CCSKテスト問題練習試そう!2025年に更新された179問あります [Q45-Q66]

Share

CCSKテスト問題練習試そう!2025年に更新された179問あります

更新された2025年04月プレミアムCCSK試験エンジンPDFで今すぐダウンロード!無料更新された179問あります

質問 # 45
Which of the following is NOT one of the vulnerabilities that can lead of risk of "abuse of high privilege roles" or "Cloud provider malicious insider''?

  • A. Poor enforcement of role definitions
  • B. AAA Vulnerabilities
  • C. Lack of data centre hardware redundancy
  • D. System and 0S vulnerabilities

正解:C

解説:
Redundancy has nothing to do with abuse of high privilege roles. All others can lead to risk of risk of
"abuse of high privilege roles" or "Cloud provider malicious insider"


質問 # 46
When designing a cloud-native application that requires scalable and durable data storage, which storage option should be primarily considered?

  • A. File storage
  • B. Network Attached Storage (NAS)
  • C. Block storage
  • D. Object storage

正解:D

解説:
Object storage is highly scalable and suitable for cloud-native applications that require durability and efficient storage of unstructured data. Reference: [CCSK Study Guide, Domain 9 - Data Storage Types]


質問 # 47
What should every cloud customer set up with its cloud service provider (CSP) that can be utilized in the event of an incident?

  • A. A communication plan
  • B. A spill remediation kit
  • C. A back-up website
  • D. A data destruction plan
  • E. A rainy day fund

正解:A


質問 # 48
Which one of the following is the key techniques to create cloud infrastructure?

  • A. Orientation
  • B. Orchestration
  • C. Automation
  • D. Data Classification

正解:B

解説:
The key techniques to create a cloud are abstraction and orchestration. We abstract the resources from the underlying physical infrastructure to create our pools, and use orchestration(and automation)to coordinate carving out and delivering a set of resources from the pools to the consumers. As you will see, these two techniques create all the essential characteristics we use to define something as a
"cloud."
Ref: CSA Security Guidelines V4.0


質問 # 49
Cloud services exhibit five essential characteristics that demonstrate their relation to, and differences from, traditional computing approaches. Which one of the five characteristics is described as: a consumer can unilaterally provision computing capabilities such as server time and network storage as needed.

  • A. On-demand self-service
  • B. Resource pooling
  • C. Broad network access
  • D. Measured service
  • E. Rapid elasticity

正解:A


質問 # 50
ln which service model. does cloud security provider has least responsibility?

  • A. PaaS
  • B. IaaS
  • C. SaaS
  • D. XaaS

正解:B

解説:
In IaaS service model. CSP is responsible only for the physical infrastructure.


質問 # 51
Which of the following establishes commonly accepted control objectives, controls and guidelines for implementing measures to protect Personally Identifiable Information(PII) in accordance with the privacy principles in IS0/IEC 29100 for the public cloud computing environment?

  • A. IS0 27017
  • B. IS0 27032
  • C. IS0 27018
  • D. IS0 27034

正解:C

解説:
IS0/IEC 27018:2014 establishes commonly accepted control objectives, controls and guidelines for implementing measures to protect Personally Identifiable Information(PII) in accordance with the privacy principles in IS0/IEC 29100 for the public cloud computing environment.


質問 # 52
Which is the primary tool for governance in Cloud Computing environment?

  • A. Governance memo
  • B. Contract
  • C. Service Level Agreement
  • D. Operational level Agreement

正解:D

解説:
Contracts: The primary tool of governance is the contract between a cloud provider and a cloud customer(this is true for public and private cloud). The contract is your only guarantee of any level of service or commitment-assuming there is no breach of contract, which tosses everything into a legal scenario. Contracts are the primary tool to extend governance into business partners and providers.
Ref: Security Guidance v4.0 Copyright2017, Cloud Security Alliance(used for educational purpose here)


質問 # 53
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what?

  • A. A support table
  • B. An access log
  • C. An entry log
  • D. A validation process
  • E. An entitlement matrix

正解:D


質問 # 54
Cloud architectures necessitate certain roles which are extremely high-risk. Examples of such roles include CP system administrators and auditors and managed security service providers dealing with intrusion detection reports and incident response. They are known as high-risk because their malicious activities can lead to abuse of high privilege roles and can impact confidentiality, integrity and availability of data.

  • A. False
  • B. True

正解:A


質問 # 55
Which activity is a critical part of the Post-Incident Analysis phase in cybersecurity incident response?

  • A. Isolating affected systems
  • B. Notifying affected parties
  • C. Restoring services to normal operations
  • D. Documenting lessons learned and improving future responses

正解:D

解説:
Documenting lessons learned is essential in the post-incident phase, as it helps improve future incident response processes. Reference: [Security Guidance v5, Domain 11 - Incident Response]


質問 # 56
An adversary uses a cloud Platform to launch a DDoS attack against XYZ company. This type of risk is termed as:

  • A. Data Breaches
  • B. Abuse of Cloud services
  • C. Malicious Insider
  • D. Account Hijacking

正解:B

解説:
Malicious actors may leverage cloud computing resources to target users, Organizations or other cloud providers. Examples of misuse of cloud service-based resources include launching DDoS attacks, email spam and phishing campaigns; "mining" for digital currency; large-scale automated click fraud; brute- force compute attacks of stolen credential databases; and hosting of malicious or pirated content.


質問 # 57
Who is ultimately liable for all data loss and breaches in the cloud environment?

  • A. Cloud access security broker(CASB)
  • B. Cloud reseller
  • C. Cloud service provider
  • D. Cloud customer

正解:D

解説:
It is the customer who is ultimately responsible for any type of data loss or breaches


質問 # 58
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services for tracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document to potential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?

  • A. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
  • B. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
  • C. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.

正解:C


質問 # 59
Which is the primary tool used to manage identity and access management of resources spread across hundreds of different clouds and resources?

  • A. Entitlement Matrix
  • B. Active Directory
  • C. SAML 2.0
  • D. Federation

正解:D

解説:
In cloud computing, the fundamental problem is that multiple organizations are now managing the identity and access management to resources, which can greatly complicate the process. For example, imagine having to provision the same user on dozens-or hundreds-of different cloud services.
Federation is the primary tool used to manage this problem, by building trust relationships between organizations and enforcing them through standards-based technologies.
Reference: CSA Security GuidelinesV.4(reproduced here for the educational purpose)


質問 # 60
The granting of right to access to a user. program or process. is called:

  • A. RBAC
  • B. Authorization
  • C. Authentication
  • D. Entitlement

正解:B

解説:
Authorization is the process of granting of right to access to a user, program or process. It should not be confused with Authentication.


質問 # 61
The key focus of any business continuity or disaster recovery should be:

  • A. Critical infrastructure
  • B. Financial documents
  • C. Health and human safety
  • D. Critical assets

正解:C

解説:
The primary goal of whole business continuity and disaster recovery exercise should be health and human safety.


質問 # 62
Why is a service type of network typically isolated on different hardware?

  • A. It manages the traffic between other networks
  • B. It requires unique security
  • C. It requires distinct access controls
  • D. It has distinct functions from other networks
  • E. It manages resource pools for cloud consumers

正解:A


質問 # 63
Which approach is essential in identifying compromised identities in cloud environments where attackers utilize automated methods?

  • A. Deploying behavioral detectors for IAM and management plane activities
  • B. Focusing exclusively on signature-based detection for known malware
  • C. Relying on IP address and connection header monitoring
  • D. Implementing full packet capture and monitoring

正解:A

解説:
Behavioral detection for IAM and management plane activities is essential for identifying unusual or suspicious actions by compromised identities, especially in environments where attackers use automated tactics. Reference: [CCSK v5 Curriculum, Domain 5 - IAM]


質問 # 64
Ben was working on a project and hosted all its data on a public cloud. The project is now complete and he wants to remove the data Which of the following is best option for him in order to leave no remanence?

  • A. Zeroing
  • B. Data-overwriting
  • C. Physically destroy the media
  • D. Cryptographic erasure

正解:D

解説:
All the options given are correct methods of destroying data but when it comes to data in cloud. the most suitable method is cryptographic erasure.
Definition: Cryptographic Erasure
Cryptographic erasure is the process of using encryption software (either built-in or deployed) on the entire data storage device. and erasing the key used to decrypt the data.


質問 # 65
Which data security control is the LEAST likely to be assigned to an IaaS provider?

  • A. Physical destruction
  • B. Application logic
  • C. Access controls
  • D. Asset management and tracking
  • E. Encryption solutions

正解:B


質問 # 66
......

正真正銘のCCSK問題集には100%合格率練習テスト問題集:https://www.jpntest.com/shiken/CCSK-mondaishu

Cloud Security Alliance CCSKリアル試験問題保証付き更新された問題集にはJPNTest:https://drive.google.com/open?id=1-_DkFMVrtZl5d1OSEr7VLCBSJek5auLP

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡