
2023 RealVCE Cloud Security Alliance CCSK Dumps and Exam Test Engine
Cloud Security Alliance CCSK DUMPS WITH REAL EXAM QUESTIONS
NEW QUESTION # 60
Which is the core technology for enabling cloud computing and used to convert fixed infrastructure into pooled resources?
- A. Auto-Scaling
- B. Application Programming Interfaces
- C. Software Defined Networking
- D. Virtualization
Answer: D
Explanation:
Virtualization isn't merely a tool for creating virtual machines-it's the core technology for enabling cloud computing. We use virtualization all throughout computing, from full operating virtual machines to virtual execution environments like the Java Virtual Machine, as well as in storage, networking, and beyond.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION # 61
Which of the below hypervisors are 0S based and are more attractive to attackers?
- A. Type II
- B. Type I
- C. Type III
- D. Type V
Answer: A
Explanation:
Type II hypervisors are 0S-based and more attractive to attackers. There are lot of vulnerabilities which are found not only on 0S but also in applications residing on the 0S.
NEW QUESTION # 62
What is true of security as it relates to cloud network infrastructure?
- A. You should always open traffic between workloads in the same virtual subnet for better visibility.
- B. You should deploy your cloud firewalls identical to the existing firewalls.
- C. You should implement a default deny with cloud firewalls.
- D. You should implement a default allow with cloud firewalls and then restrict as necessary.
- E. You should apply cloud firewalls on a per-network basis.
Answer: C
Explanation:
Explanation
NEW QUESTION # 63
In which type of environment is it impractical to allow the customer to conduct their own audit, making it important that the data center operators are required to provide auditing for the customers?
- A. Single tenant environments
- B. Distributed computing arrangements
- C. Long distance relationships
- D. Multi-application, single tenant environments
- E. Multi-tenant environments
Answer: E
NEW QUESTION # 64
Any given processor and memory will nearly always be running multiple workloads, often from different tenants.
- A. True
- B. False
Answer: A
NEW QUESTION # 65
Private clouds can be hosted off-premises as well.
- A. True
- B. False
Answer: A
Explanation:
It is true. This is how Private cloud is defined.
Private Cloud: The cloud infrastructure is operated solely for a single organization. It may be managed by the organization or by a third party and may be located on-premises or off-premises.
NEW QUESTION # 66
The process which frees the resources from their physical constraints to enable pooling is called:
- A. Classification
- B. Orchestration
- C. Automation
- D. Abstraction
Answer: D
Explanation:
Abstraction. often via virtualization. frees the resources from their physical constraints to enable pooling. Then a set of core connectivity and delivery tools(orchestration)ties these abstracted resources together. creates the pools. and provides the automation to deliver them to customers.
Ref: CSA Security Guidelines V4.0
NEW QUESTION # 67
ISO 27001 certification can be taken as proof to achieve Third-party assessment level in CSA star program.
- A. True
- B. False
Answer: A
Explanation:
The CSA STAR Certification is a rigorous third-party independent assessment of the security of a cloud service provider. The technology-neutral certification leverages the requirements of the ISO/IEC
27001:2013 management system standard together with the CSA Cloud Controls Matrix.
NEW QUESTION # 68
An important consideration when performing a remote vulnerability test of a cloud-based application is to
- A. Use application layer testing tools exclusively
- B. Obtain provider permission for test
- C. Use techniques to evade cloud provider's detection systems
- D. Use network layer testing tools exclusively
- E. Schedule vulnerability test at night
Answer: B
NEW QUESTION # 69
Which one is NOT considered as one of the building blocks of the cloud computing?
- A. Clock
- B. CPU
- C. RAM
- D. Networking
Answer: A
Explanation:
The question is asking for an exception by using "NOT"
The building blocks of cloud computing are composed of random access memory (RAM), the central processing unit(CPU), storage, and networking.
NEW QUESTION # 70
Which of the following is not one of the essential characteristics of Cloud Computing?
- A. Rapid elasticit
- B. Broad network access
- C. On-demand self service
- D. Resource Sharing
Answer: D
Explanation:
Resource sharing is not one of the key characteristics of Cloud Computing
NEW QUESTION # 71
An incident in which sensitive, protected or confidential information is released, viewed, stolen or used by an individual who is not authorized to do so, is called:
- A. Data Denial
- B. Data Breach
- C. Data Dispersion
- D. Data Disclosure
Answer: B
Explanation:
It is the definition of Data breach. It should not be confused with data disclosure. The incident can lead to information disclosure but incident, itself, will be termed as Data Breach.
NEW QUESTION # 72
The risk left in any system after all countermeasures and strategies have been applied is called:
- A. Residual Risk
- B. Annualised Risk
- C. Leftover risk
- D. Mitigated Risk
Answer: A
Explanation:
Thats the definition of residual risk
NEW QUESTION # 73
Ensuring the use of data and information complies with organizational policies, standards and strategy- including regulatory, contractual, and business objectives, known as:
- A. Enterprise Governance
- B. Data Governance
- C. IT Governance
- D. Corporate Governance
Answer: B
Explanation:
It is definition of Data Governance
NEW QUESTION # 74
Stopping a function to control further risk to business is called:
- A. Transference
- B. Mitigation
- C. Avoidance
- D. Acceptance
Answer: C
Explanation:
Risk avoidance is the practice of coming up with alternatives so that the risk in question is not realised.
NEW QUESTION # 75
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
- A. Respect the interdependency of the risks inherent in the cloud supply chain and communicate the corporate risk posture and readiness to consumers and dependent parties.
- B. Provide transparency to stakeholders and shareholders demonstrating fiscal solvency and organizational transparency.
- C. Negotiate long-term contracts with companies who use well-vetted software application to avoid the transient nature of the cloud environment.
- D. Both B and C.
- E. Inspect and account for risks inherited from other members of the cloud supply chain and take active measures to mitigate and contain risks through operational resiliency.
Answer: C
NEW QUESTION # 76
A unit of processing, which can be in a virtual machine, a container, or other abstraction and always run somewhere on a processor and consume memory is called:
- A. Host
- B. Device
- C. Controller
- D. Workload
Answer: D
Explanation:
A workload is a unit of processing, which can be in a virtual machine, a container, or other abstraction.
Workloads always run somewhere on a processor and consume memory. Workloads include a very diverse range of processing tasks, which range from traditional applications running in a virtual machine on a standard operating system, to GPU- or FPGA-based specialized tasks Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
NEW QUESTION # 77
According to ISO 27018. data processor has explicit control over how CSPs are to use PII.
- A. False
- B. True
Answer: A
Explanation:
In ISO 27018, it is the customer who has explicit right over how CSPs will use their information
NEW QUESTION # 78
What are the primary security responsibilities of the cloud provider in compute virtualizations?
- A. Enforce isolation and configure the security settings
- B. Enforce isolation and monitor and log workloads
- C. Monitor and log workloads and configure the security settings
- D. Enforce isolation and maintain a secure virtualization infrastructure
- E. Maintain a secure virtualization infrastructure and configure the security settings
Answer: D
NEW QUESTION # 79
......
2023 New RealVCE CCSK PDF Recently Updated Questions: https://examcollection.realvce.com/CCSK-original-questions.html