CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 4 of 6.
- Question #151Cloud Platform and Infrastructure Security
To increase network isolation, you should use SDN capabilities for multiple networks and cloud accounts or segments.
SDNnetwork isolationnetwork segmentationcloud security - Question #152Virtualization and Containers
Installing security software designed for physical servers onto a virtualized server can result in severe degradation in performance.
virtualization securityperformance degradationsecurity software compatibilityphysical vs virtual - Question #153Cloud Platform and Infrastructure Security
CCM: A hypothetical company called "lnfrastructure4Sure" provides Infrastructure as a Service (IaaS) to its clients. A customer wants to review Infrastructure4Sure's hypervisor sec...
hypervisor securityattack surface reductionIaaS provider controlsconfiguration hardening - Question #154Governance
CCM: What security requirements does the Identity and Access Management domain in the CCM address?
CCM domainsIdentity and Access Managementaccess controlcloud controls matrix - Question #155Cloud Computing Concepts
Which of the following cloud deployment models represents a composition of two or more clouds that remain unique identities but are bound together by standardized or proprietary te...
hybrid cloudcloud deployment modelsdata portabilityapplication portability - Question #156Cloud Data Security
What are six phases of the Data Security Lifecycle?
data security lifecyclelifecycle phasesdata managementcreate store use - Question #157Governance
Which tool is the primary tool between the cloud provider and consumer that extends governance into business partners and providers?
contractsgovernance extensioncloud provider-consumersupply chain governance - Question #158Cloud Data Security
ENISA: Because it is practically impossible to process data in encrypted form, customers should have the following expectation of cloud providers:
data encryptionplaintext exposurecloud trustcompensating controls - Question #159Cloud Data Security
Which statement best describes the options for PaaS encryption?
PaaS encryptionencryption diversityclient-side encryptiondatabase encryption - Question #160Cloud Architecture and Design
What can be implemented to help with account granularity and limit blast radius with IaaS an PaaS?
account granularityblast radiusmultiple accountsIaaS PaaS design - Question #161Cloud Platform and Infrastructure Security
Which of the following statements best defines the "authentication" component of identity, entitlement, and access management (IdEA).
authenticationidentity managementIdEAidentity assertion - Question #162Cloud Security Operations
Which of the following statements best describes the potential advantages of security as a service?
security as a servicecloud security outsourcingsecurity domain expertiseflexible security - Question #163Cloud Platform and Infrastructure Security
What is true of how the management plane is to be secured in the cloud?
management planeshared responsibilitycloud provider securityIaaS security - Question #164Cloud Incident Response
Which action is part of the containment phase of the incident response lifecycle?
incident response lifecyclecontainment phasedata loss vs availabilityincident handling - Question #165Legal, Risk, and Compliance
What is the most important reason for knowing where the cloud service provider will host the data?
data residencycompliancedata locationregulatory requirements - Question #166Cloud Computing Concepts
Which components typically comprise Infrastructure-as-a-Service (IaaS) providers?
IaaS componentshardwareAPIscloud infrastructure layers - Question #167Cloud Architecture and Design
What makes single cloud assets less resilient compared with a traditional infrastructure?
cloud resiliencevirtualization fragilitycloud vs traditionalinfrastructure reliability - Question #168Cloud Security Operations
ENISA: In Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring?
guest system monitoringIaaS responsibilitycustomer responsibilityshared responsibility model - Question #169Cloud Data Security
What are the components of an encryption system?
encryption componentskey managementencryption enginecryptography fundamentals - Question #170Cloud Incident Response
What is the main data source for detection and analysis of an incident?
incident detectionlog analysissecurity monitoringincident data sources - Question #171Cloud Data Security
Which cloud storage technology would include a content delivery network (CON), files stored in SaaS, and caching?
cloud storage typescontent delivery networkSaaS file storageapplication storage - Question #172Cloud Application Security
What is a challenge of application security in a cloud environment?
application securitycloud visibilitysecurity challengescloud environment - Question #173Cloud Computing Concepts
In which deployment model do cloud customers have a reduced ability to govern operations because the cloud provider is responsible for the management and governance of the infrastr...
public clouddeployment modelcloud governanceprovider responsibility - Question #174Governance
CCM: In the Identity & Access Management (IAM) domain, what does the number '04' in IAM-04 signify?
CCMCloud Controls MatrixIAM domaincontrol numbering - Question #175Cloud Data Security
Which of the following is NOT a method of object storage encryption?
object storageencryption methodsdata securitystorage encryption - Question #176Virtualization and Containers
Virtual appliances can become bottlenecks because they cannot fail open and must intercept all traffic.
virtual appliancesnetwork bottleneckfail opentraffic interception - Question #177Cloud Architecture and Design
In the cloud provider and consumer relationship, which entity manages the virtual or abstracted infrastructure?
virtual infrastructureshared responsibilitycloud consumerabstraction layer - Question #178Legal, Risk, and Compliance
If a provider's infrastructure is not in scope, who is responsible for building compliant applications and services?
compliance responsibilitycustomer obligationsprovider scopecloud compliance - Question #179Legal, Risk, and Compliance
ENISA: As it relates to public cloud computing, in the European Data Protection law, the customer is considered to be the:
ENISAdata controllerEuropean data protectionpublic cloud - Question #180Cloud Application Security
Immutable workloads make it faster to roll out updated versions because applications must be designed to handle individual nodes going down.
immutable workloadsapplication designdeploymentnode resilience - Question #181Cloud Security Operations
Which technique uses the management plane to detect various activities, such as file uploads or configuration changes?
event-driven securitymanagement planeactivity detectionconfiguration monitoring - Question #182Cloud Incident Response
Which phase of the incident response lifecycle includes creating and validating alerts?
incident responsedetection and analysisalert validationIR lifecycle - Question #183Cloud Platform and Infrastructure Security
ENISA: To mitigate credential compromise or theft, cloud provider can implement:
credential securityanomaly detectionENISAcloud security controls - Question #184Cloud Security Operations
Why, in the event that an enterprise seeks a new provider for Security as a Service, must they concern themselves with the problems of translating and transporting existing data an...
SecaaSproprietary loggingdata portabilityforensic integrity - Question #185Cloud Architecture and Design
In which layer is the management plane?
management planemetastructurecloud layerscloud architecture - Question #186Governance
Which security concept includes the policy, process, and internal controls comprising how an organization is run - including the structures and policies of the leadership and other...
governanceorganizational policyleadership structuresinternal controls - Question #187Legal, Risk, and Compliance
Cloud provider contract enforceability should be carefully considered in light of
contract enforceabilityjurisdictionforeign lawcloud contracts - Question #188Cloud Architecture and Design
The hub and spoke architecture uses internal identity providers or sources connected directly to cloud providers.
hub and spokeidentity federationidentity providerscloud IAM - Question #189Cloud Platform and Infrastructure Security
Who is responsible for the proper rights management and configuration of exposed controls in the management plane?
management planeaccess rightsconsumer responsibilityaccess control - Question #190Virtualization and Containers
How can cloud providers support a secure use of virtualization for cloud consumers?
virtualization securitysecure bootVM image integritychain of trust - Question #191Cloud Platform and Infrastructure Security
Which SDP component terminates network traffic and enforces communication policies?
SDPsoftware-defined perimetergatewaynetwork policy enforcement - Question #192Cloud Data Security
Database Activity Monitoring and File Activity Monitoring are specifically recommended for what type of data migrations into the cloud?
DAMFAMdata migrationmonitoring tools - Question #193Virtualization and Containers
Because virtual networks are software constructs, the use of multiple separate virtual networks might offer extensive compartmentalization advantages not possible on traditional ph...
virtual networkscompartmentalizationnetwork isolationsoftware-defined networking - Question #194Cloud Computing Concepts
The NIST defines cloud computing in part by describing five essential characteristics which are: broad network access, rapid elasticity, resource pooling, measured service and whic...
NISTcloud characteristicson-demand self-serviceessential characteristics - Question #195Cloud Application Security
Which security advantage considers that anything that goes into production is created by the CI/CD pipeline on approved code and configuration templates?
CI/CD pipelinestandardizationDevSecOpsapproved templates - Question #196Cloud Incident Response
Consumers of Infrastructure as a Service (IaaS) are primarily responsible for containment, eradication, and recovery from incidents.
IaaSshared responsibilityincident responsecontainment - Question #197Cloud Data Security
IaaS volume storage encryption protects from which following security risk(s)?
volume encryptionsnapshot cloningIaaS storagedata at rest - Question #198Cloud Application Security
You should disable remote access when working with immutable workloads.
immutable workloadsremote accesssecurity hardeningDevSecOps - Question #199Cloud Application Security
Which security advantage considers that CI/CD pipelines can track everything, down to individual character changes in source files tied to the person submitting the change, with th...
CI/CDchange managementaudit trailsource control - Question #200Cloud Data Security
Which of the following is NOT a phase in the Data Security Lifecycle?
data security lifecycledata phasesDSLdestroy