Online Questions - Valid Practice To your CCSP Exam (Updated 830 Questions) [Q165-Q186]

Share

Online Questions - Valid Practice To your CCSP Exam (Updated 830 Questions)

Practice To CCSP - Remarkable Practice On your Certified Cloud Security Professional Exam

NEW QUESTION 165
In a cloud environment, encryption should be used for all the following, except:

  • A. Near-term storage of virtualized images
  • B. Profile formatting
  • C. Long-term storage of data
  • D. Secure sessions/VPN

Answer: B

Explanation:
Explanation/Reference:
Explanation:
All of these activities should incorporate encryption, except for profile formatting, which is a made-up term.

 

NEW QUESTION 166
What is the intellectual property protection for a confidential recipe for muffins?

  • A. Trade secret
  • B. Trademark
  • C. Copyright
  • D. Patent

Answer: A

Explanation:
Confidential recipes unique to the organization are trade secrets. The other answers listed are answers to other questions.

 

NEW QUESTION 167
You are the security manager for a small application development company. Your company is considering the use of the cloud for software testing purposes. Which cloud service model is most likely to suit your needs?

  • A. SaaS
  • B. IaaS
  • C. LaaS
  • D. PaaS

Answer: D

 

NEW QUESTION 168
Unlike SOC Type 1 reports, which are based on a specific point in time, SOC Type 2 reports are done over a period of time. What is the minimum span of time for a SOC Type 2 report?

  • A. Six months
  • B. One month
  • C. One week
  • D. One year

Answer: A

Explanation:
Explanation
SOC Type 2 reports are focused on the same policies and procedures, as well as their effectiveness, as SOC Type 1 reports, but are evaluated over a period of at least six consecutive months, rather than a finite point in time.

 

NEW QUESTION 169
Which of the following represents a control on the maximum amount of resources that a single customer, virtual machine, or application can consume within a cloud environment?

  • A. Share
  • B. Limit
  • C. Reservation
  • D. Provision

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Limits are put in place to enforce a maximum on the amount of memory or processing a cloud customer can use. This can be done either on a virtual machine or as a comprehensive whole for a customer, and is meant to ensure that enormous cloud resources cannot be allocated or consumed by a single host or customer to the detriment of other hosts and customers.

 

NEW QUESTION 170
At which phase of the SDLC process should security begin participating?
Response:

  • A. Requirements gathering
  • B. Requirements analysis
  • C. Testing
  • D. Design

Answer: A

 

NEW QUESTION 171
Although host-based and network-based IDSs perform similar functions and have similar capabilities, which of the following is an advantage of a network-based IDS over a host-based IDS, assuming all capabilities are equal?

  • A. Segregated from host systems
  • B. External to system patching
  • C. Scalability
  • D. Network access

Answer: A

Explanation:
Explanation
A network-based IDS has the advantage of being segregated from host systems, and as such, it would not be open to compromise in the same manner a host-based system would be. Although a network-based IDS would be external to system patching, this is not the best answer here because it is a minor concern compared to segregation due to possible host compromise. Scalability is also not the best answer because, although a network-based IDS does remove processing from the host system, it is not a primary security concern.
Network access is not a consideration because both a host-based IDS and a network-based IDS would have access to network resources.

 

NEW QUESTION 172
When an organization is considering the use of cloud services for BCDR planning and solutions, which of the following cloud concepts would be the most important?

  • A. Portability
  • B. Interoperability
  • C. Reversibility
  • D. Elasticity

Answer: A

Explanation:
Portability is the ability for a service or system to easily move among different cloud providers.
This is essential for using a cloud solution for BCDR because vendor lock-in would inhibit easily moving and setting up services in the event of a disaster, or it would necessitate a large number of configuration or component changes to implement. Interoperability, or the ability to reuse components for other services or systems, would not be an important factor for BCDR.
Reversibility, or the ability to remove all data quickly and completely from a cloud environment, would be important at the end of a disaster, but would not be important during setup and deployment. Elasticity, or the ability to resize resources to meet current demand, would be very beneficial to a BCDR situation, but not as vital as portability.

 

NEW QUESTION 173
What are the U.S. State Department controls on technology exports known as?

  • A. EAR
  • B. ITAR
  • C. DRM
  • D. EAL

Answer: B

Explanation:
ITAR is a Department of State program. Evaluation assurance levels are part of the Common Criteria standard from ISO. Digital rights management tools are used for protecting electronic processing of intellectual property.

 

NEW QUESTION 174
Which of the following roles would be responsible for managing memberships in federations and the use and integration of federated services?

  • A. Cloud service business manager
  • B. Cloud service integrator
  • C. Cloud service administrator
  • D. Inter-cloud provider

Answer: D

Explanation:
Explanation
The inter-cloud provider is responsible for peering with other cloud services and providers, as well as overseeing and managing federations and federated services. A cloud service administrator is responsible for testing, monitoring, and securing cloud services, as well as providing usage reporting and dealing with service problems. The cloud service integrator is responsible for connecting existing systems and services with a cloud. The cloud service business manager is responsible for overseeing the billing, auditing, and purchasing of cloud services.

 

NEW QUESTION 175
You are working for a cloud service provider and receive an eDiscovery order pertaining to one of your customers.
Which of the following would be the most appropriate action to take first?

  • A. Notify the customer
  • B. Escrow the encryption keys
  • C. Take a shapshot of the virtual machines
  • D. Copy the data

Answer: A

Explanation:
Explanation
When a cloud service provider receives an eDiscovery order pertaining to one of their customers, the first action they must take is to notify the customer. This allows the customer to be aware of what was received, as well as to conduct a review to determine if any challenges are necessary or warranted. Taking snapshots of virtual machines, copying data, and escrowing encryption keys are all processes involved in the actual collection of data and should not be performed until the customer has been notified of the request.

 

NEW QUESTION 176
Data labels could include all the following, except:
Response:

  • A. Multifactor authentication
  • B. Distribution limitations
  • C. Confidentiality level
  • D. Access restrictions

Answer: A

 

NEW QUESTION 177
Which of the following service categories entails the least amount of support needed on the part of the cloud customer?

  • A. DaaS
  • B. SaaS
  • C. PaaS
  • D. IaaS

Answer: B

Explanation:
Explanation
With SaaS providing a fully functioning application that is managed and maintained by the cloud provider, cloud customers incur the least amount of support responsibilities themselves of any service category.

 

NEW QUESTION 178
Which type of audit report does many cloud providers use to instill confidence in their policies, practices, and procedures to current and potential customers?

  • A. SOX
  • B. SOC 2
  • C. SOC 1
  • D. SAS-70

Answer: B

Explanation:
Explanation/Reference:
Explanation:
One approach that many cloud providers opt to take is to undergo a SOC 2 audit and make the report available to cloud customers and potential cloud customers as a way of providing security confidence without having to open their systems or sensitive information to the masses.

 

NEW QUESTION 179
To protect data on user devices in a BYOD environment, the organization should consider requiring all the following, except:

  • A. Multifactor authentication
  • B. DLP agents
  • C. Two-person integrity
  • D. Local encryption

Answer: C

Explanation:
Although all the other options are ways to harden a mobile device, two-person integrity is a concept that has nothing to do with the topic, and, if implemented, would require everyone in your organization to walk around in pairs while using their mobile devices.

 

NEW QUESTION 180
Tokenization requires at least ____ database(s).

  • A. Two
  • B. Four
  • C. Three
  • D. One

Answer: A

 

NEW QUESTION 181
Which of the cloud cross-cutting aspects relates to the requirements placed on a system or application by law, policy, or requirements from standards?

  • A. regulatory requirements
  • B. Auditability
  • C. Governance
  • D. Service-level agreements

Answer: A

Explanation:
Regulatory requirements are those imposed upon businesses and their operations either by law, regulation, policy, or standards and guidelines. These requirements are specific either to the locality in which the company or application is based or to the specific nature of the data and transactions conducted.

 

NEW QUESTION 182
Limits for resource utilization can be set at different levels within a cloud environment to ensure that no particular entity can consume a level of resources that impacts other cloud customers.
Which of the following is NOT a unit covered by limits?

  • A. Hypervisor
  • B. Cloud customer
  • C. Virtual machine
  • D. Service

Answer: A

Explanation:
Explanation
The hypervisor level, as a backend cloud infrastructure component, is not a unit where limits may be applied to control resource utilization. Limits can be placed at the service, virtual machine, and cloud customer levels within a cloud environment.

 

NEW QUESTION 183
In a cloud environment, encryption should be used for all the following, except:

  • A. Near-term storage of virtualized images
  • B. Profile formatting
  • C. Long-term storage of data
  • D. Secure sessions/VPN

Answer: B

Explanation:
Explanation
All of these activities should incorporate encryption, except for profile formatting, which is a made-up term.

 

NEW QUESTION 184
When a system needs to be exposed to the public Internet, what type of secure system would be used to perform only the desired operations?

  • A. Firewall
  • B. Bastion
  • C. Honeypot
  • D. Proxy

Answer: B

Explanation:
Explanation
A bastion is a system that is exposed to the public Internet to perform a specific function, but it is highly restricted and secured to just that function. Any nonessential services and access are removed from the bastion so that security countermeasures and monitoring can be focused just on the bastion's specific duties. A honeypot is a system designed to look like a production system to entice attackers, but it does not contain any real data. It is used for learning about types of attacks and enabling countermeasures for them. A firewall is used within a network to limit access between IP addresses and ports. A proxy server provides additional security to and rulesets for network traffic that is allowed to pass through it to a service destination.

 

NEW QUESTION 185
APIs are defined as which of the following?

  • A. A set of routines, standards, protocols, and tools for building software applications to access a web- based software application or tool
  • B. A set of routines and tools for building software applications to access web-based software applications
  • C. A set of protocols, and tools for building software applications to access a web-based software application or tool
  • D. A set of standards for building software applications to access a web-based software application or tool

Answer: A

Explanation:
Explanation/Reference:
Explanation:
All the answers are true, but B is the most complete.

 

NEW QUESTION 186
......

True CCSP Exam Extraordinary Practice For the Exam: https://www.dumpstorrent.com/CCSP-exam-dumps-torrent.html

Get 100% Passing Success With True CCSP Exam: https://drive.google.com/open?id=1ZTMeL5jhLZuHnWrX1pT9_J9xKjuewRYZ