
Free Cloud Security Alliance (CCSK) Certification Sample Questions with Online Practice Test
CCSK Certification Study Guide Pass CCSK Fast
The benefit of obtaining the Certificate of Cloud Security Knowledge (CCSK) Exam Certification
By earning this certification, candidates will enjoy the following benefits:
- In dealing with a wide range of responsibilities, from cloud governance to configuring technical security controls, learn to create a baseline of security best practices
- Increase job prospects for cloud-certified professionals by filling the skills gap
- Display their technological expertise, experience, and abilities to use controls adapted to the cloud effectively
- Prove their experience with a company that specializes in cloud research on key cloud security issues
- Other credentials such as CISA, CISSP, and CCSP are complemented
For more info read reference:
Cloud Security Alliance CCSK Foundation Exam Syllabus Topics:
| Section | Objectives |
|---|---|
| Virtualization and Containers | -Mayor Virtualizations Categories -Network -Storage -Containers |
| Incident Response | -Incident Response Lifecycle -How the Cloud Impacts IR |
| Identity, Entitlement, and Access Management | -IAM Standards for Cloud Computing -Managing Users and Identities -Authentication and Credentials -Entitlement and Access Management |
| Information Governance | -Governance Domains -Six phases of the Data Security Lifecycle and their key elements -Data Security Functions, Actors and Controls |
| Security as a Service | -Potential Benefits and Concerns of SecaaS -Major Categories of Security as a Service Offerings |
| Application Security | -Opportunities and Challenges -Secure Software Development Lifecycle -How Cloud Impacts Application Design and Architectures -The Rise and Role of DevOps |
| Cloud Computing Concepts and Architectures | -Definitions of Cloud Computing
-Cloud Security Scope, Responsibilities, and Models |
| Infrastructure Security | -Cloud Network Virtualization -Security Changes With Cloud Networking -Challenges of Virtual Appliances -SDN Security Benefits -Micro-segmentation and the Software Defined Perimeter -Hybrid Cloud Considerations -Cloud Compute and Workload Security |
| Compliance and Audit Management | -Compliance in the Cloud
-Audit Management in the Cloud
|
| Related Technologies | -Big Data -Internet of Things -Mobile -Serverless Computing |
| Data Security and Encryption | -Data Security Controls -Cloud Data Storage Types -Managing Data Migrations to the Cloud -Securing Data in the Cloud |
| Legal Issues, Contracts and Electronic Discovery | -Legal Frameworks Governing Data Protection and Privacy
-Contracts and Provider Selection
-Electronic Discovery
|
| Governance and Enterprise Risk Management | -Tools of Cloud Governance -Enterprise Risk Management in the Cloud -Effects of various Service and Deployment Models -Cloud Risk Trade-offs and Tools |
NEW QUESTION 29
IT Risk management is best described in:
- A. FIPS 140-2
- B. NIST SP800-14
- C. ISO 27017
- D. ISO 27005
Answer: D
Explanation:
IS027005 standards describes IT Risk Management process
NEW QUESTION 30
Whose responsibility is to maintain Data Loss Prevention mechanisms in SaaS(Software as a Service) model ?
- A. Cloud Service provider
- B. Cloud Carrier
- C. Cloud Access Security Broker
- D. Cloud Customer
Answer: A
Explanation:
Although clouds customer is legally responsible for data that he stores on the cloud but Cloud Service Provider has to maintain data loss prevention mechanisms
NEW QUESTION 31
Which statement best describes the impact of Cloud Computing on business continuity management?
- A. A general lack of interoperability standards means that extra focus must be placed on the security aspects of migration between Cloud providers.
- B. Customers of SaaS providers in particular need to mitigate the risks of application lock-in.
- C. Clients need to do business continuity planning due diligence in case they suddenly need to switch providers.
- D. Geographic redundancy ensures that Cloud Providers provide highly available services.
- E. The size of data sets hosted at a Cloud provider can present challenges if migration to another provider becomes necessary.
Answer: D
NEW QUESTION 32
Private cloud model can be managed by third party who may not be part of the organization served by that private cloud.
- A. True
- B. False
Answer: A
Explanation:
This is true
This is a tricky question that you should look into carefully. Main purpose of private cloud is usage by one organization (use) but it can be managed by third party as well.
Definition: Private cloud
According to NIST, "the cloud infrastructure is provisioned for exclusive use by a single organisation comprising multiple consumers (e.g, business units). It may be owned, managed, and operated by the organisation, a third party or some combination of them, and it may exist on or off premises. "
NEW QUESTION 33
Sending data to a provider's storage over an API is likely as much more reliable and secure than setting up your own SFTP server on a VM in the same provider
- A. True
- B. False
Answer: A
NEW QUESTION 34
Exploitable bugs in programs that attackers can use to infiltrate a computer system for the purpose of stealing data, taking control of the system or disrupting service operations, are called:
- A. Threat Agents
- B. Honepots
- C. Threats
- D. Vulnerbilities
Answer: D
Explanation:
It's a definition of System Vulnerability.
NEW QUESTION 35
You, as a cloud customer, will more control on event and diagnostic data in SaaS environment than in the PaaS or IaaS environment.
- A. True
- B. False
Answer: B
Explanation:
This is false because it will be exactly opposite. ln SaaS environment, you will least amount of controls on event and diagnostic data. Your control will, in fact, increase as you for from SaaS to PaaS and eventually, in IaaS, you will have full control Event and diagnostic data (except of platform logs which is maintained by the cloud service provider).
NEW QUESTION 36
The most pragmatic option for data disposal in the cloud is which of the following?
- A. Melting
- B. Cold fusion
- C. Overwriting
- D. Crypto shredding
Answer: D
NEW QUESTION 37
Containers can be implemented without the use of VMs at all and run directly on hardware.
- A. True
- B. False
Answer: A
Explanation:
Multiple containers can run on the same virtual machine or be implemented without the use of VMs at all and run directly on hardware. The container provides code running inside a restricted environment with only access to the processes and capabilities defined in the container configuration. This allows containers to launch incredibly rapidly. since they don't need to boot an operating system or launch many(sometimes any) new services; the container only needs access to already-running services in the host 0S and some can launch in milliseconds.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION 38
Which of the following storages is typically used for swap files and other temporary storage needs and is terminated with its instance?
- A. Content Deliver
- B. Ephemeral Storage
- C. Raw Storage
- D. Object based Storage
Answer: B
Explanation:
Ephemeral storage: This type of storage is relevant for SaaS instances and exists only as long as its instance is up. It is typically used for swap files and other temporary storage needs and is terminated with its instance.
NEW QUESTION 39
Which of the following can lead to vendor lock-in?
- A. Lack of transparency in terms of use
- B. Big Data sets
- C. CSP's vendor utilisation
- D. Large supplier Redundancy
Answer: A
Explanation:
Lack of transparency in terms of use can lead to vendor lock-in. Contracts and SLAs should clearly define the relationship between Cloud Service Provider(CSP)and the cloud customer. Clause of data portability should be there.
NEW QUESTION 40
One of the part of STRIDE model is:
- A. Redundancy
- B. Reputation
- C. Denial of Service
- D. Security
Answer: C
Explanation:
The six components that made STRIDE are:
1. Spoofing: Attacker assumes identity of subject
2. Tampering: Data or messages altered by an attacker
3. Repudiation: illegitimate denial of an event
4. Information disclosure: Information obtained without authorization
5. Denial of service: Attacker overloads system to deny legitimate access
6. Elevation of privilege: Attacker gains a privilege level above what is permitted
NEW QUESTION 41
Which of the following is not a common cloud service model?
- A. Infrastructure as a Service
- B. Software as a Service
- C. Platform as a Service
- D. Programming as a Service
Answer: D
Explanation:
Programming as a Service is not a common offering; the others are ubiquitous through out the industry.
NEW QUESTION 42
Which governance domain deals with evaluating how cloud computing affects compliance with internal security policies and various legal requirements, such as regulatory and legislative?
- A. Compliance and Audit Management
- B. Infrastructure Security
- C. Governance and Enterprise Risk Management
- D. Information Governance
- E. Legal Issues: Contracts and Electronic Discovery
Answer: A
NEW QUESTION 43
In which cloud service model is the customer only responsible for the data?
- A. CaaS
- B. PaaS
- C. SaaS
- D. IaaS
Answer: C
Explanation:
SaaS is the model in which the customer supplies only the data; in the other models, the customer also supplies the 0S, the application, or both.
NEW QUESTION 44
In cloud services. risks and responsibilities are shared between the cloud provider and customer.
however. which of the following holds true?
- A. Cloud Customer has ultimate legal liability for unauthorised and illicit data disclosures
- B. Cloud Provider liability is limited to financial responsibility
- C. Cloud Customer liability is limited to financial responsibility
- D. Cloud provider has ultimate legal liability for unauthorised and illicit data disclosures
Answer: A
Explanation:
In a shared responsibility model. Data security is responsibility of the cloud consumer and he is legally liable.
NEW QUESTION 45
Which of the following is most commonly used to program Application Programming Interface(API)?
- A. HTTP
- B. JSON
- C. SOAP
- D. REST
Answer: D
Explanation:
APIs are typically REST for cloud services, since REST is easy to implement across the Internet. REST APIs have become the standard for web-based services since they run over Hl'-P/S and thus work well across diverse environments.
Reference: CSA Security GuidelinesV.4 (reproduced here for the educational purpose)
NEW QUESTION 46
"Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service. " Which of the following characteristics defines this?
- A. Broad network access
- B. Rapid elasticity
- C. Resource pooling
- D. Measured service
Answer: D
Explanation:
Measured service is defined as "Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized service. "
NEW QUESTION 47
Cloud customer can do vulnerability assessment of their whole infrastructure on cloud just like they conduct vulnerbility assessment of their traditional infrastructure.
- A. True
- B. False
Answer: B
Explanation:
It is false.
Customer will have to take permission and give notification to cloud service provider.
The cloud owner (public or private) will typically require notification of assessments and place limits on the nature of assessments. This is because they may be unable to distinguish an assessment from a real attack without prior warning.
Ref: CSA Security Guidelines V4.0
NEW QUESTION 48
As with security. compliance in the cloud is a shared responsibility model.
- A. True
- B. False
Answer: A
Explanation:
As with security. compliance in the cloud is a shared responsibility model. Both the cloud provider and customer have responsibilities. But the customer is always ultimately responsible for their own compliance. These responsibilities are defined through contracts, audits/assessments. and specifics of the compliance requirements.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION 49
......
Get Perfect Results with Premium CCSK Dumps Updated 60 Questions: https://passguide.vce4dumps.com/CCSK-latest-dumps.html