C838- CCSP Exam Questions with 100%
Correct Answers.
/data.
Live system
NOT an aspect of SAST?
public, private, hybrid and community
The 4 cloud deployment models
GitHub
A website for hosting source code in Git. It is the most common place to share and collaborate on
open source projects, and can also be used to host private repositories for companies.
Escalation
NOT a core component of an SIEM solution?
Malicious insiders
The most difficult threat type for an organization to defend against and detect
object and volume
IaaS storage types
cryptographic erasure
Data-sanitation approach is always available within a cloud environment
IPS
will make a elasticity a bigger challenge in a cloud environment.
Portability
the ability of the cloud customers to easily move services from one cloud provider to another
Spoofing
,What does the S stand for in the STRIDE threat model?
integrity
Which is not a major concern with encryption systems?
healthcare
HIPPA
Relying Party
In a federated environment, this is the party that relies on security claims authenticated by an
identity provider
use
Which phase of the cloud data lifecycle involves processing by a user or application?
Data in archive
NOT a state of data that is important for security and encryption?
FIPS 140
Standard and certification for cryptographic modules?
Type 1 hypervisor
Also known as a bare metal hypervisor it is a software program that acts as an operating system
and also provides the ability to perform virtualization of other operating systems using the
same computer.
Cross-site scripting
the following threats involves sending untrusted data to a user's browser in an attempt to have
it executed using the user's permissions and access
Tokenization
involves assigning an opaque value to sensitive data fields to protect confidentiality
Financial security
, Not one of the security domains presented within the cloud controls matrix CCM
ISO/IEC 17788
Documents the cloud definitions for staffing and official roles
ZIP code
NOT included as a part of PII as a direct identifier
Portability
concept pertains to the risk an organization entails in regard to the ability to move between
cloud providers at a later date
Hardware
NOT one of the core building blocks of cloud computing
Costs
You have been tasked with Creating an audit scope statement and are making your project
outline. Which of the following is not typically included in an audit scope statement?
PIN code
NOT be appropriate as a secondary factor after a password is used
ISO/IEC 27050
ISO/IEC standards pertains to eDiscovery processes and best practices
Cloud service administrator
Not part of ISO/IEC 17789
GLBA
relates to the use and protection of PII with financial institutions
Network
Not part of the cloud service capabilities
Correct Answers.
/data.
Live system
NOT an aspect of SAST?
public, private, hybrid and community
The 4 cloud deployment models
GitHub
A website for hosting source code in Git. It is the most common place to share and collaborate on
open source projects, and can also be used to host private repositories for companies.
Escalation
NOT a core component of an SIEM solution?
Malicious insiders
The most difficult threat type for an organization to defend against and detect
object and volume
IaaS storage types
cryptographic erasure
Data-sanitation approach is always available within a cloud environment
IPS
will make a elasticity a bigger challenge in a cloud environment.
Portability
the ability of the cloud customers to easily move services from one cloud provider to another
Spoofing
,What does the S stand for in the STRIDE threat model?
integrity
Which is not a major concern with encryption systems?
healthcare
HIPPA
Relying Party
In a federated environment, this is the party that relies on security claims authenticated by an
identity provider
use
Which phase of the cloud data lifecycle involves processing by a user or application?
Data in archive
NOT a state of data that is important for security and encryption?
FIPS 140
Standard and certification for cryptographic modules?
Type 1 hypervisor
Also known as a bare metal hypervisor it is a software program that acts as an operating system
and also provides the ability to perform virtualization of other operating systems using the
same computer.
Cross-site scripting
the following threats involves sending untrusted data to a user's browser in an attempt to have
it executed using the user's permissions and access
Tokenization
involves assigning an opaque value to sensitive data fields to protect confidentiality
Financial security
, Not one of the security domains presented within the cloud controls matrix CCM
ISO/IEC 17788
Documents the cloud definitions for staffing and official roles
ZIP code
NOT included as a part of PII as a direct identifier
Portability
concept pertains to the risk an organization entails in regard to the ability to move between
cloud providers at a later date
Hardware
NOT one of the core building blocks of cloud computing
Costs
You have been tasked with Creating an audit scope statement and are making your project
outline. Which of the following is not typically included in an audit scope statement?
PIN code
NOT be appropriate as a secondary factor after a password is used
ISO/IEC 27050
ISO/IEC standards pertains to eDiscovery processes and best practices
Cloud service administrator
Not part of ISO/IEC 17789
GLBA
relates to the use and protection of PII with financial institutions
Network
Not part of the cloud service capabilities