Free ISC CCSP Exam Questions & Answer from Training Expert SureTorrent [Q375-Q390]

Share

Free ISC CCSP Exam Questions & Answer from Training Expert SureTorrent

Top ISC CCSP Courses Online


ISC CCSP Practice Test Questions, ISC CCSP Exam Practice Test Questions

This certification is ideal for the information security and IT leaders looking to validate their knowledge of cybersecurity and securing the organization’s critical assets within Cloud. The candidates for the (ISC)2 CSSP certificate demonstrate their advanced knowledge and technical skills in designing, securing, and managing data, infrastructure, and applications in Cloud by taking the qualifying exam.

 

NEW QUESTION 375
Which aspect of cloud computing will be most negatively impacted by vendor lock-in?

  • A. Elasticity
  • B. Interoperability
  • C. Reversibility
  • D. Portability

Answer: D

Explanation:
Explanation/Reference:
Explanation:
A cloud customer utilizing proprietary APIs or services from one cloud provider that are unlikely to be available from another cloud provider will most negatively impact portability.

 

NEW QUESTION 376
APIs are defined as which of the following?

  • A. A set of routines, standards, protocols, and tools for building software applications to access a web- based software application or tool
  • B. A set of routines and tools for building software applications to access web-based software applications
  • C. A set of standards for building software applications to access a web-based software application or tool
  • D. A set of protocols, and tools for building software applications to access a web-based software application or tool

Answer: A

Explanation:
All the answers are true, but B is the most complete.

 

NEW QUESTION 377
What process entails taking sensitive data and removing the indirect identifiers from each data object so that the identification of a single entity would not be possible?

  • A. Encryption
  • B. Tokenization
  • C. Masking
  • D. Anonymization

Answer: D

Explanation:
Anonymization is a type of masking, where indirect identifiers are removed from a data set to prevent the mapping back of data to an individual. Although masking refers to the overall approach of covering sensitive data, anonymization is the best answer here because it is more specific to exactly what is being asked. Tokenization involves the replacement of sensitive data with a key value that can be matched back to the real value. However, it is not focused on indirect identifiers or preventing the matching to an individual. Encryption refers to the overall process of protecting data via key pairs and protecting confidentiality.

 

NEW QUESTION 378
What is the only data format permitted with the SOAP API?

  • A. XML
  • B. SAML
  • C. HTML
  • D. XSML

Answer: A

Explanation:
Explanation
The SOAP protocol only supports the XML data format.

 

NEW QUESTION 379
BCDR strategies typically do not involve the entire operations of an organization, but only those deemed critical to their business.
Which concept pertains to the amount of data and services needed to reach the predetermined level of operations?

  • A. RPO
  • B. RTO
  • C. SRE
  • D. RSL

Answer: A

Explanation:
Explanation
The recovery point objective (RPO) sets and defines the amount of data an organization must have available or accessible to reach the predetermined level of operations necessary during a BCDR situation. The recovery time objective (RTO) measures the amount of time necessary to recover operations to meet the BCDR plan.
The recovery service level (RSL) measures the percentage of operations that would be recovered during a BCDR situation. SRE is provided as an erroneous response.

 

NEW QUESTION 380
You work for a company that operates a production environment in the cloud. Another company using the same cloud provider is under investigation by law enforcement for racketeering. Your company should be concerned about this because of the cloud characteristic of ____________.
Response:

  • A. Pooled resources
  • B. Elasticity
  • C. Automated self-service
  • D. Virtualization

Answer: A

 

NEW QUESTION 381
Which OSI layer does IPsec operate at?

  • A. transport
  • B. Presentation
  • C. Network
  • D. Application

Answer: C

Explanation:
Explanation
A major difference between IPsec and other protocols such as TLS is that IPsec operates at the Internet network layer rather than the application layer, allowing for complete end-to-end encryption of all communications and traffic.

 

NEW QUESTION 382
Which of the following is NOT a focus or consideration of an internal audit?

  • A. Certification
  • B. Design
  • C. Operational efficiency
  • D. Costs

Answer: A

Explanation:
In order to obtain and comply with certifications, independent external audits must be performed and satisfied.
Although some testing of certification controls can be part of an internal audit, they will not satisfy requirements.

 

NEW QUESTION 383
With IaaS, what is responsible for handling the security and control over the volume storage space?

  • A. Management plane
  • B. Application
  • C. Hypervisor
  • D. Operating system

Answer: D

Explanation:
Volume storage is allocated via a LUN to a system and then treated the same as any traditional storage.
The operating system is responsible for formatting and securing volume storage as well as controlling all access to it. Applications, although they may use volume storage and have permissions to write to it, are not responsible for its formatting and security. Both a hypervisor and the management plane are outside of an individual system and are not responsible for managing the files and storage within that system.

 

NEW QUESTION 384
Which of the following is a valid risk management metric?

  • A. KRI
  • B. SOC
  • C. SLA
  • D. KPI

Answer: A

Explanation:
Explanation
KRI stands for key risk indicator. KRIs are the red flags if you will in the world of risk management. When these change, they indicate something is amiss and should be looked at quickly to determine if the change is minor or indicative of something important.

 

NEW QUESTION 385
Which of the following is the least challenging with regard to eDiscovery in the cloud?

  • A. Decentralization of data storage
  • B. Identifying roles such as data owner, controller and processor
  • C. Forensic analysis
  • D. Complexities of International law

Answer: C

Explanation:
Forensic analysis is the least challenging of the answers provided as it refers to the analysis of data once it is obtained. The challenges revolve around obtaining the data for analysis due to the complexities of international law, the decentralization of data storage or difficulty knowing where to look, and identifying the data owner, controller, and processor.

 

NEW QUESTION 386
A user signs on to a cloud-based social media platform. In another browser tab, the user finds an article worth posting to the social media platform. The user clicks on the platform's icon listed on the article's website, and the article is automatically posted to the user's account on the social media platform.
This is an example of what?
Response:

  • A. Identity federation
  • B. Single sign-on
  • C. Cross-site scripting
  • D. Insecure direct identifiers

Answer: A

 

NEW QUESTION 387
Which of the following is a management role, versus a technical role, as it pertains to data management and oversight?

  • A. Data processor
  • B. Data custodian
  • C. Data owner
  • D. Database administrator

Answer: C

Explanation:
Data owner is a management role that's responsible for all aspects of how data is used and protected. The database administrator, data custodian, and data processor are all technical roles that involve the actual use and consumption of data, or the implementation of security controls and policies with the data.

 

NEW QUESTION 388
Within a SaaS environment, what is the responsibility on the part of the cloud customer in regard to procuring the software used?

  • A. Purchasing
  • B. Development
  • C. Maintenance
  • D. Licensing

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Within a SaaS implementation, the cloud customer licenses the use of the software from the cloud provider because SaaS delivers a fully functional application to the customer. With SaaS, the cloud provider is responsible for the entire software application and any necessary infrastructure to develop, run, and maintain it. The purchasing, development, and maintenance are fully the responsibility of the cloud provider.

 

NEW QUESTION 389
Which characteristic of automated patching makes it attractive?
Response:

  • A. Speed
  • B. Cost
  • C. Noise reduction
  • D. Capability to recognize problems quickly

Answer: A

 

NEW QUESTION 390
......


Certification Path

There is no prerequisite for this ISC CCSP exam.


For more info visit:

ISC CCSP Exam Reference

 

New (2022) ISC CCSP  Exam Dumps: https://www.suretorrent.com/CCSP-exam-guide-torrent.html

CCSP Practice Dumps - Verified By SureTorrent Updated 830 Questions: https://drive.google.com/open?id=1HpRPm0qjfFIz1ik5Q8YzKeciMLksqw9U