CCSP Review Assessment,
Managing Cloud Security ACTUAL
EXAM 2025 QUESTIONS WITH CORRECT
ANSWERS||A+ ALREADY GRADED
1. Vertical Cloud Computing - ANSWER ✓ The optimization of cloud
computing and cloud services for a particular vertical (e.g., a specific
industry) or specific-use application.
2. Virtualization Technologies - ANSWER ✓ Enable cloud computing to
become a real and scalable service offering due to the savings, sharing, and
allocations of resources across multiple tenants and environments.
3. All-or-Nothing-Transform with Reed-Solomon (AONT-RS) - ANSWER ✓
4. Criminal Law - ANSWER ✓ A body of rules and statutes that defines
conduct that is prohibited by the government and is set out to protect the
safety and well-being of the public.
5. Doctrine of the Proper Law - ANSWER ✓ When a conflict of laws occurs,
this determines in which jurisdiction the dispute will be heard.
6. eDiscovery - ANSWER ✓ Refers to any process in which electronic data is
sought, located, secured, and searched with the intent of using it as evidence
in a civil or criminal legal case.
7. EU General Data Protection Regulation 2012 - ANSWER ✓ Will introduce
many significant changes for data processors and controllers. The following
may be considered as some of the more significant changes: The concept of
, consent, Transfers Abroad, The right to be forgotten, Establishment of the
role of the "Data Protection Officer", Access Requests, Home State
Regulation, Increased Sanctions
8. Gramm-Leach-Bliley Act (GLBA) - ANSWER ✓ Federal law enacted in the
United States to control the ways that financial institutions deal with the
private information of individuals.
9. Health Insurance Portability and Accountability Act of 1996 (HIPAA) -
ANSWER ✓ Adopt national standards for electronic healthcare transactions
and national identifiers for providers, health plans, and employers. Protected
Health information can be stored via cloud computing under HIPAA.
10.Information gathering - ANSWER ✓ Refers to the process of identifying,
collecting, documenting, structuring, and communicating information from
various sources in order to enable educated and swift decision making to
occur.
11.ISO/IEC 27018 - ANSWER ✓ Address the privacy aspects of cloud
computing for consumers and is the first international set of privacy controls
in the cloud.
12.Sarbanes Oxley Act (SOX) - ANSWER ✓ Legislation enacted to protect
shareholders and the general public from accounting errors and fraudulent
practices in the enterprise.
13.Service Organization Controls 1 (SOC 1) - ANSWER ✓ Reports on
Controls at Service organizations relevant to user entities' Internal Control
over financial reporting.
14.Service Organization Controls 2 (SOC 2) - ANSWER ✓ Reports on
Controls at a Service Organization Relevant to Security, Availability,
Processing Integrity, Confidentiality and Privacy.
15.Stored Communication Act - ANSWER ✓ Enacted in the United States in
1986 as part of the Electronic Communications Privacy Act. It provides
privacy protections for certain electronic communication and computing
services from unauthorized access or interception.
, 16.Tort Law - ANSWER ✓ A body of rights, obligations, and remedies that
sets out reliefs for persons suffering harm as a result of the wrongful acts of
others.
17.Integrates the AONT and erasure coding. This method first encrypts and
transforms the information and the encryption key into blocks in a way that
the information cannot be recovered without using all the blocks, and then it
uses the IDA to split the blocks into m shares that are distributed to different
cloud storage services (the same as in SSMS).
18.Anonymization - ANSWER ✓ The act of permanently and completely
removing personal identifiers from data, such as converting personally
identifiable information (PII) into aggregated data.
19.Bit Splitting - ANSWER ✓ Usually involves splitting up and storing
encrypted information across different cloud storage services.
20.Business Impact Analysis (BIA) - ANSWER ✓ An exercise that determines
the impact of losing the support of any resource to an organization,
establishes the escalation of that loss over time, identifies the minimum
resources needed to recover, and prioritizes the recovery of processes and
supporting systems.
21.Control - ANSWER ✓ Acts as a mechanism to restrict a list of possible
actions down to allowed or permitted actions.
22.Crypto-shredding - ANSWER ✓ The process of deliberately destroying the
encryption keys that were used to encrypt the data originally.
23.Data Loss Prevention (DLP) - ANSWER ✓ Audit and prevent unauthorized
data exfiltration.
24.Degaussing - ANSWER ✓ Using strong magnets for scrambling data on
magnetic media such as hard drives and tapes.