C838 -CCSP Exam 6 Questions with
100% Correct Answers.
What jurisdictional data protection includes dealing with the international transfer of
data?
Privacy regulation
What jurisdictional data protection controls the ways that financial institutions deal
with the private information of individuals?
Gramm-Leach-Bliley act (GLBA)
What jurisdictional data protection safeguards protected health information (PHI)?
Health Insurance Portability and Accountability Act (HIPAA)
How is the compliance of the cloud service provider's legal and regulatory requirements
verified when securing personally identifiable information (PII) in the cloud
Third-Party audits and attestations
What security strategy is associated with data rights management solutions
Continuous auditing
Who retains final ownership for granting data access and permissions in a shared
responsibility model?
Customer
What data retention solution should be applied to a file in order to reduce data footprint
by deleting fixed content and duplicate data?
Archiving
,What data retention method is stored with minimal amount of metadata storage with
the content?
Block-based
What standard addresses practices related to acquisition of forensic artifacts and can be
directly applied to a cloud environment
ISO/IEC 27050-1
What action enhances cloud security application deployment through standards such as
ISO/IEC 27034 for development, acquisition, and configuration of software systems
Applying the steps of a cloud software development lifecycle
A cloud customer is setting up communication paths with the cloud service provider that will
be used in the event of an incident. WHat action facilitates this type of communication
using existing open standards
A CSP provides services in the EU countries that are subject to the network information
security (NIS) directive. The CSP experiences an incident that significantly affects the
continuity of the essential services being provided. Who is the CSP required to notify under
the NIS directive
Competent authorities
A CSP operating in Australia experiences a security breach that results in disclosure of
personal information that is likely to result in serious harm. Who is the CSP legally
required to notify
Information commissioner
The security administrator for a global cloud service provider is required to globally
standardize the approaches for using forensics methodologies in the organization.
What standard should be applied
ISO 27050-1
, What method is being used when a company evaluates the acceptable loss exposure
associated with a cloud solution for a given set of objectives and resources
Risk appetite
What regulation requires a CSP to comply with copyright law for a hosted content
DMCA
What part of the logical infrastructure design is used to configure cloud resources, such as
launching virtual machines or configuring virtual networks
Management Plane
What technology allows an administrator to remotely manage a fleet of servers
Management plane
What is a component of device hardening
Patching
What result is achieved by removing all nonessential services and software of devices for
secure configuration of hardware
Hardening
Which service model influences the logical design by using additional measures in
the application to enhance security
SaaS
What logical design decision can be attributed to required regulation
Retention periods
What legislation must a trusted cloud service adhere to when utilizing the data of EU
citizens
GDPR
100% Correct Answers.
What jurisdictional data protection includes dealing with the international transfer of
data?
Privacy regulation
What jurisdictional data protection controls the ways that financial institutions deal
with the private information of individuals?
Gramm-Leach-Bliley act (GLBA)
What jurisdictional data protection safeguards protected health information (PHI)?
Health Insurance Portability and Accountability Act (HIPAA)
How is the compliance of the cloud service provider's legal and regulatory requirements
verified when securing personally identifiable information (PII) in the cloud
Third-Party audits and attestations
What security strategy is associated with data rights management solutions
Continuous auditing
Who retains final ownership for granting data access and permissions in a shared
responsibility model?
Customer
What data retention solution should be applied to a file in order to reduce data footprint
by deleting fixed content and duplicate data?
Archiving
,What data retention method is stored with minimal amount of metadata storage with
the content?
Block-based
What standard addresses practices related to acquisition of forensic artifacts and can be
directly applied to a cloud environment
ISO/IEC 27050-1
What action enhances cloud security application deployment through standards such as
ISO/IEC 27034 for development, acquisition, and configuration of software systems
Applying the steps of a cloud software development lifecycle
A cloud customer is setting up communication paths with the cloud service provider that will
be used in the event of an incident. WHat action facilitates this type of communication
using existing open standards
A CSP provides services in the EU countries that are subject to the network information
security (NIS) directive. The CSP experiences an incident that significantly affects the
continuity of the essential services being provided. Who is the CSP required to notify under
the NIS directive
Competent authorities
A CSP operating in Australia experiences a security breach that results in disclosure of
personal information that is likely to result in serious harm. Who is the CSP legally
required to notify
Information commissioner
The security administrator for a global cloud service provider is required to globally
standardize the approaches for using forensics methodologies in the organization.
What standard should be applied
ISO 27050-1
, What method is being used when a company evaluates the acceptable loss exposure
associated with a cloud solution for a given set of objectives and resources
Risk appetite
What regulation requires a CSP to comply with copyright law for a hosted content
DMCA
What part of the logical infrastructure design is used to configure cloud resources, such as
launching virtual machines or configuring virtual networks
Management Plane
What technology allows an administrator to remotely manage a fleet of servers
Management plane
What is a component of device hardening
Patching
What result is achieved by removing all nonessential services and software of devices for
secure configuration of hardware
Hardening
Which service model influences the logical design by using additional measures in
the application to enhance security
SaaS
What logical design decision can be attributed to required regulation
Retention periods
What legislation must a trusted cloud service adhere to when utilizing the data of EU
citizens
GDPR