
ISC CCSP Test Engine Practice Test Questions, Exam Dumps
100% Free CCSP Daily Practice Exam With 830 Questions
NEW QUESTION 66
With an application hosted in a cloud environment, who could be the recipient of an eDiscovery order?
- A. Both the cloud provider and cloud customer
- B. The cloud provider
- C. The cloud customer
- D. Users
Answer: A
Explanation:
Either the cloud customer or the cloud provider could receive an eDiscovery order, and in almost all circumstances they would need to work together to ensure compliance.
NEW QUESTION 67
Which component of ITIL pertains to planning, coordinating, executing, and validating changes and rollouts to production environments?
- A. Problem management
- B. Change management
- C. Availability management
- D. Release management
Answer: D
Explanation:
Release management involves planning, coordinating, executing, and validating changes and rollouts to the production environment. Change management is a higher-level component than release management and also involves stakeholder and management approval, rather than specifically focusing the actual release itself.
Availability management is focused on making sure system resources, processes, personnel, and toolsets are properly allocated and secured to meet SLA requirements. Problem management is focused on identifying and mitigating known problems and deficiencies before they occur.
NEW QUESTION 68
A main objective for an organization when utilizing cloud services is to avoid vendor lock-in so as to ensure flexibility and maintain independence.
Which core concept of cloud computing is most related to vendor lock-in?
- A. Portability
- B. Interoperability
- C. Reversibility
- D. Scalability
Answer: A
Explanation:
Explanation/Reference:
Explanation:
Portability is the ability for a cloud customer to easily move their systems, services, and applications among different cloud providers. By avoiding reliance on proprietary APIs and other vendor-specific cloud features, an organization can maintain flexibility to move among the various cloud providers with greater ease. Reversibility refers to the ability for a cloud customer to quickly and easy remove all their services and data from a cloud provider. Interoperability is the ability to reuse services and components for other applications and uses. Scalability refers to the ability of a cloud environment to add or remove resources to meet current demands.
NEW QUESTION 69
What are the two protocols that TLS uses?
- A. Transport and initiate
- B. Handshake and record
- C. Record and transmit
- D. Handshake and transport
Answer: B
Explanation:
Explanation
TLS uses the handshake protocol to establish and negotiate the TLS connection, and it uses the record protocol for the secure transmission of data.
NEW QUESTION 70
With IaaS, what is responsible for handling the security and control over the volume storage space?
- A. Application
- B. Operating system
- C. Hypervisor
- D. Management plane
Answer: B
Explanation:
Explanation
Volume storage is allocated via a LUN to a system and then treated the same as any traditional storage. The operating system is responsible for formatting and securing volume storage as well as controlling all access to it. Applications, although they may use volume storage and have permissions to write to it, are not responsible for its formatting and security. Both a hypervisor and the management plane are outside of an individual system and are not responsible for managing the files and storage within that system.
NEW QUESTION 71
Which of the following data protection methodologies maintains the ability to connect back values to the original values?
Response:
- A. Dynamic mapping
- B. Obfuscation
- C. Anonymization
- D. Tokenization
Answer: D
NEW QUESTION 72
You are the security manager for a small application development company. Your company is considering the use of the cloud for software testing purposes. Which cloud service model is most likely to suit your needs?
- A. SaaS
- B. PaaS
- C. IaaS
- D. LaaS
Answer: B
NEW QUESTION 73
Within a federated identity system, which entity accepts tokens from the identity provider?
- A. Relying party
- B. Servicing party
- C. Assertion manager
- D. Proxy party
Answer: A
Explanation:
Explanation
The relying party is attached to the application or service that a user is trying to access, and it accepts authentication tokens from the user's own identity provider in order to facilitate authentication and access. The other terms provided are all associated with federated systems, but none is the correct choice in this case.
NEW QUESTION 74
Which type of cloud model typically presents the most challenges to a cloud customer during the "destroy" phase of the cloud data lifecycle?
- A. DaaS
- B. IaaS
- C. SaaS
- D. PaaS
Answer: C
Explanation:
Explanation
With many SaaS implementations, data is not isolated to a particular customer but rather is part of the overall application. When it comes to data destruction, a particular challenge is ensuring that all of a customer's data is completely destroyed while not impacting the data of other customers.
NEW QUESTION 75
DLP can be combined with what other security technology to enhance data controls?
- A. DRM
- B. Hypervisors
- C. Kerberos
- D. SIEM
Answer: A
Explanation:
Explanation
DLP can be combined with DRM to protect intellectual property; both are designed to deal with data that falls into special categories. SIEMs are used for monitoring event logs, not live data movement. Kerberos is an authentication mechanism. Hypervisors are used for virtualization.
NEW QUESTION 76
You work for a company that operates a production environment in the cloud. Another company using the same cloud provider is under investigation by law enforcement for racketeering.
Your company should be concerned about this because of the cloud characteristic of
____________.
Response:
- A. Pooled resources
- B. Elasticity
- C. Virtualization
- D. Automated self-service
Answer: A
NEW QUESTION 77
Which aspect of cloud computing pertains to cloud customers only paying for the resources and services they actually use?
- A. Measured service
- B. Metered service
- C. Measured billing
- D. Metered billing
Answer: A
Explanation:
Measured service is the aspect of cloud computing that pertains to cloud services and resources being billed in a metered way, based only on the level of consumption and duration of the cloud customer. Although they sound similar to the correct answer, none of the other choices is the actual cloud terminology.
NEW QUESTION 78
Which of the following pertains to fire safety standards within a data center, specifically with their enormous electrical consumption?
- A. BICSI
- B. IDCA
- C. Uptime Institute
- D. NFPA
Answer: D
Explanation:
Explanation/Reference:
Explanation:
The standards put out by the National Fire Protection Association (NFPA) cover general fire protection best practices for any type of facility, but also specific publications pertaining to IT equipment and data centers.
NEW QUESTION 79
The application normative framework is best described as which of the following?
- A. The complete ONF
- B. A subnet of the ONF
- C. A stand-alone framework for storing security practices for the ONF
- D. A superset of the ONF
Answer: B
Explanation:
Explanation
Remember, there is a one-to-many ratio of ONF to ANF; each organization has one ONF and many ANFs (one for each application in the organization). Therefore, the ANF is a subset of the ONF.
NEW QUESTION 80
The Cloud Security Alliance's (CSA's) Cloud Controls Matrix (CCM) addresses all the following security architecture elements except ____________.
- A. Business drivers
- B. Application security
- C. Physical security
- D. IaaS
Answer: A
NEW QUESTION 81
Which of the cloud cross-cutting aspects relates to the ability to reuse or move components of an application or service?
- A. Portability
- B. Availability
- C. Reversibility
- D. Interoperability
Answer: D
Explanation:
Interoperability is the ease with which one can move or reuse components of an application or service. This is maximized when services are designed without specific dependencies on underlying platforms, operating systems, locations, or cloud providers.
NEW QUESTION 82
Which of the following is the optimal humidity level for a data center, per the guidelines established by the America Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE)?
- A. 20-40 percent relative humidity
- B. 30-50 percent relative humidity
- C. 40-60 percent relative humidity
- D. 50-75 percent relative humidity
Answer: C
Explanation:
The guidelines from ASHRAE establish 40-60 percent relative humidity as optimal for a data center.
NEW QUESTION 83
Which security concept is focused on the trustworthiness of data?
- A. Integrity
- B. Availability
- C. Nonrepudiation
- D. Confidentiality
Answer: A
Explanation:
Integrity is focused on the trustworthiness of data as well as the prevention of unauthorized modification or tampering of it. A prime consideration for maintaining integrity is an emphasis on the change management and configuration management aspects of operations, so that all modifications are predictable, tracked, logged, and verified, whether they are performed by actual human users or systems processes and scripts.
NEW QUESTION 84
Proper implementation of DLP solutions for successful function requires which of the following?
- A. Physical access limitations
- B. Accurate data categorization
- C. Physical presence
- D. USB connectivity
Answer: B
Explanation:
Explanation
DLP tools need to be aware of which information to monitor and which requires categorization (usually done upon data creation, by the data owners). DLPs can be implemented with or without physical access or presence. USB connectivity has nothing to do with DLP solutions.
NEW QUESTION 85
Which jurisdiction lacks specific and comprehensive privacy laws at a national or top level of legal authority?
- A. United States
- B. European Union
- C. Russia
- D. Germany
Answer: A
Explanation:
Explanation/Reference:
Explanation:
The United States lacks a single comprehensive law at the federal level addressing data security and privacy, but there are multiple federal laws that deal with different industries.
NEW QUESTION 86
Configurations and policies for a system can come from a variety of sources and take a variety of formats.
Which concept pertains to the application of a set of configurations and policies that is applied to all systems or a class of systems?
- A. Standards
- B. Hardening
- C. Leveling
- D. Baselines
Answer: D
Explanation:
Baselines are a set of configurations and policies applied to all new systems or services, and they serve as the basis for deploying any other services on top of them. Although standards often form the basis for baselines, the term is applicable in this case. Hardening is the process of securing a system, often through the application of baselines. Leveling is an extraneous but similar term to baselining.
NEW QUESTION 87
......
Use Valid New CCSP Test Notes & CCSP Valid Exam Guide: https://testprep.dumpsvalid.com/CCSP-brain-dumps.html