
[Dec 11, 2021] Valid CCSP Test Answers & CCSP Exam PDF
Valid ISC Cloud Security CCSP Dumps Ensure Your Passing
Cloud Data Security (19%):
- Implement data discovery – Here, you should show your skills in working with unstructured and structured data;
- Design & implement auditability, accountability, and traceability of data event – This module requires the individuals’ knowledge of the non-repudiation and custody chain, logging, analysis, and storage of data events, and definition of identity attribution’s event sources & requirements.
- Implement data classification – This part evaluates the knowledge of labeling, mapping, and sensitive data;
- Plan & implement data retention, deletion & archiving policies – This domain focuses on the skills related to data retention policies, legal hold, data deletion mechanisms & procedures, and data archiving mechanisms & procedures;
- Design & implement IRM (Information Rights Management) – It requires an understanding of the objectives and appropriate tools relevant to IRM;
- Explain the concepts of Cloud data – This objectives requires an understanding of the data dispersion and lifecycle phases of Cloud data;
- Design & apply the data security strategies and technologies – This topic covers an understanding of hashing, encryption & key management, tokenization, masking, data obfuscation, data loss prevention, and data de-identification;
- Design & implement the storage architectures for Cloud data – This subsection focuses on one’s knowledge of storage types, including raw disk, long-term, and ephemeral, as well as the understanding of threats to different types of storage;
NEW QUESTION 86
Which of the following is the sole responsibility of the cloud customer, regardless of which cloud model is used?
- A. Platform
- B. Application
- C. Data
- D. Infrastructure
Answer: C
Explanation:
Explanation
Regardless of which cloud-hosting model is used, the cloud customer always has sole responsibility for the data and its security.
NEW QUESTION 87
Along with humidity, temperature is crucial to a data center for optimal operations and protection of equipment.
Which of the following is the optimal temperature range as set by ASHRAE?
- A. 69.8 to 86.0 degrees Fahrenheit (21 to 30 degrees Celsius)
- B. 51.8 to 66.2 degrees Fahrenheit (11 to 19 degrees Celsius)
- C. 64.4 to 80.6 degrees Fahrenheit (18 to 27 degrees Celsius)
- D. 44.6 to 60.8 degrees Fahrenheit (7 to 16 degrees Celsius)
Answer: C
Explanation:
The American Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE) recommends 64.4 to 80.6 degrees Fahrenheit (or 18 to 27 degrees Celsius) as the optimal temperature range for data centers.
None of these options is the recommendation from ASHRAE.
NEW QUESTION 88
Data transformation in a cloud environment should be of great concern to organizations considering cloud migration because __________ could affect data classification processes/implementations.
- A. Remote access
- B. Physical distance
- C. Multitenancy
- D. Virtualization
Answer: D
NEW QUESTION 89
As part of the auditing process, getting a report on the deviations between intended configurations and actual policy is often crucial for an organization.
What term pertains to the process of generating such a report?
- A. Findings
- B. Deficiencies
- C. Gap analysis
- D. Errors
Answer: C
Explanation:
Explanation
The gap analysis determines if there are any differences between the actual configurations in use on systems and the policies that govern what the configurations are expected or mandated to be. The other terms provided are all similar to the correct answer ("findings" in particular is often used to articulate deviations in configurations), but gap analysis is the official term used.
NEW QUESTION 90
You just hired an outside developer to modernize some applications with new web services and functionality. In order to implement a comprehensive test platform for validation, the developer needs a data set that resembles a production data set in both size and composition.
In order to accomplish this, what type of masking would you use?
- A. Static
- B. Development
- C. Dynamic
- D. Replicated
Answer: A
Explanation:
Static masking takes a data set and produces a copy of it, but with sensitive data fields masked.
This allows for a full data set from production for testing purposes, but without any sensitive data.
Dynamic masking works with a live system and is not used to produce a distinct copy. The terms
"replicated" and "development" are not types of masking.
NEW QUESTION 91
What is the primary security mechanism used to protect SOAP and REST APIs?
Response:
- A. XML firewalls
- B. WAFs
- C. Firewalls
- D. Encryption
Answer: D
NEW QUESTION 92
In a cloud environment, encryption should be used for all the following, except:
- A. Near-term storage of virtualized images
- B. Secure sessions/VPN
- C. Long-term storage of data
- D. Profile formatting
Answer: D
NEW QUESTION 93
Which component of ITIL pertains to planning, coordinating, executing, and validating changes and rollouts to production environments?
- A. Problem management
- B. Availability management
- C. Change management
- D. Release management
Answer: D
Explanation:
Explanation
Release management involves planning, coordinating, executing, and validating changes and rollouts to the production environment. Change management is a higher-level component than release management and also involves stakeholder and management approval, rather than specifically focusing the actual release itself.
Availability management is focused on making sure system resources, processes, personnel, and toolsets are properly allocated and secured to meet SLA requirements. Problem management is focused on identifying and mitigating known problems and deficiencies before they occur.
NEW QUESTION 94
A DLP solution/implementation has three main components.
Which of the following is NOT one of the three main components?
- A. Monitoring
- B. Discovery and classification
- C. Auditing
- D. Enforcement
Answer: C
Explanation:
Auditing, which can be supported to varying degrees by DLP solutions, is not a core component of them.
Data loss prevention (DLP) solutions have core components of discovery and classification, enforcement, and monitoring. Discovery and classification are concerned with determining which data should be applied to the DLP policies, and then determining its classification level. Monitoring is concerned with the actual watching of data and how it's used through its various stages. Enforcement is the actual application of policies determined from the discovery stage and then triggered during the monitoring stage.
NEW QUESTION 95
Which phase of the cloud data lifecycle also typically entails the process of data classification?
Response:
- A. Store
- B. Use
- C. Archive
- D. Create
Answer: D
NEW QUESTION 96
Which of the following BCDR testing methodologies is least intrusive?
- A. Tabletop
- B. Full test
- C. Simulation
- D. Walk-through
Answer: A
NEW QUESTION 97
The European Union is often considered the world leader in regard to the privacy of personal data and has declared privacy to be a "human right." In what year did the EU first assert this principle?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: C
Explanation:
The EU passed Directive 95/46 EC in 1995, which established data privacy as a human right. The other years listed are incorrect.
NEW QUESTION 98
Which of the following is NOT a commonly used communications method within cloud environments to secure data in transit?
- A. DNSSEC
- B. VPN
- C. HTTPS
- D. IPSec
Answer: A
Explanation:
DNSSEC is used as a security extension to DNS lookup queries in order to ensure the authenticity and authoritativeness of hostname resolutions, in order to prevent spoofing and redirection of traffic. Although it is a very important concept to be employed for security practices, it is not used to secure or encrypt data transmissions. HTTPS is the most commonly used security mechanism for data communications between clients and websites and web services.
IPSec is less commonly used, but is also intended to secure communications between servers.
VPN is commonly used to secure traffic into a network area or subnet for developers and administrative users.
NEW QUESTION 99
Apart from using encryption at the file system level, what technology is the most widely used to protect data stored in an object storage system?
- A. VPN
- B. HTTPS
- C. IRM
- D. TLS
Answer: C
Explanation:
Explanation
Information rights management (IRM) technologies allow security controls and policies to be enforced on a data object regardless of where it resides. They also allow for extended controls such as expirations and copying restrictions, which are not available through traditional control mechanisms. Hypertext Transfer Protocol Secure (HTTPS), virtual private network (VPN), and Transport Layer Security (TLS) are all technologies and protocols that are widely used with cloud implementations for secure access to systems and services and likely will be used in conjunction with other object data protection strategies.
NEW QUESTION 100
Which of the following threat types involves an application developer leaving references to internal information and configurations in code that is exposed to the client?
- A. Unvalidated redirect and forwards
- B. Security misconfiguration
- C. Sensitive data exposure
- D. Insecure direct object references
Answer: D
Explanation:
An insecure direct object reference occurs when a developer has in their code a reference to something on the application side, such as a database key, the directory structure of the application, configuration information about the hosting system, or any other information that pertains to the workings of the application that should not be exposed to users or the network. Unvalidated redirects and forwards occur when an application has functions to forward users to other sites, and these functions are not properly secured to validate the data and redirect requests, allowing spoofing for malware of phishing attacks.
Sensitive data exposure occurs when an application does not use sufficient encryption and other security controls to protect sensitive application data. Security misconfigurations occur when applications and systems are not properly configured or maintained in a secure manner.
NEW QUESTION 101
With a cloud service category where the cloud customer is responsible for deploying all services, systems, and components needed for their applications, which of the following storage types are MOST likely to be available to them?
- A. Volume and object
- B. Structured and hierarchical
- C. Structured and unstructured
- D. Volume and database
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The question is describing the Infrastructure as a Service (IaaS) cloud offering, and as such, the volume and object storage types will be available to the customer. Structured and unstructured are storage types associated with PaaS, and although the other answers present similar-sounding storage types, they are a mix of real and fake names.
NEW QUESTION 102
From a security perspective, which of the following is a major concern when evaluating possible BCDR solutions?
- A. Access provisioning
- B. Jurisdictions
- C. Auditing
- D. Authorization
Answer: B
Explanation:
Explanation
When a security professional is considering cloud solutions for BCDR, a top concern is the jurisdiction where the cloud systems are hosted. If the jurisdiction is different from where the production systems are hosted, they may be subjected to different regulations and controls, which would make a seamless BCDR solution far more difficult.
NEW QUESTION 103
The Open Web Application Security Project (OWASP) Top Ten is a list of web application security threats that is composed by a member-driven OWASP committee of application development experts and published approximately every 24 months. The 2013 OWASP Top Ten list includes "unvalidated redirects and forwards." Which of the following is a good way to protect against this problem?
- A. Implement security incident/event monitoring (security information and event management (SIEM)/security information management (SIM)/security event management (SEM)) solutions.
- B. Don't use redirects/forwards in your applications.
- C. Refrain from storing credentials long term.
- D. Implement digital rights management (DRM) solutions.
Answer: B
NEW QUESTION 104
When an API is being leveraged, it will encapsulate its data for transmission back to the requesting party or service.
What is the data encapsulation used with the SOAP protocol referred to as?
- A. Packet
- B. Envelope
- C. Object
- D. Payload
Answer: B
Explanation:
Simple Object Access Protocol (SOAP) encapsulates its information in what is known as a SOAP envelope. It then leverages common communications protocols for transmission. Object is a type of cloud storage, but also a commonly used term with certain types of programming languages.
Packet and payload are terms that sound similar to envelope but are not correct in this case.
NEW QUESTION 105
What is the first stage of the cloud data lifecycle where security controls can be implemented?
- A. Share
- B. Use
- C. Create
- D. Store
Answer: D
Explanation:
Explanation
The "store" phase of the cloud data lifecycle, which typically occurs simultaneously with the "create" phase, or immediately thereafter, is the first phase where security controls can be implemented. In most case, the manner in which the data is stored will be based on its classification.
NEW QUESTION 106
Which of the following should occur at each stage of the SDLC?
- A. Repurposing of any newly developed components
- B. Verification and validation
- C. Added functionality
- D. Management review
Answer: B
NEW QUESTION 107
Which of the following are considered to be the building blocks of cloud computing?
Response:
- A. Data, access control, virtualization, and services
- B. CPU, RAM, storage and networking
- C. Storage, networking, printing and virtualization
- D. Data, CPU, RAM, and access control
Answer: B
NEW QUESTION 108
Which of the following report is most aligned with financial control audits?
- A. SOC 2
- B. SSAE 16
- C. SOC 1
- D. SOC 3
Answer: C
Explanation:
Explanation/Reference:
Explanation:
The SOC 1 report focuses primarily on controls associated with financial services. While IT controls are certainly part of most accounting systems today, the focus is on the controls around those financial systems.
NEW QUESTION 109
In which cloud service model is the customer required to maintain the OS?
- A. CaaS
- B. Iaas
- C. SaaS
- D. PaaS
Answer: B
Explanation:
In IaaS, the service is bare metal, and the customer has to install the OS and the software; the customer then is responsible for maintaining that OS. In the other models, the provider installs and maintains the OS.
NEW QUESTION 110
What is the cloud service model in which the customer is responsible for administration of the OS?
Response:
- A. SaaS
- B. QaaS
- C. IaaS
- D. PaaS
Answer: C
NEW QUESTION 111
......
The Certified Cloud Security Professional certification exam, best known as the CCSP, fulfills the growing demands for experienced and specialized Cloud Security specialists. This test was introduced in 2015 and is available in more than 800 locations and 114 countries across the globe. Particularly, such a certification is focused on specialists working with cloud technologies to ensure that data is not only safer, but that security vulnerability is recognized to overcome those risks. Also, the CCSP certification is suitable for IT security leaders seeking to demonstrate their knowledge of cybersecurity and cloud computing. As a rule, the CCSP trained specialists can identify the issues and challenges faced by several cloud computing companies around the world.
Legal, Compliance, & Risk (13%):
- Understand the privacy issues;
- Understand the inferences of Cloud/enterprise risk management;
- Understand Cloud contract design and outsourcing.
- Understand the audit process, required adaptations, and methodologies for the Cloud environment;
- Explain the legal prerequisites and distinctive risks associated with the Cloud environment;
CCSP Dumps Real Exam Questions Test Engine Dumps Training: https://www.suretorrent.com/CCSP-exam-guide-torrent.html
CCSP exam dumps and online Test Engine: https://drive.google.com/open?id=1w4oL2IZTsrZwZmJ9Liic2WSBc7goT7S3