Verified CCSP dumps Q&As - 100% Pass from ITPassLeader [Q475-Q499]

Share

Verified CCSP dumps Q&As - 100% Pass from ITPassLeader

Pass CCSP Exam in First Attempt Guaranteed 2023 Dumps!


Cloud Application Security (17%):

  • Utilize verified secure software;
  • Validate Cloud software – This area covers the security testing methodologies and functional testing;
  • Understand the basics of Cloud application architecture;

 

NEW QUESTION # 475
Which of the following roles is responsible for peering with other cloud services and providers?

  • A. Cloud service developer
  • B. Cloud auditor
  • C. Cloud service broker
  • D. Inter-cloud provider

Answer: D

Explanation:
Explanation
The inter-cloud provider is responsible for peering with other cloud services and providers, as well as overseeing and managing federations and federated services.


NEW QUESTION # 476
Which aspect of cloud computing pertains to cloud customers only paying for the resources and services they actually use?

  • A. Measured billing
  • B. Metered billing
  • C. Metered service
  • D. Measured service

Answer: D

Explanation:
Measured service is the aspect of cloud computing that pertains to cloud services and resources being billed in a metered way, based only on the level of consumption and duration of the cloud customer.
Although they sound similar to the correct answer, none of the other choices is the actual cloud terminology.


NEW QUESTION # 477
When reviewing the BIA after a cloud migration, the organization should take into account new factors related to data breach impacts. One of these new factors is:

  • A. Many states have data breach notification laws.
  • B. Breaches can cause the loss of intellectual property.
  • C. Breaches can cause the loss of proprietary data.
  • D. Legal liability can't be transferred to the cloud provider.

Answer: D

Explanation:
State notification laws and the loss of proprietary data/intellectual property pre-existed the cloud; only the lack of ability to transfer liability is new.


NEW QUESTION # 478
DLP solutions can aid in deterring loss due to which of the following?

  • A. Malicious disclosure
  • B. Power failure
  • C. Performance
  • D. Bad policy

Answer: A

Explanation:
Explanation
DLP tools can identify outbound traffic that violates the organization's policies. DLP will not protect against losses due to performance issues or power failures. The DLP solution must be configured according to the organization's policies, so bad policies will attenuate the effectiveness of DLP tools, not the other way around.


NEW QUESTION # 479
One of the main components of system audits is the ability to track changes over time and to match these changes with continued compliance and internal processes.
Which aspect of cloud computing makes this particular component more challenging than in a traditional data center?

  • A. Portability
  • B. Elasticity
  • C. Resource pooling
  • D. Virtualization

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Cloud services make exclusive use of virtualization, and systems change over time, including the addition, subtraction, and reimaging of virtual machines. It is extremely unlikely that the exact same virtual machines and images used in a previous audit would still be in use or even available for a later audit, making the tracking of changes over time extremely difficult, or even impossible. Elasticity refers to the ability to add and remove resources from a system or service to meet current demand, and although it plays a factor in making the tracking of virtual machines very difficult over time, it is not the best answer in this case.
Resource pooling pertains to a cloud environment sharing a large amount of resources between different customers and services. Portability refers to the ability to move systems or services easily between different cloud providers.


NEW QUESTION # 480
Which cloud service category would be most ideal for a cloud customer that is developing software to test its applications among multiple hosting providers to determine the best option for its needs?

  • A. SaaS
  • B. DaaS
  • C. IaaS
  • D. PaaS

Answer: D

Explanation:
Platform as a Service would allow software developers to quickly and easily deploy their applications among different hosting providers for testing and validation in order to determine the best option. Although IaaS would also be appropriate for hosting applications, it would require too much configuration of application servers and libraries in order to test code. Conversely, PaaS would provide a ready-to-use environment from the onset.
DaaS would not be appropriate in any way for software developers to use to deploy applications. IaaS would not be appropriate in this scenario because it would require the developers to also deploy and maintain the operating system images or to contract with another firm to do so. SaaS, being a fully functional software platform, would not be appropriate for deploying applications into.


NEW QUESTION # 481
DAST checks software functionality in ____________.

  • A. A runtime state
  • B. The production environment
  • C. An IaaS configuration
  • D. The cloud

Answer: A


NEW QUESTION # 482
Which type of cloud model typically presents the most challenges to a cloud customer during the "destroy" phase of the cloud data lifecycle?

  • A. DaaS
  • B. SaaS
  • C. IaaS
  • D. PaaS

Answer: B

Explanation:
With many SaaS implementations, data is not isolated to a particular customer but rather is part of the overall application. When it comes to data destruction, a particular challenge is ensuring that all of a customer's data is completely destroyed while not impacting the data of other customers.


NEW QUESTION # 483
What aspect of data center planning occurs first?
Response:

  • A. Logical design
  • B. Audit
  • C. Policy revision
  • D. Physical design

Answer: D


NEW QUESTION # 484
Which of the following is a restriction that can be enforced by information rights management (IRM) that is not possible for traditional file system controls?

  • A. Print
  • B. Delete
  • C. Read
  • D. Modify

Answer: A

Explanation:
Explanation/Reference:
Explanation:
IRM allows an organization to control who can print a set of information. This is not be possible under traditional file system controls, where if a user can read a file, they are able to print it as well.


NEW QUESTION # 485
Along with humidity, temperature is crucial to a data center for optimal operations and protection of equipment.
Which of the following is the optimal temperature range as set by ASHRAE?

  • A. 64.4 to 80.6 degrees Fahrenheit (18 to 27 degrees Celsius)
  • B. 69.8 to 86.0 degrees Fahrenheit (21 to 30 degrees Celsius)
  • C. 44.6 to 60.8 degrees Fahrenheit (7 to 16 degrees Celsius)
  • D. 51.8 to 66.2 degrees Fahrenheit (11 to 19 degrees Celsius)

Answer: A

Explanation:
The American Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE) recommends 64.4 to 80.6 degrees Fahrenheit (or 18 to 27 degrees Celsius) as the optimal temperature range for data centers. None of these options is the recommendation from ASHRAE.


NEW QUESTION # 486
Different certifications and standards take different approaches to data center design and operations. Although many traditional approaches use a tiered methodology, which of the following utilizes a macro-level approach to data center design?

  • A. NFPA
  • B. IDCA
  • C. BICSI
  • D. Uptime Institute

Answer: B

Explanation:
Explanation
The Infinity Paradigm of the International Data Center Authority (IDCA) takes a macro-level approach to data center design. The IDCA does not use a specific, focused approach on specific components to achieve tier status. Building Industry Consulting Services International (BICSI) issues certifications for data center cabling. The National Fire Protection Association (NFPA) publishes a broad range of fire safety and design standards for many different types of facilities. The Uptime Institute publishes the most widely known and used standard for data center topologies and tiers.


NEW QUESTION # 487
Which of the following actions will NOT make data part of the "create" phase of the cloud data lifecycle?

  • A. Modifying data
  • B. Constructing new data
  • C. Importing data
  • D. Modifying metadata

Answer: D

Explanation:
Explanation
Although the initial phase is called "create," it can also refer to modification. In essence, any time data is considered "new," it is in the create phase. This can come from data that is newly created, data that is imported into a system and is new to that system, or data that is already present and modified into a new form or value.
Modifying the metadata does not change the actual data.


NEW QUESTION # 488
Whereas a contract articulates overall priorities and requirements for a business relationship, which artifact enumerates specific compliance requirements, metrics, and response times?

  • A. Service level amendment
  • B. Service level agreement
  • C. Service level contract
  • D. Service compliance contract

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The service level agreement (SLA) articulates minimum requirements for uptime, availability, processes, customer service and support, security controls, auditing requirements, and any other key aspect or requirement of the contract. Although the other choices sound similar to the correct answer, none is the proper term for this concept.


NEW QUESTION # 489
ISO/IEC has established international standards for many aspects of computing and any processes or procedures related to information technology.
Which ISO/IEC standard has been established to provide a framework for handling eDiscovery processes?

  • A. ISO/IEC 27050
  • B. ISO/IEC 27002
  • C. ISO/IEC 27040
  • D. ISO/IEC 27001

Answer: A

Explanation:
ISO/IEC 27050 strives to establish an internationally accepted standard for eDiscovery processes and best practices. It encompasses all steps of the eDiscovery process, including the identification, preservation, collection, processing, review, analysis, and the final production of the requested data archive. ISO/IEC 27001 is a general security specification for an information security management system. ISO/IEC 27002 gives best practice recommendations for information security management. ISO/IEC 27040 is focused on the security of storage systems.


NEW QUESTION # 490
Which data point that auditors always desire is very difficult to provide within a cloud environment?

  • A. Access policy
  • B. Systems architecture
  • C. Privacy statement
  • D. Baselines

Answer: B

Explanation:
Explanation/Reference:
Explanation:
Cloud environments are constantly changing and often span multiple physical locations. A cloud customer is also very unlikely to have knowledge and insight into the underlying systems architecture in a cloud environment. Both of these realities make it very difficult, if not impossible, for an organization to provide a comprehensive systems design document.


NEW QUESTION # 491
Which data state would be most likely to use TLS as a protection mechanism?

  • A. Archived
  • B. Data in use
  • C. Data in transit
  • D. Data at rest

Answer: C

Explanation:
TLS would be used with data in transit, when packets are exchanged between clients or services and sent across a network. During the data-in-use state, the data is already protected via a technology such as TLS as it is exchanged over the network and then relies on other technologies such as digital signatures for protection while being used. The data-at-rest state primarily uses encryption for stored file objects. Archived data would be the same as data at rest.


NEW QUESTION # 492
What does static application security testing (SAST) offer as a tool to the testers that makes it unique compared to other common security testing methodologies?

  • A. Production system scanning
  • B. Live testing
  • C. Source code access
  • D. Injection attempts

Answer: C

Explanation:
Static application security testing (SAST) is conducted against offline systems with previous knowledge of them, including their source code. Live testing is not part of static testing but rather is associated with dynamic testing. Production system scanning is not appropriate because static testing is done against offline systems. Injection attempts are done with many different types of testing and are not unique to one particular type. It is therefore not the best answer to the question.


NEW QUESTION # 493
Which technology is most associated with tunneling?
Response:

  • A. GRE
  • B. IaaS
  • C. IPSec
  • D. XML

Answer: A


NEW QUESTION # 494
Your company maintains an on-premises data center for daily production activities but wants to use a cloud service to augment this capability during times of increased demand (cloud bursting).
Which deployment model would probably best suit the company's needs?
Response:

  • A. Hybrid
  • B. Private
  • C. Community
  • D. Public

Answer: A


NEW QUESTION # 495
Which of the following is the optimal temperature for a data center, per the guidelines established by the America Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE)?

  • A. 44.6-60-8degF(7-16degC)
  • B. 69.8-86.0degF (21-30degC)
  • C. 51.8-66.2degF(11-19degC)
  • D. 64.4-80.6degF(18-27degC)

Answer: D

Explanation:
Explanation
The guidelines from ASHRAE establish 64.4-80.6degF (18-27degC) as the optimal temperature for a data center.


NEW QUESTION # 496
Although the United States does not have a single, comprehensive privacy and regulatory framework, a number of specific regulations pertain to types of data or populations.
Which of the following is NOT a regulatory system from the United States federal government?

  • A. FISMA
  • B. PCI DSS
  • C. SOX
  • D. HIPAA

Answer: B

Explanation:
Explanation
The Payment Card Industry Data Security Standard (PCI DSS) pertains to organizations that handle credit card transactions and is an industry-regulatory standard, not a governmental one. The Sarbanes-Oxley Act (SOX) was passed in 2002 and pertains to financial records and reporting, as well as transparency requirements for shareholders and other stakeholders. The Health Insurance Portability and Accountability Act (HIPAA) was passed in 1996 and pertains to data privacy and security for medical records. FISMA refers to the Federal Information Security Management Act of 2002 and pertains to the protection of all US federal government IT systems, with the exception of national security systems.


NEW QUESTION # 497
Which of the following is NOT part of a retention policy?

  • A. Format
  • B. Costs
  • C. Accessibility
  • D. Duration

Answer: B

Explanation:
Explanation/Reference:
Explanation:
The data retention policy covers the duration, format, technologies, protection, and accessibility of archives, but does not address the specific costs of its implementation and maintenance.


NEW QUESTION # 498
You are the security manager for a small surgical center. Your organization is reviewing upgrade options for its current, on-premises data center. In order to best meet your needs, which one of the following options would you recommend to senior management?
Response:

  • A. Renting private cloud space in a Tier 2 data center
  • B. Staying with the current data center
  • C. Building a completely new data center
  • D. Leasing a data center that is currently owned by another firm

Answer: C


NEW QUESTION # 499
......

CCSP Dumps Full Questions - Exam Study Guide: https://exam-labs.itpassleader.com/ISC/CCSP-dumps-pass-exam.html

0
0
0
0