試験準備には欠かさないトップクラスのCloud Security Alliance CCSK試験学習ガイド練習問題最新版 [Q77-Q92]

Share

試験準備には欠かさないトップクラスのCloud Security Alliance CCSK試験学習ガイド練習問題最新版

今すぐCCSK問題を使おうCCSK問題集PDFで合格しよう


CCSK試験は、クラウドセキュリティの複数の領域での個人の知識とスキルをテストするように設計されています。これらには、クラウドアーキテクチャ、データセキュリティ、コンプライアンスと法的問題、およびアイデンティティとアクセス管理が含まれます。試験は60の多肢選択問題から構成され、90分以内に完了する必要があります。試験の合格点は80%です。


クラウド・セキュリティ・アライアンスCCSK(クラウド・セキュリティ・ナレッジの証明書)試験は、クラウドセキュリティに焦点を当てたベンダー中立の認定資格です。この試験は、クラウドコンピューティングにおけるセキュリティのベストプラクティスを促進することを目的とする非営利団体であるクラウド・セキュリティ・アライアンス(CSA)によって作成されました。CCSK試験は、クラウドセキュリティの概念、原則、およびベストプラクティスに関する個人の知識をテストするように設計されています。試験は、CSAのクラウドコンピューティングの重要な焦点領域に関するクラウドセキュリティガイダンスに基づいています。

 

質問 # 77
The basis for deciding which laws are most appropriate in a situation where conflicting laws exist. refers to:

  • A. Criminal law
  • B. The Restatement(Second) Conflict of Law
  • C. Tort law
  • D. Doctrine of proper law

正解:B

解説:
The Restatement(Second) Conflict of Law refers to a collation of developments in common law that help the courts stay up with changes. Many states have conflicting laws. and judges use these restatements to assist them in determining which laws should apply when conflicts occur.


質問 # 78
Policy documentation and training is a:

  • A. Technical control
  • B. Logical control
  • C. Physical control
  • D. Administrative control

正解:D

解説:
There are three, commonly accepted forms of Controls:
Administrative-These are the laws, regulations, policies, practices and guidelines that govern the overall requirements and controls for an Information Security or other operational risk program. For example, a law or regulation may require merchants and financial institutions to protect and implement controls for customer account data to prevent identity theft. The business, in order to comply with the law or regulation, may adopt policies and procedures laying out the internal requirements for protecting this data, which requirements are a form of control.
Logical -These are the virtual, application and technical controls (systems and software), such as firewalls, antivirus software, encryption and maker/checker application routines.
Physical -Whereas a firewall provides a "logical" key to obtain access to a network, a "physical" key to a door can be used to gain access to an office space or storage room. Other examples of physical controls are video surveillance systems, gates and barricades, the use of guards or other personnel to govern access to an office, and remote backup facilities.


質問 # 79
Which of the following is not an abuse or misuse of cloud services?

  • A. Launching DDoS Attacks
  • B. Data Deletion
  • C. Email Spam
  • D. Phishing campaigns

正解:B

解説:
Please note here and understand the meaning of phrase "abuse or misuse of cloud Services". This phrase means to launch attacks or campaign by using cloud as a platform, mostly, public cloud.


質問 # 80
Which provides guidelines for organizational information security standards including the selection, implementation, and management of controls taking into consideration the organization's information security risk environments?

  • A. NIST 800-9
  • B. FIPS 140-2
  • C. ISO 27001
  • D. ISO 27002

正解:D

解説:
ISO 27002 is a standard which provides detailed description of security controls and how they need to implemented to provide effective ISMS.


質問 # 81
Which one of the following is an example of misuse or abuse of cloud services?

  • A. Honeypot
  • B. DDoS Attack
  • C. Account Hijacking
  • D. XSS attacks

正解:B

解説:
Public cloud platform can be used to launch DDoS attack on other platforms.
Please note here and understand the meaning of phrase "abuse or misuse of cloud Services" This phrase means to launch attacks or campaign by using cloud as a platform. mostly. public cloud.


質問 # 82
Which of the following uses security and encryption as means to prevent unauthorized copying and limitations on distribution to only those who pay?

  • A. Data Dispersion
  • B. Data Encryption
  • C. IPSEC
  • D. Digital Rights Management(DRM)

正解:D

解説:
Digital rights management(DRM)was designed to focus on security and encryption as a means of preventing unauthorized copying and limitations on distribution of content to only those authorized(purchasers).


質問 # 83
Which is the primary tool used to manage identity and access management of resources spread across hundreds of different clouds and resources?

  • A. Active Directory
  • B. Entitlement Matrix
  • C. SAML 2.0
  • D. Federation

正解:D

解説:
In cloud computing, the fundamental problem is that multiple organizations are now managing the identity and access management to resources, which can greatly complicate the process. For example, imagine having to provision the same user on dozens-or hundreds-of different cloud services.
Federation is the primary tool used to manage this problem, by building trust relationships between organizations and enforcing them through standards-based technologies.
Reference: CSA Security GuidelinesV.4(reproduced here for the educational purpose)


質問 # 84
Audits should be robustly designed to reflect best practice, appropriate resources, and tested protocols and standards. They should also use what type of auditors?

  • A. Independent auditors
  • B. None of the above
  • C. Auditors working in the interest of the cloud customer
  • D. Auditors working in the interest of the cloud provider
  • E. Certified by CSA

正解:A


質問 # 85
ENISA: A reason for risk concerns of a cloud provider being acquired is:

  • A. Provider may change physical location
  • B. Non-binding agreements put at risk
  • C. Mass layoffs may occur
  • D. Arbitrary contract termination by acquiring company
  • E. Resource isolation may fail

正解:B

解説:
Explanation/Reference:


質問 # 86
When virtual machines may communicate with each other over a hardware backplane, Rather than a network, It gives rise to:

  • A. Multi-tenancy
  • B. Inter VM attack
  • C. DDoS
  • D. Blind spot

正解:D

解説:
It's the definition of Blind spot and it is very difficult to monitor this traffic.


質問 # 87
What is a type of computing comparable to grid computing that relies on sharing computing resources rather than having local servers or personal devices to handle applications?

  • A. Cloud computing
  • B. Server hosting
  • C. Traditional computing
  • D. Vertical computing

正解:A

解説:
Thats the definition of cloud computing


質問 # 88
Which of the following is typically a policy set that define ingress and egress rules that can apply to single assets or groups of assets, regardless of network location?

  • A. Intrusion Detection System
  • B. API Gateway
  • C. Database Activity Monitor
  • D. Security Groups

正解:D

解説:
SDN firewalls (e.g, security groups) can apply to assets based on more flexible criteria than hardware- based firewalls, since they aren't limited based on physical topology. (Note that this is true of many types of software firewalls, but is distinct from hardware firewalls). SDN firewalls are typically policy sets that define ingress and egress rules that can apply to single assets or groups of assets, regardless of network location (within a given virtual network).
Reference: CSA Security Guidelines V.4 (reproduced here for the educational purpose)


質問 # 89
In the Incident Response Lifecycle, which phase involves identifying potential security events and examining them for validity?

  • A. Detection and Analysis
  • B. Preparation
  • C. Containment, Eradication, and Recovery
  • D. Post-Incident Activity

正解:A

解説:
The Detection and Analysis phase involves identifying incidents and determining their impact. It is crucial to validate events to understand if they constitute a security incident. Reference: [Security Guidance v5, Domain
11 - Incident Response]


質問 # 90
Which of the following pair represents Storage used in IaaS infra-structure?

  • A. Structured and Unstructured Storage
  • B. Volume and object storage
  • C. Raw and long-term storage
  • D. CDN and Ephemeral

正解:B

解説:
IaaS uses the following storage types:
Volume storage: A virtual hard drive that can be attached to a virtual machine instance and be used to host data within a file System, Volumes attached to IaaS instances behave just like a physical drive or an array does. Examples include VMware Virtua Machine File System(VMFS), Amazon Elastic Block Store(EBS), RackSpace Redundant Array of Independent Disks (RAID), and OpenStack Cinder.
Object storage: Similar to a file share accessed via APIs or a web interface. Examples include Amazon S3 and Rackspace cloud files.


質問 # 91
One of the main reasons and advantage of having external audit is:

  • A. Its cheaper
  • B. Its independent
  • C. Internal staff is less qualified than external auditors.
  • D. Better tools used by external provider

正解:B

解説:
All other answers are distractors. One of the primary reasons of doing external auditing is the independence of auditors.


質問 # 92
......


CCSK認定試験は、ITマネージャー、セキュリティアナリスト、コンサルタントなど、クラウドセキュリティの管理を担当する専門家向けに設計されています。クラウドアーキテクチャ、データセキュリティ、コンプライアンス、法的問題など、さまざまなクラウドセキュリティトピックをカバーしています。この試験は、CSAのクラウドセキュリティガイダンスV4.0とENISAクラウドコンピューティングリスク評価レポートに基づいています。

 

無料Cloud Security Knowledge CCSK試験問題:https://www.jpntest.com/shiken/CCSK-mondaishu

問題集練習試験問題学習ガイドはCCSK試験で使える:https://drive.google.com/open?id=1-_DkFMVrtZl5d1OSEr7VLCBSJek5auLP

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡