C838- Exam 3 Questions with 100%
Correct Answers.
82. All of the following are reasons to perform review and maintenance actions on user
accounts except ____________.
a. To determine whether the user still needs the same access b.
To determine whether the user is still with the organization
c. To determine whether the data set is still applicable to the user 's
role d. To determine whether the user is still performing well
D
83. Who should be involved in review and maintenance of user
accounts/access? a. The user 's manager
b. The security manager
c. The accounting department
d. The incident response team
A
84. Which of the following protocols is most applicable to the identification process aspect
of identity and access management (IAM)?
a. Secure Sockets Layer (SSL)
b. Internet Protocol security (IPsec)
c. Lightweight Directory Access Protocol (LDAP)
d. Amorphous ancillary data transmission (AADT)
C
85. Privileged user (administrators, managers, and so forth) accounts need to be
reviewed more closely than basic user accounts. Why is this?
a. Privileged users have more encryption
keys. b. Regular users are more trustworthy.
,c. There are extra controls on privileged user accounts.
d. Privileged users can cause more damage to the organization.
D
86. The additional review activities that might be performed for privileged user accounts
could include all of the following except _____________.
a. Deeper personnel background checks
b. Review of personal financial accounts for privileged users
c. More frequent reviews of the necessity for access
d. Pat-down checks of privileged users to deter against physical theft
D
87. If personal financial account reviews are performed as an additional review control for
privileged users, which of the following characteristics is least likely to be a useful
indicator for review purposes?
a. Too much money in the account
b. Too little money in the account
c. The bank branch being used by the privileged
user d. Specific senders/recipients
C
88. How often should the accounts of privileged users be reviewed?
a. Annually
b. Twice a year
c. Monthly
d. More often than regular user account reviews
D
89. Privileged user account access should be
__________. a. Temporary
b. Pervasive
,c. Thorough
d. Granular
A
90. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of
common threats to organizations participating in cloud computing. According to the
CSA 's Notorious Nine list, data breaches can be ____________.
a. Overt or covert
b. International or subterranean
c. From internal or external sources
d. Voluminous or specific
C
91. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of
common threats to organizations participating in cloud computing. According to the
CSA, an organization that operates in the cloud environment and suffers a data
breach may be required to __________.
a. Notify affected users
b. Reapply for cloud service
c. Scrub all affected physical memory
d. Change regulatory frameworks
A
92. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, an
organization that suffers a data breach might suffer all of the following negative
effects except __________.
a. Cost of compliance with notification
laws b. Loss of public perception/goodwill
c. Loss of market share
d. Cost of detection
, D
93. The Cloud Security Alliance (CSA) publishes, the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, in the
event of a data breach, a cloud customer will likely need to comply with all the
following data breach notification requirements except ____________.
a. Multiple state laws
b. Contractual notification requirements c.
All standards-based notification schemes
d. Any applicable federal regulations
C
94. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, data
loss can be suffered as a result of ____________ activity.
a. Malicious or inadvertent
b. Casual or explicit
c. Web-based or stand-alone
d. Managed or independent
A
95. The Cloud Security Alliance (CSA) publishes, the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, all of the
following activity can result in data loss except ____________.
a. Misplaced crypto keys
b. Improper policy
c. Ineffectual backup procedures
d. Accidental overwrite
B
96. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, service
Correct Answers.
82. All of the following are reasons to perform review and maintenance actions on user
accounts except ____________.
a. To determine whether the user still needs the same access b.
To determine whether the user is still with the organization
c. To determine whether the data set is still applicable to the user 's
role d. To determine whether the user is still performing well
D
83. Who should be involved in review and maintenance of user
accounts/access? a. The user 's manager
b. The security manager
c. The accounting department
d. The incident response team
A
84. Which of the following protocols is most applicable to the identification process aspect
of identity and access management (IAM)?
a. Secure Sockets Layer (SSL)
b. Internet Protocol security (IPsec)
c. Lightweight Directory Access Protocol (LDAP)
d. Amorphous ancillary data transmission (AADT)
C
85. Privileged user (administrators, managers, and so forth) accounts need to be
reviewed more closely than basic user accounts. Why is this?
a. Privileged users have more encryption
keys. b. Regular users are more trustworthy.
,c. There are extra controls on privileged user accounts.
d. Privileged users can cause more damage to the organization.
D
86. The additional review activities that might be performed for privileged user accounts
could include all of the following except _____________.
a. Deeper personnel background checks
b. Review of personal financial accounts for privileged users
c. More frequent reviews of the necessity for access
d. Pat-down checks of privileged users to deter against physical theft
D
87. If personal financial account reviews are performed as an additional review control for
privileged users, which of the following characteristics is least likely to be a useful
indicator for review purposes?
a. Too much money in the account
b. Too little money in the account
c. The bank branch being used by the privileged
user d. Specific senders/recipients
C
88. How often should the accounts of privileged users be reviewed?
a. Annually
b. Twice a year
c. Monthly
d. More often than regular user account reviews
D
89. Privileged user account access should be
__________. a. Temporary
b. Pervasive
,c. Thorough
d. Granular
A
90. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of
common threats to organizations participating in cloud computing. According to the
CSA 's Notorious Nine list, data breaches can be ____________.
a. Overt or covert
b. International or subterranean
c. From internal or external sources
d. Voluminous or specific
C
91. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of
common threats to organizations participating in cloud computing. According to the
CSA, an organization that operates in the cloud environment and suffers a data
breach may be required to __________.
a. Notify affected users
b. Reapply for cloud service
c. Scrub all affected physical memory
d. Change regulatory frameworks
A
92. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, an
organization that suffers a data breach might suffer all of the following negative
effects except __________.
a. Cost of compliance with notification
laws b. Loss of public perception/goodwill
c. Loss of market share
d. Cost of detection
, D
93. The Cloud Security Alliance (CSA) publishes, the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, in the
event of a data breach, a cloud customer will likely need to comply with all the
following data breach notification requirements except ____________.
a. Multiple state laws
b. Contractual notification requirements c.
All standards-based notification schemes
d. Any applicable federal regulations
C
94. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, data
loss can be suffered as a result of ____________ activity.
a. Malicious or inadvertent
b. Casual or explicit
c. Web-based or stand-alone
d. Managed or independent
A
95. The Cloud Security Alliance (CSA) publishes, the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, all of the
following activity can result in data loss except ____________.
a. Misplaced crypto keys
b. Improper policy
c. Ineffectual backup procedures
d. Accidental overwrite
B
96. The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common
threats to organizations participating in cloud computing. According to the CSA, service