WGU Course C838 - Managing Cloud Security (CCSP) Quizlet by Brian
MacFarlane EXAM QUESTIONS WITH 100% CORRECT ANSWERS/A+ GRADE
_______ drive security decisions.
A Public opinion
B Business requirements
C Surveys
D Customer service responses - ✔✔B
________ reports review controls relevant to security, availability, processing
integrity, confidentiality, or privacy. This is the report of most use to cloud
customers (to determine the suitability of cloud providers) and IT security
practitioners. - ✔✔SOC 2
__________ usually concerns modifications to a known set of parameters
regarding each element of the network, including what settings each has, how
the controls are implemented, and so forth. - ✔✔Configuration management
___________ abstracts the running of code (including operating systems) from
the underlying hardware and most commonly refers to virtual machines. -
✔✔Compute virtualization
___________ are the logs, documentation, and other materials needed for
audits and compliance; they are the evidence to support compliance activities. -
✔✔Artifacts
,____________ are applied to existing systems and components, whereas
upgrades are the replacement of older elements for new ones. - ✔✔Updates
____________ refers to the process of identifying and obtaining electronic
evidence for either prosecutorial or litigation purposes. Determining which data
in a set is pertinent can be difficult. Regardless of whether it is databases,
records, email, or just simple files. - ✔✔Electronic discovery (eDiscovery)
____________ specifies a management system that is intended to bring
information security under management control and gives specific
requirements. Organizations that meet the requirements may be certified by an
accredited certification body following successful completion of an audit. -
✔✔ISO/IEC 27001
_____________ usually deals with modifications to the network, such as the
acquisition and deployment of new systems and components and the disposal
of those taken out of service. - ✔✔Change management
______________ efforts are concerned with maintaining critical operations
during any interruption in service, whereas disaster recovery efforts are focused
on the resumption of operations after an interruption due to disaster. -
✔✔Business continuity
______________ is an advisory organization for matters related to IT service. -
✔✔Uptime Institute
______________ talks about personally identifiable information (PII) as a name,
date of birth, and Social Security number. HIPAA calls this type of data
"electronic protected health information" (ePHI), and it also includes any
,patient information, including medical records, and facial photos. GLBA includes
customer account information such as account numbers and balances. -
✔✔NIST Special Publication (SP) 800-122
_______________ is a protocol specification providing for the exchange of
structured information or data in web services. It also works over other
protocols such as SMTP, FTP, and HTTP.
Standards-based
Reliant on XML
Highly intolerant of errors
Slower
Built-in error handling - ✔✔Simple Object Access Protocol (SOAP)
_________________ can be caused when the cloud provider goes out of
business, is acquired by another interest, or ceases operation for any reason. In
these circumstances, the concern is whether the customer can still readily
access and recover their data. - ✔✔Vendor lock-out
_________________ is the amount of risk that the leadership and stakeholders
of an organization are willing to accept.
It varies based on asset value and the requirements of a particular asset. -
✔✔Risk tolerance
_________________ refers to the body of rights, obligations, and remedies that
set out reliefs for persons who have been harmed by others and seeks to
provide for the compensation of victims that suffered at the hand of others by
shifting their costs to the person who caused them. - ✔✔Tort law
, ___________________ is a full application and distributed model that's
managed and hosted by the provider. Consumers access it with a web browser,
mobile app, or a lightweight client app.
Includes everything listed in the previous Infrastructure as a Service (IaaS) and
Platform as a Service (PaaS) models, with the addition of software programs. -
✔✔Software as a Service (SaaS)
___________________ is considered a black-box test since the code is not
revealed and the test must look for problems and vulnerabilities while the
application is running. It is most effective when used against standard HTTP and
other HTML web application interfaces. - ✔✔Dynamic application security
testing (DAST)
___________________ is the practice of viewing the application from the
perspective of a potential attacker. Realistically, it involves more than just
causing a breach or gaining access (the "penetration") - ✔✔Threat modeling
____________________ abstracts and provides development or application
platforms, such as databases, application platforms (e.g. a place to run Python,
PHP, or other code), file storage and collaboration, or even proprietary
application processing (such as machine learning, big data processing, or direct
API access to features of a full SaaS application). The key differentiator is that,
with PaaS, you don't manage the underlying servers, networks, or other
infrastructure.
It contains everything included in IaaS, with the addition of OSs. This model is
especially useful for software development operations (DevOps). - ✔✔Platform
as a Service (PaaS)
MacFarlane EXAM QUESTIONS WITH 100% CORRECT ANSWERS/A+ GRADE
_______ drive security decisions.
A Public opinion
B Business requirements
C Surveys
D Customer service responses - ✔✔B
________ reports review controls relevant to security, availability, processing
integrity, confidentiality, or privacy. This is the report of most use to cloud
customers (to determine the suitability of cloud providers) and IT security
practitioners. - ✔✔SOC 2
__________ usually concerns modifications to a known set of parameters
regarding each element of the network, including what settings each has, how
the controls are implemented, and so forth. - ✔✔Configuration management
___________ abstracts the running of code (including operating systems) from
the underlying hardware and most commonly refers to virtual machines. -
✔✔Compute virtualization
___________ are the logs, documentation, and other materials needed for
audits and compliance; they are the evidence to support compliance activities. -
✔✔Artifacts
,____________ are applied to existing systems and components, whereas
upgrades are the replacement of older elements for new ones. - ✔✔Updates
____________ refers to the process of identifying and obtaining electronic
evidence for either prosecutorial or litigation purposes. Determining which data
in a set is pertinent can be difficult. Regardless of whether it is databases,
records, email, or just simple files. - ✔✔Electronic discovery (eDiscovery)
____________ specifies a management system that is intended to bring
information security under management control and gives specific
requirements. Organizations that meet the requirements may be certified by an
accredited certification body following successful completion of an audit. -
✔✔ISO/IEC 27001
_____________ usually deals with modifications to the network, such as the
acquisition and deployment of new systems and components and the disposal
of those taken out of service. - ✔✔Change management
______________ efforts are concerned with maintaining critical operations
during any interruption in service, whereas disaster recovery efforts are focused
on the resumption of operations after an interruption due to disaster. -
✔✔Business continuity
______________ is an advisory organization for matters related to IT service. -
✔✔Uptime Institute
______________ talks about personally identifiable information (PII) as a name,
date of birth, and Social Security number. HIPAA calls this type of data
"electronic protected health information" (ePHI), and it also includes any
,patient information, including medical records, and facial photos. GLBA includes
customer account information such as account numbers and balances. -
✔✔NIST Special Publication (SP) 800-122
_______________ is a protocol specification providing for the exchange of
structured information or data in web services. It also works over other
protocols such as SMTP, FTP, and HTTP.
Standards-based
Reliant on XML
Highly intolerant of errors
Slower
Built-in error handling - ✔✔Simple Object Access Protocol (SOAP)
_________________ can be caused when the cloud provider goes out of
business, is acquired by another interest, or ceases operation for any reason. In
these circumstances, the concern is whether the customer can still readily
access and recover their data. - ✔✔Vendor lock-out
_________________ is the amount of risk that the leadership and stakeholders
of an organization are willing to accept.
It varies based on asset value and the requirements of a particular asset. -
✔✔Risk tolerance
_________________ refers to the body of rights, obligations, and remedies that
set out reliefs for persons who have been harmed by others and seeks to
provide for the compensation of victims that suffered at the hand of others by
shifting their costs to the person who caused them. - ✔✔Tort law
, ___________________ is a full application and distributed model that's
managed and hosted by the provider. Consumers access it with a web browser,
mobile app, or a lightweight client app.
Includes everything listed in the previous Infrastructure as a Service (IaaS) and
Platform as a Service (PaaS) models, with the addition of software programs. -
✔✔Software as a Service (SaaS)
___________________ is considered a black-box test since the code is not
revealed and the test must look for problems and vulnerabilities while the
application is running. It is most effective when used against standard HTTP and
other HTML web application interfaces. - ✔✔Dynamic application security
testing (DAST)
___________________ is the practice of viewing the application from the
perspective of a potential attacker. Realistically, it involves more than just
causing a breach or gaining access (the "penetration") - ✔✔Threat modeling
____________________ abstracts and provides development or application
platforms, such as databases, application platforms (e.g. a place to run Python,
PHP, or other code), file storage and collaboration, or even proprietary
application processing (such as machine learning, big data processing, or direct
API access to features of a full SaaS application). The key differentiator is that,
with PaaS, you don't manage the underlying servers, networks, or other
infrastructure.
It contains everything included in IaaS, with the addition of OSs. This model is
especially useful for software development operations (DevOps). - ✔✔Platform
as a Service (PaaS)