CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 2 of 6.
- Question #51
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
- Question #52
ENISA: A reason for risk concerns of a cloud provider being acquired is:
- Question #53
Which communication methods within a cloud environment must be exposed for partners or consumers to access database information using a web application?
- Question #54
A cloud deployment of two or more unique clouds is known as:
- Question #55
ENISA: Which is not one of the five key legal issues common across all scenarios:
- Question #56
ENISA: An example high risk role for malicious insiders within a Cloud Provider includes
- Question #57
What are the primary security responsibilities of the cloud provider in the management infrastructure?
- Question #58
What is true of a workload?
- Question #59
ENISA: Which is a potential security benefit of cloud computing?
- Question #60
The Software Defined Perimeter (SDP) includes which components?
- Question #61
A security failure at the root network of a cloud provider will not compromise the security of all customers because of multitenancy configuration.
- Question #62
When investigating an incident in an Infrastructure as a Service (IaaS) environment, what can the user investigate on their own?
- Question #63
If in certain litigations and investigations, the actual cloud application or environment itself is relevant to resolving the dispute in the litigation or investigation, how is the...
- Question #64
The containment phase of the incident response lifecycle requires taking systems offline.
- Question #65
What are the primary security responsibilities of the cloud provider in compute virtualizations?
- Question #66
CCM: A company wants to use the IaaS offering of some CSP. Which of the following options for using CCM is NOT suitable for the company as a cloud customer?
- Question #67
If the management plane has been breached, you should confirm the templates/configurations for your infrastructure or applications have not also been compromised.
- Question #68
CCM: A hypothetical start-up company called "ABC" provides a cloud based IT management solution. They are growing rapidly and therefore need to put controls in place in order to ma...
- Question #69
Containers are highly portable code execution environments.
- Question #70
Which statement best describes the Data Security Lifecycle?
- Question #71
Which of the following encryption methods would be utilized when object storage is used as the back-end for an application?
- Question #72
In the Software-as-a-service relationship, who is responsible for the majority of the security?
- Question #73
What method can be utilized along with data fragmentation to enhance security?
- Question #74
Which of the following statements best defines the "authorization" as a component of identity, entitlement, and access management?
- Question #75
How can web security as a service be deployed for a cloud consumer?
- Question #76
When configured properly, logs can track every code, infrastructure, and configuration change and connect it back to the submitter and approver, including the test results.
- Question #77
What of the following is NOT an essential characteristic of cloud computing?
- Question #78
Without virtualization, there is no cloud.
- Question #79
All assets require the same continuity in the cloud.
- Question #80
Which type of application security testing tests running applications and includes tests such as web vulnerability testing and fuzzing?
- Question #81
CCM: The Cloud Service Delivery Model Applicability column in the CCM indicates the applicability of the cloud security control to which of the following elements?
- Question #82
Any given processor and memory will nearly always be running multiple workloads, often from different tenants.
- Question #83
In which deployment model should the governance strategy consider the minimum common set of controls comprised of the Cloud Service Provider contract and the organization's interna...
- Question #84
What is known as the interface used to connect with the metastructure and configure the cloud environment?
- Question #85
What does it mean if the system or environment is built automatically from a template?
- Question #86
Which type of application security testing involves manual activity that is not necessarily integrated into automated testing?
- Question #87
Which meta-phase does the Cloud Security Alliance use to focus on the security and testing activities when moving code from an isolated development environment to production?
- Question #88
Even with immutable infrastructures, the production environment, should be actively monitored for changes and deviations from approved baselines.
- Question #89
Highly regulated industries such as finance and health care should consider the impact of cloud providers operating in diverse geographic locations and ______________.
- Question #90
The key concern of data location is:
- Question #91
ENISA: Licensing Risks refer to:
- Question #92
Which architecture for hybrid cloud connectivity allows you to connect multiple, different cloud networks to a data center using a single hybrid connection?
- Question #93
CCM: Which of the following statement about CSA's CCM and Security Guidance is False?
- Question #94
What are the barriers to developing full confidence in security as a service (SecaaS)?
- Question #95
Of the choices below which option allows for the most interoperability in security authentication in a cloud environment?
- Question #96
The key concern of data backup and recovery schemes is:
- Question #97
Which regulation affects data controllers with business in Japan?
- Question #98
Which component is a key part of software container systems?
- Question #99
CCM: What is the role of the Scope Applicability column in the CCM?
- Question #100
When considering business continuity and disaster recovery with a cloud provider, which layer of the logical stack includes code and message queues?