Download the Latest CCSK Dumps - 2021 CCSK Exam Questions [Q134-Q150]

Share

Download the Latest CCSK Dumps - 2021 CCSK Exam Questions

Latest Cloud Security Alliance CCSK Certification Practice Test Questions


How much Certificate of Cloud Security Knowledge (CCSK) Exam Cost

The Certificate of Cloud Security Knowledge (CCSK) Exam costs USD 395 which includes two attempts for the candidates. In case of failure, each further attempt will cost USD 395. Candidates may incur other costs during the preparation phase of the exam like purchasing the CCSk dumps pdf and then practicing for the exam via the CCSK practice test.

 

NEW QUESTION 134
Which is the most important trust mechanism between cloud service provider and cloud customer?

  • A. Audit reports
  • B. Meeting SLA requirements
  • C. Logging and Monitoring reports
  • D. Contract

Answer: D

Explanation:
Contract is the most important document which defines trust and relationship between cloud service provider and the customer.

 

NEW QUESTION 135
ANF and ONF are referred in which of the following ISO standards?

  • A. ISO 27032
  • B. ISO 27001
  • C. ISO 27005
  • D. ISO 27034-1

Answer: D

Explanation:
ISO/ IEC 27034-1, "Information Technology - Security Techniques - Application Security," provides one of the most widely accepted set of standards and guidelines for secure application development. IS0/ IEC27034-1 is a comprehensive set of standards that cover many aspects of application development. A few of the key elements include the organizational normative framework (ONF), the application normative framework (ANF), and the application security management process (APSM).

 

NEW QUESTION 136
Inability of customer to leave, migrate, Or transfer to an alternate cloud service provider because of technical or nontechnical constraints. is known as:

  • A. Vendor lock-out
  • B. Vendor Limit
  • C. Vendor Lock
  • D. Vendor lock-in

Answer: D

Explanation:
Vendor lock-in is a situation in which a customer using a product or service cannot easily transition to a competitor's product or service. Vendor lock-in is usually the result of proprietary technologies that are incompatible with those of competitors.

 

NEW QUESTION 137
Who is responsible for the security of the physical infrastructure and virtualization platform?

  • A. The cloud consumer
  • B. The responsibility is split equally
  • C. The majority is covered by the consumer
  • D. It depends on the agreement
  • E. The cloud provider

Answer: E

 

NEW QUESTION 138
A health care facility has to only comply with HIPAA and do not need to comply with PCI DSS.

  • A. False
  • B. True

Answer: A

Explanation:
This is a tricky question. It is true that health care facility need to comply with HIPAA but if the healthcare facility is processing credit cards, they will have to comply with PCI DSS as well

 

NEW QUESTION 139
Cloud Service Provider and Cloud Customer are jointly responsible for ownership of the all risks in shared responsibility model for security across all service models.

  • A. False
  • B. True

Answer: A

Explanation:
This is false. This is again a tricky question and one should be careful when answering this type of question. It is the cloud customer is who is ultimately responsible for the ownership of risk in the cloud environment. Consumer just passes some of risk management responsibilities to the cloud service provider.

 

NEW QUESTION 140
Due to multi-tenancy nature of cloud. there is the possibility that data belonging to one customer will be read or received by another. This is known as:

  • A. Wilful data disclosure
  • B. Data disclosure
  • C. Data dispersion
  • D. Information Bleed

Answer: D

Explanation:
Information Bleed With multiple customers processing and storing data over the same infrastructure, there is the possibility that data belonging to one customer will be read or received by another.
Moreover, even if this does not happen with raw data, it might be possible for one customer to detect telltale information about another customer's activity, such as when the customer is processing data, how long the procedure takes, and so on.

 

NEW QUESTION 141
One of the main reasons and advantage of having external audit is:

  • A. Internal staff is less qualified than external auditors.
  • B. Its independent
  • C. Its cheaper
  • D. Better tools used by external provider

Answer: B

Explanation:
All other answers are distractors. One of the primary reasons of doing external auditing is the independence of auditors.

 

NEW QUESTION 142
Interoperability is the ability that enables the migration of cloud services from one cloud provider to another or between public cloud and a private cloud.

  • A. False
  • B. True

Answer: A

Explanation:
This is false, as this is the definition of Portability and not interoperability

 

NEW QUESTION 143
According to ISO 27018. data processor has explicit control over how CSPs are to use PII.

  • A. False
  • B. True

Answer: A

Explanation:
In ISO 27018, it is the customer who has explicit right over how CSPs will use their information

 

NEW QUESTION 144
In ability to provide enough capacity to the cloud customer can lead to which of the following risk:

  • A. Resource Exhaustion
  • B. Data Dispersion
  • C. Resource Utilization
  • D. Data Breach

Answer: A

Explanation:
Cloud services are on-demand Therefore there is a level of calculated risk in allocating all the resources of a cloud service, because resources are allocated according to statistical projections. In accurate modelling of resources usage common resources allocation algorithms are vulnerable to distortions of fairness or inadequate resource provisioning and inadequate investments in infrastructure.

 

NEW QUESTION 145
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document to potential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?

  • A. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
  • B. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
  • C. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.

Answer: C

 

NEW QUESTION 146
The process which frees the resources from their physical constraints to enable pooling is called:

  • A. Classification
  • B. Orchestration
  • C. Abstraction
  • D. Automation

Answer: C

Explanation:
Abstraction. often via virtualization. frees the resources from their physical constraints to enable pooling. Then a set of core connectivity and delivery tools(orchestration)ties these abstracted resources together. creates the pools. and provides the automation to deliver them to customers.
Ref: CSA Security Guidelines V4.0

 

NEW QUESTION 147
One of key focus of ISO 27001 standard is:

  • A. Find the data breaches in the organization
  • B. Develop ISMS (Information Security management system)
  • C. Put security controls in place
  • D. Define organizational structure

Answer: B

Explanation:
ISO/IEC 27001 is the best-known standard in the family providing requirements for an information security management system (ISMS).
An ISMS is a systematic approach to managing sensitive company information so that it remains secure.
It includes people, processes and IT systems by applying a risk management process.

 

NEW QUESTION 148
What is the characteristic that allows the cloud provider to meet various demands from customers while remaining financially viable?

  • A. Rapid elasticit
  • B. Resource pooling
  • C. Broad network access
  • D. Measured service

Answer: B

Explanation:
Resource pooling is characteristic that allows the cloud provider to meet various demands from customers while remaining financially viable.

 

NEW QUESTION 149
Metrics which govern the contractual obligations of cloud service are found in:

  • A. Service Level agreements(SLA)
  • B. Service Book
  • C. Contract itself
  • D. Operational Level Agreement(OLA)

Answer: A

Explanation:
The SLA is the list of defined, specific, numerical metrics that will used to determine whether the provider is sufficiently meeting the contract terms during each period of performance.

 

NEW QUESTION 150
......


For more info read reference:

Register for the exam

Exam Details

FAQs and Guide

 

Verified CCSK Dumps Q&As - 1 Year Free & Quickly Updates: https://www.validdumps.top/CCSK-exam-torrent.html

Get 2021 Updated Free Cloud Security Alliance CCSK Exam Questions & Answer: https://drive.google.com/open?id=1o4qEo-xir_1YDW618BSpfsNqfeT7Fmqj