
Get Latest [Apr-2022] Conduct effective penetration tests using PassTestking CCSK
Penetration testers simulate CCSK exam PDF
Topics of Certificate of Cloud Security Knowledge (CCSK) Exam
This syllabus outline for the Certificate of Cloud Security Knowledge (CCSK) Exam can be found in the CCSk exam dumps pdf and focuses on the critical areas of the exam. Below, the main sections along with their subsections are listed:
1. Cloud Computing Concepts and Architectures
Objectives covered by this section:
- Logical Model
- Reference and Architecture Models
- Service Models
2. Governance and Enterprise Risk Management
Objectives covered by this section:
- Effects of various Service and Deployment Models
- Tools of Cloud Governance
- Cloud Risk Trade-offs and Tools
- Enterprise Risk Management in the Cloud
3. Legal Issues, Contracts, and Electronic Discovery
Objectives covered by this section:
- Cross-Border Data Transfer
- Data Custody
- Contracts and Provider Selection
- Response to a Subpoena or Search Warrant
- Data Preservation
- Contracts
4. Compliance and Audit Management
Objectives covered by this section:
- Auditor requirements
- Compliance in the Cloud
- Audit scope
- Right to audit
- Audit Management in the Cloud
5. Information Governance
Objectives covered by this section:
- Six phases of the Data Security Lifecycle and their key elements
- Data Security Functions, Actors and Controls
- Governance Domains
6. Management Plane and Business Continuity
Objectives covered by this section:
- Management Plane Security
- Architect for Failure
- Business Continuity and Disaster Recovery in the Cloud
7. Infrastructure Security
Objectives covered by this section:
- Cloud Compute and Workload Security
- Micro-segmentation and the Software-Defined Perimeter
- Security Changes With Cloud Networking
- Hybrid Cloud Considerations
- SDN Security Benefits
- Challenges of Virtual Appliances
8. Virtualization and Containers
Objectives covered by this section:
- Storage
- Containers
- Mayor Virtualizations Categories
- Network
9. Incident Response
Objectives covered by this section:
- Incident Response Lifecycle
- How the Cloud Impacts IR
10. Application Security
Objectives covered by this section:
- Opportunities and Challenges
- The Rise and Role of DevOps
- Secure Software Development Lifecycle
- How Cloud Impacts Application Design and Architectures
11. Data Security and Encryption
Objectives covered by this section:
- Data Security Controls
- Securing Data in the Cloud
- Managing Data Migrations to the Cloud
- Cloud Data Storage Types
12. Identity, Entitlement, and Access Management
Objectives covered by this section:
- Entitlement and Access Management
- Managing Users and Identities
- IAM Standards for Cloud Computing
- Authentication and Credentials
13. Security as a Service
Objectives covered by this section:
- Potential Benefits and Concerns of SecaaS
- Major Categories of Security as a Service Offerings
14. Related Technologies
Objectives covered by this section:
- Mobile
- Internet of Things
- Serverless Computing
- Big Data
15. ENISA Cloud Computing: Benefits, Risks, and Recommendations for Information Security
Objectives covered by this section:
- Isolation failure
- Risk concerns of a cloud provider being acquired
- Data controller versus data processor definitions
- Underlying vulnerability in Loss of Governance
- Top security risks in ENISA research
- Economic Denial of Service
- VM hopping
- Licensing Risks
- Security benefits of cloud
- Five key legal issues common across all scenarios
- OVF
- In Infrastructure as a Service (IaaS), who is responsible for guest systems monitoring
- Risks R.1 - R.35 and underlying vulnerabilities
16. Cloud Security Alliance - Cloud Controls Matrix
Objectives covered by this section:
- CCM Domains
- CCM Controls
- Mapped Standards and Frameworks
How to book the Certificate of Cloud Security Knowledge (CCSK) Exam
Follow the steps mentioned below to book the CCSk exam test:
- Step 1: Access the Cloud Security Alliance's website by clicking here
- Step 2: Click the “Login to buy” button
- Step 3: On the page that appears, create your account
- Step 4: Select your exam and purchase the exam token
- Step 5: After payment, follow the steps to schedule the exam
NEW QUESTION 118
NIST defines five characteristics of cloud computing- Rapid Elasticity, Broad Network Access, 0n demand self-service, Metered Usage & Resource pooling. However, IS0/lEC17788 mentions one more characteristic in addition is those 5. Which of the following is that characterstic?
- A. Isolation
- B. Segregation
- C. Automation
- D. Multitenancy
Answer: D
Explanation:
IS0/lEC17788 lists six key characteristics. the first five of which are identical to the NIST characteristics.
The only addition is multitenancy. which is distinct from resource pooling.
Ref: CSA Security Guidelines V4.0
NEW QUESTION 119
Which of the following Storage type is NOT associated with SaaS solution?
- A. Ephemeral Storage
- B. Raw Storage
- C. Content Delivery network
- D. Volume Storage
Answer: D
Explanation:
Volume storage is commonly associated with IaaS solutions.
All the other 3 options are related to SaaS solutions
NEW QUESTION 120
Your cloud and on-premises infrastructures should always use the same network address ranges.
- A. False
- B. True
Answer: A
NEW QUESTION 121
Where does the encryption engine and key reside when doing file-level encryption?
- A. On the instance attached to the system
- B. Encryption engine resides on the server and keys on the client side
- C. On the client side
- D. On the KMS attached to the system
Answer: A
Explanation:
File-level encryption: Database servers typically reside on volume storage. For this deployment, you are encrypting the volume or folder of the database, with the encryption engine and keys residing on the instances attached to the volume.
External file system encryption protects from media theft, lost backups, and external attack but does not protect against attacks with access to the application layer, the instances 0S, or the data
NEW QUESTION 122
In volume storage, what method is often used to support resiliency and security?
- A. data rights management
- B. random placement
- C. hypervisor agents
- D. data dispersion
- E. proxy encryption
Answer: D
NEW QUESTION 123
Which of the following is not one of the essential characteristics as defined by NIST 800-145?
- A. Resource Pooling
- B. On-demand Shelf service
- C. Rapid Elasticity
- D. Broad Network Access
Answer: B
Explanation:
The key characteristic is on-demand self-service and not shelf" service.
NEW QUESTION 124
ENISA: A reason for risk concerns of a cloud provider being acquired is:
- A. Provider may change physical location
- B. Mass layoffs may occur
- C. Resource isolation may fail
- D. Arbitrary contract termination by acquiring company
- E. Non-binding agreements put at risk
Answer: E
Explanation:
Explanation/Reference:
NEW QUESTION 125
Which of the following processes plays a major role in managing system vulnerabilities?
- A. Capacity Management
- B. Patch Management
- C. Incident Management
- D. Release Management
Answer: B
Explanation:
Although other process are part of overall security strategy proper patch management plays key role in keeping control on system vulnerabilities.
NEW QUESTION 126
Security Governance, Risk and Compliance(GRC) is, generally, responsibility of which of the following across all the platforms (IaaS, PaaS and SaaS)?
- A. Joint Responsibility
- B. Shared responsibility
- C. Cloud Service Provider
- D. Customer
Answer: D
Explanation:
GRC is responsibility of the customer across all service models.
NEW QUESTION 127
The basis for deciding which laws are most appropriate in a situation where conflicting laws exist. refers to:
- A. Criminal law
- B. Doctrine of proper law
- C. The Restatement(Second) Conflict of Law
- D. Tort law
Answer: C
Explanation:
The Restatement(Second) Conflict of Law refers to a collation of developments in common law that help the courts stay up with changes. Many states have conflicting laws. and judges use these restatements to assist them in determining which laws should apply when conflicts occur.
NEW QUESTION 128
One of the primary benefits of the cloud is the ability to perform dynamic allocation of physical resources when required. The most common approach is a multi-tenant environment. However, it increases risk of disclosure of customer dat a. This can happen because of which of the following?
- A. Tenancy termination
- B. No disaster recovery plan
- C. Increased DDoS
- D. Isolation Failure
Answer: D
Explanation:
All resources allocated to a particular tenant should be "isolated" and protected to avoid disclosure of information to other tenants For example, when allocated storage is no longer needed IIS Security Considerations for Cloud Computing by a client it can be freely reallocated to another enterprise. ln that case, sensitive data could be disclosed if the storage has not been scrubbed thoroughly(e.g, using forensic software).
NEW QUESTION 129
Insufficient Identity. Credential and Access Management can lead to which of the following?
- A. Spoofing Identity
- B. Tampering with Data
- C. All of the above
- D. Information Disclosure
Answer: C
Explanation:
Sufficient Identity and Access Management practice should be followed in cloud environment.
Weakness in Identity, Credential and Access Management can lead to all types of threats as a compromised credential opens door to complete internal infrastructure.
NEW QUESTION 130
You, as a cloud customer, will more control on event and diagnostic data in SaaS environment than in the PaaS or IaaS environment.
- A. False
- B. True
Answer: A
Explanation:
This is false because it will be exactly opposite. ln SaaS environment, you will least amount of controls on event and diagnostic data. Your control will, in fact, increase as you for from SaaS to PaaS and eventually, in IaaS, you will have full control Event and diagnostic data (except of platform logs which is maintained by the cloud service provider).
NEW QUESTION 131
When Database as a Service is offered on Platform as a Service(PaaS) model, who is responsible for security features that needs to applied to the Databases?
- A. Cloud Access Security Broker (CASB)
- B. Cloud Carrier
- C. Cloud Service Provider
- D. Cloud Consumer
Answer: D
Explanation:
This is a tricky question.
When using a Database as a Service, the provider manages fundamental security, patching, and core configuration, while the cloud user is responsible for everything else, including which security features of the database to use, managing accounts, or even authentication methods.
Ref: CSA Security Guidelines v4.0
NEW QUESTION 132
What is true of security as it relates to cloud network infrastructure?
- A. You should apply cloud firewalls on a per-network basis.
- B. You should always open traffic between workloads in the same virtual subnet for better visibility.
- C. You should implement a default deny with cloud firewalls.
- D. You should deploy your cloud firewalls identical to the existing firewalls.
- E. You should implement a default allow with cloud firewalls and then restrict as necessary.
Answer: C
NEW QUESTION 133
......
Introduction to Certificate of Cloud Security Knowledge (CCSK) Exam
Learn the core concepts, best practices, and recommendations for securing an organization on the cloud regardless of the provider or platform. Covering all the 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage the information from CSA's vendor-neutral research to keep data secure on the cloud.
They need information security experts who are cloud-savvy as companies move to the cloud. The CCSK certificate is generally accepted as the cloud protection standard of expertise and gives you the foundations you need to protect data in the cloud. It is your decision on how you choose to draw on that experience.
The certification has the following objectives. These objectives can be fulfilled by carefully studying the CCSk exam dumps:
- Recommendations from the cloud guidelines of the European Union Agency for Network and Information Security (ENISA)
- Compared to internationally agreed requirements, the knowledge to build a comprehensive cloud protection program effectively
- Using the cloud-specific governance & enforcement tool, how to determine the protection of cloud providers and your organization: Cloud Controls Matrix
- An in-depth understanding of cloud computing's full capabilities
Tested Material Used To CCSK Test Engine: https://www.passtestking.com/Cloud-Security-Alliance/CCSK-practice-exam-dumps.html
Steps Necessary To Pass The CCSK Exam: https://drive.google.com/open?id=1DLCDDJwp4PT-rS9xmluDNMxbd5VREmk8