Section 4: Certificate of Cloud Security Knowledge (CCSK) V4 (Anthony Sequeira)” Flashcards
What area of cloud security deals with the policy, process, and internal controls that comprise how an organization is run?
A.Enterprise Risk Management
B.Governance
C.Information Risk Management
D.Information Security
B.Governance
Which statement regarding your enterprise’s governance in a public cloud environment is true?
A.Your enterprise may now outsource responsibility for governance to the public cloud provider
B.Your enterprise may now outsource responsibility for governance to the vendor that supports the public cloud provider
C.Your enterprise can never outsource responsibility for governance
D.Your enterprise can only outsource the responsibility for governance if the cloud provider attests to perform all required security of the cloud infrastructure
C.Your enterprise can never outsource responsibility for governance
In the case of a public cloud relationship with your enterprise, what is the primary tool of governance?
A.The contract
B.A supplier assessment
C.Compliance reporting
D.A CSA Audit Report
A.The contract
You have carefully reviewed the risks that your cloud provider will manage for you. What is the term for the remaining risk?
A.Rejected Risk
B.Insignificant Risk
C.Unplanned Risk
D.Residual Risk
D.Residual Risk