CLOUD SECURITY EXAM RATED 2023
WITH VERIFIED 1000+ qs and Ans
Which of the following best describes data masking?
A A method where the last few numbers in a dataset are not obscured. These are
often used for authentication.
B A method for creating similar but inauthentic datasets used for software testing
and user training.
C A method used to protect prying eyes from data such as social security numbers
and credit card data.
D Data masking involves stripping out all similar digits in a string of numbers so as
to obscure the original number.
Database activity monitoring (DAM) can be:
A Used in the place of encryption
B Used in place of data masking
C Host-based or network-based
,D Server-based or client-based
SOAP is a protocol specification providing for the exchange of structured
information or data in web services. Which of the following is not true of SOAP?
A Works over numerous protocols
B Standards-based
C Reliant on XML
D Extremely fast
Dynamic application security testing (DAST) is best described as which of the
following?
A Masking
B Test performed on an application or software product while being consumed by
cloud customers
C Test performed on an application or software product while it is being executed
in memory in an operating system
D Test performed on an application or software product while it is using real data
in production
Which of the following best describes SAML?
,A A standard for exchanging usernames and passwords across devices
B A standard for exchanging authentication and authorization data between
security domains
C A standard for developing secure application management logistics
D A standard used for directory synchronization
Web application firewalls (WAFs) are designed primarily to protect applications
from common attacks like
A Syn floods
B Password cracking
C XSS and SQL injection
D Ransomware
The application normative framework is best described as which of the following?
A A superset of the ONF
B The complete ONF
C A stand-alone framework for storing security practices for the ONF
D A subset of the ONF
, In a federated identity arrangement using a trusted third-party model, who is the
identity provider and who is the relying party?
A A contracted third party/the various member organizations of the federation
B Each member organization/each member organization
C Each member organization/a trusted third party
D The users of the various organizations within the federation/a CASB
Which of the following best describes the purpose and scope of ISO/IEC 27034-1?
A Provides an overview of network and infrastructure security designed to secure
cloud applications
B Serves as a newer replacement for NIST 800-53 r4
C Provides an overview of application security that introduces definitive concepts,
principles, and processes involved in application security
D Describes international privacy standards for cloud computing
Which of the following best describes the Organizational Normative Framework
(ONF)?
A A set of application security, and best practices, catalogued and leveraged by
the organization
B A framework of containers for all components of application security, best
practices, catalogued and leveraged by the organization