CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 3 of 6.
- Question #101
What factor(s), if any, allows for more efficient and effective containment and recovery in a cloud environment than in a non-cloud environment.
- Question #102
What is true of cloud built-in firewalls?
- Question #103
What are the NIST defined essential characteristics of cloud computing?
- Question #104
Generally speaking, in the United States, a party is obligated to take reasonable steps to prevent the destruction or modification of data in its possession that it reasonably shou...
- Question #105
Which of the following is NOT a common storage option with Infrastructure as a Service?
- Question #106
Which part of the incident response process is greatly complicated by the resource pooling and rapid elasticity of cloud infrastructure?
- Question #107
What best describes the tradeoff of Infrastructure as a Service as compared to other cloud service models?
- Question #108
How can you monitor and filter data in a virtual network when traffic might not cross the physical network?
- Question #109
Which concept is defined as the unique expression of an entity within a given namespace?
- Question #110
What is a method used to decouple the network control plane from the data plane?
- Question #111
For cloud consumers to be able to properly configure and manage their network security, what must cloud providers do?
- Question #112
What is true of Software Defined Network firewalls?
- Question #113
Which deployment model is commonly used to describe a non-cloud data center bridged directly to a cloud provider?
- Question #114
What is a core tenant of risk management?
- Question #115
The level of attention and scrutiny paid to enterprise risk assessments should be directly related to what?
- Question #116
Why do blind spots occur in a virtualized environment, where network-based security controls may not be able to monitor certain types of traffic?
- Question #117
When associating the functions to an actor, what is used to restrict a list of possible actions dowr to allowed actions?
- Question #118
Which type of application security testing should incorporate checks on API calls to the cloud service?
- Question #119
Which facet is focused on protecting the management plane components, such as web and API servers, from attacks?
- Question #120
In a cloud environment, how can you best determine data/information security risks and potential controls?
- Question #121
What is it called when a customer's information and/or processes are compromised by the actions of another customer in a multi-tenancy environment?
- Question #122
What are the three main aspects for data security controls?
- Question #123
Which SDP component is used for authentication and authorization?
- Question #124
While the cloud consumer is responsible for implementing the security controls, the cloud provider implements the security of the workload.
- Question #125
Which of the following items is one of the major regulatory compliance problems associated with cloud environments?
- Question #126
What are major factors to building and managing a secure management plane?
- Question #127
Cloud storage will most often utilize the same types of data storage used in traditional data storage technologies.
- Question #128
Prominent recommended standards to enable federation of identity in cloud environments include:
- Question #129
How can you reduce the blast radius if an attacker compromises one system?
- Question #130
What are the three valid options for protecting data as it moves to and within the cloud?
- Question #131
To what extent does the CSA Guidance document suffice for legal advice in setting up relationships with cloud service providers?
- Question #132
ENISA: A key area of controls for cloud provider network architecture is
- Question #133
What makes the metastructure layer of cloud computing so different from traditional computing?
- Question #134
While a virtual machine is a full abstraction of an operating system, a container is a constrained place to run segregated processes while still using the kernel and other OS capab...
- Question #135
What are the main considerations for key management?
- Question #136
A key element of the "Destroy" phase of the Data Security Lifecycle is:
- Question #137
CCM: A hypothetical start-up company called "IT4Sure" provides a cloud based IT management solution. They are growing rapidly and have some security measures in place but the emplo...
- Question #138
What is a benefit of application security in a cloud environment?
- Question #139
You have a business relationship with a cloud provider for all sales management functionality. Through the APIs and SDKs, you have customized the interface and some functionality,...
- Question #140
Absent other evidence, such as tampering or hacking, documents should not be considered more or less admissible or credible because they were created or stored in the cloud.
- Question #141
What are the encryption options available for SaaS consumers?
- Question #142
When the application components communicate directly with the cloud service, the management plane and metastructure might fall within the application security scope.
- Question #143
In the case of Infrastructure as a Service (IaaS) or Platform as a Service (PaaS) the responsibility to effectively manage the security of the application running in the cloud prim...
- Question #144
At a minimum, how often should incident response testing occur?
- Question #145
CCM: A hypothetical company called "Security4Sure" provides a cloud based service to share confidential documents. The confidential documents are stored in their servers and are en...
- Question #146
ENISA: Which of the following is among the vulnerabilities contributing to a high risk ranking for Network Management?
- Question #147
When configuring SDN firewalls, after adding all assets, what is typically the first configuration you must address?
- Question #148
Identified issues, risks, and recommended remediations are included when determining compliance.
- Question #149
Which common component of big data is focused on the mechanisms used to ingest large volumes of data, often of a streaming nature?
- Question #150
Which statement best describes a data (information) dispersion fragmentation scheme?