CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 1 of 6.
- Question #1
All cloud services utilize virtualization technologies.
- Question #2
If there are gaps in network logging data, what can you do?
- Question #3
CCM: In the CCM tool, a _____________________ is a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.
- Question #4
Who is responsible for the security of the physical infrastructure and virtualization platform?
- Question #5
What factors should you understand about the data specifically due to legal, regulatory, and jurisdictional factors?
- Question #6
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?
- Question #7
CCM: The following list of controls belong to which domain of the CCM? GRM 06 '" Policy GRM 07 '" Policy Enforcement GRM 08 '" Policy Impact on Risk Assessments GRM 09 '" Policy Re...
- Question #8
Which attack surfaces, if any, does virtualization technology introduce?
- Question #9
APIs and web services require extensive hardening and must assume attacks from authenticated and unauthenticated adversaries.
- Question #10
Which of the following is NOT a cloud computing characteristic that impacts incidence response?
- Question #11
Big data includes high volume, high variety, and high velocity.
- Question #12
CCM: A hypothetical company called: 'Health4Sure' is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA...
- Question #13
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what...
- Question #14
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.
- Question #15
Your cloud and on-premises infrastructures should always use the same network address ranges.
- Question #16
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?
- Question #17
Why is a service type of network typically isolated on different hardware?
- Question #18
Which governance domain deals with evaluating how cloud computing affects compliance with internal security policies and various legal requirements, such as regulatory and legislat...
- Question #19
An important consideration when performing a remote vulnerability test of a cloud-based application is to
- Question #20
Cloud services exhibit five essential characteristics that demonstrate their relation to, and differences from, traditional computing approaches. Which one of the five characterist...
- Question #21
REST APIs are the standard for web-based services because they run over HTTPS and work well across diverse environments.
- Question #22
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
- Question #23
What is defined as the process by which an opposing party may obtain private documents for use in litigation?
- Question #24
What item below allows disparate directory services and independent security domains to be interconnected?
- Question #25
Use elastic servers when possible and move workloads to new instances.
- Question #26
To understand their compliance alignments and gaps with a cloud provider, what must cloud customers rely on?
- Question #27
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?
- Question #28
Which data security control is the LEAST likely to be assigned to an IaaS provider?
- Question #29
How does virtualized storage help avoid data loss if a drive fails?
- Question #30
What is the newer application development methodology and philosophy focused on automation of application development and deployment?
- Question #31
Sending data to a provider's storage over an API is likely as much more reliable and secure than setting up your own SFTP server on a VM in the same provider
- Question #32
Select the best definition of 'compliance' from the options below.
- Question #33
CCM: In the CCM tool, 'Encryption and Key Management' is an example of which of the following?
- Question #34
In volume storage, what method is often used to support resiliency and security?
- Question #35
What is true of security as it relates to cloud network infrastructure?
- Question #36
Which statement best describes the impact of Cloud Computing on business continuity management?
- Question #37
What is known as a code execution environment running within an operating system that shares and uses the resources of the operating system?
- Question #38
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?
- Question #39
What is true of companies considering a cloud computing business relationship?
- Question #40
Dynamic Application Security Testing (DAST) might be limited or require pre-testing permission from the provider.
- Question #41
When deploying Security as a Service in a highly regulated industry or environment, what should both parties agree on in advance and include in the SLA?
- Question #42
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?
- Question #43
Which of the following items is NOT an example of Security as a Service (SecaaS)?
- Question #44
How is encryption managed on multi-tenant storage?
- Question #45
Which statement best describes why it is important to know how data is being accessed?
- Question #46
What is resource pooling?
- Question #47
Your SLA with your cloud provider ensures continuity for all services.
- Question #48
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
- Question #49
In which type of environment is it impractical to allow the customer to conduct their own audit, making it important that the data center operators are required to provide auditing...
- Question #50
ENISA: Lock-in is ranked as a high risk in ENISA research, a key underlying vulnerability causing lock in is: