CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 1 of 6.
- Question #1Hadoop Ecosystem Fundamentals
All cloud services utilize virtualization technologies.
cloud computingvirtualization - Question #2Performance Tuning and Troubleshooting
If there are gaps in network logging data, what can you do?
cloud loggingmonitoringinstrumentationnetwork logging - Question #3Hadoop Ecosystem Fundamentals
CCM: In the CCM tool, a _____________________ is a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.
CCMcloud controls matrixrisk managementcontrol specification - Question #4Hadoop Ecosystem Fundamentals
Who is responsible for the security of the physical infrastructure and virtualization platform?
cloud securityshared responsibility modelcloud provider - Question #5Hadoop Ecosystem Fundamentals
What factors should you understand about the data specifically due to legal, regulatory, and jurisdictional factors?
data governancedata jurisdictionregulatory compliancedata location - Question #6Hadoop Ecosystem Fundamentals
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?
cloud service modelsPaaSIaaSSaaS - Question #7Hadoop Ecosystem Fundamentals
CCM: The following list of controls belong to which domain of the CCM? GRM 06 '" Policy GRM 07 '" Policy Enforcement GRM 08 '" Policy Impact on Risk Assessments GRM 09 '" Policy Re...
CCMgovernancerisk managementcloud controls - Question #8Hadoop Ecosystem Fundamentals
Which attack surfaces, if any, does virtualization technology introduce?
virtualization securityhypervisorattack surfaceVM sprawl - Question #9Hadoop Ecosystem Fundamentals
APIs and web services require extensive hardening and must assume attacks from authenticated and unauthenticated adversaries.
API securityweb serviceshardeningauthentication - Question #10Hadoop Ecosystem Fundamentals
Which of the following is NOT a cloud computing characteristic that impacts incidence response?
cloud computingincident responsecloud characteristicsdata jurisdiction - Question #11Hadoop Ecosystem Fundamentals
Big data includes high volume, high variety, and high velocity.
big data3Vsvolumevelocity - Question #12Legal, Risk, and Compliance
CCM: A hypothetical company called: 'Health4Sure' is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA...
CCMHIPAA/HITECHcompliance mappingsecurity assessment - Question #13Cloud Platform and Infrastructure Security
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what...
entitlement matrixaccess controlIAMauthorization - Question #14Cloud Architecture and Design
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.
virtual networksnetwork segregationcloud isolation - Question #15Cloud Architecture and Design
Your cloud and on-premises infrastructures should always use the same network address ranges.
network addressinghybrid cloudcloud networkingIP ranges - Question #16Cloud Platform and Infrastructure Security
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?
infrastructure layercloud layerssecure foundationmetastructure - Question #17Cloud Platform and Infrastructure Security
Why is a service type of network typically isolated on different hardware?
service networknetwork isolationnetwork architecturehardware separation - Question #18Auditing
Which governance domain deals with evaluating how cloud computing affects compliance with internal security policies and various legal requirements, such as regulatory and legislat...
compliance managementaudit managementCSA domainsregulatory requirements - Question #19Cloud Security Operations
An important consideration when performing a remote vulnerability test of a cloud-based application is to
vulnerability testingpenetration testingprovider permissioncloud testing - Question #20Cloud Computing Concepts
Cloud services exhibit five essential characteristics that demonstrate their relation to, and differences from, traditional computing approaches. Which one of the five characterist...
NIST cloud characteristicson-demand self-servicecloud fundamentals - Question #21Cloud Application Security
REST APIs are the standard for web-based services because they run over HTTPS and work well across diverse environments.
REST APIHTTPSweb servicesAPI standards - Question #22Governance
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
enterprise risk managementcloud governancesupply chain riskstakeholder transparency - Question #23Legal, Risk, and Compliance
What is defined as the process by which an opposing party may obtain private documents for use in litigation?
eDiscoverylitigationlegal proceedingsdocument production - Question #24Cloud Platform and Infrastructure Security
What item below allows disparate directory services and independent security domains to be interconnected?
federationidentity managementdirectory servicestrust domains - Question #25Cloud Architecture and Design
Use elastic servers when possible and move workloads to new instances.
elasticityimmutable infrastructurecloud workloadsserver lifecycle - Question #26Auditing
To understand their compliance alignments and gaps with a cloud provider, what must cloud customers rely on?
third-party attestationcompliance auditprovider transparencycloud assurance - Question #27Governance
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?
enterprise risk managementcloud riskcontract relianceaudit dependency - Question #28Cloud Data Security
Which data security control is the LEAST likely to be assigned to an IaaS provider?
IaaSshared responsibility modeldata security controlsapplication logic - Question #29Virtualization and Containers
How does virtualized storage help avoid data loss if a drive fails?
virtualized storagedata redundancyfault toleranceavailability - Question #30Cloud Application Security
What is the newer application development methodology and philosophy focused on automation of application development and deployment?
DevOpsapplication automationCI/CDdeployment methodology - Question #31Cloud Data Security
Sending data to a provider's storage over an API is likely as much more reliable and secure than setting up your own SFTP server on a VM in the same provider
API securitycloud storagesecure data transferSFTP vs API - Question #32Legal, Risk, and Compliance
Select the best definition of 'compliance' from the options below.
compliance definitionobligationsadherencerisk prioritization - Question #33Governance
CCM: In the CCM tool, 'Encryption and Key Management' is an example of which of the following?
CCMcloud controls matrixencryption key managementdomain classification - Question #34Cloud Data Security
In volume storage, what method is often used to support resiliency and security?
volume storagedata dispersionresiliencystorage security - Question #35Cloud Platform and Infrastructure Security
What is true of security as it relates to cloud network infrastructure?
cloud firewalldefault denynetwork segmentationvirtual network security - Question #36Cloud Security Operations
Which statement best describes the impact of Cloud Computing on business continuity management?
business continuitycloud portabilityprovider dependencyBCP planning - Question #37Virtualization and Containers
What is known as a code execution environment running within an operating system that shares and uses the resources of the operating system?
containerOS-level virtualizationworkload isolationruntime environment - Question #38Cloud Security Operations
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?
chaos engineeringresiliency testingbusiness continuityfault injection - Question #39Legal, Risk, and Compliance
What is true of companies considering a cloud computing business relationship?
data custodianshipdata ownershipcloud responsibilitycustomer data - Question #40Cloud Application Security
Dynamic Application Security Testing (DAST) might be limited or require pre-testing permission from the provider.
DASTdynamic application security testingprovider permissionpenetration testing - Question #41Legal, Risk, and Compliance
When deploying Security as a Service in a highly regulated industry or environment, what should both parties agree on in advance and include in the SLA?
SecaaS SLAregulatory complianceservice level agreementregulated industry - Question #42Cloud Platform and Infrastructure Security
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?
volume storageblock storagevirtual hard driveVM storage - Question #43Cloud Security Operations
Which of the following items is NOT an example of Security as a Service (SecaaS)?
SecaaSsecurity as a serviceservice categoriescloud security services - Question #44Cloud Data Security
How is encryption managed on multi-tenant storage?
multi-tenant encryptionkey managementdata isolationper-tenant keys - Question #45Cloud Data Security
Which statement best describes why it is important to know how data is being accessed?
data accessdevice diversityapplication clientsaccess governance - Question #46Cloud Computing Concepts
What is resource pooling?
resource poolingmulti-tenancyNIST cloud characteristicsshared infrastructure - Question #47Legal, Risk, and Compliance
Your SLA with your cloud provider ensures continuity for all services.
SLAcloud continuityprovider limitationsservice guarantees - Question #48Cloud Data Security
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
CASBDLPshadow IT detectiondata migration prevention - Question #49Auditing
In which type of environment is it impractical to allow the customer to conduct their own audit, making it important that the data center operators are required to provide auditing...
multi-tenant auditingthird-party auditcloud complianceaudit access - Question #50Legal, Risk, and Compliance
ENISA: Lock-in is ranked as a high risk in ENISA research, a key underlying vulnerability causing lock in is:
ENISAvendor lock-intransparencyterms of use