
[Nov-2023] CCSK Exam Dumps Pass with Updated 2023 Certificate of Cloud Security Knowledge (v4.0) Exam
Free CCSK Exam Dumps to Pass Exam Easily
NEW QUESTION # 31
Erin has a picture which he wants to store in the cloud and would like to share its URL so that his friends can see the picture. What type of cloud storage would you recommend for him?
- A. Raw storage
- B. Glacier
- C. Block Storage
- D. Object Storage
Answer: D
Explanation:
Object storage(also referred to as object-based storage) is a general term that refers to the way in which we organize and work with units of storage, called objects.
Every object contains three things:
The data itself: The data can be anything you want to store, from a family photo to a400,000-page manual for assembling an aircraft.
An expandable amount of metadata: The metadata is defined by whoever creates the object storage; it contains contextual information about what the data is, what it should be used for, its confidentiality, or anything else that is relevant to the way in which the data is used.
A globally unique identifier: The identifier is an address given to the object in order for the object to be found over a distributed system. This way, it's possible to find the data without having to know the physical location of the data(which could exist within different parts of a data center or different parts of the world).
NEW QUESTION # 32
Which ISO standards addresses Privacy in the cloud environment?
- A. ISO 27034
- B. ISO 27017
- C. ISO 27018
- D. ISO 27032
Answer: C
Explanation:
ISO/IEC 27018:2014 establishes commonly accepted control objectives, controls and guidelines for implementing measures to protect Personally Identifiable Information (PII) in accordance with the privacy principles in ISO/IEC 29100 for the public cloud computing environment.
NEW QUESTION # 33
Which is the key technology that enables the sharing of resources and makes cloud computing most viable in terms of cost savings?
- A. Software Defined Networking(SDN)
- B. Virtualization
- C. Content Delivery Networks(CDN)
- D. Scalability
Answer: B
Explanation:
Virtualization is the foundational technology that underlies and makes cloud computing possible.
Virtualization is based on the use of powerful host computers to provide a shared resource pool that can be managed to maximize the number of guest operating systems(OSs) running on each host.
NEW QUESTION # 34
CCM: Cloud Controls Matrix (CCM) is a completely independent cloud
assessment toolkit that does not map any existing standards.
- A. False
- B. True
Answer: A
NEW QUESTION # 35
Stopping a function to control further risk to business is called:
- A. Mitigation
- B. Transference
- C. Avoidance
- D. Acceptance
Answer: C
Explanation:
Risk avoidance is the practice of coming up with alternatives so that the risk in question is not realised.
NEW QUESTION # 36
Single cloud assets are typically less resilient than in the case of traditional infrastructure.
- A. True
- B. False
Answer: A
Explanation:
Cloud platforms can be incredibly resilient. but single cloud assets are typically less resilient than in the case of traditional infrastructure. This is due to the inherently greater fragility of virtualized resources running in highly-complex environments.
Reference: CSA Security Guidelines V.4 (reproduced here for the educational purpose)
NEW QUESTION # 37
Which one of the following is NOT one of phases for cloud auditing?
- A. Report data breaches
- B. Conduct Audit
- C. Report lesson learned
- D. Define Audit objectives
Answer: A
Explanation:
Reporting data breaches is not part of Auditing and not a function of Auditors.
NEW QUESTION # 38
Which of the following is an assurance program and documentation registry for cloud provider assessments?
- A. CSA Cloud Controls Matrix
- B. CSA Consensus Assessments Initiative Questionnaire
- C. CSA Star
- D. CSA governance charter
Answer: C
Explanation:
The Cloud Security Alliance STAR Registry is an assurance program and documentation registry or cloud provider assessments based on the CSA Cloud Controls Matrix and Consensus Assessments Initiative Questionnaire. Some providers also disclose documentation for additional certifications and assessments(including self-assessments).
Ref: Security Guidance v4.0 Copyright2017, Cloud Security Alliance(used for educational purpose here)
NEW QUESTION # 39
Which of the following statements best describes an identity
federation?
- A. Several countries which have agreed to define their identities with
similar attributes - B. A group of entities which have decided to exist together in a single
cloud - C. The connection of one identity repository to another
- D. Identities which share similar attributes
- E. A library of data definitions
Answer: C
NEW QUESTION # 40
CCM: The Cloud Service Delivery Model Applicability column in the CCM indicates the applicability of the cloud security control to which of the following elements?
- A. Mappings to well-known standards and frameworks
- B. Physical, Network, Compute, Storage, Application or Data
- C. SaaS, PaaS or IaaS
- D. Service Provider or Tenant/Consumer
Answer: C
NEW QUESTION # 41
Which one of the following is an example of misuse or abuse of cloud services?
- A. Account Hijacking
- B. XSS attacks
- C. Honeypot
- D. DDoS Attack
Answer: D
Explanation:
Public cloud platform can be used to launch DDoS attack on other platforms.
Please note here and understand the meaning of phrase "abuse or misuse of cloud Services" This phrase means to launch attacks or campaign by using cloud as a platform. mostly. public cloud.
NEW QUESTION # 42
Due to multi-tenancy nature of cloud. there is the possibility that data belonging to one customer will be read or received by another. This is known as:
- A. Data disclosure
- B. Wilful data disclosure
- C. Data dispersion
- D. Information Bleed
Answer: D
Explanation:
Information Bleed With multiple customers processing and storing data over the same infrastructure, there is the possibility that data belonging to one customer will be read or received by another.
Moreover, even if this does not happen with raw data, it might be possible for one customer to detect telltale information about another customer's activity, such as when the customer is processing data, how long the procedure takes, and so on.
NEW QUESTION # 43
In the IaaS hosted environment. who is ultimately responsible for platform security?
- A. Customer
- B. Joint responsibility
- C. Cloud Service Provider
- D. System Administrator
Answer: A
Explanation:
In IaaS hosted environment, Platform security is responsibility of the customer whereas infrastructure security is a shared responsibility between cloud service provider and the customer
NEW QUESTION # 44
Cloud services exhibit five essential characteristics that demonstrate their relation to, and differences from, traditional computing approaches. Which one of the five characteristics is described as: a consumer can unilaterally provision computing capabilities such as server time and network storage as needed.
- A. Measured service
- B. Rapid elasticity
- C. Resource pooling
- D. On-demand self-service
- E. Broad network access
Answer: D
NEW QUESTION # 45
Any given processor and memory will nearly always be running multiple workloads, often from different tenants.
- A. True
- B. False
Answer: A
NEW QUESTION # 46
In a cloud environment, "unclear roles& responsibilities" and "no control over vulnerability process" on part of cloud customer can lead to:
- A. Loss of Governance
- B. Denial of Service Attacks
- C. Lack of Disaster Recovery
- D. Poor management of cloud Infrastructure
Answer: A
Explanation:
It can lead to loss of governance.
In using cloud infrastructures, the client necessarily cedes control to the cloud service provider(CSP) on several issues which may affect security.
The loss of governance and control could have a potentially severe impact on the organization's strategy and therefore on the capacity to meet its mission and goals. The loss of control and governance could lead to the impossibility of complying with the security requirements, a lack of confidentiality, integrity and availability of data, and a deterioration of performance and quality of service, not to mention the introduction of compliance challenges.
Source: ENISA- Security Risk and Benefits
NEW QUESTION # 47
Which attack surfaces, if any, does virtualization technology introduce?
- A. All of the above
- B. The hypervisor
- C. Configuration and VM sprawl issues
- D. Virtualization management components apart from the hypervisor
Answer: A
NEW QUESTION # 48
Containers can be implemented without the use of VMs at all and run directly on hardware.
- A. True
- B. False
Answer: A
Explanation:
Multiple containers can run on the same virtual machine or be implemented without the use of VMs at all and run directly on hardware. The container provides code running inside a restricted environment with only access to the processes and capabilities defined in the container configuration. This allows containers to launch incredibly rapidly. since they don't need to boot an operating system or launch many(sometimes any) new services; the container only needs access to already-running services in the host 0S and some can launch in milliseconds.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION # 49
Centralization of log streams is charactertic of which devices?
- A. SIEM
- B. IPS
- C. DLP
- D. IDS
Answer: A
Explanation:
SIEM is a combination of Security Incident Management(SIM)and Security Event Management(SEM).
A SEM system centralizes the storage and interpretation of logs and allows near real-time analysis which enables security personnel to take defensive actions more quickly. A SIM system collects data into a central repository for trend analysis and provides automated reporting for compliance and centralised reporting.
NEW QUESTION # 50
Which of the following describes the cloud security reference architecture?
- A. ISO 17789
- B. ISO 27032
- C. ISO 27001
- D. ISO 17788
Answer: D
Explanation:
ISO 17788 has a cloud reference architecture
NEW QUESTION # 51
......
Cloud Security Alliance CCSK (Certificate of Cloud Security Knowledge (v4.0)) Certification Exam is a globally recognized certification that validates an individual's knowledge of cloud security best practices and principles. Certificate of Cloud Security Knowledge (v4.0) Exam certification is designed for IT professionals who are responsible for securing cloud environments, including security managers, IT auditors, and system administrators. CCSK exam covers a range of topics related to cloud security, such as cloud architecture, data security, compliance, and legal issues.
CCSK Exam Dumps, CCSK Practice Test Questions: https://tesking.pass4cram.com/CCSK-dumps-torrent.html