CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 5 of 6.
- Question #201Cloud Security Operations
What must the monitoring scope cover in addition to the deployed assets?
management planemonitoring scopecloud visibilitysecurity monitoring - Question #202Legal, Risk, and Compliance
In addition to preserving primary customer data, legal experts advise cloud providers to protect secondary information such as
metadatadata preservationlegal compliancesecondary information - Question #203Virtualization and Containers
Regardless of the technology platform, container security includes properly securing the image repository.
container securityimage repositorysecurity baselinemulti-tenant - Question #204Auditing
How can a multi-tenant data center provider readily meet the audit requirements of most customers?
multi-tenantauditregulatory standardsecurity certification - Question #205Cloud Platform and Infrastructure Security
ENISA: Which is not identified as a top security risk in ENISA research?
ENISAcloud security risksisolation failureloss of governance - Question #206Cloud Architecture and Design
Which computing model contains the protocols and mechanisms providing the interface between the infrastructure and other layers?
metastructurecloud architectureinfrastructure interfacelogical model - Question #207Legal, Risk, and Compliance
In general, the majority of laws and regulations regarding data in a network or cloud environment are designed to do what?
data protection lawpersonal dataregulatory complianceprivacy - Question #208Cloud Architecture and Design
Which of the following facilitates the underlying communications method for components within a cloud, some of which are exposed to the cloud user to manage their resources and con...
APIcloud communicationsresource managementmanagement interface - Question #209Cloud Architecture and Design
Which layer of the logical stack includes code and message queues?
applistructurelogical stackmessage queuescloud layers - Question #210Cloud Computing Concepts
Which of the following is a cloud infrastructure that is shared by several organizations and supports a specific group that has shared concerns?
community clouddeployment modelsshared infrastructuremulti-tenant - Question #211Cloud Platform and Infrastructure Security
Which plane is used by consumers to launch virtual machines or configure virtual networks?
management planevirtual machinesvirtual networkscloud control - Question #212Cloud Computing Concepts
Which of the following essential characteristics of a cloud allows customers to closely match resource consumption with demand?
rapid elasticitycloud characteristicsresource scalingNIST cloud model - Question #213Governance
Which of the following is the primary tool of governance between a cloud provider and a cloud customer which is true for both public and private cloud?
contractscloud governanceprovider-customer relationshipSLA - Question #214Legal, Risk, and Compliance
What is true of searching data across cloud environments?
e-discoverycloud data accessadministrative rightsdata search - Question #215Cloud Platform and Infrastructure Security
How does running applications on distinct virtual networks and only connecting networks as needed help?
network isolationblast radiusvirtual networksnetwork segmentation - Question #216Virtualization and Containers
How can virtual machine communications bypass network security controls?
VM communicationhypervisor networkingnetwork security bypasseast-west traffic - Question #217Virtualization and Containers
ENISA: 'VM hopping' is:
VM hoppinghypervisor attackVM escapevirtualization threats - Question #218Cloud Platform and Infrastructure Security
Which concept is a mapping of an identity, including roles, personas, and attributes, to an authorization?
entitlementidentity mappingauthorizationIAM - Question #219Cloud Computing Concepts
Which concept provides the abstraction needed for resource pools?
virtualizationresource poolingabstractioncloud infrastructure - Question #220Cloud Security Operations
Network logs from cloud providers are typically flow records, not full packet captures.
network logsflow recordspacket capturecloud monitoring - Question #221Governance
Which of the following is an underlying vulnerability related to loss of Governance?
loss of governanceasset ownershipcloud riskENISA risks - Question #222Legal, Risk, and Compliance
Which of the following defines the amount of risk that the leadership and stakeholders of an organization are willing to accept?
risk tolerancerisk appetiterisk managementorganizational risk - Question #223Cloud Security Operations
Which of the following can the cloud provider implement to mitigate credential compromise or theft?
credential theftanomaly detectioncloud provider controlsidentity security - Question #224Legal, Risk, and Compliance
Which of the following reflects the claim of an individual to have certain data deleted so that third persons can no longer trace them?
right to be forgottendata privacyGDPRdata subject rights - Question #225Legal, Risk, and Compliance
When entrusting a third party to process the data on its behalf, who remains responsible for the collection and processing of the data?
data controllerdata processordata responsibilityprivacy law - Question #226Auditing
Which of the following is a form of a compliance inheritance in which all or some of the cloud provider's infrastructure and services undergo an audit to a compliance standard?
pass-through auditcompliance inheritancecloud complianceaudit standards - Question #227Cloud Platform and Infrastructure Security
Which of the following is not a security benefit of Immutable workloads?
immutable workloadsworkload hardeningimage-based deploymentcloud security controls - Question #228Cloud Platform and Infrastructure Security
Which of the following leverages virtual network topologies to run smaller, and more isolated networks without incurring additional hardware costs?
microsegmentationvirtual networkingnetwork isolationSDN - Question #229Virtualization and Containers
Installing traditional agents designed for physical servers will not result in the same amount of efficiency and performance on a virtualized server.
virtual agentsvirtualization performancesecurity agentsVM efficiency - Question #230Virtualization and Containers
Which of the following are the primary security responsibilities of the cloud provider in compute virtualization? (Select 2)
compute virtualizationprovider responsibilitiesisolationshared responsibility - Question #231Cloud Incident Response
What should every cloud customer set up with its cloud service provider (CSP) that can be utilized in the event of an incident?
incident responsecommunication planCSP coordinationcloud incident - Question #232Auditing
Audits should be robustly designed to reflect best practice, appropriate resources, and tested protocols and standards. They should also use what type of auditors?
audit designindependent auditorsaudit best practices - Question #233Cloud Data Security
Which of the following statements is true in regards to Data Loss Prevention (DLP)?
DLPpolicy enforcementdata classificationcloud data controls - Question #234Governance
CCM: The Architectural Relevance column in the CCM indicates the applicability of the cloud security control to which of the following elements?
CCMarchitectural relevancecloud control mappingsecurity controls - Question #235Auditing
For third-party audits or attestations, what is critical for providers to publish and customers to evaluate?
third-party auditattestation scopeprovider transparencyassessment criteria - Question #236Cloud Data Security
When mapping functions to lifecycle phases, which functions are required to successfully process data?
data lifecyclelifecycle phasescreate and usedata processing - Question #237Cloud Data Security
When designing an encryption system, you should start with a threat model.
encryption designthreat modelingsecurity design principles - Question #238Cloud Computing Concepts
Which of the following is one of the five essential characteristics of cloud computing as defined by NIST?
NIST cloud definitionmeasured serviceessential characteristicscloud computing - Question #239Governance
What type of information is contained in the Cloud Security Alliance's Cloud Control Matrix?
CCMcloud security standardsregulatory requirementsCSA - Question #240Cloud Application Security
Vulnerability assessments cannot be easily integrated into CI/CD pipelines because of provider restrictions.
vulnerability assessmentCI/CD pipelineDevSecOpscloud security testing - Question #241Cloud Data Security
How can key management be leveraged to prevent cloud providers from inappropriately accessing customer data?
key managementkey segregationprovider access controldata encryption - Question #242Cloud Platform and Infrastructure Security
Which of the following WAN virtualization technology is used to create networks which span multiple base networks?
cloud overlay networksWAN virtualizationnetwork spanningvirtual networking - Question #243Cloud Platform and Infrastructure Security
The most fundamental security control for any multitenant network is?
multitenant networknetwork segregationtraffic isolationnetwork security - Question #244Cloud Security Operations
What must the monitoring scope cover in addition to the deployed assets?
monitoring scopemanagement planecloud monitoringsecurity operations - Question #245Cloud Incident Response
Resource pooling practiced by the cloud services may especially complicate which part of the IR process?
incident responseforensicsresource poolingmulti-tenancy - Question #246Cloud Application Security
In which of the five main phases of secure application design and development, you perform Threat Modelling?
secure SDLCthreat modelingdesign phaseapplication security - Question #247Cloud Security Operations
Which of the following will not help to detect actual migrations, monitor cloud usage, and any data transfers to the cloud?
CASBcloud usage monitoringshadow IT detectiondata transfer monitoring - Question #248Cloud Data Security
Which of the following should be the main consideration for key management?
key managementavailabilityaccess controlsecurity considerations - Question #249Cloud Platform and Infrastructure Security
Identity brokers handle federating between identity providers and relying parties
identity federationidentity brokeridentity providerrelying party - Question #250Cloud Platform and Infrastructure Security
Which of the following is a preferred model for cloud-based access management?
attribute-based access controlABACcloud IAMaccess management