CCSK Exam Questions
257 real CCSK exam questions with expert-verified answers and explanations. Page 5 of 6.
- Question #201
What must the monitoring scope cover in addition to the deployed assets?
- Question #202
In addition to preserving primary customer data, legal experts advise cloud providers to protect secondary information such as
- Question #203
Regardless of the technology platform, container security includes properly securing the image repository.
- Question #204
How can a multi-tenant data center provider readily meet the audit requirements of most customers?
- Question #205
ENISA: Which is not identified as a top security risk in ENISA research?
- Question #206
Which computing model contains the protocols and mechanisms providing the interface between the infrastructure and other layers?
- Question #207
In general, the majority of laws and regulations regarding data in a network or cloud environment are designed to do what?
- Question #208
Which of the following facilitates the underlying communications method for components within a cloud, some of which are exposed to the cloud user to manage their resources and con...
- Question #209
Which layer of the logical stack includes code and message queues?
- Question #210
Which of the following is a cloud infrastructure that is shared by several organizations and supports a specific group that has shared concerns?
- Question #211
Which plane is used by consumers to launch virtual machines or configure virtual networks?
- Question #212
Which of the following essential characteristics of a cloud allows customers to closely match resource consumption with demand?
- Question #213
Which of the following is the primary tool of governance between a cloud provider and a cloud customer which is true for both public and private cloud?
- Question #214
What is true of searching data across cloud environments?
- Question #215
How does running applications on distinct virtual networks and only connecting networks as needed help?
- Question #216
How can virtual machine communications bypass network security controls?
- Question #217
ENISA: 'VM hopping' is:
- Question #218
Which concept is a mapping of an identity, including roles, personas, and attributes, to an authorization?
- Question #219
Which concept provides the abstraction needed for resource pools?
- Question #220
Network logs from cloud providers are typically flow records, not full packet captures.
- Question #221
Which of the following is an underlying vulnerability related to loss of Governance?
- Question #222
Which of the following defines the amount of risk that the leadership and stakeholders of an organization are willing to accept?
- Question #223
Which of the following can the cloud provider implement to mitigate credential compromise or theft?
- Question #224
Which of the following reflects the claim of an individual to have certain data deleted so that third persons can no longer trace them?
- Question #225
When entrusting a third party to process the data on its behalf, who remains responsible for the collection and processing of the data?
- Question #226
Which of the following is a form of a compliance inheritance in which all or some of the cloud provider's infrastructure and services undergo an audit to a compliance standard?
- Question #227
Which of the following is not a security benefit of Immutable workloads?
- Question #228
Which of the following leverages virtual network topologies to run smaller, and more isolated networks without incurring additional hardware costs?
- Question #229
Installing traditional agents designed for physical servers will not result in the same amount of efficiency and performance on a virtualized server.
- Question #230
Which of the following are the primary security responsibilities of the cloud provider in compute virtualization? (Select 2)
- Question #231
What should every cloud customer set up with its cloud service provider (CSP) that can be utilized in the event of an incident?
- Question #232
Audits should be robustly designed to reflect best practice, appropriate resources, and tested protocols and standards. They should also use what type of auditors?
- Question #233
Which of the following statements is true in regards to Data Loss Prevention (DLP)?
- Question #234
CCM: The Architectural Relevance column in the CCM indicates the applicability of the cloud security control to which of the following elements?
- Question #235
For third-party audits or attestations, what is critical for providers to publish and customers to evaluate?
- Question #236
When mapping functions to lifecycle phases, which functions are required to successfully process data?
- Question #237
When designing an encryption system, you should start with a threat model.
- Question #238
Which of the following is one of the five essential characteristics of cloud computing as defined by NIST?
- Question #239
What type of information is contained in the Cloud Security Alliance's Cloud Control Matrix?
- Question #240
Vulnerability assessments cannot be easily integrated into CI/CD pipelines because of provider restrictions.
- Question #241
How can key management be leveraged to prevent cloud providers from inappropriately accessing customer data?
- Question #242
Which of the following WAN virtualization technology is used to create networks which span multiple base networks?
- Question #243
The most fundamental security control for any multitenant network is?
- Question #244
What must the monitoring scope cover in addition to the deployed assets?
- Question #245
Resource pooling practiced by the cloud services may especially complicate which part of the IR process?
- Question #246
In which of the five main phases of secure application design and development, you perform Threat Modelling?
- Question #247
Which of the following will not help to detect actual migrations, monitor cloud usage, and any data transfers to the cloud?
- Question #248
Which of the following should be the main consideration for key management?
- Question #249
Identity brokers handle federating between identity providers and relying parties
- Question #250
Which of the following is a preferred model for cloud-based access management?