chapter7 Flashcards
Which of the following is NOT a recommendation for the “create” phase of the security lifecycle?
A. Identification of data labeling and classification capabilities.
B. User tagging to classify data.
C. Leveraging of content discovery tools
D. enterprise digital rights management
C. Leveraging of content discovery tools
Which of the following is NOT a recommendation for the “use” phase of the data security lifecycle?
A. Data loss prevention for content-based data protection.
B. Activity monitoring and enforcement.
C. Application logic.
D. Object level controls within DBMS solutions.
A. Data loss prevention for content-based data protection.
Which of the following is NOT a recommendation for the "archive" phase of the data security lifecycle? A. Asset management. B. Disk wiping. C. Asset tracking. D. Both A and B.
B. Disk wiping.
Degaussing of physical media is a recommendation for which of the following phases of the data security lifecycle? A. destroy B. use C. share D. archive
A. destroy
Which of the following would be an acceptable reason for an organization to switch cloud service providers?
A. Unacceptable increase in cost during contract renewal time.
B. A business dispute between customer and provider.
C. Closure of one or more services, without acceptable migration plans.
D. All of the above.
D. All of the above.
When switching service providers, reserving/enhancing the security functionality provided by the application is the focus in which of the following service models? A. software as a service B. platform as a service C. infrastructure as a service D. both A and B
A. software as a service
When switching service providers, minimizing the amount of application rewriting is the focus in which of the following service models? A. software as a service B. platform as a service C. infrastructure as a service D. none of the above
B. platform as a service
Having the applications and the data migrate to and run at a new provider is the sole focus for which of the following service models? A. software as a service B. platform as a service C. infrastructure as a service D. all of the above
C. infrastructure as a service
Application modification is necessary to achieve portability. This is the expectation for which of the following service models? A. software as a service B. platform as a service C. infrastructure as a service D. both A and C
B. platform as a service
According to the Cloud Security Alliance (CSA), substituting cloud service providers is, in almost all cases, a:
A. positive business transaction for at least one party.
B. negative business transaction for at least one party.
C. neither a positive nor negative business transaction for any party.
D. it is impossible to determine.
B. negative business transaction for at least one party.
11. According to the Cloud Security Alliance (CSA), understanding how virtual machine images can be captured and ported to service providers is necessary for which of the following service models? A. software as a service B. platform as a service C. infrastructure as a service D. both A and C
C. infrastructure as a service
According to the Cloud Security Alliance (CSA), gaining access to system logs, traces and billing records is recommended for which of the following service models? A. software as a service B. platform as a service C. infrastructure as a service D. all of the above
C. infrastructure as a service
13. According to the Cloud Security Alliance (CSA), using platform components with a standard syntax is recommended for which of the following service models? A. software as a service B. platform as a service C. infrastructure as a service D. all of the above
B. platform as a service
According to the Cloud Security Alliance (CSA), understanding how service/application testing will be completed before and after migration is
recommended for which of the following service models?
A. software as a service
B. platform as a service
C. infrastructure as a service
D. both A and B
B. platform as a service
According to the Cloud Security Alliance (CSA), understanding if metadata can be preserved and migrated is recommended for which of the following service models? A. software as a service B. platform as a service C. infrastructure as a service D. none of the above
A. software as a service