CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 2 of 6.
- Question #51Cloud Data Security
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
data deletionkey managementcrypto-shreddingcloud data removal - Question #52Legal, Risk, and Compliance
ENISA: A reason for risk concerns of a cloud provider being acquired is:
cloud provider acquisitionnon-binding agreementsENISA risksvendor risk - Question #53Cloud Application Security
Which communication methods within a cloud environment must be exposed for partners or consumers to access database information using a web application?
APIweb applicationcloud communicationdata access - Question #54Cloud Computing Concepts
A cloud deployment of two or more unique clouds is known as:
hybrid cloudcloud deployment modelsmulti-cloud - Question #55Legal, Risk, and Compliance
ENISA: Which is not one of the five key legal issues common across all scenarios:
ENISAlegal issuesintellectual propertycloud legal - Question #56Cloud Security Operations
ENISA: An example high risk role for malicious insiders within a Cloud Provider includes
ENISAinsider threatmalicious insiderprivileged roles - Question #57Cloud Platform and Infrastructure Security
What are the primary security responsibilities of the cloud provider in the management infrastructure?
shared responsibilitymanagement infrastructurenetwork securitycloud provider - Question #58Cloud Computing Concepts
What is true of a workload?
workloadcloud computingunit of processing - Question #59Cloud Computing Concepts
ENISA: Which is a potential security benefit of cloud computing?
ENISAcloud security benefitssystem updatesrisk assessment - Question #60Cloud Platform and Infrastructure Security
The Software Defined Perimeter (SDP) includes which components?
Software Defined PerimeterSDPzero trustnetwork architecture - Question #61Cloud Platform and Infrastructure Security
A security failure at the root network of a cloud provider will not compromise the security of all customers because of multitenancy configuration.
multitenancynetwork securitycloud isolationshared infrastructure - Question #62Cloud Incident Response
When investigating an incident in an Infrastructure as a Service (IaaS) environment, what can the user investigate on their own?
IaaSincident investigationshared responsibilityvirtual instances - Question #63Legal, Risk, and Compliance
If in certain litigations and investigations, the actual cloud application or environment itself is relevant to resolving the dispute in the litigation or investigation, how is the...
litigationsubpoenacloud evidencelegal discovery - Question #64Cloud Incident Response
The containment phase of the incident response lifecycle requires taking systems offline.
incident responsecontainment phaseIR lifecyclecloud incident - Question #65Virtualization and Containers
What are the primary security responsibilities of the cloud provider in compute virtualizations?
compute virtualizationshared responsibilityisolationhypervisor security - Question #66Governance
CCM: A company wants to use the IaaS offering of some CSP. Which of the following options for using CCM is NOT suitable for the company as a cloud customer?
CCMCSA STARIaaScloud customer controls - Question #67Cloud Incident Response
If the management plane has been breached, you should confirm the templates/configurations for your infrastructure or applications have not also been compromised.
management planeconfiguration integrityincident responseinfrastructure compromise - Question #68Cloud Security Operations
CCM: A hypothetical start-up company called "ABC" provides a cloud based IT management solution. They are growing rapidly and therefore need to put controls in place in order to ma...
CCMchange managementconfiguration managementproduction environment - Question #69Virtualization and Containers
Containers are highly portable code execution environments.
containersportabilitycontainerization - Question #70Cloud Data Security
Which statement best describes the Data Security Lifecycle?
data security lifecycleDSLnon-linear stagescloud data management - Question #71Cloud Data Security
Which of the following encryption methods would be utilized when object storage is used as the back-end for an application?
object storageclient-side encryptionapplication encryptionencryption methods - Question #72Cloud Architecture and Design
In the Software-as-a-service relationship, who is responsible for the majority of the security?
SaaSshared responsibility modelcloud provider security - Question #73Cloud Data Security
What method can be utilized along with data fragmentation to enhance security?
data fragmentationencryptiondata security techniques - Question #74Cloud Platform and Infrastructure Security
Which of the following statements best defines the "authorization" as a component of identity, entitlement, and access management?
authorizationIAMaccess managementidentity entitlement - Question #75Cloud Application Security
How can web security as a service be deployed for a cloud consumer?
web security as a serviceproxyon-premise deploymentSECaaS - Question #76Cloud Security Operations
When configured properly, logs can track every code, infrastructure, and configuration change and connect it back to the submitter and approver, including the test results.
loggingaudit trailchange trackingconfiguration management - Question #77Cloud Computing Concepts
What of the following is NOT an essential characteristic of cloud computing?
NIST cloud characteristicsessential cloud traitscloud computing fundamentals - Question #78Virtualization and Containers
Without virtualization, there is no cloud.
virtualizationcloud computing foundationhypervisor - Question #79Cloud Architecture and Design
All assets require the same continuity in the cloud.
business continuityasset classificationcloud continuity planning - Question #80Cloud Application Security
Which type of application security testing tests running applications and includes tests such as web vulnerability testing and fuzzing?
DASTdynamic application security testingfuzzingweb vulnerability testing - Question #81Governance
CCM: The Cloud Service Delivery Model Applicability column in the CCM indicates the applicability of the cloud security control to which of the following elements?
CCMCloud Controls MatrixSaaS PaaS IaaSCSA framework - Question #82Virtualization and Containers
Any given processor and memory will nearly always be running multiple workloads, often from different tenants.
multi-tenancyworkload isolationresource poolingshared infrastructure - Question #83Governance
In which deployment model should the governance strategy consider the minimum common set of controls comprised of the Cloud Service Provider contract and the organization's interna...
hybrid cloud governanceminimum common controlsCSP contractdeployment model - Question #84Cloud Platform and Infrastructure Security
What is known as the interface used to connect with the metastructure and configure the cloud environment?
management planemetastructurecloud interfaceadministrative access - Question #85Cloud Platform and Infrastructure Security
What does it mean if the system or environment is built automatically from a template?
immutable infrastructureinfrastructure as codetemplate automationproduction changes - Question #86Cloud Application Security
Which type of application security testing involves manual activity that is not necessarily integrated into automated testing?
code reviewmanual security testingapplication security testingSDLC - Question #87Cloud Application Security
Which meta-phase does the Cloud Security Alliance use to focus on the security and testing activities when moving code from an isolated development environment to production?
CSA SDLC phasessecure deploymentDevSecOpscode promotion - Question #88Cloud Security Operations
Even with immutable infrastructures, the production environment, should be actively monitored for changes and deviations from approved baselines.
immutable infrastructurecontinuous monitoringbaseline deviationsecurity operations - Question #89Legal, Risk, and Compliance
Highly regulated industries such as finance and health care should consider the impact of cloud providers operating in diverse geographic locations and ______________.
legal jurisdictiondata residencyregulated industriesgeographic compliance - Question #90Cloud Data Security
The key concern of data location is:
data locationdata sovereigntyregulatory compliancedata residency - Question #91Legal, Risk, and Compliance
ENISA: Licensing Risks refer to:
ENISAlicensing riskcloud risk frameworksoftware licensing - Question #92Cloud Architecture and Design
Which architecture for hybrid cloud connectivity allows you to connect multiple, different cloud networks to a data center using a single hybrid connection?
hybrid cloud connectivitybastion architecturemulti-cloud networkingnetwork design - Question #93Governance
CCM: Which of the following statement about CSA's CCM and Security Guidance is False?
CSA CCMSecurity Guidancecloud controls frameworkcontrol objectives - Question #94Cloud Security Operations
What are the barriers to developing full confidence in security as a service (SecaaS)?
SecaaSmulti-tenancyvendor lock-incompliance barriers - Question #95Cloud Application Security
Of the choices below which option allows for the most interoperability in security authentication in a cloud environment?
SAMLfederationauthenticationinteroperability - Question #96Cloud Data Security
The key concern of data backup and recovery schemes is:
data backupdisaster recoverydata loss preventiondata integrity - Question #97Legal, Risk, and Compliance
Which regulation affects data controllers with business in Japan?
privacy regulationJapanAPPIdata protection law - Question #98Virtualization and Containers
Which component is a key part of software container systems?
containersexecution environmentcontainer architecturesoftware containers - Question #99Governance
CCM: What is the role of the Scope Applicability column in the CCM?
CSA CCMscope applicabilityindustry standards mappingcontrol domains - Question #100Cloud Architecture and Design
When considering business continuity and disaster recovery with a cloud provider, which layer of the logical stack includes code and message queues?
applistructurelogical stackbusiness continuitycloud layers