
CCSP PDF Exam Material 2023 Realistic CCSP Dumps Questions
Updated ISC CCSP Dumps – PDF & Online Engine
NEW QUESTION 380
Which of the following service capabilities gives the cloud customer the least amount of control over configurations and deployments?
- A. Platform
- B. Desktop
- C. Infrastructure
- D. Software
Answer: D
Explanation:
The software service capability gives the cloud customer a fully established application, where only minimal user configuration options are allowed.
NEW QUESTION 381
A denial of service (DoS) attack can potentially impact all customers within a cloud environment with the continued allocation of additional resources. Which of the following can be useful for a customer to protect themselves from a DoS attack against another customer?
- A. Borrows
- B. Limits
- C. Reservations
- D. Shares
Answer: C
NEW QUESTION 382
Which of the following cloud aspects complicates eDiscovery?
- A. Measured service
- B. Multitenancy
- C. On-demand self-service
- D. Resource pooling
Answer: B
Explanation:
With multitenancy, eDiscovery becomes more complicated because the data collection involves extra steps to ensure that only those customers or systems that are within scope are turned over to the requesting authority.
NEW QUESTION 383
Which phase of the cloud data lifecycle represents the first instance where security controls can be implemented?
- A. Use
- B. Share
- C. Store
- D. Create
Answer: C
Explanation:
The store phase occurs immediately after the create phase, and as data is committed to storage structures, the first opportunity for security controls to be implemented is realized. During the create phase, the data is not yet part of a system where security controls can be applied, and although the use and share phases also entail the application of security controls, they are not the first phase where the process occurs.
NEW QUESTION 384
Data center and operations design traditionally takes a tiered, topological approach.
Which of the following standards is focused on that approach and is prevalently used throughout the industry?
- A. BICSI
- B. Uptime Institute
- C. IDCA
- D. NFPA
Answer: B
Explanation:
Explanation
The Uptime Institute publishes the most widely known and used standard for data center topologies and tiers.
The National Fire Protection Association (NFPA) publishes a broad range of fire safety and design standards for many different types of facilities. Building Industry Consulting Services International (BICSI) issues certifications for data center cabling. The International Data Center Authority (IDCA) offers the Infinity Paradigm, which takes a macro-level approach to data center design.
NEW QUESTION 385
What does dynamic application security testing (DAST) NOT entail?
- A. Discovery
- B. Probing
- C. Knowledge of the system
- D. Scanning
Answer: C
Explanation:
Explanation/Reference:
Explanation:
Dynamic application security testing (DAST) is considered "black box" testing and begins with no inside knowledge of the application or its configurations. Everything about the application must be discovered during the testing.
NEW QUESTION 386
All policies within the organization should include a section that includes all of the following, except:
- A. Policy adjudication
- B. Policy enforcement
- C. Policy review
- D. Policy maintenance
Answer: A
Explanation:
Explanation/Reference:
Explanation:
All the elements except adjudication need to be addressed in each policy. Adjudication is not an element of policy.
NEW QUESTION 387
What are the U.S. State Department controls on technology exports known as?
- A. ITAR
- B. DRM
- C. EAL
- D. EAR
Answer: D
Explanation:
ITAR is a Department of State program. Evaluation assurance levels are part of the Common Criteria standard from ISO. Digital rights management tools are used for protecting electronic processing of intellectual property.
NEW QUESTION 388
Which of the following terms is NOT a commonly used category of risk acceptance?
- A. Moderate
- B. Critical
- C. Accepted
- D. Minimal
Answer: C
Explanation:
Explanation
Explanation
Accepted is not a risk acceptance category. The risk acceptance categories are minimal, low, moderate, high, and critical.
NEW QUESTION 389
Which term relates to the application of scientific methods and practices to evidence?
- A. Measured
- B. Theoretical
- C. Forensics
- D. Methodical
Answer: C
Explanation:
Explanation
Forensics is the application of scientific and methodical processes to identify, collect, preserve, analyze, and summarize/report digital information and evidence.
NEW QUESTION 390
The destruction of a cloud customer's data can be required by all of the following except
___________.
Response:
- A. The cloud provider's policy
- B. Statute
- C. Contract
- D. Regulation
Answer: A
NEW QUESTION 391
Which protocol does the REST API depend on?
- A. SSH
- B. HTTP
- C. XML
- D. SAML
Answer: B
Explanation:
Explanation
Representational State Transfer (REST) is a software architectural scheme that applies the components, connectors, and data conduits for many web applications used on the Internet. It uses and relies on the HTTP protocol and supports a variety of data formats.
NEW QUESTION 392
What aspect of data center planning occurs first?
Response:
- A. Policy revision
- B. Physical design
- C. Audit
- D. Logical design
Answer: B
NEW QUESTION 393
What are third-party providers of IAM functions for the cloud environment?
- A. AESs
- B. CASBs
- C. SIEMs
- D. DLPs
Answer: B
Explanation:
Explanation
Data loss, leak prevention, and protection is a family of tools used to reduce the possibility of unauthorized disclosure of sensitive information. SIEMs are tools used to collate and manage log data. AES is an encryption standard.
NEW QUESTION 394
Which type of audit report is considered a "restricted use" report for its intended audience?
- A. SOC Type 2
- B. SOC Type 1
- C. SSAE-16
- D. SAS-70
Answer: B
Explanation:
Explanation
SOC Type 1 reports are considered "restricted use" reports. They are intended for management and stakeholders of an organization, clients of the service organization, and auditors of the organization. They are not intended for release beyond those audiences.
NEW QUESTION 395
Along with humidity, temperature is crucial to a data center for optimal operations and protection of equipment.
Which of the following is the optimal temperature range as set by ASHRAE?
- A. 51.8 to 66.2 degrees Fahrenheit (11 to 19 degrees Celsius)
- B. 69.8 to 86.0 degrees Fahrenheit (21 to 30 degrees Celsius)
- C. 64.4 to 80.6 degrees Fahrenheit (18 to 27 degrees Celsius)
- D. 44.6 to 60.8 degrees Fahrenheit (7 to 16 degrees Celsius)
Answer: C
Explanation:
The American Society of Heating, Refrigeration, and Air Conditioning Engineers (ASHRAE) recommends 64.4 to 80.6 degrees Fahrenheit (or 18 to 27 degrees Celsius) as the optimal temperature range for data centers. None of these options is the recommendation from ASHRAE.
NEW QUESTION 396
All the following are data analytics modes, except:
- A. Datamining
- B. Refractory iterations
- C. Agile business intelligence
- D. Real-time analytics
Answer: B
Explanation:
All the others are data analytics methods, but "refractory iterations" is a nonsense term thrown in as a red herring.
NEW QUESTION 397
Which of the following pertains to a macro level approach to data center design rather than the traditional tiered approach to data centers?
- A. BICSI
- B. NFPA
- C. Uptime Institute
- D. IDCA
Answer: D
Explanation:
Explanation
The standards put out by the International Data Center Authority (IDCA) have established the Infinity Paradigm, which is intended to be a comprehensive data center design and operations framework. The Infinity Paradigm shifts away from many models that rely on tiered architecture for data centers, where each successive tier increases redundancy. Instead, it emphasizes data centers being approached at a macro level, without a specific and isolated focus on certain aspects to achieve tier status.
NEW QUESTION 398
Which of the following is NOT a component of access control?
- A. Authorization
- B. Authentication
- C. Accounting
- D. Federation
Answer: D
Explanation:
Explanation
Federation is not a component of access control. Instead, it is used to allow users possessing credentials from other authorities and systems to access services outside of their domain. This allows for access and trust without the need to create additional, local credentials. Access control encompasses not only the key concepts of authorization and authentication, but also accounting. Accounting consists of collecting and maintaining logs for both authentication and authorization for operational and regulatory requirements.
NEW QUESTION 399
You are the security manager of a small firm that has just purchased a DLP solution to implement in your cloud-based production environment.
In order to get truly holistic coverage of your environment, you should be sure to include
__________ as a step in the deployment process.
- A. Adoption of the tool in all routers between your users and the cloud provider
- B. Installation of the solution on all assets in the cloud data center
- C. All of your customers to install the tool
- D. Getting signed user agreements from all users
Answer: D
NEW QUESTION 400
Which of the following best describes SAML?
- A. A standard used for directory synchronization
- B. A standard for exchanging usernames and passwords across devices.
- C. A standard for developing secure application management logistics
- D. A standards for exchanging authentication and authorization data between security domains.
Answer: D
NEW QUESTION 401
......
ISC CCSP Dumps PDF Are going to be The Best Score: https://practicetorrent.exam4pdf.com/CCSP-dumps-torrent.html

