[2022] Use Valid New CCSP Questions - Top choice Help You Gain Success [Q386-Q409]

Share

[2022] Use Valid New CCSP Questions - Top choice Help You Gain Success

CCSP Exam Practice Materials Collection


ISC2 CCSP Exam Syllabus Topics:

TopicDetails

Cloud Concepts, Architecture and Design (17%)

Understand Cloud Computing Concepts- Cloud Computing Definitions
- Cloud Computing Roles (e.g., cloud service customer, cloud service provider, cloud service partner, cloud service broker)
- Key Cloud Computing Characteristics (e.g., on-demand self-service, broad network access, multi-tenancy, rapid elasticity and scalability, resource pooling, measured service)
- Building Block Technologies (e.g., virtualization, storage, networking, databases, orchestration)
Describe Cloud Reference Architecture- Cloud Computing Activities
- Cloud Service Capabilities (e.g., application capability types, platform capability types, infrastructure capability types
- Cloud Service Categories (e.g., Software as a Service (SaaS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS))
- Cloud Deployment Models (e.g., public, private, hybrid, community)
- Cloud Shared Considerations (e.g., interoperability, portability, reversibility, availability, security, privacy, resiliency, performance, governance, maintenance and versioning, service levels and Service Level Agreements (SLA), auditability, regulatory)
- Impact of Related Technologies (e.g., machine learning, artificial intelligence, blockchain, Internet of Things (IoT), containers, quantum computing)
Understand Security Concepts Relevant to Cloud Computing- Cryptography and Key Management
- Access Control
- Data and Media Sanitization (e.g., overwriting, cryptographic erase)
- Network Security (e.g., network security groups)
- Virtualization Security (e.g., hypervisor security, container security
- Common Threats
Understand Design Principles of Secure Cloud Computing- Cloud Secure Data Lifecycle
- Cloud based Disaster Recovery (DR) and Business Continuity (BC) planning
- Cost Benefit Analysis
- Functional Security Requirements (e.g., portability, interoperability, vendor lock-in)
- Security Considerations for Different Cloud Categories (e.g., Software as a Service (SaaS), Infrastructure as a Service (IaaS), Platform as a Service (PaaS))
Evaluate Cloud Service Providers- Verification Against Criteria (e.g., International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27017, Payment Card Industry Data Security Standard (PCI DSS))
- System/subsystem Product Certifications (e.g., Common Criteria (CC), Federal Information Processing Standard (FIPS) 140-2)

Cloud Data Security (19%)

Describe Cloud Data Concepts- Cloud Data Life Cycle Phases
- Data Dispersion
Design and Implement Cloud Data Storage Architectures- Storage Types (e.g. long term, ephemeral, raw-disk)
- Threats to Storage Types
Design and Apply Data Security Technologies and Strategies- Encryption and Key Management
- Hashing
- Masking
- Tokenization
- Data Loss Prevention (DLP)
- Data Obfuscation
- Data De-identification (e.g., anonymization)
Implement Data Discovery- Structured Data
- Unstructured Data
Implement Data Classification- Mapping
- Labeling
- Sensitive data (e.g., Protected Health Information (PHI), Personally Identifiable Information (PII), card holder data)
Design and Implement Information Rights Management (IRM)- Objectives (e.g., data rights, provisioning, access models)
- Appropriate Tools (e.g., issuing and revocation of certificates)
Plan and Implement Data Retention, Deletion and Archiving Policies- Data Retention Policies
- Data Deletion Procedures and Mechanisms
- Data Archiving Procedures and Mechanisms
- Legal Hold
Design and Implement Auditability, Traceability and Accountability of Data Events- Definition of Event Sources and Requirement of Identity Attribution
- Logging, Storage and Analysis of Data Events
- Chain of Custody and Non-repudiation

Cloud Platform and Infrastructure Security (17%)

Comprehend Cloud Infrastructure Components- Physical Environment
- Network and Communications
- Compute
- Virtualization
- Storage
- Management Plane
Design a Secure Data Center- Logical Design (e.g., tenant partitioning, access control)
- Physical Design (e.g. location, buy or build)
- Environmental Design (e.g., Heating, Ventilation and Air Conditioning (HVAC), multi-vendor pathway connectivity)
Analyze Risks Associated with Cloud Infrastructure- Risk Assessment and Analysis
- Cloud Vulnerabilities, Threats and Attacks
- Virtualization Risks
- Counter-measure Strategies
Design and Plan Security Controls- Physical and Environmental Protection (e.g., on-premise)
- System and Communication Protection
- Virtualization Systems Protection
- Identification, Authentication and Authorization in Cloud Infrastructure
- Audit Mechanisms (e.g., log collection, packet capture)
Plan Disaster Recovery (DR) and Business Continuity (BC)- Risks Related to the Cloud Environment
- Business Requirements (e.g., Recovery Time Objective (RTO), Recovery Point Objective (RPO), Recovery Service Level (RSL))
- Business Continuity/Disaster Recovery Strategy
- Creation, Implementation and Testing of Plan

Cloud Application Security (17%)

Advocate Training and Awareness for Application Security- Cloud Development Basics
- Common Pitfalls
- Common Cloud Vulnerabilities

 

NEW QUESTION 386
Which of the following best describes the Organizational Normative Framework (ONF)?

  • A. A set of application security, and best practices, catalogued and leveraged by the organization
  • B. A framework of containers for some of the components of application security, best practices, catalogued and leveraged by the organization
  • C. A framework of containers for all components of application security, best practices, catalogued and leveraged by the organization.
  • D. A container for components of an application's security, best practices catalogued and leveraged by the organization

Answer: C

Explanation:
Explanation
Option B is incorrect, because it refers to a specific applications security elements, meaning it is about an ANF, not the ONF. C is true, but not as complete as D, making D the better choice. C suggests that the framework contains only "some" of the components, which is why B (which describes "all" components) is better

 

NEW QUESTION 387
What provides the information to an application to make decisions about the authorization level appropriate when granting access?

  • A. Relying party
  • B. Federation
  • C. Identity Provider
  • D. User

Answer: C

Explanation:
Upon successful user authentication, the identity provider gives information about the user to the relying party that it needs to make authorization decisions for granting access as well as the level of access needed.

 

NEW QUESTION 388
Digital investigations have adopted many of the same methodologies and protocols as other types of criminal or scientific inquiries.
What term pertains to the application of scientific norms and protocols to digital investigations?

  • A. Scientific
  • B. Investigative
  • C. Methodological
  • D. Forensics

Answer: D

Explanation:
Explanation/Reference:
Explanation:
Forensics refers to the application of scientific methods and protocols to the investigation of crimes.
Although forensics has traditionally been applied to well-known criminal proceedings and investigations, the term equally applies to digital investigations and methods. Although the other answers provide similar- sounding terms and ideas, none is the appropriate answer in this case.

 

NEW QUESTION 389
Along with humidity, temperature is crucial to a data center for optimal operations and protection of equipment.
Which of the following is the optimal temperature range as set by ASHRAE?

  • A. 44.6 to 60.8 degrees Fahrenheit (7 to 16 degrees Celsius)
  • B. 51.8 to 66.2 degrees Fahrenheit (11 to 19 degrees Celsius)
  • C. 69.8 to 86.0 degrees Fahrenheit (21 to 30 degrees Celsius)
  • D. 64.4 to 80.6 degrees Fahrenheit (18 to 27 degrees Celsius)

Answer: D

Explanation:
Explanation
The American Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE) recommends
64.4 to 80.6 degrees Fahrenheit (or 18 to 27 degrees Celsius) as the optimal temperature range for data centers.
None of these options is the recommendation from ASHRAE.

 

NEW QUESTION 390
Within a federated identity system, which of the following would you be MOST likely to use for sending information for consumption by a relying party?

  • A. WS-Federation
  • B. XML
  • C. HTML
  • D. SAML

Answer: D

Explanation:
The Security Assertion Markup Language (SAML) is the most widely used method for encoding and sending attributes and other information from an identity provider to a relying party.WS- Federation, which is used by Active Directory Federation Services (ADFS), is the second most used method for sending information to a relying party, but it is not a better choice than SAML.
XML is similar to SAML in the way it encodes and labels data, but it does not have all of the required extensions that SAML does. HTML is not used within federated systems at all.

 

NEW QUESTION 391
What is the biggest concern with hosting a key management system outside of the cloud environment?

  • A. Availability
  • B. Portability
  • C. Integrity
  • D. Confidentiality

Answer: A

Explanation:
When a key management system is outside of the cloud environment hosting the application, availability is a primary concern because any access issues with the encryption keys will render the entire application unusable.

 

NEW QUESTION 392
Countermeasures for protecting cloud operations against external attackers include all of the following except:

  • A. Regular and detailed configuration/change management activities
  • B. Hardened devices and systems, including servers, hosts, hypervisors, and virtual machines.
  • C. Detailed and extensive background checks.
  • D. Continual monitoring for anomalous activity.

Answer: C

Explanation:
Explanation
Background checks are controls for attenuating potential threats from internal actors; external threats aren't likely to submit to background checks.

 

NEW QUESTION 393
What are the U.S. State Department controls on technology exports known as?

  • A. EAL
  • B. DRM
  • C. EAR
  • D. ITAR

Answer: D

Explanation:
Explanation
Explanation:
ITAR is a Department of State program. Evaluation assurance levels are part of the Common Criteria standard from ISO. Digital rights management tools are used for protecting electronic processing of intellectual property.

 

NEW QUESTION 394
What is the biggest negative to leasing space in a data center versus building or maintain your own?

  • A. Certification
  • B. Costs
  • C. Control
  • D. Regulation

Answer: C

Explanation:
Explanation/Reference:
Explanation:
When leasing space in a data center, an organization will give up a large degree of control as to how it is built and maintained, and instead must conform to the policies and procedures of the owners and operators of the data center.

 

NEW QUESTION 395
Which of the following provides assurance, to a predetermined acceptable level of certainty, that an entity is indeed who they claim to be?

  • A. Authorization
  • B. Proofing
  • C. Identification
  • D. Authentication

Answer: D

Explanation:
Explanation
Authentication goes a step further than identification by providing a means for proving an entity's identification. Authentication is most commonly done through mechanisms such as passwords. Identification involves ascertaining who the entity is, but without a means of proving it, such as a name or user ID.
Authorization occurs after authentication and sets access permissions and other privileges within a system or application for the user. Proofing is not a term that is relevant to the question.

 

NEW QUESTION 396
At which layer does the IPSec protocol operate to encrypt and protect communications between two parties?

  • A. Data link
  • B. Transport
  • C. Application
  • D. Network

Answer: D

 

NEW QUESTION 397
There are many situations when testing a BCDR plan is appropriate or mandated.
Which of the following would not be a necessary time to test a BCDR plan?

  • A. After software updates
  • B. After major configuration changes
  • C. After regulatory changes
  • D. Annually

Answer: C

Explanation:
Regulatory changes by themselves would not trigger a need for new testing of a BCDR plan. Any changes necessary for regulatory compliance would be accomplished through configuration changes or software updates, which in turn would then trigger the necessary new testing. Annual testing is crucial to any BCDR plan. Also, any time major configuration changes or software updates are done, the plan should be evaluated and tested to ensure it is still valid and complete.

 

NEW QUESTION 398
When using an IaaS solution, what is a key benefit provided to the customer?

  • A. Transferred cost of ownership
  • B. The ability to scale up infrastructure services based on projected usage
  • C. Metered and priced on the basis of units consumed
  • D. Increased energy and cooling system efficiencies

Answer: C

Explanation:
Explanation
Explanation:
IaaS has a number of key benefits for organizations, which include but are not limited to these: -- - Usage is metered and priced on the basis of units (or instances) consumed. This can also be billed back to specific departments or functions.
- It has an ability to scale up and down infrastructure services based on actual usage. This is particularly useful and beneficial where there are significant spikes and dips within the usage curve for infrastructure.
- It has a reduced cost of ownership. There is no need to buy assets for everyday use, no loss of asset value over time, and reduced costs of maintenance and support.
- It has a reduced energy and cooling costs along with "green IT" environment effect with optimum use of IT resources and systems.

 

NEW QUESTION 399
Access should be based on ____________.
Response:

  • A. User requirements and management requests
  • B. Optimum performance and security provision
  • C. Business needs and acceptable risk
  • D. Regulatory mandates

Answer: C

 

NEW QUESTION 400
Over time, what is a primary concern for data archiving?

  • A. Regulatory changes
  • B. Recoverability
  • C. Format of archives
  • D. Size of archives

Answer: B

Explanation:
Over time, maintaining the ability to restore and read archives is a primary concern for data archiving. As technologies change and new systems are brought in, it is imperative for an organization to ensure they are still able to restore and access archives for the duration of the required retention period.

 

NEW QUESTION 401
Which of the following is a possible negative aspect of bit-splitting?

  • A. Greater chance of physical theft of assets
  • B. Some risk to availability, depending on the implementation
  • C. Loss of public image
  • D. A small fire hazard

Answer: B

 

NEW QUESTION 402
Which aspect of archiving must be tested regularly for the duration of retention requirements?

  • A. Portability
  • B. Auditability
  • C. Availability
  • D. Recoverability

Answer: D

Explanation:
Explanation
In order for any archiving system to be deemed useful and compliant, regular tests must be performed to ensure the data can still be recovered and accessible, should it ever be needed, for the duration of the retention requirements.

 

NEW QUESTION 403
What type of masking would you employ to produce a separate data set for testing purposes based on production data without any sensitive information?

  • A. Replicated
  • B. Static
  • C. Dynamic
  • D. Tokenized

Answer: B

Explanation:
Explanation
Static masking involves taking a data set and replacing sensitive fields and values with non-sensitive or garbage data. This is done to enable testing of an application against data that resembles production data, both in size and format, but without containing anything sensitive. Dynamic masking involves the live and transactional masking of data while an application is using it. Tokenized would refer to tokenization, which is the replacing of sensitive data with a key value that can later be matched back to the original value, and although it could be used as part of the production of test data, it does not refer to the overall process.
Replicated is provided as an erroneous answer, as replicated data would be identical in value and would not accomplish the production of a test set.

 

NEW QUESTION 404
Which of the cloud cross-cutting aspects relates to the oversight of processes and systems, as well as to ensuring their compliance with specific policies and regulations?

  • A. Regulatory requirements
  • B. Service-level agreements
  • C. Governance
  • D. Auditability

Answer: D

Explanation:
Auditing involves reports and evidence that show user activity, compliance with controls and regulations, the systems and processes that run and what they do, as well as information and data access and modification records. A cloud environment adds additional complexity to traditional audits because the cloud customer will not have the same level of access to systems and data as they would in a traditional data center.

 

NEW QUESTION 405
Many aspects and features of cloud computing can make eDiscovery compliance more difficult or costly.
Which aspect of cloud computing would be the MOST complicating factor?

  • A. Broad network access
  • B. Portability
  • C. Measured service
  • D. Multitenancy

Answer: D

Explanation:
Explanation
With multitenancy, multiple customers share the same physical hardware and systems. With the nature of a cloud environment and how it writes data across diverse systems that are shared by others, the process of eDiscovery becomes much more complicated. Administrators cannot pull physical drives or easily isolate which data to capture. They not only have to focus on which data they need to collect, while ensuring they find all of it, but they also have to make sure that other data is not accidently collected and exposed along with it.
Measured service is the aspect of a cloud where customers only pay for the services they are actually using, and for the duration of their use. Portability refers to the ease with which an application or service can be moved among different cloud providers. Broad network access refers to the nature of cloud services being accessed via the public Internet, either with or without secure tunneling technologies. None of these concepts would pertain to eDiscovery.

 

NEW QUESTION 406
What are the U.S. Commerce Department controls on technology exports known as?

  • A. EAL
  • B. EAR
  • C. ITAR
  • D. DRM

Answer: B

Explanation:
Explanation
EAR is a Commerce Department program. Evaluation assurance levels are part of the Common Criteria standard from ISO. Digital rights management tools are used for protecting electronic processing of intellectual property.

 

NEW QUESTION 407
Which format is the most commonly used standard for exchanging information within a federated identity system?

  • A. XML
  • B. HTML
  • C. SAML
  • D. JSON

Answer: C

Explanation:
Explanation
Security Assertion Markup Language (SAML) is the most common data format for information exchange within a federated identity system. It is used to transmit and exchange authentication and authorization data.XML is similar to SAML, but it's used for general-purpose data encoding and labeling and is not used for the exchange of authentication and authorization data in the way that SAML is for federated systems. JSON is used similarly to XML, as a text-based data exchange format that typically uses attribute-value pairings, but it's not used for authentication and authorization exchange. HTML is used only for encoding web pages for web browsers and is not used for data exchange--and certainly not in a federated system.

 

NEW QUESTION 408
What are the two protocols that TLS uses?

  • A. Transport and initiate
  • B. Record and transmit
  • C. Handshake and transport
  • D. Handshake and record

Answer: D

Explanation:
Explanation/Reference:
Explanation:
TLS uses the handshake protocol to establish and negotiate the TLS connection, and it uses the record protocol for the secure transmission of data.

 

NEW QUESTION 409
......

Maximum Grades By Making ready With CCSP Dumps: https://www.prep4sureguide.com/CCSP-prep4sure-exam-guide.html

Get Latest and 100% Accurate CCSP Exam Questions: https://drive.google.com/open?id=1CV16xU3d6TL9sz8TsiJwY_87bivugggt