ISC CCSP Practice Test - Questions Answers, Page 37
List of questions
Your IT steering committee has, at a high level, approved your project to begin using cloud services. However, the committee is concerned with getting locked into a single cloud provider and has flagged the ability to easily move between cloud providers as a top priority. It also wants to save costs by reusing components.
Which cross-cutting aspect of cloud computing would be your primary focus as your project plan continues to develop and you begin to evaluate cloud providers?
Which of the following provides assurance, to a predetermined acceptable level of certainty, that an entity is indeed who they claim to be?
Whereas a contract articulates overall priorities and requirements for a business relationship, which artifact enumerates specific compliance requirements, metrics, and response times?
When an organization is considering the use of cloud services for BCDR planning and solutions, which of the following cloud concepts would be the most important?
What masking strategy involves the replacing of sensitive data at the time it is accessed and used as it flows between the data and application layers of a service?
Which of the following would be considered an example of insufficient due diligence leading to security or operational problems when moving to a cloud?
Which aspect of cloud computing serves as the biggest challenge to using DLP to protect data at rest?
What category of PII data can carry potential fines or even criminal charges for its improper use or disclosure?
A variety of security systems can be integrated within a network--some that just monitor for threats and issue alerts, and others that take action based on signatures, behavior, and other types of rules to actively stop potential threats.
Which of the following types of technologies is best described here?
Upon completing a risk analysis, a company has four different approaches to addressing risk. Which approach it takes will be based on costs, available options, and adherence to any regulatory requirements from independent audits.
Which of the following groupings correctly represents the four possible approaches?
Question