Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the ISC Cloud Security CCSP Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CCSP Premium Access

View all detail and faqs for the CCSP exam


790 Students Passed

93% Average Score

98% Same Questions
Viewing page 2 out of 11 pages
Viewing questions 16-30 out of questions
Questions # 16:

Which of the following is NOT one of five principles of SOC Type 2 audits?

Options:

A.

Privacy

B.

Processing integrity

C.

Financial

D.

Security

Questions # 17:

Which audit type has been largely replaced by newer approaches since 2011?

Options:

A.

SOC Type 1

B.

SSAE-16

C.

SAS-70

D.

SOC Type 2

Questions # 18:

Which of the following is NOT a domain of the Cloud Controls Matrix (CCM)?

Options:

A.

Data center security

B.

Human resources

C.

Mobile security

D.

Budgetary and cost controls

Questions # 19:

What does dynamic application security testing (DAST) NOT entail?

Options:

A.

Scanning

B.

Probing

C.

Discovery

D.

Knowledge of the system

Questions # 20:

Which of the following is a widely used tool for code development, branching, and collaboration?

Options:

A.

GitHub

B.

Maestro

C.

Orchestrator

D.

Conductor

Questions # 21:

Which aspect of security is DNSSEC designed to ensure?

Options:

A.

Integrity

B.

Authentication

C.

Availability

D.

Confidentiality

Questions # 22:

What strategy involves hiding data in a data set to prevent someone from identifying specific individuals based on other data fields present?

Options:

A.

Anonymization

B.

Tokenization

C.

Masking

D.

Obfuscation

Questions # 23:

Which entity requires all collection and storing of data on their citizens to be done on hardware that resides within their borders?

Options:

A.

Russia

B.

France

C.

Germany

D.

United States

Questions # 24:

What type of host is exposed to the public Internet for a specific reason and hardened to perform only that function for authorized users?

Options:

A.

Proxy

B.

Bastion

C.

Honeypot

D.

WAF

Questions # 25:

Which of the following is NOT a function performed by the handshake protocol of TLS?

Options:

A.

Key exchange

B.

Encryption

C.

Negotiation of connection

D.

Establish session ID

Questions # 26:

Which of the following would NOT be a reason to activate a BCDR strategy?

Options:

A.

Staffing loss

B.

Terrorism attack

C.

Utility disruptions

D.

Natural disaster

Questions # 27:

Which OSI layer does IPsec operate at?

Options:

A.

Network

B.

transport

C.

Application

D.

Presentation

Questions # 28:

Which of the cloud cross-cutting aspects relates to the ability for a cloud customer to easily remove their applications and data from a cloud environment?

Options:

A.

Reversibility

B.

Availability

C.

Portability

D.

Interoperability

Questions # 29:

Unlike SOC Type 1 reports, which are based on a specific point in time, SOC Type 2 reports are done over a period of time. What is the minimum span of time for a SOC Type 2 report?

Options:

A.

Six months

B.

One month

C.

One year

D.

One week

Questions # 30:

Which of the following is the MOST important requirement and guidance for testing during an audit?

Options:

A.

Stakeholders

B.

Shareholders

C.

Management

D.

Regulations

Viewing page 2 out of 11 pages
Viewing questions 16-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.