CYBERSECURITY MANAGEMENT II -
TACTICAL - C795 SOBS EXAM
UPDATED QUESTIONS AND CORRECT
ANSWERS.
____________ subjects are granted only the privileges necessary to perform assigned work
tasks and no more. Keep in mind that privilege in this context includes both permissions to data
and rights to perform tasks on systems. - ANS The principle of least privilege states that
____________ ensures that no single person has total control over a critical function or system.
This is necessary to ensure that no single person can compromise the system or its security. -
ANS Separation of duties and responsibilities
___________is similar in concept to separation of duties and responsibilities. A separation-of-
privilege policy requires the use of granular rights and permissions. - ANS Separation of
privilege
____________ is known as management of changes made to the system's hardware, software,
or firmware throughout its operational life cycle. - ANS Configuration management
____________ ............ they run as guest operating systems on physical servers. The physical
servers include extra processing power, memory, and disk storage to handle the VM
requirements. - ANS 1. Virtual Machines (VMs):
__________ is sometimes called a virtual desktop environment (VDE), hosts a user's desktop as
a VM on a server. Users can connect to the server to access their desktop from almost any
1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
,system, including from mobile devices. Persistent virtual desktops retain a custom desktop for
the user. Nonpersistent virtual desktops are identical for all users. If a user makes changes, the
desktop reverts to a known state after the user logs off. - ANS 1. Virtual Desktop
Infrastructure (VDI):
_____________.....they decouple the control plane from the data plane (or forwarding plane).
The control plane uses protocols to decide where to send traffic, and the data plane includes
rules that decide whether traffic will be forwarded. Instead of traditional networking
equipment such as routers and switches, an SDN controller handles traffic routing using simpler
network devices that accept instructions from the controller. This eliminates some of the
complexity related to traditional networking protocols. - ANS 1. Software-Defined Networks
(SDNs):
_____________A SAN is a dedicated high-speed network that hosts multiple storage devices.
They are often used with servers that need high-speed access to data. These have historically
been expensive due to the complex hardware requirements of the SAN. VSANs bypass these
complexities with virtualization. - ANS 1. Virtual Storage Area Networks (VSANs):
________________ models provide fully functional applications typically accessible via a web
browser. For example, Google's Gmail is a SaaS application. The CSP (Google in this example) is
responsible for all maintenance of the SaaS services. Consumers do not manage or control any
of the cloud-based assets. - ANS 1. Software as a service (SaaS): Software as a service (SaaS)
________________ models provide consumers with a computing platform, including hardware,
an operating system, and applications. In some cases, consumers install the applications from a
list of choices provided by the CSP. Consumers manage their applications and possibly some
configuration settings on the host. However, the CSP is responsible for maintenance of the host
and the underlying cloud infrastructure. - ANS 1. Platform as a service (PaaS): Platform as a
service (PaaS)
______________ models provide basic computing resources to consumers. This includes
servers, storage, and in some cases, networking resources. Consumers install operating systems
and applications and perform all required maintenance on the operating systems and
applications. The CSP maintains the cloud-based infrastructure, ensuring that consumers have
access to leased systems. The distinction between IaaS and PaaS models isn't always clear when
evaluating public services. However, when leasing cloud-based services, the label the CSP uses
isn't as important as clearly understanding who is responsible for performing different
2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, maintenance and security actions. - ANS 1. Infrastructure as a service (IaaS): Infrastructure as
a service (IaaS)
___________ includes assets available for any consumers to rent or lease and is hosted by an
external CSP. Service-level agreements can be effective at ensuring that the CSP provides the
cloud-based services at a level acceptable to the organization. - ANS 1. A public cloud model
______________ is used for cloud-based assets for a single organization. Organizations can
create and host private clouds using their own on-premises resources. If so, the organization is
responsible for all maintenance. However, an organization can also rent resources from a third
party for exclusive use of the organization. Maintenance requirements are typically split based
on the service model (SaaS, PaaS, or IaaS). - ANS 1. The private cloud deployment model
_______________provides cloud-based assets to two or more organizations. Assets can be
owned and managed by one or more of the organizations. Maintenance responsibilities are
shared based on who is hosting the assets and the service models. - ANS 1. A community
cloud deployment model
_____________ includes a combination of two or more clouds. Similar to a community cloud
model, maintenance responsibilities are shared based on who is hosting the assets and the
service models in use - ANS 1. A hybrid cloud model
Organizations apply ______________ to ensure that resources are securely provisioned and
managed. As an example, desktop computers are often deployed using imaging techniques to
ensure that they start in a known secure state - ANS various resource protection techniques
_______________ ensure that the systems are kept up-to-date with required changes. The
techniques vary depending on the resource and are described in the following sections. -
ANS Change management and patch management techniques
____________ helps verify that systems are not vulnerable to known threats. -
ANS vulnerability management
___________ ensures that appropriate patches are applied - ANS a. . Patch management
3 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
TACTICAL - C795 SOBS EXAM
UPDATED QUESTIONS AND CORRECT
ANSWERS.
____________ subjects are granted only the privileges necessary to perform assigned work
tasks and no more. Keep in mind that privilege in this context includes both permissions to data
and rights to perform tasks on systems. - ANS The principle of least privilege states that
____________ ensures that no single person has total control over a critical function or system.
This is necessary to ensure that no single person can compromise the system or its security. -
ANS Separation of duties and responsibilities
___________is similar in concept to separation of duties and responsibilities. A separation-of-
privilege policy requires the use of granular rights and permissions. - ANS Separation of
privilege
____________ is known as management of changes made to the system's hardware, software,
or firmware throughout its operational life cycle. - ANS Configuration management
____________ ............ they run as guest operating systems on physical servers. The physical
servers include extra processing power, memory, and disk storage to handle the VM
requirements. - ANS 1. Virtual Machines (VMs):
__________ is sometimes called a virtual desktop environment (VDE), hosts a user's desktop as
a VM on a server. Users can connect to the server to access their desktop from almost any
1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
,system, including from mobile devices. Persistent virtual desktops retain a custom desktop for
the user. Nonpersistent virtual desktops are identical for all users. If a user makes changes, the
desktop reverts to a known state after the user logs off. - ANS 1. Virtual Desktop
Infrastructure (VDI):
_____________.....they decouple the control plane from the data plane (or forwarding plane).
The control plane uses protocols to decide where to send traffic, and the data plane includes
rules that decide whether traffic will be forwarded. Instead of traditional networking
equipment such as routers and switches, an SDN controller handles traffic routing using simpler
network devices that accept instructions from the controller. This eliminates some of the
complexity related to traditional networking protocols. - ANS 1. Software-Defined Networks
(SDNs):
_____________A SAN is a dedicated high-speed network that hosts multiple storage devices.
They are often used with servers that need high-speed access to data. These have historically
been expensive due to the complex hardware requirements of the SAN. VSANs bypass these
complexities with virtualization. - ANS 1. Virtual Storage Area Networks (VSANs):
________________ models provide fully functional applications typically accessible via a web
browser. For example, Google's Gmail is a SaaS application. The CSP (Google in this example) is
responsible for all maintenance of the SaaS services. Consumers do not manage or control any
of the cloud-based assets. - ANS 1. Software as a service (SaaS): Software as a service (SaaS)
________________ models provide consumers with a computing platform, including hardware,
an operating system, and applications. In some cases, consumers install the applications from a
list of choices provided by the CSP. Consumers manage their applications and possibly some
configuration settings on the host. However, the CSP is responsible for maintenance of the host
and the underlying cloud infrastructure. - ANS 1. Platform as a service (PaaS): Platform as a
service (PaaS)
______________ models provide basic computing resources to consumers. This includes
servers, storage, and in some cases, networking resources. Consumers install operating systems
and applications and perform all required maintenance on the operating systems and
applications. The CSP maintains the cloud-based infrastructure, ensuring that consumers have
access to leased systems. The distinction between IaaS and PaaS models isn't always clear when
evaluating public services. However, when leasing cloud-based services, the label the CSP uses
isn't as important as clearly understanding who is responsible for performing different
2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, maintenance and security actions. - ANS 1. Infrastructure as a service (IaaS): Infrastructure as
a service (IaaS)
___________ includes assets available for any consumers to rent or lease and is hosted by an
external CSP. Service-level agreements can be effective at ensuring that the CSP provides the
cloud-based services at a level acceptable to the organization. - ANS 1. A public cloud model
______________ is used for cloud-based assets for a single organization. Organizations can
create and host private clouds using their own on-premises resources. If so, the organization is
responsible for all maintenance. However, an organization can also rent resources from a third
party for exclusive use of the organization. Maintenance requirements are typically split based
on the service model (SaaS, PaaS, or IaaS). - ANS 1. The private cloud deployment model
_______________provides cloud-based assets to two or more organizations. Assets can be
owned and managed by one or more of the organizations. Maintenance responsibilities are
shared based on who is hosting the assets and the service models. - ANS 1. A community
cloud deployment model
_____________ includes a combination of two or more clouds. Similar to a community cloud
model, maintenance responsibilities are shared based on who is hosting the assets and the
service models in use - ANS 1. A hybrid cloud model
Organizations apply ______________ to ensure that resources are securely provisioned and
managed. As an example, desktop computers are often deployed using imaging techniques to
ensure that they start in a known secure state - ANS various resource protection techniques
_______________ ensure that the systems are kept up-to-date with required changes. The
techniques vary depending on the resource and are described in the following sections. -
ANS Change management and patch management techniques
____________ helps verify that systems are not vulnerable to known threats. -
ANS vulnerability management
___________ ensures that appropriate patches are applied - ANS a. . Patch management
3 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED