
Get Latest [Jan-2022] Conduct effective penetration tests using PassTorrent CCSK
Penetration testers simulate CCSK exam PDF
What is the duration, language, and format of the Certificate of Cloud Security Knowledge (CCSK) Exam
- Format: Multiple Choice Questions
- Number of questions: 60
- Language of Exam: English, Spanish
- Time Allowed: 90 minutes
- Passing score: 80%
NEW QUESTION 90
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?
- A. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
- B. More physical control over assets and processes.
- C. None of the above.
- D. Decreased requirement for proactive management of relationship and adherence to contracts.
- E. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.
Answer: E
NEW QUESTION 91
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?
- A. Infrastructure-as-a-service (IaaS)
- B. Desktop-as-a-service (DaaS)
- C. Identity-as-a-service (IDaaS)
- D. Platform-as-a-service (PaaS)
- E. Software-as-a-service (SaaS)
Answer: D
NEW QUESTION 92
Which of the following storage types are associated with PaaS?
- A. Raw and Long-Term Storage
- B. Volume and Object
- C. Structured and Unstructured
- D. Ephemeral and Content Deliver
Answer: C
Explanation:
PaaS utilizes the following data storage types:
Structured: Information with a high degree of organisation, such that inclusion in a relational database is seam less and readily searchable by simple, straightforward search engine algorithms or other search operations.
Unstructured: Information that does not reside in a traditional row-column database.
Unstructured data files often include text and multimedia content. Examples include email messages, word processing documents, videos, photos, audio files, presentations, web pages, and many other kinds of business documents. Although these sorts of files may have an internal structure, they are still considered unstructured because the data they contain does not fit neatly in a database.
NEW QUESTION 93
An adversary uses a cloud Platform to launch a DDoS attack against XYZ company. This type of risk is termed as:
- A. Data Breaches
- B. Malicious Insider
- C. Abuse of Cloud services
- D. Account Hijacking
Answer: C
Explanation:
Malicious actors may leverage cloud computing resources to target users, Organizations or other cloud providers. Examples of misuse of cloud service-based resources include launching DDoS attacks, email spam and phishing campaigns; "mining" for digital currency; large-scale automated click fraud; brute- force compute attacks of stolen credential databases; and hosting of malicious or pirated content.
NEW QUESTION 94
Which of the following is most commonly used to program Application Programming Interface(API)?
- A. JSON
- B. HTTP
- C. SOAP
- D. REST
Answer: D
Explanation:
APIs are typically REST for cloud services, since REST is easy to implement across the Internet. REST APIs have become the standard for web-based services since they run over Hl'-P/S and thus work well across diverse environments.
Reference: CSA Security GuidelinesV.4 (reproduced here for the educational purpose)
NEW QUESTION 95
Like security and compliance. BC/DR is not a shared responsibility.
- A. True
- B. False
Answer: A
Explanation:
This is True
Like security and compliance, BC/DR is a shared responsibility. There are aspects that the cloud provider has to manage, but the cloud customer is also ultimately responsible for how they use and manage the cloud service. This is especially true when planning for outages of the cloud provider (or parts of the cloud provider's service).
Ref Reference: CSA Security GuidelinesV.4(reproduced here for the educational purpose)
NEW QUESTION 96
Private cloud model can be managed by third party who may not be part of the organization served by that private cloud.
- A. True
- B. False
Answer: A
Explanation:
This is true
This is a tricky question that you should look into carefully. Main purpose of private cloud is usage by one organization (use) but it can be managed by third party as well.
Definition: Private cloud
According to NIST, "the cloud infrastructure is provisioned for exclusive use by a single organisation comprising multiple consumers (e.g, business units). It may be owned, managed, and operated by the organisation, a third party or some combination of them, and it may exist on or off premises. "
NEW QUESTION 97
How is encryption managed on multi-tenant storage?
- A. C for data subject to the EU Data Protection Directive; B for all others
- B. The answer could be A, B, or C depending on the provider
- C. Single key for all data owners
- D. Multiple keys per data owner
- E. One key per data owner
Answer: E
NEW QUESTION 98
What is resource pooling?
- A. Placing Internet ("cloud") data centers near multiple sources of energy, such as hydroelectric dams.
- B. None of the above.
- C. Internet-based CPUs are pooled to enable multi-threading.
- D. The dedicated computing resources of each client are pooled together in a colocation facility.
- E. The provider's computing resources are pooled to serve multiple consumers.
Answer: E
NEW QUESTION 99
Who is responsible for Governance, Risk & Compliance in Software as a Service(SaaS) service model?
- A. Cloud Carrier
- B. Cloud Service Provider
- C. It's a shared responsibility between Cloud Service Provider and Cloud Customer
- D. Cloud Customer
Answer: D
Explanation:
Remember, GRC will always remain responsibility of the cloud customer in all service models
NEW QUESTION 100
Which is the set of technologies that are designed to detect conditions indicative of a security vulnerability in an application in its running state?
- A. Dynamic application security testing(DAST)
- B. Enterprise Threat Modelling
- C. STRIDE
- D. Static application security Testing(SAST)
Answer: A
Explanation:
Definitions:
SAST- Static application security testing(SAST) is a type of security testing that relies on inspecting the source code of an application. ln general, SAST involves looking at the ways the code is designed to pinpoint possible security flaws.
DAST- Dynamic application security testing(DAST) technologies are designed to detect conditions indicative of a security vulnerability in an application in its running state
NEW QUESTION 101
You, as a cloud customer, will more control on event and diagnostic data in SaaS environment than in the PaaS or IaaS environment.
- A. False
- B. True
Answer: A
Explanation:
This is false because it will be exactly opposite. ln SaaS environment, you will least amount of controls on event and diagnostic data. Your control will, in fact, increase as you for from SaaS to PaaS and eventually, in IaaS, you will have full control Event and diagnostic data (except of platform logs which is maintained by the cloud service provider).
NEW QUESTION 102
Which of the following is not one of the essential characteristics of Cloud Computing?
- A. Broad network access
- B. On-demand self service
- C. Resource Sharing
- D. Rapid elasticit
Answer: C
Explanation:
Resource sharing is not one of the key characteristics of Cloud Computing
NEW QUESTION 103
Who is responsible for infrastructure Security in Software as a Service(SaaS) service model?
- A. Cloud Customer
- B. Cloud Carrier
- C. It's a shared responsibility between Cloud Service Provider and Cloud Customer
- D. Cloud Service Provider
Answer: D
Explanation:
Cloud service Provider is responsible for infrastructure in Software as a service(SaaS) service Model
NEW QUESTION 104
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
- A. Both B and D.
- B. Practice Integration of Duties (IOD) so that everyone is able to delete the encrypted data.
- C. Maintaining customer managed key management and revoking or deleting keys from the key management system to prevent the data from being accessed again.
- D. Allowing the cloud provider to manage your keys so that they have the ability to access and delete the data from the main and back-up storage.
- E. Keep the keys stored on the client side so that they are secure and so that the users have the ability to delete their own data.
Answer: C
NEW QUESTION 105
ENISA: "VM hopping" is:
- A. Instability in VM patch management causing VM routing errors.
- B. Lack of vulnerability management standards.
- C. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.
- D. Looping within virtualized routing systems.
- E. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
Answer: C
NEW QUESTION 106
Who is responsible for infrastructure security in Infrastructure as a service(IaaS) model?
- A. Cloud Service User
- B. Cloud Service provider
- C. Shared responsibility between cloud service provider and cloud service customer
- D. Cloud Service Architect
Answer: C
Explanation:
Infrastructure security is shared responsibility between cloud service provider and cloud customer.
NEW QUESTION 107
ln order to determine critical assets and processes of the organization, it must first conduct a:
- A. Business Impact Analysis(BIA)
- B. Datacentre monitoring
- C. Host hardening
- D. Risk Assessment
Answer: A
Explanation:
This is a process known as the business impact analysis(BIA). We determine a value for every asset(usually in terms of dollars),,what it would cost the organization if we lost that asset(either temporarily or permanently), what it would cost to replace or repair that asset, and any alternate methods for dealing with that loss.
NEW QUESTION 108
Code execution environments that run within an operating system. sharing and leveraging resources of that operating system is called :
- A. Sandbox
- B. Instance
- C. Container
- D. Virtual Machine
Answer: C
Explanation:
Containers are code execution environments that run within an operating system(for now), sharing and leveraging resources of that operating system. While a VM is a full abstraction of an operating system, a container is a constrained place to run segregated processes while still utilizing the kernel and other capabilities of the base 0S. Multiple containers can run on the same virtual machine or be implemented without the use of VMs at all and run directly on hardware.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION 109
Which of the followinglS0 Standard provides Code of practice for information security controls based on IS0/IEC 27002for cloud services?
- A. ISO 27018
- B. ISO 27034
- C. ISO 27017
- D. ISO 27032
Answer: C
Explanation:
IS0 27017 provides Code of practice for information security controls based on ISO/IEC27002 for cloud services.
NEW QUESTION 110
Enterprise Risk Management is part of over all information Risk Management of the organization
- A. False
- B. True
Answer: A
Explanation:
It is False and it is other way round. Information Risk management is part of Enterprise Risk.
NEW QUESTION 111
......
Tested Material Used To CCSK Test Engine: https://freepdf.passtorrent.com/CCSK-latest-torrent.html