CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 4 of 6.
- Question #151
To increase network isolation, you should use SDN capabilities for multiple networks and cloud accounts or segments.
- Question #152
Installing security software designed for physical servers onto a virtualized server can result in severe degradation in performance.
- Question #153
CCM: A hypothetical company called "lnfrastructure4Sure" provides Infrastructure as a Service (IaaS) to its clients. A customer wants to review Infrastructure4Sure's hypervisor sec...
- Question #154
CCM: What security requirements does the Identity and Access Management domain in the CCM address?
- Question #155
Which of the following cloud deployment models represents a composition of two or more clouds that remain unique identities but are bound together by standardized or proprietary te...
- Question #156
What are six phases of the Data Security Lifecycle?
- Question #157
Which tool is the primary tool between the cloud provider and consumer that extends governance into business partners and providers?
- Question #158
ENISA: Because it is practically impossible to process data in encrypted form, customers should have the following expectation of cloud providers:
- Question #159
Which statement best describes the options for PaaS encryption?
- Question #160
What can be implemented to help with account granularity and limit blast radius with IaaS an PaaS?
- Question #161
Which of the following statements best defines the "authentication" component of identity, entitlement, and access management (IdEA).
- Question #162
Which of the following statements best describes the potential advantages of security as a service?
- Question #163
What is true of how the management plane is to be secured in the cloud?
- Question #164
Which action is part of the containment phase of the incident response lifecycle?
- Question #165
What is the most important reason for knowing where the cloud service provider will host the data?
- Question #166
Which components typically comprise Infrastructure-as-a-Service (IaaS) providers?
- Question #167
What makes single cloud assets less resilient compared with a traditional infrastructure?
- Question #168
ENISA: In Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring?
- Question #169
What are the components of an encryption system?
- Question #170
What is the main data source for detection and analysis of an incident?
- Question #171
Which cloud storage technology would include a content delivery network (CON), files stored in SaaS, and caching?
- Question #172
What is a challenge of application security in a cloud environment?
- Question #173
In which deployment model do cloud customers have a reduced ability to govern operations because the cloud provider is responsible for the management and governance of the infrastr...
- Question #174
CCM: In the Identity & Access Management (IAM) domain, what does the number '04' in IAM-04 signify?
- Question #175
Which of the following is NOT a method of object storage encryption?
- Question #176
Virtual appliances can become bottlenecks because they cannot fail open and must intercept all traffic.
- Question #177
In the cloud provider and consumer relationship, which entity manages the virtual or abstracted infrastructure?
- Question #178
If a provider's infrastructure is not in scope, who is responsible for building compliant applications and services?
- Question #179
ENISA: As it relates to public cloud computing, in the European Data Protection law, the customer is considered to be the:
- Question #180
Immutable workloads make it faster to roll out updated versions because applications must be designed to handle individual nodes going down.
- Question #181
Which technique uses the management plane to detect various activities, such as file uploads or configuration changes?
- Question #182
Which phase of the incident response lifecycle includes creating and validating alerts?
- Question #183
ENISA: To mitigate credential compromise or theft, cloud provider can implement:
- Question #184
Why, in the event that an enterprise seeks a new provider for Security as a Service, must they concern themselves with the problems of translating and transporting existing data an...
- Question #185
In which layer is the management plane?
- Question #186
Which security concept includes the policy, process, and internal controls comprising how an organization is run - including the structures and policies of the leadership and other...
- Question #187
Cloud provider contract enforceability should be carefully considered in light of
- Question #188
The hub and spoke architecture uses internal identity providers or sources connected directly to cloud providers.
- Question #189
Who is responsible for the proper rights management and configuration of exposed controls in the management plane?
- Question #190
How can cloud providers support a secure use of virtualization for cloud consumers?
- Question #191
Which SDP component terminates network traffic and enforces communication policies?
- Question #192
Database Activity Monitoring and File Activity Monitoring are specifically recommended for what type of data migrations into the cloud?
- Question #193
Because virtual networks are software constructs, the use of multiple separate virtual networks might offer extensive compartmentalization advantages not possible on traditional ph...
- Question #194
The NIST defines cloud computing in part by describing five essential characteristics which are: broad network access, rapid elasticity, resource pooling, measured service and whic...
- Question #195
Which security advantage considers that anything that goes into production is created by the CI/CD pipeline on approved code and configuration templates?
- Question #196
Consumers of Infrastructure as a Service (IaaS) are primarily responsible for containment, eradication, and recovery from incidents.
- Question #197
IaaS volume storage encryption protects from which following security risk(s)?
- Question #198
You should disable remote access when working with immutable workloads.
- Question #199
Which security advantage considers that CI/CD pipelines can track everything, down to individual character changes in source files tied to the person submitting the change, with th...
- Question #200
Which of the following is NOT a phase in the Data Security Lifecycle?