Section 4: Certificate of Cloud Security Knowledge (CCSK) V4 (Anthony Sequeira)” Flashcards

1
Q

What area of cloud security deals with the policy, process, and internal controls that comprise how an organization is run?

A.Enterprise Risk Management
B.Governance
C.Information Risk Management
D.Information Security

A

B.Governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which statement regarding your enterprise’s governance in a public cloud environment is true?

A.Your enterprise may now outsource responsibility for governance to the public cloud provider
B.Your enterprise may now outsource responsibility for governance to the vendor that supports the public cloud provider
C.Your enterprise can never outsource responsibility for governance
D.Your enterprise can only outsource the responsibility for governance if the cloud provider attests to perform all required security of the cloud infrastructure

A

C.Your enterprise can never outsource responsibility for governance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

In the case of a public cloud relationship with your enterprise, what is the primary tool of governance?

A.The contract
B.A supplier assessment
C.Compliance reporting
D.A CSA Audit Report

A

A.The contract

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

You have carefully reviewed the risks that your cloud provider will manage for you. What is the term for the remaining risk?

A.Rejected Risk
B.Insignificant Risk
C.Unplanned Risk
D.Residual Risk

A

D.Residual Risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly