Pass Your CCSP Exam Easily - Real CCSP Practice Dump Updated Nov 12, 2021 [Q333-Q352]

Share

Pass Your CCSP Exam Easily - Real CCSP Practice Dump Updated Nov 12, 2021

2021 Realistic Verified Free ISC CCSP Exam Questions 

NEW QUESTION 333
In order to comply with regulatory requirements, which of the following secure erasure methods would be available to a cloud customer using volume storage within the IaaS service model?

  • A. Demagnetizing
  • B. Shredding
  • C. Degaussing
  • D. Cryptographic erasure

Answer: D

Explanation:
Explanation
Cryptographic erasure is a secure method to destroy data by destroying the keys that were used to encrypt it.
This method is universally available for volume storage on IaaS and is also extremely quick. Shredding, degaussing, and demagnetizing are all physically destructive methods that would not be permitted within a cloud environment using shared resources.

 

NEW QUESTION 334
APIs are defined as which of the following?

  • A. A set of routines, standards, protocols, and tools for building software applications to access a web-based software application or tool
  • B. A set of standards for building software applications to access a web-based software application or tool
  • C. A set of routines and tools for building software applications to access web-based software applications
  • D. A set of protocols, and tools for building software applications to access a web-based software application or tool

Answer: A

Explanation:
Explanation
All the answers are true, but B is the most complete.

 

NEW QUESTION 335
Which of the following are cloud computing roles?

  • A. Cloud service broker and user
  • B. Cloud customer and financial auditor
  • C. CSP and backup service provider
  • D. Cloud service auditor and object

Answer: C

Explanation:
Explanation
The following groups form the key roles and functions associated with cloud computing. They do not constitute an exhaustive list but highlight the main roles and functions within cloud computing:
- Cloud customer: An individual or entity that utilizes or subscribes to cloud based services or resources.
- CSP: A company that provides cloud-based platform, infrastructure, application, or storage services to other organizations or individuals, usually for a fee; otherwise known to clients "as a service.
- Cloud backup service provider: A third-party entity that manages and holds operational responsibilities for cloud-based data backup services and solutions to customers from a central data center.
- CSB: Typically a third-party entity or company that looks to extend or enhance value to multiple customers of cloud-based services through relationships with multiple CSPs. It acts as a liaison between cloud services customers and CSPs, selecting the best provider for each customer and monitoring the services. The CSB can be utilized as a "middleman" to broker the best deal and customize services to the customer's requirements.
May also resell cloud services.
- Cloud service auditor: Third-party organization that verifies attainment of SLAs.

 

NEW QUESTION 336
Which cloud storage type uses an opaque value or descriptor to categorize and organize data?

  • A. Unstructured
  • B. Volume
  • C. Structured
  • D. Object

Answer: A

 

NEW QUESTION 337
What's a potential problem when object storage versus volume storage is used within IaaS for application use and dependency?

  • A. Object storage is dependent on access control from the host server.
  • B. Object storage may have availability issues.
  • C. Object storage is only optimized for small files.
  • D. Object storage is its own system, and data consistency depends on replication.

Answer: D

Explanation:
Object storage runs on its own independent systems, which have their own redundancy and distribution.
To ensure data consistency, sufficient time is needed for objects to fully replicate to all potential locations before being accessed. Object storage is optimized for high availability and will not be any less reliable than any other virtual machine within a cloud environment. It is hosted on a separate system that does not have dependencies in local host servers for access control, and it is optimized for files of all different sizes and uses.

 

NEW QUESTION 338
Different certifications and standards take different approaches to data center design and operations. Although many traditional approaches use a tiered methodology, which of the following utilizes a macro-level approach to data center design?

  • A. BICSI
  • B. Uptime Institute
  • C. NFPA
  • D. IDCA

Answer: D

Explanation:
Explanation/Reference:
Explanation:
The Infinity Paradigm of the International Data Center Authority (IDCA) takes a macro-level approach to data center design. The IDCA does not use a specific, focused approach on specific components to achieve tier status. Building Industry Consulting Services International (BICSI) issues certifications for data center cabling.
The National Fire Protection Association (NFPA) publishes a broad range of fire safety and design standards for many different types of facilities. The Uptime Institute publishes the most widely known and used standard for data center topologies and tiers.

 

NEW QUESTION 339
SOC Type 1 reports are considered "restricted use," in that they are intended only for limited audiences and purposes.
Which of the following is NOT a population that would be appropriate for a SOC Type 1 report?

  • A. Auditors
  • B. Potential clients
  • C. The service organization
  • D. Current clients

Answer: B

Explanation:
Potential clients are not served by SOC Type 1 audits. A Type 2 or Type 3 report would be appropriate for potential clients. SOC Type 1 reports are intended for restricted use, where only the service organization itself, current clients, or auditors would have access to them.

 

NEW QUESTION 340
Which of the following characteristics is associated with digital rights management (DRM) solutions (sometimes referred to as information rights management, or IRM)?

  • A. Trepidation
  • B. Resistance
  • C. Persistence
  • D. Influence

Answer: C

 

NEW QUESTION 341
Within a SaaS environment, what is the responsibility on the part of the cloud customer in regard to procuring the software used?

  • A. Development
  • B. Licensing
  • C. Purchasing
  • D. Maintenance

Answer: B

Explanation:
Explanation
Within a SaaS implementation, the cloud customer licenses the use of the software from the cloud provider because SaaS delivers a fully functional application to the customer. With SaaS, the cloud provider is responsible for the entire software application and any necessary infrastructure to develop, run, and maintain it. The purchasing, development, and maintenance are fully the responsibility of the cloud provider.

 

NEW QUESTION 342
Which format is the most commonly used standard for exchanging information within a federated identity system?

  • A. HTML
  • B. JSON
  • C. XML
  • D. SAML

Answer: D

Explanation:
Security Assertion Markup Language (SAML) is the most common data format for information exchange within a federated identity system. It is used to transmit and exchange authentication and authorization data.XML is similar to SAML, but it's used for general-purpose data encoding and labeling and is not used for the exchange of authentication and authorization data in the way that SAML is for federated systems. JSON is used similarly to XML, as a text-based data exchange format that typically uses attribute-value pairings, but it's not used for authentication and authorization exchange. HTML is used only for encoding web pages for web browsers and is not used for data exchange--and certainly not in a federated system.

 

NEW QUESTION 343
A denial of service (DoS) attack can potentially impact all customers within a cloud environment with the continued allocation of additional resources. Which of the following can be useful for a customer to protect themselves from a DoS attack against another customer?

  • A. Borrows
  • B. Limits
  • C. Shares
  • D. Reservations

Answer: D

 

NEW QUESTION 344
You are the security manager for a software development firm. Your company is interested in using a managed cloud service provider for hosting its testing environment. Management is interested in adopting an Agile development style.
This will be typified by which of the following traits?

  • A. Rigorous, repeated security testing
  • B. Short, iterative work periods
  • C. Isolated programming experts for specific functional elements
  • D. Reliance on a concrete plan formulated during the Define phase

Answer: B

 

NEW QUESTION 345
An organization could have many reasons that are common throughout the industry to activate a BCDR situation. Which of the following is NOT a typical reason to activate a BCDR plan?
Response:

  • A. Staff loss
  • B. Utility outage
  • C. Natural disaster
  • D. Terrorist attack

Answer: A

 

NEW QUESTION 346
Every cloud service provider that opts to join the CSA STAR program registry must complete a
___________.

  • A. Consensus Assessment Initiative Questionnaire (CAIQ)
  • B. SOC 2, Type 2 audit report
  • C. NIST 800-37 RMF audit
  • D. ISO 27001 ISMS review

Answer: A

 

NEW QUESTION 347
The management plane is used to administer a cloud environment and perform administrative tasks across a variety of systems, but most specifically it's used with the hypervisors. What does the management plane typically leverage for this orchestration?

  • A. TLS
  • B. Scripts
  • C. XML
  • D. APIs

Answer: D

Explanation:
The management plane uses APIs to execute remote calls across the cloud environment to various management systems, especially hypervisors. This allows a centralized administrative interface, often a web portal, to orchestrate tasks throughout an enterprise. Scripts may be utilized to execute API calls, but they are not used directly to interact with systems. XML is used for data encoding and transmission, but not for executing remote calls. TLS is used to encrypt communications and may be used with API calls, but it is not the actual process for executing commands.

 

NEW QUESTION 348
Who will determine data classifications for the cloud customer?

  • A. Regulators
  • B. The cloud customer
  • C. The cloud provider
  • D. NIST

Answer: B

 

NEW QUESTION 349
Which of the following is considered a physical control?

  • A. Doors
  • B. Fences
  • C. Carpets
  • D. Ceilings

Answer: B

Explanation:
Fences are physical controls; carpets and ceilings are architectural features, and a door is not necessarily a control: the lock on the door would be a physical security control. Although you might think of a door as a potential answer, the best answer is the fence; the exam will have questions where more than one answer is correct, and the answer that will score you points is the one that is most correct.

 

NEW QUESTION 350
What is the risk to the organization posed by dashboards that display data discovery results?
Response:

  • A. Flawed management decisions based on massaged displays
  • B. Raised incidence of physical theft
  • C. Higher likelihood of inadvertent disclosure
  • D. Increased chance of external penetration

Answer: A

 

NEW QUESTION 351
Which protocol, as a part of TLS, handles the actual secure communications and transmission of data?

  • A. Record
  • B. Negotiation
  • C. Transfer
  • D. Handshake

Answer: A

Explanation:
The TLS record protocol is the actual secure communications method for transmitting data; it's responsible for encrypting and authenticating packets throughout their transmission between the parties, and in some cases it also performs compression. The TLS handshake protocol is what negotiates and establishes the TLS connection between two parties and enables the secure communications channel to then handle data transmissions. Negotiation and transfer are not protocols under TLS.

 

NEW QUESTION 352
......

CCSP Real Exam Questions and Answers FREE: https://www.pass4guide.com/CCSP-exam-guide-torrent.html

CCSP Exam Questions | Real CCSP Practice Dumps: https://drive.google.com/open?id=1UhKIGr_D4TtOY4on6WDACHrV7uCripAz