ExamGecko
Home Home / ISC / CCSP

ISC CCSP Practice Test - Questions Answers, Page 22

Question list
Search
Search

List of questions

Search

Within a SaaS environment, what is the responsibility on the part of the cloud customer in regard to procuring the software used?

A.
Maintenance
A.
Maintenance
Answers
B.
Licensing
B.
Licensing
Answers
C.
Development
C.
Development
Answers
D.
Purchasing
D.
Purchasing
Answers
Suggested answer: B

Explanation:

Within a SaaS implementation, the cloud customer licenses the use of the software from the cloud provider because SaaS delivers a fully functional application to the customer. With SaaS, the cloud provider is responsible for the entire software application and any necessary infrastructure to develop, run, and maintain it. The purchasing, development, and maintenance are fully the responsibility of the cloud provider.

Implementing baselines on systems would take an enormous amount of time and resources if the staff had to apply them to each server, and over time, it would be almost impossible to keep all the systems in sync on an ongoing basis.

Which of the following is NOT a package that can be used for implementing and maintaining baselines across an enterprise?

A.
Puppet
A.
Puppet
Answers
B.
SCCM
B.
SCCM
Answers
C.
Chef
C.
Chef
Answers
D.
GitHub
D.
GitHub
Answers
Suggested answer: D

Explanation:

GitHub is a software development platform that serves as a code repository and versioning system. It is solely used for software development and would not be appropriate for applying baselines to systems. Puppet is an open-source configuration management tool that runs on many platforms and can be used to apply and maintain baselines. The Software Center Configuration Manager (SCCM) was developed by Microsoft for managing systems across large groups of servers.

Chef is also a system for maintaining large groups of systems throughout an enterprise.

From the perspective of compliance, what is the most important consideration when it comes to data center location?

A.
Natural disasters
A.
Natural disasters
Answers
B.
Utility access
B.
Utility access
Answers
C.
Jurisdiction
C.
Jurisdiction
Answers
D.
Personnel access
D.
Personnel access
Answers
Suggested answer: C

Explanation:

Jurisdiction will dictate much of the compliance and audit requirements for a data center. Although all the aspects listed are very important to security, from a strict compliance perspective, jurisdiction is the most important. Personnel access, natural disasters, and utility access are all important operational considerations for selecting a data center location, but they are not related to compliance issues like jurisdiction is.

Different certifications and standards take different approaches to data center design and operations. Although many traditional approaches use a tiered methodology, which of the following utilizes a macro-level approach to data center design?

A.
IDCA
A.
IDCA
Answers
B.
BICSI
B.
BICSI
Answers
C.
Uptime Institute
C.
Uptime Institute
Answers
D.
NFPA
D.
NFPA
Answers
Suggested answer: A

Explanation:

The Infinity Paradigm of the International Data Center Authority (IDCA) takes a macro-level approach to data center design. The IDCA does not use a specific, focused approach on specific components to achieve tier status. Building Industry Consulting Services International (BICSI) issues certifications for data center cabling. The National Fire Protection Association (NFPA) publishes a broad range of fire safety and design standards for many different types of facilities. The

Uptime Institute publishes the most widely known and used standard for data center topologies and tiers.

The European Union is often considered the world leader in regard to the privacy of personal data and has declared privacy to be a "human right." In what year did the EU first assert this principle?

A.
1995
A.
1995
Answers
B.
2000
B.
2000
Answers
C.
2010
C.
2010
Answers
D.
1999
D.
1999
Answers
Suggested answer: A

Explanation:

The EU passed Directive 95/46 EC in 1995, which established data privacy as a human right. The other years listed are incorrect.

A DLP solution/implementation has three main components.

Which of the following is NOT one of the three main components?

A.
Monitoring
A.
Monitoring
Answers
B.
Enforcement
B.
Enforcement
Answers
C.
Auditing
C.
Auditing
Answers
D.
Discovery and classification
D.
Discovery and classification
Answers
Suggested answer: C

Explanation:

Auditing, which can be supported to varying degrees by DLP solutions, is not a core component of them. Data loss prevention (DLP) solutions have core components of discovery and classification, enforcement, and monitoring. Discovery and classification are concerned with determining which data should be applied to the DLP policies, and then determining its classification level. Monitoring is concerned with the actual watching of data and how it's used through its various stages. Enforcement is the actual application of policies determined from the discovery stage and then triggered during the monitoring stage.

What type of storage structure does object storage employ to maintain files?

A.
Directory
A.
Directory
Answers
B.
Hierarchical
B.
Hierarchical
Answers
C.
tree
C.
tree
Answers
D.
Flat
D.
Flat
Answers
Suggested answer: D

Explanation:

Object storage uses a flat file system to hold storage objects; it assigns files a key value that is then used to access them, rather than relying on directories or descriptive filenames. Typical storage layouts such as tree, directory, and hierarchical structures are used within volume storage, whereas object storage maintains a flat structure with key values.

Which cloud storage type requires special consideration on the part of the cloud customer to ensure they do not program themselves into a vendor lock-in situation?

A.
Unstructured
A.
Unstructured
Answers
B.
Object
B.
Object
Answers
C.
Volume
C.
Volume
Answers
D.
Structured
D.
Structured
Answers
Suggested answer: D

Explanation:

Structured storage is designed, maintained, and implemented by a cloud service provider as part of a PaaS offering. It is specific to that cloud provider and the way they have opted to implement systems, so special care is required to ensure that applications are not designed in a way that will lock the cloud customer into a specific cloud provider with that dependency. Unstructured storage for auxiliary files would not lock a customer into a specific provider. With volume and object storage, because the cloud customer maintains their own systems with IaaS, moving and replicating to a different cloud provider would be very easy.

Which cloud deployment model would be ideal for a group of universities looking to work together, where each university can gain benefits according to its specific needs?

A.
Private
A.
Private
Answers
B.
Public
B.
Public
Answers
C.
Hybrid
C.
Hybrid
Answers
D.
Community
D.
Community
Answers
Suggested answer: D

Explanation:

A community cloud is owned and maintained by similar organizations working toward a common goal. In this case, the universities would all have very similar needs and calendar requirements, and they would not be financial competitors of each other. Therefore, this would be an ideal group for working together within a community cloud. A public cloud model would not work in this scenario because it is designed to serve the largest number of customers, would not likely be targeted toward specific requirements for individual customers, and would not be willing to make changes for them. A private cloud could accommodate such needs, but would not meet the criteria for a group working together, and a hybrid cloud spanning multiple cloud providers would not fit the specifics of the question.

Data centers have enormous power resources that are distributed and consumed throughout the entire facility.

Which of the following standards pertains to the proper fire safety standards within that scope?

A.
IDCA
A.
IDCA
Answers
B.
BICSI
B.
BICSI
Answers
C.
NFPA
C.
NFPA
Answers
D.
Uptime Institute
D.
Uptime Institute
Answers
Suggested answer: C

Explanation:

The National Fire Protection Association (NFPA) publishes a broad range of fire safety and design standards for many different types of facilities. Building Industry Consulting Services International (BICSI) issues certifications for data center cabling. The Uptime Institute publishes the most widely known and used standard for data center topologies and tiers. The International Data Center Authority (IDCA) offers the Infinity Paradigm, which takes a macro-level approach to data center design.

Total 512 questions
Go to page: of 52