Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
0% found this document useful (0 votes)
335 views6 pages

Exam Questions CCSP: Certified Cloud Security Professional

Download as pdf or txt
Download as pdf or txt
Download as pdf or txt
You are on page 1/ 6

Recommend!!

Get the Full CCSP dumps in VCE and PDF From SurePassExam
https://www.surepassexam.com/CCSP-exam-dumps.html ( New Questions)

ISC2
Exam Questions CCSP
Certified Cloud Security Professional

Passing Certification Exams Made Easy visit - https://www.surepassexam.com


Recommend!! Get the Full CCSP dumps in VCE and PDF From SurePassExam
https://www.surepassexam.com/CCSP-exam-dumps.html ( New Questions)

NEW QUESTION 1
- (Exam Topic 1)
You are the security manager for a small application development company. Your company is considering the use of the cloud for software testing purposes.
Which cloud service model is most likely to suit your needs?
Response:

A. IaaS
B. PaaS
C. SaaS
D. LaaS

Answer: B

NEW QUESTION 2
- (Exam Topic 1)
All of the following are usually nonfunctional requirements except ______.
Response:

A. Color
B. Sound
C. Security
D. Function

Answer: D

NEW QUESTION 3
- (Exam Topic 1)
Which of the following is essential for getting full security value from your system baseline? Response:

A. Capturing and storing an image of the baseline


B. Keeping a copy of upcoming suggested modifications to the baseline
C. Having the baseline vetted by an objective third party
D. Using a baseline from another industry member so as not to engage in repetitious efforts

Answer: A

NEW QUESTION 4
- (Exam Topic 1)
Which of the following is a risk in the cloud environment that is not existing or is as prevalent in the legacy environment?
Response:

A. Legal liability in multiple jurisdictions


B. Loss of productivity due to DDoS
C. Ability of users to gain access to their physical workplace
D. Fire

Answer: A

NEW QUESTION 5
- (Exam Topic 1)
Which of the following data sanitation methods would be the MOST effective if you needed to securely remove data as quickly as possible in a cloud environment?
Response:

A. Zeroing
B. Cryptographic erasure
C. Overwriting
D. Degaussing

Answer: B

NEW QUESTION 6
- (Exam Topic 1)
Which type of report is considered for “general” use and does not contain any sensitive information? Response:

A. SOC 1
B. SAS-70
C. SOC 3
D. SOC 2

Answer: C

NEW QUESTION 7
- (Exam Topic 1)
A honeypot should contain data______.
Response:

Passing Certification Exams Made Easy visit - https://www.surepassexam.com


Recommend!! Get the Full CCSP dumps in VCE and PDF From SurePassExam
https://www.surepassexam.com/CCSP-exam-dumps.html ( New Questions)

A. Raw
B. Production
C. Useless
D. Sensitive

Answer: C

NEW QUESTION 8
- (Exam Topic 2)
Which of the following characteristics is associated with digital rights management (DRM) solutions (sometimes referred to as information rights management, or
IRM)?
Response:

A. Mapping to existing access control lists (ACLs)


B. Delineating biometric catalogs
C. Preventing multifactor authentication
D. Prohibiting unauthorized transposition

Answer: A

NEW QUESTION 9
- (Exam Topic 2)
A process for ______ can aid in protecting against data disclosure due to lost devices. Response:

A. User punishment
B. Credential revocation
C. Law enforcement notification
D. Device tracking

Answer: B

NEW QUESTION 10
- (Exam Topic 2)
Which type of cloud service category would having a vendor-neutral encryption scheme for data at rest (DAR) be the MOST important?
Response:

A. Public
B. Hybrid
C. Private
D. Community

Answer: B

NEW QUESTION 11
- (Exam Topic 2)
Which of the following is a risk associated with manual patching especially in the cloud?
Response:

A. No notice before the impact is realized


B. Lack of applicability to the environment
C. Patches may or may not address the vulnerability they were designed to fix.
D. The possibility for human error

Answer: D

NEW QUESTION 12
- (Exam Topic 2)
When designing a cloud data center, which of the following aspects is not necessary to ensure continuity of operations during contingency operations?
Response:

A. Access to clean water


B. Broadband data connection
C. Extended battery backup
D. Physical access to the data center

Answer: C

NEW QUESTION 13
- (Exam Topic 2)
What is a cloud storage architecture that manages the data in caches of copied content close to locations of high demand?
Response:

A. Object-based storage
B. File-based storage
C. Database
D. CDN

Passing Certification Exams Made Easy visit - https://www.surepassexam.com


Recommend!! Get the Full CCSP dumps in VCE and PDF From SurePassExam
https://www.surepassexam.com/CCSP-exam-dumps.html ( New Questions)

Answer: D

NEW QUESTION 14
- (Exam Topic 2)
DLP solutions typically involve all of the following aspects except ______.
Response:

A. Data discovery
B. Tokenization
C. Monitoring
D. Enforcement

Answer: B

NEW QUESTION 15
- (Exam Topic 2)
You are the IT director for a small contracting firm. Your company is considering migrating to a cloud production environment.
Which service model would best fit your needs if you wanted an option that reduced the chance of vendor lock-in but also did not require the highest degree of
administration by your own personnel?
Response:

A. IaaS
B. PaaS
C. SaaS
D. TanstaafL

Answer: B

NEW QUESTION 16
- (Exam Topic 3)
Cloud vendors are held to contractual obligations with specified metrics by:
Response:

A. SLAs
B. Regulations
C. Law
D. Discipline

Answer: A

NEW QUESTION 17
- (Exam Topic 3)
A cloud provider is looking to provide a higher level of assurance to current and potential cloud customers about the design and effectiveness of their security
controls.
Which of the following audit reports would the cloud provider choose as the most appropriate to accomplish this goal?
Response:

A. SAS-70
B. SOC 1
C. SOC 2
D. SOC 3

Answer: D

NEW QUESTION 18
- (Exam Topic 3)
What is the major difference between authentication/authorization? Response:

A. Code verification/code implementation


B. Identity validation/access permission
C. Inverse incantation/obverse instantiation
D. User access/privileged access

Answer: B

NEW QUESTION 19
- (Exam Topic 3)
Which of the following might make crypto-shredding difficult or useless? Response:

A. Cloud provider also managing the organization’s keys


B. Lack of physical access to the environment
C. External attackers
D. Lack of user training and awareness

Answer: A

Passing Certification Exams Made Easy visit - https://www.surepassexam.com


Recommend!! Get the Full CCSP dumps in VCE and PDF From SurePassExam
https://www.surepassexam.com/CCSP-exam-dumps.html ( New Questions)

NEW QUESTION 20
- (Exam Topic 3)
Which ISO/IEC standards set documents the cloud definitions for staffing and official roles? Response:

A. ISO/IEC 27001
B. ISO/IEC 17788
C. ISO/IEC 17789
D. ISO/IEC 27040

Answer: B

NEW QUESTION 21
......

Passing Certification Exams Made Easy visit - https://www.surepassexam.com


Recommend!! Get the Full CCSP dumps in VCE and PDF From SurePassExam
https://www.surepassexam.com/CCSP-exam-dumps.html ( New Questions)

Thank You for Trying Our Product

We offer two products:

1st - We have Practice Tests Software with Actual Exam Questions

2nd - Questons and Answers in PDF Format

CCSP Practice Exam Features:

* CCSP Questions and Answers Updated Frequently

* CCSP Practice Questions Verified by Expert Senior Certified Staff

* CCSP Most Realistic Questions that Guarantee you a Pass on Your FirstTry

* CCSP Practice Test Questions in Multiple Choice Formats and Updatesfor 1 Year

100% Actual & Verified — Instant Download, Please Click


Order The CCSP Practice Test Here

Passing Certification Exams Made Easy visit - https://www.surepassexam.com


Powered by TCPDF (www.tcpdf.org)

You might also like