Authentic CCSK Dumps With 100% Passing Rate Practice Tests Dumps [Q51-Q75]

Share

Authentic CCSK Dumps With 100% Passing Rate Practice Tests Dumps

Cloud Security Alliance CCSK Real Exam Questions Guaranteed Updated Dump from PracticeVCE

NEW QUESTION # 51
Which of the following is NOT one of the vulnerabilities that can lead of risk of "abuse of high privilege roles" or "Cloud provider malicious insider''?

  • A. System and 0S vulnerabilities
  • B. Lack of data centre hardware redundancy
  • C. Poor enforcement of role definitions
  • D. AAA Vulnerabilities

Answer: B

Explanation:
Redundancy has nothing to do with abuse of high privilege roles. All others can lead to risk of risk of
"abuse of high privilege roles" or "Cloud provider malicious insider"


NEW QUESTION # 52
Amount of risk that the leadership and stakeholders of an organization are willing to accept. is known as:

  • A. Risk Limitation
  • B. Residual Risk
  • C. Risk Avoidance
  • D. Risk Tolerance

Answer: D

Explanation:
Risk tolerance is the amount of risk that the leadership and stakeholders of an organization are willing to accept.


NEW QUESTION # 53
Which of the following storage types are associated with PaaS?

  • A. Volume and Object
  • B. Raw and Long-Term Storage
  • C. Structured and Unstructured
  • D. Ephemeral and Content Deliver

Answer: C

Explanation:
PaaS utilizes the following data storage types:
Structured: Information with a high degree of organisation, such that inclusion in a relational database is seam less and readily searchable by simple, straightforward search engine algorithms or other search operations.
Unstructured: Information that does not reside in a traditional row-column database.
Unstructured data files often include text and multimedia content. Examples include email messages, word processing documents, videos, photos, audio files, presentations, web pages, and many other kinds of business documents. Although these sorts of files may have an internal structure, they are still considered unstructured because the data they contain does not fit neatly in a database.


NEW QUESTION # 54
Which statement best describes the Data Security Lifecycle?

  • A. The Data Security Lifecycle has five stages, can be non-linear, and is distinct in that data must always pass through all phases.
  • B. The Data Security Lifecycle has six stages, can be non-linear, and varies in that some data may never pass through all stages.
  • C. The Data Security Lifecycle has six stages, can be non-linear, and is distinct in that data must always pass through all phases.
  • D. The Data Security Lifecycle has six stages, is strictly linear, and never varies.
  • E. The Data Security Lifecycle has five stages, is circular, and varies in that some data may never pass through all stages.

Answer: B


NEW QUESTION # 55
Which of the following is NOT key Cloud computing characteristics?

  • A. Metered servicing
  • B. On Demand self service
  • C. Metered pricing
  • D. Broad Network Access

Answer: A

Explanation:
Often, this type of questions looks simple, but a confusion is created and you need to be careful while picking up the right options ln our case, metered pricing and metered servicing looks similar but Metered pricing is one of the characteristics of cloud computing.


NEW QUESTION # 56
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?

  • A. Chaos Engineering
  • B. Organized Downtime
  • C. Expected Engineering
  • D. Planned Outages
  • E. Resiliency Planning

Answer: A


NEW QUESTION # 57
What defines easiness to move and reuse application components regardless of the provider, platform,
0S, infrastructure, location, storage, format of data or APIs, how well applications work together, and how well new applications work with other solutions present in the business, organization, or provider's existing architecture?

  • A. Elasticity
  • B. Scalability
  • C. Interoperability
  • D. Portability

Answer: C

Explanation:
Interoperability is an important characteristic.
Definition: Interoperability
Interoperability is the ability of a system or a product to work with other systems or products without special effort on the part of the customer.


NEW QUESTION # 58
Any given processor and memory will nearly always be running multiple workloads, often from different tenants.

  • A. True
  • B. False

Answer: A


NEW QUESTION # 59
In the cloud provider and consumer relationship, which entity
manages the virtual or abstracted infrastructure?

  • A. Only the cloud provider
  • B. It is determined in the agreement between the entities
  • C. Both the cloud provider and consumer
  • D. Only the cloud consumer
  • E. It is outsourced as per the entity agreement

Answer: C


NEW QUESTION # 60
ENISA: "VM hopping" is:

  • A. Looping within virtualized routing systems.
  • B. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
  • C. Lack of vulnerability management standards.
  • D. Instability in VM patch management causing VM routing errors.
  • E. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.

Answer: E


NEW QUESTION # 61
Which of the following is NOT a characteristic of cloud computing?

  • A. Reduced personnel cost
  • B. Resource Pooling
  • C. On-demand self service
  • D. Metered service

Answer: A

Explanation:
The characteristics of cloud computing are
1. 0n-demand self-service: A consumer can unilaterally provision computing capabilities, such as server time and network storage, as needed automatically without requiring human interaction with each service provider.
2. Broad network access: Capabilities are available over the network and accessed through standard mechanisms that promote use by heterogeneous thin or thick client platforms(e.g, mobile phones, tablets, laptops and workstations).
3. Resource pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources dynamically assigned and reassigned according to consumer demand. There is a sense of location independence in that the customer generally has no control or knowledge over the exact location of the provided resources but may be able to specify location at a higher level of abstraction(e.g, country, state or datacenter).
Examples of resources include storage, processing, memory and network bandwidth.
4. Rapid elasticity: Capabilities can be elastically provisioned and released, in some cases automatically, to scale rapidly outward and inward commensurate with demand. To the consumer, the capabilities available for provisioning often appear to be unlimited and can be appropriated in any quantity at anytime.
5. Measured service: Cloud systems automatically control and optimize resource use by leveraging a metering capability at some level of abstraction appropriate to the type of service(e.g, storage, processing, bandwidth and active user accounts).
Resource usage can be monitored, controlled and reported, providing transparency for the provider and consumer.


NEW QUESTION # 62
If there are gaps in network logging data, what can you do?

  • A. Nothing. There are simply limitations around the data that can be logged in the cloud.
  • B. Ask the cloud provider to open more ports.
  • C. Nothing. The cloud provider must make the information available.
  • D. You can instrument the technology stack with your own logging.
  • E. Ask the cloud provider to close more ports.

Answer: D


NEW QUESTION # 63
Cloud Service Provider and Cloud Customer are jointly responsible for ownership of the all risks in shared responsibility model for security across all service models.

  • A. False
  • B. True

Answer: A

Explanation:
This is false. This is again a tricky question and one should be careful when answering this type of question. It is the cloud customer is who is ultimately responsible for the ownership of risk in the cloud environment. Consumer just passes some of risk management responsibilities to the cloud service provider.


NEW QUESTION # 64
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07 - Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework

  • A. Governing and Risk Metrics
  • B. Governance and Risk Management
  • C. Governance and Retention Management

Answer: B

Explanation:
Explanation/Reference:


NEW QUESTION # 65
Exploitable bugs in programs that attackers can use to infiltrate a computer system for the purpose of stealing data, taking control of the system or disrupting service operations, are called:

  • A. Threat Agents
  • B. Honepots
  • C. Vulnerbilities
  • D. Threats

Answer: C


NEW QUESTION # 66
Which is the set of technologies that are designed to detect conditions indicative of a security vulnerability in an application in its running state?

  • A. STRIDE
  • B. Dynamic application security testing(DAST)
  • C. Enterprise Threat Modelling
  • D. Static application security Testing(SAST)

Answer: B

Explanation:
Definitions:
SAST- Static application security testing(SAST) is a type of security testing that relies on inspecting the source code of an application. ln general, SAST involves looking at the ways the code is designed to pinpoint possible security flaws.
DAST- Dynamic application security testing(DAST) technologies are designed to detect conditions indicative of a security vulnerability in an application in its running state


NEW QUESTION # 67
Which one of the following is an example of misuse or abuse of cloud services?

  • A. Account Hijacking
  • B. Honeypot
  • C. DDoS Attack
  • D. XSS attacks

Answer: C

Explanation:
Public cloud platform can be used to launch DDoS attack on other platforms.
Please note here and understand the meaning of phrase "abuse or misuse of cloud Services" This phrase means to launch attacks or campaign by using cloud as a platform. mostly. public cloud.


NEW QUESTION # 68
As with security. compliance in the cloud is a shared responsibility model.

  • A. True
  • B. False

Answer: A

Explanation:
As with security. compliance in the cloud is a shared responsibility model. Both the cloud provider and customer have responsibilities. But the customer is always ultimately responsible for their own compliance. These responsibilities are defined through contracts, audits/assessments. and specifics of the compliance requirements.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)


NEW QUESTION # 69
Which concept provides the abstraction needed for resource pools?

  • A. Metastructure
  • B. Applistructure
  • C. Hypervisor
  • D. Virtualization
  • E. Orchestration

Answer: D


NEW QUESTION # 70
In the Software-as-a-service relationship, who is responsible for the majority of the security?

  • A. Application Consumer
  • B. Application Developer
  • C. Database Manager
  • D. Web Application CISO
  • E. Cloud Provider

Answer: E


NEW QUESTION # 71
A unit of processing, which can be in a virtual machine, a container, or other abstraction and always run somewhere on a processor and consume memory is called:

  • A. Host
  • B. Device
  • C. Controller
  • D. Workload

Answer: D

Explanation:
A workload is a unit of processing, which can be in a virtual machine, a container, or other abstraction.
Workloads always run somewhere on a processor and consume memory. Workloads include a very diverse range of processing tasks, which range from traditional applications running in a virtual machine on a standard operating system, to GPU- or FPGA-based specialized tasks Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)


NEW QUESTION # 72
Credentials and cryptographic keys must not be embedded in source code or distributed in public facing repositories such as GitHub.

  • A. True
  • B. False

Answer: A

Explanation:
This is true. Credentials and cryptographic keys must not be embedded in source code or distributed in public facing repositories such as GitHub, because there is a significant chance of discovery and misuse.
Keys need to be appropriately secured and a well- secured public key infrastructure (PKI) is needed to ensure key-management activities are carried out.


NEW QUESTION # 73
Which of the following decouples the network control plane from the data plane and allows to abstract networking from the tradition a limitations of a LAN?

  • A. Converged Networking
  • B. VLANS
  • C. Traditional Networking
  • D. Software defined networking

Answer: D

Explanation:
Software Defined Networking(SDN):A more complete abstraction layer on top of networking hardware, SDNs decouple the network control plane from the data plane(you can read more on SDN principles at this Wikipedia entry).This allows us to abstract networking from the traditional limitations of a LAN.
Reference: CSA Security Guidelines V4.0


NEW QUESTION # 74
ln which service model. does cloud security provider has least responsibility?

  • A. PaaS
  • B. SaaS
  • C. IaaS
  • D. XaaS

Answer: C

Explanation:
In IaaS service model. CSP is responsible only for the physical infrastructure.


NEW QUESTION # 75
......

Verified Pass CCSK Exam in First Attempt Guaranteed: https://vce4exams.practicevce.com/Cloud-Security-Alliance/CCSK-practice-exam-dumps.html