
Get ISC CCSP Dumps Questions [2021] To Gain Brilliant Result
CCSP dumps - Pass4training - 100% Passing Guarantee
NEW QUESTION 65
What is a key component of GLBA?
- A. The information security program
- B. The right to be forgotten
- C. EU Data Directives
- D. The right to audit
Answer: A
NEW QUESTION 66
What is the experimental technology that might lead to the possibility of processing encrypted data without having to decrypt it first?
- A. Link encryption
- B. AES
- C. One-time pads
- D. Homomorphic encryption
Answer: D
Explanation:
AES is an encryption standard. Link encryption is a method for protecting communications traffic. One-time pads are an encryption method.
NEW QUESTION 67
What is a serious complication an organization faces from the perspective of compliance with international operations?
- A. Different operational procedures
- B. Different certifications
- C. Different capabilities
- D. Multiple jurisdictions
Answer: D
Explanation:
Explanation
When operating within a global framework, a security professional runs into a multitude of jurisdictions and requirements, and many times they might be in contention with one other or not clearly applicable. These requirements can include the location of the users and the type of data they enter into systems, the laws governing the organization that owns the application and any regulatory requirements they may have, as well as the appropriate laws and regulations for the jurisdiction housing the IT resources and where the data is actually stored, which might be multiple jurisdictions as well.
NEW QUESTION 68
If a company needed to guarantee through contract and SLAs that a cloud provider would always have available sufficient resources to start their services and provide a certain level of provisioning, what would the contract need to refer to?
- A. Limit
- B. Assurance
- C. Reservation
- D. Guarantee
Answer: C
Explanation:
A reservation guarantees to a cloud customer that they will have access to a minimal level of resources to run their systems, which will help mitigate against DoS attacks or systems that consume high levels of resources. A limit refers to the enforcement of a maximum level of resources that can be consumed by or allocated to a cloud customer, service, or system. Both guarantee and assurance are terms that sound similar to reservation, but they are not correct choices.
NEW QUESTION 69
Which of the following could be used as a second component of multifactor authentication if a user has an RSA token?
- A. USB thumb drive
- B. Retina scan
- C. Access card
- D. RFID
Answer: B
Explanation:
A retina scan could be used in conjunction with an RSA token because it is a biometric factor, and thus a different type of factor. An access card, RFID, and USB thumb drive are all items in possession of a user, the same as an RSA token, and as such would not be appropriate.
NEW QUESTION 70
ISO/IEC has established international standards for many aspects of computing and any processes or procedures related to information technology.
Which ISO/IEC standard has been established to provide a framework for handling eDiscovery processes?
- A. ISO/IEC 27050
- B. ISO/IEC 27040
- C. ISO/IEC 27002
- D. ISO/IEC 27001
Answer: A
Explanation:
Explanation/Reference:
Explanation:
ISO/IEC 27050 strives to establish an internationally accepted standard for eDiscovery processes and best practices. It encompasses all steps of the eDiscovery process, including the identification, preservation, collection, processing, review, analysis, and the final production of the requested data archive. ISO/IEC
27001 is a general security specification for an information security management system. ISO/IEC 27002 gives best practice recommendations for information security management. ISO/IEC 27040 is focused on the security of storage systems.
NEW QUESTION 71
Which of the following best describes a sandbox?
- A. A space where you can safely execute malicious code to see what it does.
- B. An isolated space where untested code and experimentation can safely occur within the production environment.
- C. An isolated space where transactions are protected from malicious software
- D. An isolated space where untested code and experimentation can safely occur separate from the production environment.
Answer: D
Explanation:
Explanation
Options C and B are also correct, but A is more general and incorporates them both. D is incorrect, because sandboxing does not take place in the production environment.
NEW QUESTION 72
Cryptographic keys should be secured ________________ .
- A. To a level at least as high as the data they can decrypt
- B. By armed guards
- C. With two-person integrity
- D. In vaults
Answer: A
Explanation:
Explanation
The physical security of crypto keys is of some concern, but guards or vaults are not always necessary.
Two-person integrity might be a good practice for protecting keys. The best answer to this question is option A, because it is always true, whereas the remaining options depend on circumstances.
NEW QUESTION 73
For service provisioning and support, what is the ideal amount of interaction between a cloud customer and cloud provider?
- A. Depends on the contract
- B. Full
- C. Half
- D. Minimal
Answer: D
Explanation:
Explanation
The goal with any cloud-hosting setup is for the cloud customer to be able to perform most or all its functions for service provisioning and configuration without any need for support from or interaction with the cloud provider beyond the automated tools provided. To fulfill the tenants of on-demand self-service, required interaction with the cloud provider--either half time, full time, or a commensurate amount of time based on the contract--would be in opposition to a cloud's intended use. As such, these answers are incorrect.
NEW QUESTION 74
You are a consultant performing an external security review on a large manufacturing firm. You determine that its newest assembly plant, which cost $24 million, could be completely destroyed by a fire but that a fire suppression system could effectively protect the plant.
The fire suppression system costs $15 million. An insurance policy that would cover the full replacement cost of the plant costs $1 million per month.
In order to establish the true annualized loss expectancy (ALE), you would need all of the following information except ____________.
Response:
- A. The length of time it would take to rebuild the plant
- B. The rate at which the plant generates revenue
- C. The amount of product the plant creates
- D. The amount of revenue generated by the plant
Answer: C
NEW QUESTION 75
Data center and operations design traditionally takes a tiered, topological approach.
Which of the following standards is focused on that approach and is prevalently used throughout the industry?
- A. IDCA
- B. NFPA
- C. BICSI
- D. Uptime Institute
Answer: D
Explanation:
Explanation
The Uptime Institute publishes the most widely known and used standard for data center topologies and tiers.
The National Fire Protection Association (NFPA) publishes a broad range of fire safety and design standards for many different types of facilities. Building Industry Consulting Services International (BICSI) issues certifications for data center cabling. The International Data Center Authority (IDCA) offers the Infinity Paradigm, which takes a macro-level approach to data center design.
NEW QUESTION 76
Unlike SOC Type 1 reports, which are based on a specific point in time, SOC Type 2 reports are done over a period of time. What is the minimum span of time for a SOC Type 2 report?
- A. Six months
- B. One month
- C. One week
- D. One year
Answer: A
Explanation:
Explanation/Reference:
Explanation:
SOC Type 2 reports are focused on the same policies and procedures, as well as their effectiveness, as SOC Type 1 reports, but are evaluated over a period of at least six consecutive months, rather than a finite point in time.
NEW QUESTION 77
Which of the following is a risk in the cloud environment that is not existing or is as prevalent in the legacy environment?
Response:
- A. Fire
- B. Ability of users to gain access to their physical workplace
- C. Legal liability in multiple jurisdictions
- D. Loss of productivity due to DDoS
Answer: C
NEW QUESTION 78
As part of the auditing process, getting a report on the deviations between intended configurations and actual policy is often crucial for an organization.
What term pertains to the process of generating such a report?
- A. Gap analysis
- B. Deficiencies
- C. Findings
- D. Errors
Answer: A
Explanation:
Explanation
The gap analysis determines if there are any differences between the actual configurations in use on systems and the policies that govern what the configurations are expected or mandated to be. The other terms provided are all similar to the correct answer ("findings" in particular is often used to articulate deviations in configurations), but gap analysis is the official term used.
NEW QUESTION 79
All of the following are identity federation standards commonly found in use today except
____________.
- A. OAuth
- B. WS-Federation
- C. PGP
- D. OpenID
Answer: C
NEW QUESTION 80
You are the security manager for a software development firm. Your company is interested in using a managed cloud service provider for hosting its testing environment. Previous releases have shipped with major flaws that were not detected in the testing phase; leadership wants to avoid repeating that problem.
What tool/technique/technology might you suggest to aid in identifying programming errors?
- A. SOC audits
- B. Open source review
- C. Regulatory review
- D. Vulnerability scans
Answer: B
NEW QUESTION 81
You are the security subject matter expert (SME) for an organization considering a transition from the legacy environment into a hosted cloud provider's data center. One of the challenges you're facing is whether the provider will have undue control over your data once it is within the provider's data center; will the provider be able to hold your organization hostage because they have your data?
This is a(n) _________ issue.
- A. Portability
- B. Interoperability
- C. Availability
- D. Security
Answer: A
NEW QUESTION 82
Which technique involves replacing values within a specific data field to protect sensitive data?
- A. Masking
- B. Anonymization
- C. Tokenization
- D. Obfuscation
Answer: A
Explanation:
Explanation
Masking involves replacing specific data within a data set with new values. For example, with credit card fields, as most who have ever purchased anything online can attest, nearly the entire credit card number is masked with a character such as an asterisk, with the last four digits left visible for identification and confirmation.
NEW QUESTION 83
Which phase of the cloud data lifecycle would be the MOST appropriate for the use of DLP technologies to protect the data?
- A. Create
- B. Use
- C. Share
- D. Store
Answer: C
Explanation:
During the share phase, data is allowed to leave the application for consumption by other vendors, systems, or services. At this point, as the data is leaving the security controls of the application, the use of DLP technologies is appropriate to control how the data is used or to force expiration. During the use, create, and store phases, traditional security controls are available and are more appropriate because the data is still internal to the application.
NEW QUESTION 84
What type of storage structure does object storage employ to maintain files?
- A. Directory
- B. Flat
- C. Hierarchical
- D. tree
Answer: B
Explanation:
Explanation/Reference:
Explanation:
Object storage uses a flat file system to hold storage objects; it assigns files a key value that is then used to access them, rather than relying on directories or descriptive filenames. Typical storage layouts such as tree, directory, and hierarchical structures are used within volume storage, whereas object storage maintains a flat structure with key values.
NEW QUESTION 85
To address shared monitoring and testing responsibilities in a cloud configuration, the provider might offer all these to the cloud customer except:
- A. SIM, SEIM. and SEM logs
- B. DLP solution results
- C. Access to audit logs and performance data
- D. Security control administration
Answer: D
Explanation:
While the provider might share any of the other options listed, the provider will not share administration of security controls with the customer. Security controls are the sole province of the provider.
NEW QUESTION 86
From a security perspective, automation of configuration aids in ____________.
- A. Reducing need for administrative personnel
- B. Reducing potential attack vectors
- C. Increasing ease of use of the systems
- D. Enhancing performance
Answer: B
NEW QUESTION 87
......
Get 100% Passing Success With True CCSP Exam: https://www.pass4training.com/CCSP-pass-exam-training.html
Premium Quality ISC CCSP Online dumps: https://drive.google.com/open?id=1MS4Mdiwspc91XXxiEaiPCBQ01o9J1-5F

