Exam:CCSK
Title:
https://www.passcert.com/CCSK.html
Thesafer,easierwaytohelpyoupassanyITexams
1.Whatisthenewerapplicationdevelopmentmethodologyandphilosophyfocusedonautomationof applicationdevelopmentanddeployment?
A.Agile
BBusOps
CDevOps
DSecDevOps
EScrum
Answer:C
2Whatistrueofsearchingdataacrosscloudenvironments?
AYoumightnothavetheabilityoradministrativerightstosearchoraccessallhosteddata
B.Thecloudprovidermustconductthesearchwiththefulladministrativecontrols.
CAllcloud-hostedemailaccountsareeasilysearchable
D.Searchanddiscoverytimeisalwaysfactoredintoacontractbetweentheconsumerandprovider.
EYoucaneasilysearchacrossyourenvironmentusinganyE-Discoverytool
Answer:A
3.HowshouldanSDLCbemodifiedtoaddressapplicationsecurityinaCloudComputingenvironment?
AIntegrateddevelopmentenvironments
BUpdatedthreatandtrustmodels
CNomodificationisneeded
DJust-in-timecompilers
EBothBandC
Answer:A
4Whichgovernancedomainfocusesonproperandadequateincidentdetection,response,notification, andremediation?
ADataSecurityandEncryption
B.InformationGovernance
CIncidentResponse,NotificationandRemediation
D.ComplianceandAuditManagement
EInfrastructureSecurity
Answer:C
5.Adefiningsetofrulescomposedofclaimsandattributesoftheentitiesinatransaction,whichisusedto determinetheirlevelofaccesstocloud-basedresourcesiscalledwhat?
AAnentitlementmatrix
BAsupporttable
CAnentrylog
DAvalidationprocess
EAnaccesslog
Answer:D
6WhichcloudstoragetechnologyisbasicallyavirtualharddriveforinstancedorVMs?
Thesafer,easierwaytohelpyoupassanyITexams
A.Volumestorage
BPlatform
C.Database
DApplication
EObjectstorage
Answer:A
7Whichopportunityhelpsreducecommonapplicationsecurityissues?
AElasticinfrastructure
BDefaultdeny
CDecreaseduseofmicro-services
D.Segregationbydefault
EFewerserverlessconfigurations
Answer:A
8.Howdoesvirtualizedstoragehelpavoiddatalossifadrivefails?
AMultiplecopiesindifferentlocations
B.Drivesarebackedup,swapped,andarchivedconstantly
CFullbackupsweekly
DDatalossisunavoidablewithdrivefailures
EIncrementalbackupsdaily
Answer:A
9Whichtypeofapplicationsecuritytestingtestsrunningapplicationsandincludestestssuchasweb vulnerabilitytestingandfuzzing?
ACodeReview
BStaticApplicationSecurityTesting(SAST)
CUnitTesting
D.FunctionalTesting
EDynamicApplicationSecurityTesting(DAST)
Answer:E
10.Whichlayeristhemostimportantforsecuringbecauseitisconsideredtobethefoundationforsecure cloudoperations?
A.Infrastructure
BDatastructure
CInfostructure
DApplistructure
EMetastructure
Answer:A