100% satisfaction guarantee Immediately available after payment Both online and in PDF No strings attached 4.2 TrustPilot
logo-home
Exam (elaborations)

CCSK Domain 10 Application Security Questions with 100% Actual correct answers | verified | latest update | Graded A+ | Already Passed | Complete Solution

Rating
-
Sold
-
Pages
7
Grade
A
Uploaded on
18-06-2024
Written in
2023/2024

CCSK Domain 10 Application Security Questions with 100% Actual correct answers | verified | latest update | Graded A+ | Already Passed | Complete Solution










Whoops! We can’t load your doc right now. Try again or contact support.

Document information

Uploaded on
June 18, 2024
Number of pages
7
Written in
2023/2024
Type
Exam (elaborations)
Contains
Questions & answers

Subjects

Content preview

CCSK Domain 10 Application Security
XACML - ANS-eXtensible Access Control Markup Language

OpenID - ANS-an open standard permitting users to be authenticated in a decentralized
manner

OAuth - ANS-Open Authorization, an open standard for authorization allowing users to
share their private resources with tokens instead of credentials

SAML - ANS-Security Assertion Markup Language, an XML-based OASIS open
standard for exchanging authentication & authorization data between security domains

IdEA - ANS-Identity
Entitlement
Access Management

ISAE 3402 / SSAE 16 - ANS-replaces SAS 70

What are the components of IdEA? - ANS-Authentication
Authorization
Administration
Audit and Compliance
Policy

For user-centric authorization model, the user is the _______________. The user
determines the access for their resources, and the service provider acts as
_______________. - ANS-PDP, PEP

OAuth is widely used for this model, and User Managed Access (UMA) is also an
emerging standard in this space.

For an enterprise-centric authorization model, the enterprise is the _______________
or _______________ and the service provider acts as _______________ - ANS-PDP
Policy Access Point (PAP)
PEP

Authorization - ANS-in broadest terms refers to enforcing the rules by which access is
granted to the resources

, What are the 3 approaches for interoperability testing? - ANS-Testing all pairs
Testing some of the combinations
Testing against a reference implementation

OWASP Testing Guide V3.0

Penetration Testing - ANS-Configuration Management Testing
Business Logic Testing
Authentication Testing
Session Management Testing
Data Validation Testing
Denial of Service
Web Service Testing
Ajax Testing (RIA Security Testing)

Mash-up - ANS-A mashup in web development is a web page or web application, that
uses content from more than one-source to create a single new service displayed in a
single graphical interface.

The term implies easy, fast integration, frequently using open API and data sources to
produce enriched results that were not necessarily the original reason for producing the
raw source data

Threat for cloud apps & cooresponding address by IdEA - ANS-Spoofing --
Authentication
Tampering -- Hash or Digital Signature
Repudiation -- Digital Signature (use SAML) *****************audit logging
Information Disclosure -- SSL, encryption
*****************(strictly not IdEA specific)
Denial of Service -- Security Gateway
Elevation of Privileges -- Authorization (OAuth)

SAPM - ANS-Shared Acct Password Management

manages highly privileged accounts allows for segregation of duties and least priviledge

SCIM - ANS-Simple Cloud Identity Management
(new emerging standard)

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
DoctorHkane Havard School
View profile
Follow You need to be logged in order to follow users or courses
Sold
732
Member since
4 year
Number of followers
168
Documents
22476
Last sold
1 week ago

Explore my Stuvia collection for essential study aids: test banks, exams, summaries, and cases. With five years of expertise as an academic writer, I have honed my skills in crafting top-notch essays, exams, and research dissertations. My proficiency lies in producing well-structured and thoroughly researched content that meets academic standards. I am adept at handling various subjects and ensuring a seamless flow of ideas. Whether it's delivering compelling arguments in essays, creating challenging yet fair exam questions, or delving into in-depth research for dissertations, my experience equips me to excel in diverse academic writing tasks. I pride myself on meeting deadlines and maintaining the highest quality in every piece I produce. REACH ON iamnjokikelvin1@gmail

Read more Read less
4.6

386 reviews

5
308
4
29
3
21
2
10
1
18

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Frequently asked questions