CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 3 of 6.
- Question #101Cloud Incident Response
What factor(s), if any, allows for more efficient and effective containment and recovery in a cloud environment than in a non-cloud environment.
incident containmentvirtualizationcloud elasticityrecovery - Question #102Cloud Platform and Infrastructure Security
What is true of cloud built-in firewalls?
cloud firewallsvirtual firewallsSDNnetwork security - Question #103Cloud Computing Concepts
What are the NIST defined essential characteristics of cloud computing?
NIST cloud definitionessential characteristicson-demand self-servicecloud computing - Question #104Legal, Risk, and Compliance
Generally speaking, in the United States, a party is obligated to take reasonable steps to prevent the destruction or modification of data in its possession that it reasonably shou...
legal holde-discoverydata preservationlitigation - Question #105Cloud Platform and Infrastructure Security
Which of the following is NOT a common storage option with Infrastructure as a Service?
IaaS storageobject storagevolume storageCDN - Question #106Cloud Incident Response
Which part of the incident response process is greatly complicated by the resource pooling and rapid elasticity of cloud infrastructure?
digital forensicsresource poolingrapid elasticityincident response - Question #107Cloud Computing Concepts
What best describes the tradeoff of Infrastructure as a Service as compared to other cloud service models?
IaaSservice modelscost tradeoffscloud economics - Question #108Cloud Platform and Infrastructure Security
How can you monitor and filter data in a virtual network when traffic might not cross the physical network?
virtual network monitoringSDNvirtual appliancetraffic filtering - Question #109Cloud Application Security
Which concept is defined as the unique expression of an entity within a given namespace?
identityIAMnamespacedigital identity - Question #110Cloud Platform and Infrastructure Security
What is a method used to decouple the network control plane from the data plane?
SDNcontrol planedata planenetwork virtualization - Question #111Cloud Platform and Infrastructure Security
For cloud consumers to be able to properly configure and manage their network security, what must cloud providers do?
security controlsnetwork securitycloud provider responsibilitiestenant configuration - Question #112Cloud Platform and Infrastructure Security
What is true of Software Defined Network firewalls?
SDN firewallssoftware defined networkingnetwork virtualizationvirtual networks - Question #113Cloud Computing Concepts
Which deployment model is commonly used to describe a non-cloud data center bridged directly to a cloud provider?
hybrid clouddeployment modelscloud bridgingdata center - Question #114Legal, Risk, and Compliance
What is a core tenant of risk management?
risk managementrisk treatment optionsrisk transferrisk acceptance - Question #115Legal, Risk, and Compliance
The level of attention and scrutiny paid to enterprise risk assessments should be directly related to what?
enterprise risk assessmentinformation valuerisk prioritizationrisk management - Question #116Virtualization and Containers
Why do blind spots occur in a virtualized environment, where network-based security controls may not be able to monitor certain types of traffic?
virtualization blind spotseast-west trafficvirtual networkingnetwork monitoring - Question #117Cloud Security Operations
When associating the functions to an actor, what is used to restrict a list of possible actions dowr to allowed actions?
access controlsauthorizationIAMactor permissions - Question #118Cloud Application Security
Which type of application security testing should incorporate checks on API calls to the cloud service?
SASTapplication security testingAPI securitysecure SDLC - Question #119Cloud Platform and Infrastructure Security
Which facet is focused on protecting the management plane components, such as web and API servers, from attacks?
management planeperimeter securityweb server securityAPI protection - Question #120Cloud Data Security
In a cloud environment, how can you best determine data/information security risks and potential controls?
cloud storage architecturedata security riskrisk assessmentdata protection - Question #121Cloud Platform and Infrastructure Security
What is it called when a customer's information and/or processes are compromised by the actions of another customer in a multi-tenancy environment?
isolation failuremulti-tenancytenant isolationcloud security - Question #122Cloud Data Security
What are the three main aspects for data security controls?
data security controlscontrol frameworkdata protectionenforcement - Question #123Cloud Platform and Infrastructure Security
Which SDP component is used for authentication and authorization?
Software Defined PerimeterSDP controllerauthenticationzero trust - Question #124Cloud Architecture and Design
While the cloud consumer is responsible for implementing the security controls, the cloud provider implements the security of the workload.
shared responsibility modelcloud consumercloud providersecurity ownership - Question #125Legal, Risk, and Compliance
Which of the following items is one of the major regulatory compliance problems associated with cloud environments?
data residencyregulatory compliancedistributed storagecloud compliance - Question #126Cloud Platform and Infrastructure Security
What are major factors to building and managing a secure management plane?
management plane securityperimeter securityauthenticationauthorization - Question #127Cloud Computing Concepts
Cloud storage will most often utilize the same types of data storage used in traditional data storage technologies.
cloud storagetraditional storagedata storage technologiescloud architecture - Question #128Cloud Application Security
Prominent recommended standards to enable federation of identity in cloud environments include:
identity federationSAMLcloud identitySSO - Question #129Cloud Architecture and Design
How can you reduce the blast radius if an attacker compromises one system?
blast radiusnetwork segmentationvirtual networksmicro-segmentation - Question #130Cloud Data Security
What are the three valid options for protecting data as it moves to and within the cloud?
data in transitencryptionproxy-based encryptionnetwork encryption - Question #131Legal, Risk, and Compliance
To what extent does the CSA Guidance document suffice for legal advice in setting up relationships with cloud service providers?
CSA guidancelegal advicecloud compliancegovernance frameworks - Question #132Cloud Platform and Infrastructure Security
ENISA: A key area of controls for cloud provider network architecture is
VM hardeningnetwork architectureENISAcloud controls - Question #133Cloud Architecture and Design
What makes the metastructure layer of cloud computing so different from traditional computing?
metastructuremanagement planecloud layerscloud architecture - Question #134Virtualization and Containers
While a virtual machine is a full abstraction of an operating system, a container is a constrained place to run segregated processes while still using the kernel and other OS capab...
containersvirtual machineskernel abstractionOS isolation - Question #135Cloud Data Security
What are the main considerations for key management?
key managementaccessibilityperformanceencryption - Question #136Cloud Data Security
A key element of the "Destroy" phase of the Data Security Lifecycle is:
data security lifecyclecrypto-shreddingdata destructiondata management - Question #137Cloud Security Operations
CCM: A hypothetical start-up company called "IT4Sure" provides a cloud based IT management solution. They are growing rapidly and have some security measures in place but the emplo...
mobile device managementMDM policyCCMdevice protection - Question #138Cloud Application Security
What is a benefit of application security in a cloud environment?
application securityisolated environmentscloud security benefits - Question #139Cloud Computing Concepts
You have a business relationship with a cloud provider for all sales management functionality. Through the APIs and SDKs, you have customized the interface and some functionality,...
PaaScloud service modelsAPI customizationshared responsibility - Question #140Legal, Risk, and Compliance
Absent other evidence, such as tampering or hacking, documents should not be considered more or less admissible or credible because they were created or stored in the cloud.
digital evidencecloud admissibilitylegal compliancedocument integrity - Question #141Cloud Data Security
What are the encryption options available for SaaS consumers?
SaaS encryptionproxy encryptionprovider-managed encryptiondata protection - Question #142Cloud Application Security
When the application components communicate directly with the cloud service, the management plane and metastructure might fall within the application security scope.
application security scopemanagement planemetastructurecloud components - Question #143Cloud Platform and Infrastructure Security
In the case of Infrastructure as a Service (IaaS) or Platform as a Service (PaaS) the responsibility to effectively manage the security of the application running in the cloud prim...
shared responsibilityIaaSPaaScloud consumer - Question #144Cloud Incident Response
At a minimum, how often should incident response testing occur?
incident response testingtesting frequencysecurity operations - Question #145Cloud Data Security
CCM: A hypothetical company called "Security4Sure" provides a cloud based service to share confidential documents. The confidential documents are stored in their servers and are en...
encryption at restkey managementdata protectionCCM - Question #146Cloud Platform and Infrastructure Security
ENISA: Which of the following is among the vulnerabilities contributing to a high risk ranking for Network Management?
network managementENISAOS vulnerabilitiesrisk ranking - Question #147Cloud Platform and Infrastructure Security
When configuring SDN firewalls, after adding all assets, what is typically the first configuration you must address?
SDN firewallsfirewall configurationnetwork connectionssoftware-defined networking - Question #148Auditing
Identified issues, risks, and recommended remediations are included when determining compliance.
complianceaudit findingsrisk assessmentremediation - Question #149Emerging Technologies
Which common component of big data is focused on the mechanisms used to ingest large volumes of data, often of a streaming nature?
big datadistributed data collectionstreaming datadata ingestion - Question #150Cloud Data Security
Which statement best describes a data (information) dispersion fragmentation scheme?
data dispersionfragmentationdistributed storagefile splitting