
Latest Cloud Security Alliance CCSK Free Certification Exam Material with 120 Q&As
UPDATED CCSK Exam Questions Certification Test Engine to PDF
NEW QUESTION # 57
Which of the following is also knows as white-box test and can be used to find XSS errors, SQL injection.
buffer overflows. unhandled error conditions. and potential backdoors?
- A. Threat Modelling
- B. Static Application Security Testing(SAST)
- C. Dynamic Application Security Testing(DAST)
- D. Static Application Security Testing(SAST)
Answer: B
Explanation:
Static application security testing(SAST) is generally considered a white-box test, where the application test performs an analysis of the application source code, byte code, and binaries without executing the application code. SAST is used to determine coding errors and omissions that are indicative of security vulnerabilities. SAST is often used as a test method while the tool is under development(early in the development lifecycle).
SAST can be used to find XSS errors, SQL injection, buffer overflows, unhandled error conditions, and potential backdoors.
NEW QUESTION # 58
Which of the following is NOT key Cloud computing characteristics?
- A. On Demand self service
- B. Broad Network Access
- C. Metered servicing
- D. Metered pricing
Answer: C
Explanation:
Often, this type of questions looks simple, but a confusion is created and you need to be careful while picking up the right options ln our case, metered pricing and metered servicing looks similar but Metered pricing is one of the characteristics of cloud computing.
NEW QUESTION # 59
Which of the following is key component of regulated PII components?
- A. Data disclosure
- B. Cloud Service Provider Consent
- C. E-discovery
- D. Mandatory Breach Reporting
Answer: D
Explanation:
The key component and differentiator related to regulated PII is mandatory breach reporting requirements. At present. 47 states and territories within the United States, including the District of Columbia. Puerto Rico. and the Virgin Islands, have legislation in place that requires both private and government entities to notify and inform individuals of any security breaches involving PII.
NEW QUESTION # 60
When the data is transferred to third party. who is ultimately responsible for security of data?
- A. Cloud Processor
- B. Cloud Service Provider
- C. Cloud Security Broker
- D. Cloud Controller
Answer: D
Explanation:
Whatever will be the scenario. Data controller will be responsible for security of data in cloud
NEW QUESTION # 61
Which of the following processes plays a major role in managing system vulnerabilities?
- A. Capacity Management
- B. Patch Management
- C. Release Management
- D. Incident Management
Answer: B
Explanation:
Although other process are part of overall security strategy proper patch management plays key role in keeping control on system vulnerabilities.
NEW QUESTION # 62
When a cloud customer uploads PII to a cloud provider. who becomes ultimately responsible for the security of that PII?
- A. The individuals who are the subject of the PII
- B. Regulator
- C. Cloud customer
- D. Cloud Provider
Answer: C
Explanation:
Under current law, the data owner is responsible for any breaches that result in unauthorized disclosure of PII; this includes breaches caused by contracted parties and outsources services. The data owner is the cloud customer.
NEW QUESTION # 63
When designing an encryption system, you should start with a threat model.
- A. True
- B. False
Answer: A
NEW QUESTION # 64
What is true of searching data across cloud environments?
- A. You might not have the ability or administrative rights to search or access all hosted data.
- B. All cloud-hosted email accounts are easily searchable.
- C. Search and discovery time is always factored into a contract between the consumer and provider.
- D. You can easily search across your environment using any E-Discovery tool.
- E. The cloud provider must conduct the search with the full administrative controls.
Answer: A
NEW QUESTION # 65
According to ENISA(European Network and Information Security Agency) document on Security risk and recommendation. Isolation Failure is:
- A. Technical Risk
- B. Organizational Risk
- C. Compliance Risk
- D. Management Risk
Answer: A
Explanation:
Isolation failure is defined as:
Multi-tenancy and shared resources are two of the defining characteristics of cloud computing environments. Computing capacity, storage, and network are shared between multiple users. This class of risks includes the failure of mechanisms separating storage, memory, routing, and even reputation between different tenants of the shared infrastructure(e.g, so-called guest-hopping attacks, SQL injection attacks exposing multiple customers' data stored in the same table, and side channel attacks).
NEW QUESTION # 66
Which of the following are key Data functions?
- A. Access, Procure & Store
- B. Access, Process & Store
- C. Access, Process & Save
- D. Access, Procure & Save
Answer: B
Explanation:
The key data functions are Access, process & Store
NEW QUESTION # 67
Your SLA with your cloud provider ensures continuity for all services.
- A. False
- B. True
Answer: A
Explanation:
Explanation
NEW QUESTION # 68
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
- A. Practice Integration of Duties (IOD) so that everyone is able to delete the encrypted data.
- B. Keep the keys stored on the client side so that they are secure and so that the users have the ability to delete their own data.
- C. Maintaining customer managed key management and revoking or deleting keys from the key management system to prevent the data from being accessed again.
- D. Both B and D.
- E. Allowing the cloud provider to manage your keys so that they have the ability to access and delete the data from the main and back-up storage.
Answer: C
NEW QUESTION # 69
What type of information is contained in the Cloud Security Alliance's Cloud Control Matrix?
- A. A list of cloud configurations including traffic logic and efficient routes
- B. The command and control management hierarchy of typical cloud company
- C. Network traffic rules for cloud environments
- D. A number of requirements to be implemented, based upon numerous standards and regulatory requirements
- E. Federal legal business requirements for all cloud operators
Answer: D
NEW QUESTION # 70
Who is responsible for Application Security in Software as a Service(SaaS) service model?
- A. It's a shared responsibility between Cloud Service Provider and Cloud Customer
- B. Cloud Service Provider
- C. Cloud Carrier
- D. Cloud Customer
Answer: A
Explanation:
Its always a shared responsbility
NEW QUESTION # 71
Which of the following reports is of most interest to the customer but may not be provided by Cloud Service Provider?
- A. SOC3
- B. SOC2 Type I
- C. SOC2 Type II
- D. SOC1 Type I
Answer: C
Explanation:
SOC2 Type II is the report which will be of lot of interest to the customers but it will not be provided by the cloud service provider as it may release lot of information about security controls put in place which can harm cloud service providers infrastructure adversely.
SOC2 Type II is a report on management's description of the service organisation's system and the suitability of the design and operating effectiveness of the controls
NEW QUESTION # 72
Select the statement below which best describes the relationship between identities and attributes
- A. Identities are the network names given to servers. Attributes are the characteristics of each server.
- B. An attribute is a unique object within a database. Each attribute it has a number of identities which help define its parameters.
- C. Attributes are made unique by their identities.
- D. An identity is a distinct and unique object within a particular namespace. Attributes are properties which belong to an identity. Each identity can have multiple attributes.
- E. Attributes belong to entities and identities belong to attributes. Each attribute can have multiple identities but only one entity.
Answer: C
NEW QUESTION # 73
In Platform as a Service (PaaS), platform security is a responsibility of:
- A. Cloud service provider
- B. Customer
- C. Neither of them
- D. It's a shared responsibility
Answer: D
Explanation:
This is a very confusing question and we need to understand that its a shared responsibility between cloud service provider and customer.
NEW QUESTION # 74
As with security. compliance in the cloud is a shared responsibility model.
- A. True
- B. False
Answer: A
Explanation:
As with security. compliance in the cloud is a shared responsibility model. Both the cloud provider and customer have responsibilities. But the customer is always ultimately responsible for their own compliance. These responsibilities are defined through contracts, audits/assessments. and specifics of the compliance requirements.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION # 75
According to ISO 27018. data processor has explicit control over how CSPs are to use PII.
- A. False
- B. True
Answer: A
Explanation:
In ISO 27018, it is the customer who has explicit right over how CSPs will use their information
NEW QUESTION # 76
......
Get The Important Preparation Guide With CCSK Dumps: https://www.validdumps.top/CCSK-exam-torrent.html
Get Totally Free Updates on CCSK Dumps PDF Questions: https://drive.google.com/open?id=1Vjt8V7zts8wS5sy2itXkDtPpAeldWjFT