A data custodian is responsible for which of the following?
Reveal answer details Close answer details
Correct answerC
A data custodian is responsible for the safe custody, transport, and storage of data, and the implementation of business roles.
ISC · CCSP
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
A data custodian is responsible for which of the following? Reveal answer details Close answer detailsCorrect answerC Explanation A data custodian is responsible for the safe custody, transport, and storage of data, and the implementation of business roles.
Single choice
What are the U.S. Reveal answer details Close answer detailsCorrect answerC Explanation ITAR is a Department of State program. Evaluation assurance levels are part of the Common Criteria standard from ISO. Digital rights management tools are used for protecting electronic processing of intellectual property.
Single choice
Which of the cloud deployment models is used by popular services such as iCloud, Dropbox, and OneDrive? Reveal answer details Close answer detailsCorrect answerB Explanation Popular services such as iCloud, Dropbox, and OneDrive are all publicly available and are open to any user for free, with possible add-on services offered for a cost.
Single choice
As part of the auditing process, getting a report on the deviations between intended configurations and actual policy is often crucial for an organization. What term pertains to the process of generating such a report? Reveal answer details Close answer detailsCorrect answerC Explanation The gap analysis determines if there are any differences between the actual configurations in use on systems and the policies that govern what the configurations are expected or mandated to be. The other terms provided are all similar to the correct answer ("findings" in particular is often used to articulate deviations in configurations), but gap analysis is the official term used.
Single choice
Which aspect of data poses the biggest challenge to using automated tools for data discovery and programmatic data classification? Reveal answer details Close answer detailsCorrect answerC Explanation The biggest challenge for properly using any programmatic tools in data discovery is the actual quality of the data, including the data being uniform and well structured, labels being properly applied, and other similar facets. Without data being organized in such a manner, it is extremely difficult for programmatic tools to automatically synthesize and make determinations from it. The overall quantity of data, as well as the number of sources, does not pose an enormous challenge for data discovery programs, other than requiring a longer time to process the data. The language of the data itself should not matter to a program that is designed to process it, as long as the data is well formed and consistent.
Single choice
Clustered systems can be used to ensure high availability and load balancing across individual systems through a variety of methodologies. What process is used within a clustered system to ensure proper load balancing and to maintain the health of the overall system to provide high availability? Reveal answer details Close answer detailsCorrect answerD Explanation Distributed resource scheduling (DRS) is used within all clustered systems as the method for providing high availability, scaling, management, workload distribution, and the balancing of jobs and processes.
Single choice
What are third-party providers of IAM functions for the cloud environment? Reveal answer details Close answer detailsCorrect answerD Explanation Data loss, leak prevention, and protection is a family of tools used to reduce the possibility of unauthorized disclosure of sensitive information. SIEMs are tools used to collate and manage log data. AES is an encryption standard.
Single choice
Which of the following actions will NOT make data part of the create phase of the cloud data lifecycle? Reveal answer details Close answer detailsCorrect answerB Explanation Modifying the metadata does not change the actual data. Although this initial phase is called "create," it can also refer to modification. In essence, any time data is considered "new," it is in the create phase. This can come from data that is newly created, data that is imported into a system and is new to that system, or data that is already present and is modified into a new form or value.
Single choice
Which of the following is NOT a factor that is part of a firewall configuration? Reveal answer details Close answer detailsCorrect answerA Explanation Firewalls take into account source IP, destination IP, the port the traffic is using, as well as the network protocol (UDP/TCP). Whether or not the traffic is encrypted is not something a firewall is concerned with.
Single choice
Which of the following is a widely used tool for code development, branching, and collaboration? Reveal answer details Close answer detailsCorrect answerA Explanation GitHub is an open source tool that developers leverage for code collaboration, branching, and versioning.
Single choice
DLP solutions can aid in deterring loss due to which of the following? Reveal answer details Close answer detailsCorrect answerC Explanation DLP solutions may protect against inadvertent disclosure. Randomization is a technique for obscuring data, not a risk to data. DLP tools will not protect against risks from natural disasters, or against impacts due to device failure.
Single choice
Which is the lowest level of the CSA STAR program? Reveal answer details Close answer detailsCorrect answerB Explanation The lowest level is Level 1, which is self-assessment, Level 2 is an external third-party attestation, and Level 3 is a continuous-monitoring program. Hybridization does not exist as part of the CSA STAR program.
Single choice
Which of the following is a commonly used tool for maintaining system configurations? Reveal answer details Close answer detailsCorrect answerC Explanation Puppet is a commonly used tool for maintaining system configurations based on policies, and done so from a centralized authority.
Single choice
Each of the following are dependencies that must be considered when reviewing the BIA after cloud migration except: Reveal answer details Close answer detailsCorrect answerC Explanation The cloud provider's resellers are a marketing and sales mechanism, not an operational dependency that could affect the security of a cloud customer.
Single choice
Which of the following is considered an administrative control? Reveal answer details Close answer detailsCorrect answerB Explanation A process is an administrative control; sometimes, the process includes elements of other types of controls (in this case, the access control mechanism might be a technical control, or it might be a physical control), but the process itself is administrative. Keystroke logging is a technical control (or an attack, if done for
Single choice
Apart from using encryption at the file system level, what technology is the most widely used to protect data stored in an object storage system? Reveal answer details Close answer detailsCorrect answerD Explanation Information rights management (IRM) technologies allow security controls and policies to be enforced on a data object regardless of where it resides. They also allow for extended controls such as expirations and copying restrictions, which are not available through traditional control mechanisms. Hypertext Transfer Protocol Secure (HTTPS), virtual private network (VPN), and Transport Layer Security (TLS) are all technologies and protocols that are widely used with cloud implementations for secure access to systems and services and likely will be used in conjunction with other object data protection strategies.
Single choice
What concept does the "D" represent with the STRIDE threat model? Reveal answer details Close answer detailsCorrect answerB Explanation Any application can be a possible target of denial-of-service (DoS) attacks. From the application side, the developers should minimize how many operations are performed for non-authenticated users. This will keep the application running as quickly as possible and using the least amount of system resources to help minimize the impact of any such attacks.
Single choice
Many aspects and features of cloud computing can make eDiscovery compliance more difficult or costly. Which aspect of cloud computing would be the MOST complicating factor? Reveal answer details Close answer detailsCorrect answerC Explanation With multitenancy, multiple customers share the same physical hardware and systems. With the nature of a cloud environment and how it writes data across diverse systems that are shared by others, the process of eDiscovery becomes much more complicated. Administrators cannot pull physical drives or easily isolate which data to capture. They not only have to focus on which data they need to collect, while ensuring they find all of it, but they also have to make sure that other data is not accidently collected and exposed along with it. Measured service is the aspect of a cloud where customers only pay for the services they are actually using, and for the duration of their use. Portability refers to the ease with which an application or service can be moved among different cloud providers. Broad network access refers to the nature of cloud services being accessed via the public Internet, either with or without secure tunneling technologies. None of these concepts would pertain to eDiscovery.
Single choice
Whereas a contract articulates overall priorities and requirements for a business relationship, which artifact enumerates specific compliance requirements, metrics, and response times? Reveal answer details Close answer detailsCorrect answerA Explanation The service level agreement (SLA) articulates minimum requirements for uptime, availability, processes, customer service and support, security controls, auditing requirements, and any other key aspect or requirement of the contract.
Single choice
Jurisdictions have a broad range of privacy requirements pertaining to the handling of personal data and information. Which jurisdiction requires all storage and processing of data that pertains to its citizens to be done on hardware that is physically located within its borders? Reveal answer details Close answer detailsCorrect answerD Explanation The Russian government requires all data and processing of information about its citizens to be done solely on systems and applications that reside within the physical borders of the country. The United States, European Union, and Japan focus their data privacy laws on requirements and methods for the protection of data, rather than where the data physically resides.
Single choice
Different certifications and standards take different approaches to data center design and operations. Reveal answer details Close answer detailsCorrect answerA Explanation The Infinity Paradigm of the International Data Center Authority (IDCA) takes a macro-level approach to data center design. The IDCA does not use a specific, focused approach on specific components to achieve tier status. Building Industry Consulting Services International (BICSI) issues certifications for data center cabling. The National Fire Protection Association (NFPA) publishes a broad range of fire safety and design standards for many different types of facilities. The Uptime Institute publishes the most widely known and used standard for data center topologies and tiers.
Single choice
What is a serious complication an organization faces from the compliance perspective with international operations? Reveal answer details Close answer detailsCorrect answerA Explanation When operating within a global framework, a security professional runs into a multitude of jurisdictions and requirements, which often may not be clearly applicable or may be in contention with each other. These requirements can involve the location of the users and the type of data they enter into systems, the laws governing the organization that owns the application and any regulatory requirements they may have, and finally the appropriate laws and regulations for the jurisdiction housing the IT resources and where the data is actually stored, which may be multiple jurisdictions as well. Different certifications would not come into play as a challenge because the major IT and data center certifications are international and would apply to any cloud provider. Different capabilities and different operational procedures would be mitigated by the organization's selection of a cloud provider and would not be a challenge if an appropriate provider was chosen, regardless of location.
Single choice
What changes are necessary to application code in order to implement DNSSEC? Reveal answer details Close answer detailsCorrect answerD Explanation To implement DNSSEC, no additional changes are needed to applications or their code because the integrity checks are all performed at the system level.
Single choice
Which of the following areas of responsibility always falls completely under the purview of the cloud provider, regardless of which cloud service category is used? Reveal answer details Close answer detailsCorrect answerC Explanation Regardless of the cloud service category used, the physical environment is always the sole responsibility of the cloud provider. In many instances, the cloud provider will supply audit reports or some general information about their physical security practices, especially to those customers or potential customers that may have regulatory requirements, but otherwise the cloud customer will have very little insight into the physical environment. With IaaS, the infrastructure is a shared responsibility between the cloud provider and cloud customer. With all cloud service categories, the data and governance are always the sole responsibility of the cloud customer.
Single choice
Data labels could include all the following, except: Reveal answer details Close answer detailsCorrect answerA Explanation All the others might be included in data labels, but multifactor authentication is a procedure used for access control, not a label.
Single choice
Which process serves to prove the identity and credentials of a user requesting access to an application or data? Reveal answer details Close answer detailsCorrect answerB Explanation Authentication is the process of proving whether the identity presented by a user is true and valid. This can be done through common mechanisms such as user ID and password combinations or with more secure methods such as multifactor authentication.
Single choice
In the wake of many scandals with major corporations involving fraud and the deception of investors and regulators, which of the following laws was passed to govern accounting and financial records and disclosures? Reveal answer details Close answer detailsCorrect answerD Explanation The Sarbanes-Oxley Act (SOX) regulates the financial and accounting practices used by organizations in order to protect shareholders from improper practices and accounting errors.The Health Insurance Portability and Accountability Act (HIPAA) pertains to the protection of patient medical records and privacy.
Single choice
Which of the following roles would be responsible for managing memberships in federations and the use and integration of federated services? Reveal answer details Close answer detailsCorrect answerA Explanation The inter-cloud provider is responsible for peering with other cloud services and providers, as well as overseeing and managing federations and federated services. A cloud service administrator is responsible for testing, monitoring, and securing cloud services, as well as providing usage reporting and dealing with service problems. The cloud service integrator is responsible for connecting existing systems and services with a cloud. The cloud service business manager is responsible for overseeing the billing, auditing, and purchasing of cloud services.
Single choice
Which of the cloud cross-cutting aspects relates to the assigning of jobs, tasks, and roles, as well as to ensuring they are successful and properly performed? Reveal answer details Close answer detailsCorrect answerB Explanation Governance at its core is the idea of assigning jobs, takes, roles, and responsibilities and ensuring they are satisfactory performed.
Single choice
Which of the following is not an example of a highly regulated environment? Reveal answer details Close answer detailsCorrect answerD Explanation Wholesalers or distributors are generally not regulated, although the products they sell may be.
Single choice
Who would be responsible for implementing IPsec to secure communications for an application? Reveal answer details Close answer detailsCorrect answerB Explanation Because IPsec is implemented at the system or network level, it is the responsibility of the systems staff.
Single choice
Which aspect of cloud computing serves as the biggest challenge to using DLP to protect data at rest? Reveal answer details Close answer detailsCorrect answerB Explanation Resource pooling serves as the biggest challenge to using DLP solutions to protect data at rest because data is spread across large systems, which are also shared by many different clients. With the data always moving and being distributed, additional challenges for protection are created versus a physical and isolated storage system. Portability is the ability to easily move between different cloud providers, and interoperability is focused on the ability to reuse components or services. Reversibility pertains to the ability of a cloud customer to easily and completely remove their data and services from a cloud provider.
Single choice
Which of the following are distinguishing characteristics of a managed service provider? Reveal answer details Close answer detailsCorrect answerA Explanation According to the MSP Alliance, typically MSPs have the following distinguishing characteristics:
Single choice
Which of the following roles is responsible for overseeing customer relationships and the processing of financial transactions? Reveal answer details Close answer detailsCorrect answerC Explanation The cloud service business manager is responsible for overseeing business plans and customer relationships as well as processing financial transactions.
Single choice
What is the biggest benefit to leasing space in a data center versus building or maintain your own? Reveal answer details Close answer detailsCorrect answerB Explanation When leasing space in a data center, an organization can avoid the enormous startup and building costs associated with a data center, and can instead leverage economies of scale by grouping with other organizations and sharing costs.
Single choice
The GAPP framework was developed through a joint effort between the major Canadian and American professional accounting associations in order to assist their members with managing and preventing risks to the privacy of their data and customers. Which of the following is the meaning of GAPP? Reveal answer details Close answer detailsCorrect answerC
Single choice
If a company needed to guarantee through contract and SLAs that a cloud provider would always have available sufficient resources to start their services and provide a certain level of provisioning, what would the contract need to refer to? Reveal answer details Close answer detailsCorrect answerB Explanation A reservation guarantees to a cloud customer that they will have access to a minimal level of resources to run their systems, which will help mitigate against DoS attacks or systems that consume high levels of resources. A limit refers to the enforcement of a maximum level of resources that can be consumed by or allocated to a cloud customer, service, or system. Both guarantee and assurance are terms that sound similar to reservation, but they are not correct choices.
Single choice
Which aspect of cloud computing makes data classification even more vital than in a traditional data center? Reveal answer details Close answer detailsCorrect answerC Explanation With multiple tenants within the same hosting environment, any failure to properly classify data may lead to potential exposure to other customers and applications within the same environment.
Single choice
There is a large gap between the privacy laws of the United States and those of the European Union. Which US program was designed to help companies overcome these differences? Reveal answer details Close answer detailsCorrect answerD Explanation The Safe Harbor regulations were developed by the Department of Commerce and are meant to serve as a way to bridge the gap between privacy regulations of the European Union and the United States. Due to the lack of adequate privacy laws and protection on the federal level in the US, European privacy regulations generally prohibit the exporting of PII from Europe to the United States. Participation in the Safe Harbor program is voluntary on the part of US organizations. These organizations must conform to specific requirements and policies that mirror those from the EU, thus possibly fulfilling the EU requirements for data sharing and export. This way, American businesses can be allowed to serve customers in the EU. The Health Insurance Portability and Accountability Act (HIPAA) pertains to the protection of patient medical records and privacy. The Gramm-Leach-Bliley Act (GLBA) focuses on the use of PII within financial institutions. The Sarbanes-Oxley Act (SOX) regulates the financial and accounting practices used by organizations in order to protect shareholders from improper practices and errors.
Single choice
When using a SaaS solution, what is the capability provided to the customer? Reveal answer details Close answer detailsCorrect answerD Explanation According to "The NIST Definition of Cloud Computing," in SaaS, "The capability provided to the consumer is to use the provider's applications running on a cloud infrastructure. The applications are accessible from various client devices through either a thin client interface, such as a web browser (e.g., web-based e- mail), or a program interface. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings."
Single choice
What type of PII is controlled based on laws and carries legal penalties for noncompliance with requirements? Reveal answer details Close answer detailsCorrect answerB Explanation Regulated PII involves those requirements put forth by specific laws or regulations, and unlike contractual PII, where a violation can lead to contractual penalties, a violation of regulated PII can lead to fines or even criminal charges in some jurisdictions. PII regulations can depend on either the jurisdiction that applies to the hosting location or application or specific legislation based on the industry or type of data used.
Single choice
What does SDN stand for within a cloud environment? Reveal answer details Close answer detailsCorrect answerB Explanation Software-defined networking separates the administration of network filtering and network forwarding to allow for distributed administration.
Single choice
The European Union passed the first major regulation declaring data privacy to be a human right. Reveal answer details Close answer detailsCorrect answerC Explanation Adopted in 1995, Directive 95/46 EC establishes strong data protection and policy requirements, including the declaring of data privacy to be a human right. It establishes that an individual has the right to be notified when their personal data is being access or processed, that it only will ever be accessed for legitimate purposes, and that data will only be accessed to the exact extent it needs to be for the particular process or request.
Single choice
What is the concept of segregating information or processes, within the same system or application, for security reasons? Reveal answer details Close answer detailsCorrect answerB Explanation Sandboxing involves segregating and isolating information or processes from others within the same system or application, typically for security concerns. This is generally used for data isolation (for example, keeping different communities and populations of users isolated from other similar data).
Single choice
With finite resources available within a cloud, even the largest cloud providers will at times need to determine which customers will receive additional resources first. What is the term associated with this determination? Reveal answer details Close answer detailsCorrect answerC Explanation Shares are used within a cloud environment to prioritize resource allocation when customer requests exceed the available resources. Cloud providers utilize shares by assigning a priority score to each customer and allocating resources to those with the highest scores first. Scoring is a component of shares that determines the actual order in which to allocate resources. Neither weighting nor prioritization is the correct term in this case.
Single choice
Which of the following threat types involves an application developer leaving references to internal information and configurations in code that is exposed to the client? Reveal answer details Close answer detailsCorrect answerC Explanation An insecure direct object reference occurs when a developer has in their code a reference to something on the application side, such as a database key, the directory structure of the application, configuration information about the hosting system, or any other information that pertains to the workings of the application that should not be exposed to users or the network. Unvalidated redirects and forwards occur when an application has functions to forward users to other sites, and these functions are not properly secured to validate the data and redirect requests, allowing spoofing for malware of phishing attacks.
Single choice
Within an IaaS implementation, which of the following would NOT be a metric used to quantify service charges for the cloud customer? Reveal answer details Close answer detailsCorrect answerB Explanation Within IaaS, where the cloud customer is responsible for everything beyond the physical network, the number of users on a system would not be a factor in billing or service charges. The core cloud services for IaaS are based on the memory, storage, and CPU requirements of the cloud customer. Because the cloud customer with IaaS is responsible for its own images and deployments, these components comprise the basis of its cloud provisioning and measured services billing.
Single choice
Which of the following storage types is most closely associated with a database-type storage implementation? Reveal answer details Close answer detailsCorrect answerD Explanation Structured storage involves organized and categorized data, which most closely resembles and operates like a database system would.
Single choice
Which of the following statements best describes a Type 1 hypervisor? Reveal answer details Close answer detailsCorrect answerD Explanation With a Type 1 hypervisor, the hypervisor software runs directly on top of the bare-metal system, without any intermediary layer or hosting system. None of these statements describes a Type 1 hypervisor.
Single choice
Which protocol allows a system to use block-level storage as if it was a SAN, but over TCP network traffic instead? Reveal answer details Close answer detailsCorrect answerB Explanation iSCSI is a protocol that allows for the transmission and use of SCSI commands and features over a TCP- based network. iSCSI allows systems to use block-level storage that looks and behaves as a SAN would with physical servers, but to leverage the TCP network within a virtualized environment and cloud.
Single choice
Deviations from the baseline should be investigated and __________________. Reveal answer details Close answer detailsCorrect answerB Explanation All deviations from the baseline should be documented, including details of the investigation and outcome.
Single choice
When data discovery is undertaken, three main approaches or strategies are commonly used to determine what the type of data, its format, and composition are for the purposes of classification. Which of the following is NOT one of the three main approaches to data discovery? Reveal answer details Close answer detailsCorrect answerB Explanation Hashing involves taking a block of data and, through the use of a one-way operation, producing a fixed-size value that can be used for comparison with other data. It is used primarily for protecting data and allowing for rapid comparison when matching data values such as passwords. Labels involve looking for header information or other categorizations of data to determine its type and possible classifications.
Single choice
Configurations and policies for a system can come from a variety of sources and take a variety of formats. Which concept pertains to the application of a set of configurations and policies that is applied to all systems or a class of systems? Reveal answer details Close answer detailsCorrect answerC Explanation Baselines are a set of configurations and policies applied to all new systems or services, and they serve as the basis for deploying any other services on top of them. Although standards often form the basis for baselines, the term is applicable in this case. Hardening is the process of securing a system, often through the application of baselines. Leveling is an extraneous but similar term to baselining.
Single choice
Which of the following does NOT fall under the "IT" aspect of quality of service (QoS)? Reveal answer details Close answer detailsCorrect answerB Explanation KPIs fall under the "business" aspect of QoS, along with monitoring and measuring of events and business processes. Services, security, and applications are all core components and concepts of the "IT" aspect of
Single choice
A main objective for an organization when utilizing cloud services is to avoid vendor lock-in so as to ensure flexibility and maintain independence. Which core concept of cloud computing is most related to vendor lock-in? Reveal answer details Close answer detailsCorrect answerC Explanation Portability is the ability for a cloud customer to easily move their systems, services, and applications among different cloud providers. By avoiding reliance on proprietary APIs and other vendor-specific cloud features, an organization can maintain flexibility to move among the various cloud providers with greater ease. Reversibility refers to the ability for a cloud customer to quickly and easy remove all their services and data from a cloud provider. Interoperability is the ability to reuse services and components for other applications and uses. Scalability refers to the ability of a cloud environment to add or remove resources to meet current demands.
Single choice
Most APIs will support a variety of different data formats or structures. However, the SOAP API will only support which one of the following data formats? Reveal answer details Close answer detailsCorrect answerA Explanation The Simple Object Access Protocol (SOAP) protocol only supports the Extensible Markup Language (XML) data format. Although the other options are all data formats or data structures, they are not supported by SOAP.
Single choice
Which of the following would be a reason to undertake a BCDR test? Reveal answer details Close answer detailsCorrect answerA Explanation Any time a major functional change of an application occurs, a new BCDR test should be done to ensure the overall strategy and process are still applicable and appropriate.
Single choice
Cloud systems are increasingly used for BCDR solutions for organizations. What aspect of cloud computing makes their use for BCDR the most attractive? Reveal answer details Close answer detailsCorrect answerB Explanation Business continuity and disaster recovery (BCDR) solutions largely sit idle until they are actually needed.
Single choice
Cryptographic keys for encrypted data stored in the cloud should be ________________ . Reveal answer details Close answer detailsCorrect answerA Explanation Cryptographic keys should not be stored along with the data they secure, regardless of key length. We don't split crypto keys or generate redundant keys (doing so would violate the principle of secrecy necessary for keys to serve their purpose).
Single choice
You are working for a cloud service provider and receive an eDiscovery order pertaining to one of your customers. Which of the following would be the most appropriate action to take first? Reveal answer details Close answer detailsCorrect answerD Explanation When a cloud service provider receives an eDiscovery order pertaining to one of their customers, the first action they must take is to notify the customer. This allows the customer to be aware of what was received, as well as to conduct a review to determine if any challenges are necessary or warranted. Taking snapshots of virtual machines, copying data, and escrowing encryption keys are all processes involved in the actual collection of data and should not be performed until the customer has been notified of the request.
Single choice
Which of the following types of data would fall under data rights management (DRM) rather than information rights management (IRM)? Reveal answer details Close answer detailsCorrect answerC Explanation Whereas IRM is used to protect a broad range of data, DRM is focused specifically on the protection of consumer media, such as publications, music, movies, and so on. IRM is used to protect general institution data, so financial records, personnel data, and security profiles would all fall under the auspices of IRM.
Single choice
When an API is being leveraged, it will encapsulate its data for transmission back to the requesting party or service. What is the data encapsulation used with the SOAP protocol referred to as? Reveal answer details Close answer detailsCorrect answerD Explanation Simple Object Access Protocol (SOAP) encapsulates its information in what is known as a SOAP envelope. It then leverages common communications protocols for transmission. Object is a type of cloud storage, but also a commonly used term with certain types of programming languages. Packet and payload are terms that sound similar to envelope but are not correct in this case.
Single choice
Because cloud providers will not give detailed information out about their infrastructures and practices to the general public, they will often use established auditing reports to ensure public trust, where the reputation of the auditors serves for assurance. Which type of audit reports can be used for general public trust assurances? Reveal answer details Close answer detailsCorrect answerC Explanation SOC Type 3 audit reports are very similar to SOC Type 2, with the exception that they are intended for general release and public audiences.SAS-70 audits have been deprecated. SOC Type 1 audit reports have a narrow scope and are intended for very limited release, whereas SOC Type 2 audit reports are intended for wider audiences but not general release.
Single choice
SOC Type 1 reports are considered "restricted use," in that they are intended only for limited audiences and purposes. Which of the following is NOT a population that would be appropriate for a SOC Type 1 report? Reveal answer details Close answer detailsCorrect answerC Explanation Potential clients are not served by SOC Type 1 audits. A Type 2 or Type 3 report would be appropriate for potential clients. SOC Type 1 reports are intended for restricted use, where only the service organization itself, current clients, or auditors would have access to them.
Single choice
When reviewing the BIA after a cloud migration, the organization should take into account new factors related to data breach impacts. One of these new factors is: Reveal answer details Close answer detailsCorrect answerD Explanation State notification laws and the loss of proprietary data/intellectual property pre-existed the cloud; only the lack of ability to transfer liability is new.
Single choice
Which of the following systems is used to employ a variety of different techniques to discover and alert on threats and potential threats to systems and networks? Reveal answer details Close answer detailsCorrect answerA Explanation An intrusion detection system (IDS) is implemented to watch network traffic and operations, using predefined criteria or signatures, and alert administrators if anything suspect is found. An intrusion prevention system (IPS) is similar to an IDS but actually takes action against suspect traffic, whereas an IDS just alerts when it finds anything suspect. A firewall works at the network level and only takes into account IP addresses, ports, and protocols; it does not inspect the traffic for patterns or content. A web
Single choice
Which aspect of SaaS will alleviate much of the time and energy organizations spend on compliance (specifically baselines)? Reveal answer details Close answer detailsCorrect answerC Explanation With the entire software platform being controlled by the cloud provider, the standardization of configurations and versioning is done automatically for the cloud customer. This alleviates the customer's need to track upgrades and releases for its own systems and development; instead, the onus is on the
Single choice
Which of the cloud cross-cutting aspects relates to the requirements placed on the cloud provider by the cloud customer for minimum performance standards and requirements that must be met? Reveal answer details Close answer detailsCorrect answerB Explanation Whereas a contract spells out general terms and costs for services, the SLA is where the real meat of the business relationship and concrete requirements come into play. The SLA spells out in clear terms the minimum requirements for uptime, availability, processes, customer service and support, security controls and requirements, auditing and reporting, and potentially many other areas that define the business relationship and the success of it.
Single choice
Which of the following technologies is NOT commonly used for accessing systems and services in a cloud environment in a secure manner? Reveal answer details Close answer detailsCorrect answerA Explanation A keyboard-video-mouse (KVM) system is commonly used for directly accessing server terminals in a data center. It is not a method that would be possible within a cloud environment, primarily due to the use virtualized systems, but also because only the cloud provider's staff would be allowed the physical access to hardware systems that's provided by a KVM. Hypertext Transfer Protocol Secure (HTTPS), virtual private network (VPN), and Transport Layer Security (TLS) are all technologies and protocols that are widely used with cloud implementations for secure access to systems and services.
Single choice
Which aspect of cloud computing pertains to cloud customers only paying for the resources and services they actually use? Reveal answer details Close answer detailsCorrect answerD Explanation Measured service is the aspect of cloud computing that pertains to cloud services and resources being billed in a metered way, based only on the level of consumption and duration of the cloud customer.
Single choice
A comprehensive BCDR plan will encapsulate many or most of the traditional concerns of operating a system in any data center. However, what is one consideration that is often overlooked with the formulation of a BCDR plan? Reveal answer details Close answer detailsCorrect answerC Explanation BCDR planning tends to focus so much on the failing over of services in the case of a disaster that recovery back to primary hosting after the disaster is often overlooked. In many instances, this can be just as complex a process as failing over, if not more so. Availability of staff, capacity at the BCDR site, and change management processes are typically integral to BCDR plans and are common components of them.
Single choice
Which of the following best describes data masking? Reveal answer details Close answer detailsCorrect answerA Explanation All of these answers are actually correct, but A is the best answer, because it is the most general, includes the others, and is therefore the optimum choice. This is a good example of the type of question that can appear on the actual exam.
Single choice
Which of the following threat types can occur when baselines are not appropriately applied or unauthorized changes are made? Reveal answer details Close answer detailsCorrect answerC Explanation Security misconfigurations occur when applications and systems are not properly configured or maintained in a secure manner. This can be caused from a shortcoming in security baselines or configurations, unauthorized changes to system configurations, or a failure to patch and upgrade systems as the vendor releases security patches.
Single choice
Which value refers to the amount of data an organization would need to recover in the event of a BCDR situation in order to reach an acceptable level of operations? Reveal answer details Close answer detailsCorrect answerC Explanation The recovery point objective (RPO) is defined as the amount of data a company would need to maintain and recover in order to function at a level acceptable to management. This may or may not be a restoration to full operating capacity, depending on what management deems as crucial and essential.
Single choice
Which cloud storage type resembles a virtual hard drive and can be utilized in the same manner and with the same type of features and capabilities? Reveal answer details Close answer detailsCorrect answerA Explanation Volume storage is allocated and mounted as a virtual hard drive within IaaS implementations, and it can be maintained and used the same way a traditional file system can. Object storage uses a flat structure on remote services that is accessed via opaque descriptors, structured storage resembles database storage, and unstructured storage is used to hold auxiliary files in conjunction with applications hosted within a PaaS implementation.
Single choice
Which of the following APIs are most commonly used within a cloud environment? Reveal answer details Close answer detailsCorrect answerB Explanation Simple Object Access Protocol (SOAP) and Representational State Transfer (REST) are the most commonly used APIs within a cloud environment. Extensible Markup Language (XML) and Security Assertion Markup Language (SAML) are both standards for exchanging encoded data between two parties, with XML being for more general use and SAML focused on authentication and authorization data.
Single choice
Which technology can be useful during the "share" phase of the cloud data lifecycle to continue to protect data as it leaves the original system and security controls? Reveal answer details Close answer detailsCorrect answerC Explanation Data loss prevention (DLP) can be applied to data that is leaving the security enclave to continue to enforce access restrictions and policies on other clients and systems. |