
Best Quality ISC CCSP Exam Questions ITExamSimulator Realistic Practice Exams [2021]
Critical Information To Certified Cloud Security Professional Pass the First Time
NEW QUESTION 253
Which of the following is NOT considered a type of data loss?
- A. Stolen by hackers
- B. Lost or destroyed encryption keys
- C. Data corruption
- D. Accidental deletion
Answer: A
Explanation:
Explanation
Explanation:
The exposure of data by hackers is considered a data breach. Data loss focuses on the data availability rather than security. Data loss occurs when data becomes lost, unavailable, or destroyed, when it should not have been.
NEW QUESTION 254
What are the objectives of change management?
(Choose all that apply.)
Response:
- A. Ensure that all changes are prioritized, planned, tested, implemented, documented, and reviewed in a controlled manner
- B. Ensure that changes are recorded and evaluated
- C. Respond to a customer's changing business requirements while maximizing value and reducing incidents, disruption, and rework
- D. Respond to business and IT requests for change that will disassociate services with business needs
Answer: B,C
NEW QUESTION 255
The BCDR plan/process should be written and documented in such a way that it can be used by
____________.
Response:
- A. Regulators
- B. Essential BCDR team members
- C. Someone with the requisite skills
- D. Users
Answer: C
NEW QUESTION 256
There is a large gap between the privacy laws of the United States and those of the European Union.
Bridging this gap is necessary for American companies to do business with European companies and in European markets in many situations, as the American companies are required to comply with the stricter requirements.
Which US program was designed to help companies overcome these differences?
- A. HIPAA
- B. Safe Harbor
- C. SOX
- D. GLBA
Answer: B
Explanation:
Explanation/Reference:
Explanation:
The Safe Harbor regulations were developed by the Department of Commerce and are meant to serve as a way to bridge the gap between privacy regulations of the European Union and the United States. Due to the lack of adequate privacy laws and protection on the federal level in the US, European privacy regulations generally prohibit the exporting of PII from Europe to the United States. Participation in the Safe Harbor program is voluntary on the part of US organizations. These organizations must conform to specific requirements and policies that mirror those from the EU, thus possibly fulfilling the EU requirements for data sharing and export. This way, American businesses can be allowed to serve customers in the EU. The Health Insurance Portability and Accountability Act (HIPAA) pertains to the protection of patient medical records and privacy. The Gramm-Leach-Bliley Act (GLBA) focuses on the use of PII within financial institutions. The Sarbanes-Oxley Act (SOX) regulates the financial and accounting practices used by organizations in order to protect shareholders from improper practices and errors.
NEW QUESTION 257
Which of the following is considered an internal redundancy for a data center?
- A. Network circuits
- B. Power feeds
- C. Generators
- D. Chillers
Answer: D
Explanation:
Chillers and cooling systems are internal to a data center and its operations, and as such they are considered an internal redundancy. Power feeds, network circuits, and generators are all external to a data center and provide utility services to them, which makes them an external redundancy.
NEW QUESTION 258
A crucial decision any company must make is in regard to where it hosts the data systems it depends on. A debate exists as to whether it's best to lease space in a data center or build your own data center--and now with cloud computing, whether to purchase resources within a cloud.
What is the biggest advantage to leasing space in a data center versus procuring cloud services?
- A. Regulations
- B. Security
- C. Costs
- D. Control
Answer: D
Explanation:
When leasing space in a data center versus utilizing cloud services, a customer has a much greater control over its systems and services, from both the hardware/software perspective and the operational management perspective. Costs, regulations, and security are all prime considerations regardless of the hosting type selected. Although regulations will be the same in either hosting solution, in most instances, costs and security will be greater factors with leased space.
NEW QUESTION 259
During the assessment phase of a risk evaluation, what are the two types of tests that are performed?
Response:
- A. Qualitative and quantitative
- B. Physical and logical
- C. Internal and external
- D. Technical and managerial
Answer: A
NEW QUESTION 260
What are third-party providers of IAM functions for the cloud environment?
- A. AESs
- B. CASBs
- C. DLPs
- D. SIEMs
Answer: B
NEW QUESTION 261
Which cloud deployment model is MOST likely to offer free or very cheap services to users?
- A. Community
- B. Private
- C. Public
- D. Hybrid
Answer: C
Explanation:
Public clouds offer services to anyone, regardless of affiliation, and are the most likely to offer free services to users. Examples of public clouds with free services include iCloud, Dropbox, and OneDrive.
Private cloud models are designed for specific customers and for their needs, and would not offer services to the public at large, for free or otherwise. A community cloud is specific to a group of similar organizations and would not offer free or widely available public services. A hybrid cloud model would not fit the specifics of the question.
NEW QUESTION 262
In order to ensure ongoing compliance with regulatory requirements, which phase of the cloud data lifecycle must be tested regularly?
- A. Share
- B. Destroy
- C. Store
- D. Archive
Answer: D
Explanation:
In order to ensure compliance with regulations, it is important for an organization to regularly test the restorability of archived data. As technologies change and older systems are deprecated, the risk rises for an organization to lose the ability to restore data from the format in which it is stored. With the destroy, store, and share phases, the currently used technologies will be sufficient for an organization's needs in an ongoing basis, so the risk that is elevated with archived data is not present.
NEW QUESTION 263
The nature of cloud computing and how it operates make complying with data discovery and disclosure orders more difficult. Which of the following concepts provides the biggest challenge in regard to data collection, pursuant to a legal order?
Response:
- A. Multitenancy
- B. Reversibility
- C. Portability
- D. Auto-scaling
Answer: A
NEW QUESTION 264
Proper ________ need to be assigned to each data classification/category.
Response:
- A. Metadata
- B. Dollar values
- C. Policies
- D. Security controls
Answer: D
NEW QUESTION 265
Many different common threats exist against web-exposed services and applications. One attack involves attempting to leverage input fields to execute queries in a nested fashion that is unintended by the developers.
What type of attack is this?
- A. Missing function-level access control
- B. Injection
- C. Cross-site request forgery
- D. Cross-site scripting
Answer: B
Explanation:
An injection attack is where a malicious actor sends commands or other arbitrary data through input and data fields with the intent of having the application or system execute the code as part of its normal processing and queries. This can trick an application into exposing data that is not intended or authorized to be exposed, or it can potentially allow an attacker to gain insight into configurations or security controls.
Missing function-level access control exists where an application only checks for authorization during the initial login process and does not further validate with each function call. Cross-site request forgery occurs when an attack forces an authenticated user to send forged requests to an application running under their own access and credentials. Cross-site scripting occurs when an attacker is able to send untrusted data to a user's browser without going through validation processes.
NEW QUESTION 266
Which of the following in a federated environment is responsible for consuming authentication tokens?
- A. Identity provider
- B. Cloud services broker
- C. Authentication provider
- D. Relying party
Answer: D
NEW QUESTION 267
With a cloud service category where the cloud customer is provided a full application framework into which to deploy their code and services, which storage types are MOST likely to be available to them?
- A. Volume and object
- B. Volume and database
- C. Structured and unstructured
- D. Structured and hierarchical
Answer: C
Explanation:
Explanation/Reference:
Explanation:
The question is describing the Platform as a Service (PaaS) cloud offering, and as such, structured and unstructured storage types will be available to the customer. Volume and object are storage types associated with IaaS, and although the other answers present similar-sounding storage types, they are a mix of real and fake names.
NEW QUESTION 268
Although encryption can help an organization to effectively decrease the possibility of data breaches, which other type of threat can it increase the chances of?
- A. Account hijacking
- B. Insecure interfaces
- C. System vulnerabilities
- D. Data loss
Answer: D
NEW QUESTION 269
When an organization is considering a cloud environment for hosting BCDR solutions, which of the following would be the greatest concern?
- A. Availability
- B. Self-service
- C. Resource pooling
- D. Location
Answer: D
Explanation:
If an organization wants to use a cloud service for BCDR, the location of the cloud hosting becomes a very important security consideration due to regulations and jurisdiction, which could be dramatically different from the organization's normal hosting locations. Availability is a hallmark of any cloud service provider, and likely will not be a prime consideration when an organization is considering using a cloud for BCDR; the same goes for self-service options.
Resource pooling is common among all cloud systems and would not be a concern when an organization is dealing with the provisioning of resources during a disaster.
NEW QUESTION 270
Which United States program was designed to enable organizations to bridge the gap between privacy laws and requirements of the United States and the European Union?
- A. HIPAA
- B. Safe Harbor
- C. SOX
- D. GLBA
Answer: B
Explanation:
Due to the lack of an adequate privacy law or protection at the federal level in the United States, European privacy regulations generally prohibit the exporting or sharing of PII from Europe with the United States.
Participation in the Safe Harbor program is voluntary on behalf of an organization, but it does require them to conform to specific requirements and policies that mirror those from the EU.
Thus, organizations can fulfill requirements for data sharing and export and possibly serve customers in the EU.
NEW QUESTION 271
Which of the following is not typically included as a basic phase of the software development life cycle?
- A. Develop
- B. Describe
- C. Define
- D. Design
Answer: B
NEW QUESTION 272
According to OWASP recommendations, active software security testing should include all of the following except ____________.
Response:
- A. Input validation testing
- B. Session initiation testing
- C. Testing for weak cryptography
- D. Testing for error handling
Answer: B
NEW QUESTION 273
When using an IaaS solution, what is a key benefit provided to the customer?
- A. Increased energy and cooling system efficiencies
- B. Metered and priced on the basis of units consumed
- C. Transferred cost of ownership
- D. The ability to scale up infrastructure services based on projected usage
Answer: B
Explanation:
IaaS has a number of key benefits for organizations, which include but are not limited to these: --
- Usage is metered and priced on the basis of units (or instances) consumed. This can also be billed back to specific departments or functions.
- It has an ability to scale up and down infrastructure services based on actual usage. This is particularly useful and beneficial where there are significant spikes and dips within the usage curve for infrastructure.
- It has a reduced cost of ownership. There is no need to buy assets for everyday use, no loss of asset value over time, and reduced costs of maintenance and support.
- It has a reduced energy and cooling costs along with "green IT" environment effect with optimum use of IT resources and systems.
NEW QUESTION 274
What is the only data format permitted with the SOAP API?
- A. HTML
- B. XSML
- C. SAML
- D. XML
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The SOAP protocol only supports the XML data format.
NEW QUESTION 275
You are the security manager for a software development firm. Your company is interested in using a managed cloud service provider for hosting its testing environment. Management is interested in adopting an Agile development style.
This will be typified by which of the following traits?
Response:
- A. Isolated programming experts for specific functional elements
- B. Reliance on a concrete plan formulated during the Define phase
- C. Rigorous, repeated security testing
- D. Short, iterative work periods
Answer: D
NEW QUESTION 276
Which of the following is NOT one of the main intended goals of a DLP solution?
- A. Managing and minimizing risk
- B. Showing due diligence
- C. Preventing malicious insiders
- D. Regulatory compliance
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Data loss prevention (DLP) extends the capabilities for data protection beyond the standard and traditional security controls that are offered by operating systems, application containers, and network devices. DLP is not specifically implemented to counter malicious insiders, and would not be particularly effective in doing so, because a malicious insider with legitimate access would have other ways to obtain data. DLP is a set of practices and controls to manage and minimize risk, comply with regulatory requirements, and show due diligence with the protection of data.
NEW QUESTION 277
......
CCSP EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.itexamsimulator.com/CCSP-brain-dumps.html
Best Quality ISC CCSP Exam Questions: https://drive.google.com/open?id=19i-JQ3RhqI6_TBcTUjTq-2ThqS0i5gN_

