C838- CCSP Exam Questions with 100% Correct
Answers.
Data discovery
Your organization has just been served with an eDiscovery order. Because the organization has
moved to a cloud environment, what is the biggest challenge when it comes to full compliance
with an eDiscovery order?
FIPS 140-2 US Crypto modules
Your organization is considering a move to a cloud environment and is looking for certifications
or audit reports from cloud providers to ensure adequate security controls and processes. Which
of the following is NOT a security certification or audit report that would be pertinent?
Classification
You are developing a new process for data discovery for your organization and are charged with
ensuring that all applicable data is included. Which of the following is NOT one of the 3
methods of data discovery?
Dynamic Application Security Testing (DAST)
Management has requested that security testing be done against their live cloud-based
applications, with the testers not having internal knowledge of the system.
Not attempting to actually breach systems or inject data is also a top requirement. Which of the
following would be the appropriate approach to take?
SaaS (Software as a Service)
Which of the following cloud categories would allow for the LEAST amount of customization
by the cloud customer?
Responding
Which phase of the risk management process involves an organization deciding how to mitigate
risk that is discovered during the course of an audit?
,Auditing
During the testing phase of the SDLC, which of the following is NOT included as a core activity
of testing?
XML (Extensible Markup Language)
You have decided to use SOAP as the protocol for exchanging information between services for
your application. Which of the following is the only data format that can be used with SOAP?
SOC 3
A cloud provider is looking to provide a higher level of assurance to current and potential cloud
customers about the design and effectiveness of its security controls. Which of the following
audit reports would the cloud provider choose as the most appropriate to accomplish this goal?
Requirement Gathering
At which stage of the software development lifecycle is the most appropriate place to begin the
involvement of security?
Encryption
not part of the data archiving?
Impact on systems
While an audit is being conducted, which of the following could cause management and the
auditors to change the original plan in order to continue with the audit?
STRIDE
Which threat model has elevation of privilege
Qualitative
What type of risk assessment is based on a documentation review and making informed
judgement calls about risk from operational procedures and system designs?
security
With SOC2 auditing report, which of the following principles must always be included?
, Sandboxing
An isolated test environment that simulates the production environment but will not affect
production components/data.
Live system
NOT an aspect of SAST?
public, private, hybrid and community
The 4 cloud deployment models
GitHub
A website for hosting source code in Git. It is the most common place to share and collaborate
on open source projects, and can also be used to host private repositories for companies.
Escalation
NOT a core component of an SIEM solution?
Malicious insiders
The most difficult threat type for an organization to defend against and detect
object and volume
IaaS storage types
cryptographic erasure
Data-sanitation approach is always available within a cloud environment
IPS
will make a elasticity a bigger challenge in a cloud environment.
Portability
the ability of the cloud customers to easily move services from one cloud provider to another
Spoofing
Answers.
Data discovery
Your organization has just been served with an eDiscovery order. Because the organization has
moved to a cloud environment, what is the biggest challenge when it comes to full compliance
with an eDiscovery order?
FIPS 140-2 US Crypto modules
Your organization is considering a move to a cloud environment and is looking for certifications
or audit reports from cloud providers to ensure adequate security controls and processes. Which
of the following is NOT a security certification or audit report that would be pertinent?
Classification
You are developing a new process for data discovery for your organization and are charged with
ensuring that all applicable data is included. Which of the following is NOT one of the 3
methods of data discovery?
Dynamic Application Security Testing (DAST)
Management has requested that security testing be done against their live cloud-based
applications, with the testers not having internal knowledge of the system.
Not attempting to actually breach systems or inject data is also a top requirement. Which of the
following would be the appropriate approach to take?
SaaS (Software as a Service)
Which of the following cloud categories would allow for the LEAST amount of customization
by the cloud customer?
Responding
Which phase of the risk management process involves an organization deciding how to mitigate
risk that is discovered during the course of an audit?
,Auditing
During the testing phase of the SDLC, which of the following is NOT included as a core activity
of testing?
XML (Extensible Markup Language)
You have decided to use SOAP as the protocol for exchanging information between services for
your application. Which of the following is the only data format that can be used with SOAP?
SOC 3
A cloud provider is looking to provide a higher level of assurance to current and potential cloud
customers about the design and effectiveness of its security controls. Which of the following
audit reports would the cloud provider choose as the most appropriate to accomplish this goal?
Requirement Gathering
At which stage of the software development lifecycle is the most appropriate place to begin the
involvement of security?
Encryption
not part of the data archiving?
Impact on systems
While an audit is being conducted, which of the following could cause management and the
auditors to change the original plan in order to continue with the audit?
STRIDE
Which threat model has elevation of privilege
Qualitative
What type of risk assessment is based on a documentation review and making informed
judgement calls about risk from operational procedures and system designs?
security
With SOC2 auditing report, which of the following principles must always be included?
, Sandboxing
An isolated test environment that simulates the production environment but will not affect
production components/data.
Live system
NOT an aspect of SAST?
public, private, hybrid and community
The 4 cloud deployment models
GitHub
A website for hosting source code in Git. It is the most common place to share and collaborate
on open source projects, and can also be used to host private repositories for companies.
Escalation
NOT a core component of an SIEM solution?
Malicious insiders
The most difficult threat type for an organization to defend against and detect
object and volume
IaaS storage types
cryptographic erasure
Data-sanitation approach is always available within a cloud environment
IPS
will make a elasticity a bigger challenge in a cloud environment.
Portability
the ability of the cloud customers to easily move services from one cloud provider to another
Spoofing