
[2025年04月] 無料お試しCloud Security Alliance CCSK問題集PDFは必ずベストの問題集オプションを使おう
CCSK試験資料Cloud Security Alliance学習ガイド
質問 # 51
Which statement best describes why it is important to know how data is being accessed?
- A. The device may affect data dispersion.
- B. The devices used to access data use a variety of applications or clients and may have different security characteristics.
- C. The devices used to access data use a variety of operating systems and may have different programs installed on them.
- D. The devices used to access data may have different ownership characteristics.
- E. The devices used to access data have different storage formats.
正解:B
質問 # 52
IT Risk management is best described in:
- A. ISO 27017
- B. FIPS 140-2
- C. NIST SP800-14
- D. ISO 27005
正解:D
解説:
IS027005 standards describes IT Risk Management process
質問 # 53
Containers are highly portable code execution environments.
- A. True
- B. False
正解:A
質問 # 54
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?
- A. Planned Outages
- B. Expected Engineering
- C. Resiliency Planning
- D. Organized Downtime
- E. Chaos Engineering
正解:E
質問 # 55
What does it mean if the system or environment is built automatically from a template?
- A. Changes made in production are overwritten by the next code or template change.
- B. Nothing.
- C. Changes made in production are untouched by the next code or template change.
- D. It depends on how the automation is configured.
- E. Changes made in test are overwritten by the next code or template change.
正解:E
質問 # 56
When the data is transferred to third party. who is ultimately responsible for security of data?
- A. Cloud Controller
- B. Cloud Processor
- C. Cloud Security Broker
- D. Cloud Service Provider
正解:A
解説:
Whatever will be the scenario. Data controller will be responsible for security of data in cloud
質問 # 57
Sending data to a provider's storage over an API is likely as much more reliable and secure than setting up your own SFTP server on a VM in the same provider
- A. True
- B. False
正解:A
質問 # 58
Like security and compliance. BC/DR is not a shared responsibility.
- A. True
- B. False
正解:A
解説:
This is True
Like security and compliance, BC/DR is a shared responsibility. There are aspects that the cloud provider has to manage, but the cloud customer is also ultimately responsible for how they use and manage the cloud service. This is especially true when planning for outages of the cloud provider (or parts of the cloud provider's service).
Ref Reference: CSA Security GuidelinesV.4(reproduced here for the educational purpose)
質問 # 59
Centralization of log streams is charactertic of which devices?
- A. IPS
- B. SIEM
- C. IDS
- D. DLP
正解:B
解説:
SIEM is a combination of Security Incident Management(SIM)and Security Event Management(SEM).
A SEM system centralizes the storage and interpretation of logs and allows near real-time analysis which enables security personnel to take defensive actions more quickly. A SIM system collects data into a central repository for trend analysis and provides automated reporting for compliance and centralised reporting.
質問 # 60
Who is responsible for Governance, Risk & Compliance in Software as a Service(SaaS) service model?
- A. Cloud Carrier
- B. Cloud Customer
- C. It's a shared responsibility between Cloud Service Provider and Cloud Customer
- D. Cloud Service Provider
正解:B
解説:
Remember, GRC will always remain responsibility of the cloud customer in all service models
質問 # 61
Which of the following is not one of the categories of risks as defined in, ENISA (European Network and Information Security Agency) document on Security risk and recommendation?
- A. Environmental Risk
- B. Legal Risk
- C. Technical Risk
- D. Policy and organisational risk
正解:A
解説:
Environmental Risk are not defined as a category in the ENISA document however. all the other three are defined as categories.
質問 # 62
Which of the following storage types are associated with PaaS?
- A. Ephemeral and Content Deliver
- B. Structured and Unstructured
- C. Volume and Object
- D. Raw and Long-Term Storage
正解:B
解説:
PaaS utilizes the following data storage types:
Structured: Information with a high degree of organisation, such that inclusion in a relational database is seam less and readily searchable by simple, straightforward search engine algorithms or other search operations.
Unstructured: Information that does not reside in a traditional row-column database.
Unstructured data files often include text and multimedia content. Examples include email messages, word processing documents, videos, photos, audio files, presentations, web pages, and many other kinds of business documents. Although these sorts of files may have an internal structure, they are still considered unstructured because the data they contain does not fit neatly in a database.
質問 # 63
Stopping a function to control further risk to business is called:
- A. Acceptance
- B. Transference
- C. Mitigation
- D. Avoidance
正解:D
解説:
Risk avoidance is the practice of coming up with alternatives so that the risk in question is not realised.
質問 # 64
How can key management be leveraged to prevent cloud providers from inappropriately accessing customer data?
- A. Use strong multi-factor authentication
- B. Stipulate encryption in contract language
- C. Segregate keys from the provider hosting data
- D. Select cloud providers within the same country as customer
- E. Secure backup processes for key management systems
正解:C
質問 # 65
According to CSA Security Guidelines, there are four layers of Logical Model for cloud computing. Which of the following is not one of the layers as defined by Cloud Security Alliance?
- A. Softstructure
- B. Metastructure
- C. Applistructure
- D. Infrasturcture
正解:A
解説:
The four layers of Logical Model for cloud computing according to Cloud Security Alliance are:
1. Infrastructure: The core components of a computing system: compute, network, and storage. The foundation that everything else is built on. The moving parts.
2. Metastructure: The protocols and mechanisms that provide the interface between the infrastructure layer and the other layers. The glue that ties the technologies and enables management and configuration.
3. Infostructure: The data and information. Content in a database, file storage, etc.
4. Applistructure: The applications deployed in the cloud and the underlying application services used to build them. For example, Platform as a Service features like message queues, artificial intelligence analysis, or notification services.
質問 # 66
What type of information is contained in the Cloud Security Alliance's Cloud Control Matrix?
- A. A list of cloud configurations including traffic logic and efficient routes
- B. A number of requirements to be implemented, based upon numerous standards and regulatory requirements
- C. Federal legal business requirements for all cloud operators
- D. Network traffic rules for cloud environments
- E. The command and control management hierarchy of typical cloud company
正解:B
質問 # 67
When deploying Security as a Service in a highly regulated industry or environment, what should both parties agree on in advance and include in the SLA?
- A. The metrics defining the service level required to achieve regulatory objectives.
- B. The duration of time that a security violation can occur before the client begins assessing regulatory fines.
- C. The cost per incident for security breaches of regulated information.
- D. The regulations that are pertinent to the contract and how to circumvent them.
- E. The type of security software which meets regulations and the number of licenses that will be needed.
正解:A
質問 # 68
CCM: In the CCM tool, a _____________________ is a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.
- A. Control Specification
- B. Domain
- C. Risk Impact
正解:A
質問 # 69
The basis for deciding which laws are most appropriate in a situation where conflicting laws exist. refers to:
- A. Doctrine of proper law
- B. Tort law
- C. Criminal law
- D. The Restatement(Second) Conflict of Law
正解:D
解説:
The Restatement(Second) Conflict of Law refers to a collation of developments in common law that help the courts stay up with changes. Many states have conflicting laws. and judges use these restatements to assist them in determining which laws should apply when conflicts occur.
質問 # 70
Which one of the following is not a risk mitigation strategy?
- A. Acceptance
- B. Avoidance
- C. Transfer
- D. Suppression
正解:D
解説:
Following are the risk mitigation strategies
質問 # 71
NIST defines five characteristics of cloud computing- Rapid Elasticity, Broad Network Access, 0n demand self-service, Metered Usage & Resource pooling. However, IS0/lEC17788 mentions one more characteristic in addition is those 5. Which of the following is that characterstic?
- A. Automation
- B. Isolation
- C. Segregation
- D. Multitenancy
正解:D
解説:
IS0/lEC17788 lists six key characteristics. the first five of which are identical to the NIST characteristics.
The only addition is multitenancy. which is distinct from resource pooling.
Ref: CSA Security Guidelines V4.0
質問 # 72
ENISA: "VM hopping" is:
- A. Looping within virtualized routing systems.
- B. Lack of vulnerability management standards.
- C. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.
- D. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
- E. Instability in VM patch management causing VM routing errors.
正解:C
質問 # 73
Which is the core technology for enabling cloud computing and used to convert fixed infrastructure into pooled resources?
- A. Application Programming Interfaces
- B. Software Defined Networking
- C. Virtualization
- D. Auto-Scaling
正解:C
解説:
Virtualization isn't merely a tool for creating virtual machines-it's the core technology for enabling cloud computing. We use virtualization all throughout computing, from full operating virtual machines to virtual execution environments like the Java Virtual Machine, as well as in storage, networking, and beyond.
Reference: CSA Security Guidelines V.4(reproduced here for the educational purpose)
質問 # 74
You, as a cloud customer, will more control on event and diagnostic data in SaaS environment than in the PaaS or IaaS environment.
- A. True
- B. False
正解:B
解説:
This is false because it will be exactly opposite. ln SaaS environment, you will least amount of controls on event and diagnostic data. Your control will, in fact, increase as you for from SaaS to PaaS and eventually, in IaaS, you will have full control Event and diagnostic data (except of platform logs which is maintained by the cloud service provider).
質問 # 75
The Software Defined Perimeter (SDP) includes which components?
- A. Client, Controller, and Gateway
- B. Client, Controller, Firewall, and Gateway
- C. Controller, Firewall, and Gateway
- D. Client, Firewall, and Gateway
- E. Client, Controller, and Firewall
正解:A
質問 # 76
......
有効な問題最新版を試そうCCSKテスト解釈CCSK有効な試験ガイド:https://www.jpntest.com/shiken/CCSK-mondaishu
CCSK実際の問題解答PDFは100%カバー率でリアル試験問題:https://drive.google.com/open?id=1fRhFbxAqGIP3QQLujJEYQEFyjMsO35MQ