CLOUD SECURITY IMPLEMENTATION
PLAN ACTUAL TEST PAPER COMPLETE
QUESTIONS AND ANSWERS FULL
SOLUTION
●● Which privacy issue does the CLOUD Act address?
Answer: Conflicting regulations in different jurisdictions
●● What should an organization do next after selecting a new vendor?
Answer: Confirm contractual details and arrange technical agreements,
data transfers, and encryption standards
●● Which mechanisms should an engineer use for segmentation
between two cloud deployments?
Answer: Ports and protocols
●● What refers to sharing physical assets among multiple customers in
cloud computing?
Answer: Resource pooling
●● Which technique should a service provider use to verify a customer's
private information without seeing all of it?
Answer: Masking
, ●● What action should an organization take if it lacks understanding of
its infrastructure for disaster recovery?
Answer: Perform an inventory of assets
●● What security control involves checking employees against a
database before granting access?
Answer: Authorization
●● Which methodology involves testing the interaction of end users
with new code for a patch?
Answer: Functional testing
●● What common API threat occurs when attackers send malicious code
through a form input?
Answer: Injection
●● Which testing standard guides SOC audits outside the United States?
Answer: ISAE 3402
●● Which tool should a developer use to describe requirements for a
code improvement?
Answer: Stories
PLAN ACTUAL TEST PAPER COMPLETE
QUESTIONS AND ANSWERS FULL
SOLUTION
●● Which privacy issue does the CLOUD Act address?
Answer: Conflicting regulations in different jurisdictions
●● What should an organization do next after selecting a new vendor?
Answer: Confirm contractual details and arrange technical agreements,
data transfers, and encryption standards
●● Which mechanisms should an engineer use for segmentation
between two cloud deployments?
Answer: Ports and protocols
●● What refers to sharing physical assets among multiple customers in
cloud computing?
Answer: Resource pooling
●● Which technique should a service provider use to verify a customer's
private information without seeing all of it?
Answer: Masking
, ●● What action should an organization take if it lacks understanding of
its infrastructure for disaster recovery?
Answer: Perform an inventory of assets
●● What security control involves checking employees against a
database before granting access?
Answer: Authorization
●● Which methodology involves testing the interaction of end users
with new code for a patch?
Answer: Functional testing
●● What common API threat occurs when attackers send malicious code
through a form input?
Answer: Injection
●● Which testing standard guides SOC audits outside the United States?
Answer: ISAE 3402
●● Which tool should a developer use to describe requirements for a
code improvement?
Answer: Stories