framework and does not include any methodology The Cloud Security Alliance Cloud Controls Matrix(CCM) is an essential and up-to-date security controls framework that is addressed to the cloud community and stakeholders. A fundamental richness of the CCM is its ability to provide mapping and cross relationships with the main industry-accepted security
NEW QUESTION 55
Which of the following best describes the relationship between a cloud provider and the customer?
- A. Operational level Agreement
- B. Service Level Agreement
- C. Privacy Level Agreement
- D. Contract
Answer: D
Explanation:
Contract is the most suitable answer here. It can be argued that Service Level Agreement could also be an answer but SLA is a negotiation/agreement for minimum service-levels expected. Contract is the document that defines the relation-ship between Cloud service provider and customer
NEW QUESTION 56
Exploitable bugs in programs that attackers can use to infiltrate a computer system for the purpose of stealing data, taking control of the system or disrupting service operations, are called:
- A. Vulnerbilities
- B. Threat Agents
- C. Threats
- D. Honepots
Answer: A
NEW QUESTION 57
Which of the following reports the cloud service provide normally share with customer WITHOUT any non-disclosure agreement and is in the public domain?
- A. SOC3
- B. SOC2 Type1
- C. SOC2 Type2
- D. SOC1 Type1
Answer: A
Explanation:
A Soc3 reports on the same information as a Soc2 report. The main difference between the two is that a Soc3 is intended fora general audience. These reports are shorter and do not include the same details as a Soc2 report, which is distributed to an informed audience of stakeholders. Due to their more general nature, Soc3 reports can be shared openly and posted on a company's website with a seal indicating their compliance
NEW QUESTION 58
Cloud Service Provider and Cloud Customer are jointly responsible for ownership of the all risks in shared responsibility model for security across all service models.
- A. True
- B. False
Answer: B
Explanation:
This is false. This is again a tricky question and one should be careful when answering this type of question. It is the cloud customer is who is ultimately responsible for the ownership of risk in the cloud environment. Consumer just passes some of risk management responsibilities to the cloud service provider.
NEW QUESTION 59
Which form of storage has features are typically minimal. allowing you to only store, retrieve, copy and delete files as well as the ability to control which users can undertake these actions?
- A. Volume Storage
- B. Object Storage
- C. Ephemeral Storage
- D. Block Storage
Answer: B
Explanation:
Object Storage has features are typically minimal, allowing you to only store, retrieve, copy, and delete files as well as the ability to control which users can undertake these actions.
NEW QUESTION 60
What is true of security as it relates to cloud network infrastructure?
- A. You should apply cloud firewalls on a per-network basis.
- B. You should implement a default deny with cloud firewalls.
- C. You should implement a default allow with cloud firewalls and then restrict as necessary.
- D. You should always open traffic between workloads in the same virtual subnet for better visibility.
- E. You should deploy your cloud firewalls identical to the existing firewalls.
Answer: B
Explanation:
Explanation
NEW QUESTION 61
......
Who should take the Certificate of Cloud Security Knowledge (CCSK) Exam
For any IT professional working in cloud computing, the CCSK is planned. It’s a no-brainer for safety practitioners. As the CCSK is designed to give you a well-rounded view of cloud security, we also see non-security professionals get value from it, particularly developers, IT operations, and audit/compliance.
The exam is targeted for the following people:
- Manager
- Security Analyst
- Consultant
Anyone who finds the CCSk exams dumps interesting and following their interests should consider getting this certification.
Guaranteed Success in Cloud Security Knowledge CCSK Exam Dumps: https://www.verifieddumps.com/CCSK-valid-exam-braindumps.html
Cloud Security Alliance CCSK Daily Practice Exam New 2021 Updated 300 Questions: https://drive.google.com/open?id=1EXgLCKZlPj70Rd_pHscTHNpY4QT04Xdl
