C838 - Exam 8 Questions with 100% Correct
Answers.
125 What is the definition of transportable as it relates to cloud contract design
requirements?
a. Available to be accessed by mobile devices
b. Able to be archived quickly
c. Able to be moved to another vendor
d. Available in a proprietary format
c. Able to be moved to another vendor
124 Which document, commonly existing in an IT enterprise, can be used to speed up the
process of identifying a potential cloud service provider (CSP)?
a. Egress safety design
b. Entity relationship and data flow diagrams
c. Physical plant blueprint
d. Business continuity and disaster recovery plan
d. Business continuity and disaster recovery plan
123 Which risk is unable to be highlighted from the outset in a cloud services contract?
a. Sunsetting of aging technology
b. Changes resulting from contract renewals
c. introduction of new technology
d. Result of an unforeseen event
d. Result of an unforeseen event
122 Which aspect of strong authentication is part of enterprise risk management?
a. Distributed organizations
b. Entitlement consideration
c. Federated identities
d. Privileged user management
,b. Entitlement consideration
121 Which risk is assumed by an enterprise that chooses to use vendor-provided cloud
resources?
a. Loss of certification
b. Multitenant deployments
c. Lack of skilled technical personnel
d. Incompatible infrastructure
b. Multitenant deployments
120 Which risk mitigation technique will compensate a cloud service customer for failures
on the part of the cloud service provider?
a. Recovery time objective
b. Suspension of service clause
c. Data protection requirements
d. SLA penalties
d. SLA penalties
119 An organization is undergoing an ISO-27001 audit that includes a software as a service
(Saas) solution within scope, and the auditor has requested evidence of controls. What
evidence should the organization provide the auditor?
a. Physical diagram of the data center
b. Operating system patch logs
c. Network firewall rules
d. Provider compliance attestation
d. Provider compliance attestation
118. A business wants to avoid buying physical hardware and wants to host a PCI-DSS
compliant application using the infrastructure as a service (laaS) model of a public cloud
provider. Which method can be used to provide network monitoring security controls in
this environment?
a. Redundant network firewalls
,b. Host agent intrusion detection system
c. Cloud Service Provider audit logs
d. Sniffed network ports
c. Cloud Service Provider audit logs
117 Which characteristic could affect the audit process for a customer of a cloud service
provider?
a. Lack of physical access to the cloud infrastructure
b. Utilization constraints on the bandwidth imposed by the cloud service vendor
c. Restrictions on the data storage options offered by the cloud service provider
d. Limits for up-time of the hosted system
b. Utilization constraints on the bandwidth imposed by the cloud service vendor
116 What must be provided by a European Union (EU) citizen, according to the general
data protection regulation (GDPR), before a firm may process the personal data of that
individual?
a. Statement about need for the data to be processed
b. Specific consent for the processing of the data
c. Attestation on the legal purpose for processing the data
d. Verification of the accuracy of the data
b. Specific consent for the processing of the data
115 Which country lacks a national law assuring individual personal privacy?
a. New Zealand
b. Israel
c United States
d. Canada
c United States
The United States does not have a national law that specifically guarantees individuals the right
to privacy. However, there are a number of federal laws that offer some privacy protection. For
, example, the Privacy Act of 1974 establishes restrictions on how the federal government can
collect, use, and disclose personal information.
114 Which requirement for cross-border data transfer is part of the general data
protection regulation (GDPR)?
a. Formal consent of the data owner
b. Acknowledgement of liability for protection by the entity receiving the data transfer
c. Acceptance of liability for protection by the transferring entity
d. Demonstration of adequate level of protection similar to GDPR
.d. Demonstration of adequate level of protection similar to GDPR
113 Which general body of law covers data breach violations in a cloud environment at a
federal agency?
a. Administrative
b. Tort
c. Criminal
d. Civil
c. Criminal
112 Which guide remedies the challenge of the international nature of cloud forensics and
is known for becoming the premier standard for eDiscovery?
a. ISO/IEC 27050-1:2016
b. ISO/IEC 27037-2012
c ISO/ IEC 27041:2015
d. ISO/IEC 27042 2015
a. ISO/IEC 27050-1:2016
111 Which model does the cloud security alliance (CSA) use as its standard for defining
cloud computing?
a. SAS 70
b. SOX
Answers.
125 What is the definition of transportable as it relates to cloud contract design
requirements?
a. Available to be accessed by mobile devices
b. Able to be archived quickly
c. Able to be moved to another vendor
d. Available in a proprietary format
c. Able to be moved to another vendor
124 Which document, commonly existing in an IT enterprise, can be used to speed up the
process of identifying a potential cloud service provider (CSP)?
a. Egress safety design
b. Entity relationship and data flow diagrams
c. Physical plant blueprint
d. Business continuity and disaster recovery plan
d. Business continuity and disaster recovery plan
123 Which risk is unable to be highlighted from the outset in a cloud services contract?
a. Sunsetting of aging technology
b. Changes resulting from contract renewals
c. introduction of new technology
d. Result of an unforeseen event
d. Result of an unforeseen event
122 Which aspect of strong authentication is part of enterprise risk management?
a. Distributed organizations
b. Entitlement consideration
c. Federated identities
d. Privileged user management
,b. Entitlement consideration
121 Which risk is assumed by an enterprise that chooses to use vendor-provided cloud
resources?
a. Loss of certification
b. Multitenant deployments
c. Lack of skilled technical personnel
d. Incompatible infrastructure
b. Multitenant deployments
120 Which risk mitigation technique will compensate a cloud service customer for failures
on the part of the cloud service provider?
a. Recovery time objective
b. Suspension of service clause
c. Data protection requirements
d. SLA penalties
d. SLA penalties
119 An organization is undergoing an ISO-27001 audit that includes a software as a service
(Saas) solution within scope, and the auditor has requested evidence of controls. What
evidence should the organization provide the auditor?
a. Physical diagram of the data center
b. Operating system patch logs
c. Network firewall rules
d. Provider compliance attestation
d. Provider compliance attestation
118. A business wants to avoid buying physical hardware and wants to host a PCI-DSS
compliant application using the infrastructure as a service (laaS) model of a public cloud
provider. Which method can be used to provide network monitoring security controls in
this environment?
a. Redundant network firewalls
,b. Host agent intrusion detection system
c. Cloud Service Provider audit logs
d. Sniffed network ports
c. Cloud Service Provider audit logs
117 Which characteristic could affect the audit process for a customer of a cloud service
provider?
a. Lack of physical access to the cloud infrastructure
b. Utilization constraints on the bandwidth imposed by the cloud service vendor
c. Restrictions on the data storage options offered by the cloud service provider
d. Limits for up-time of the hosted system
b. Utilization constraints on the bandwidth imposed by the cloud service vendor
116 What must be provided by a European Union (EU) citizen, according to the general
data protection regulation (GDPR), before a firm may process the personal data of that
individual?
a. Statement about need for the data to be processed
b. Specific consent for the processing of the data
c. Attestation on the legal purpose for processing the data
d. Verification of the accuracy of the data
b. Specific consent for the processing of the data
115 Which country lacks a national law assuring individual personal privacy?
a. New Zealand
b. Israel
c United States
d. Canada
c United States
The United States does not have a national law that specifically guarantees individuals the right
to privacy. However, there are a number of federal laws that offer some privacy protection. For
, example, the Privacy Act of 1974 establishes restrictions on how the federal government can
collect, use, and disclose personal information.
114 Which requirement for cross-border data transfer is part of the general data
protection regulation (GDPR)?
a. Formal consent of the data owner
b. Acknowledgement of liability for protection by the entity receiving the data transfer
c. Acceptance of liability for protection by the transferring entity
d. Demonstration of adequate level of protection similar to GDPR
.d. Demonstration of adequate level of protection similar to GDPR
113 Which general body of law covers data breach violations in a cloud environment at a
federal agency?
a. Administrative
b. Tort
c. Criminal
d. Civil
c. Criminal
112 Which guide remedies the challenge of the international nature of cloud forensics and
is known for becoming the premier standard for eDiscovery?
a. ISO/IEC 27050-1:2016
b. ISO/IEC 27037-2012
c ISO/ IEC 27041:2015
d. ISO/IEC 27042 2015
a. ISO/IEC 27050-1:2016
111 Which model does the cloud security alliance (CSA) use as its standard for defining
cloud computing?
a. SAS 70
b. SOX