
CCSP練習試験テスト最新問題2023年05月
CCSP試験を一発合格保証問題集!
質問 # 375
All the following are data analytics modes, except:
- A. Agile business intelligence
- B. Datamining
- C. Real-time analytics
- D. Refractory iterations
正解:D
解説:
All the others are data analytics methods, but "refractory iterations" is a nonsense term thrown in as a red herring.
質問 # 376
Which of the following service capabilities gives the cloud customer the most control over resources and configurations?
- A. Infrastructure
- B. Desktop
- C. Software
- D. Platform
正解:A
解説:
Explanation
The infrastructure service capability gives the cloud customer substantial control in provisioning and configuring resources, including processing, storage, and network resources.
質問 # 377
Which strategy involves using a fake production system to lure attackers in order to learn about their tactics?
- A. Honeypot
- B. IPS
- C. IDS
- D. Firewall
正解:A
質問 # 378
Which of the following are cloud computing roles?
- A. Cloud service broker and user
- B. CSP and backup service provider
- C. Cloud service auditor and object
- D. Cloud customer and financial auditor
正解:B
解説:
Explanation/Reference:
Explanation:
The following groups form the key roles and functions associated with cloud computing. They do not constitute an exhaustive list but highlight the main roles and functions within cloud computing:
- Cloud customer: An individual or entity that utilizes or subscribes to cloud based services or resources.
- CSP: A company that provides cloud-based platform, infrastructure, application, or storage services to other organizations or individuals, usually for a fee; otherwise known to clients "as a service.
- Cloud backup service provider: A third-party entity that manages and holds operational responsibilities for cloud-based data backup services and solutions to customers from a central data center.
- CSB: Typically a third-party entity or company that looks to extend or enhance value to multiple customers of cloud-based services through relationships with multiple CSPs. It acts as a liaison between cloud services customers and CSPs, selecting the best provider for each customer and monitoring the services. The CSB can be utilized as a "middleman" to broker the best deal and customize services to the customer's requirements. May also resell cloud services.
- Cloud service auditor: Third-party organization that verifies attainment of SLAs.
質問 # 379
The Transport Layer Security (TLS) protocol creates a secure communications channel over public media (such as the Internet). In a typical TLS session, what is the usual means for establishing trust between the parties?
Response:
- A. Out-of-band authentication
- B. PKI certificates
- C. Multifactor authentication
- D. Preexisting knowledge of each other
正解:B
質問 # 380
What is a data custodian responsible for?
- A. Logging and alerts for all data
- B. Customer access and alerts for all data
- C. The safe custody, transport, storage of the data, and implementation of business rules
- D. Data content, context, and associated business rules
正解:C
質問 # 381
Which concept BEST describes the capability for a cloud environment to automatically scale a system or application, based on its current resource demands?
- A. Rapid elasticity
- B. Resource pooling
- C. Measured service
- D. On-demand self-service
正解:A
解説:
Explanation
Rapid elasticity allows a cloud environment to automatically add or remove resources to or from a system or application based on its current demands. Whereas a traditional data center model would require standby hardware and substantial effort to add resources in response to load increases, a cloud environment can easily and rapidly expand to meet resources demands, so long as the application is properly implemented for it.
質問 # 382
Which networking concept in a cloud environment allows for network segregation and isolation of IP spaces?
- A. WAN
- B. VLAN
- C. PLAN
- D. LAN
正解:B
解説:
Explanation/Reference:
Explanation:
A virtual area network (VLAN) allows the logical separation and isolation of networks and IP spaces to provide enhanced security and controls.
質問 # 383
Which of the following represents a prioritization of applications or cloud customers for the allocation of additional requested resources when there is a limitation on available resources?
- A. Reservation
- B. Share
- C. Limit
- D. Provision
正解:B
解説:
Explanation
The concept of shares within a cloud environment is used to mitigate and control the request for resource allocations from customers that the environment may not have the current capability to allow. Shares work by prioritizing hosts within a cloud environment through a weighting system that is defined by the cloud provider.
When periods of high utilization and allocation are reached, the system automatically uses scoring of each host based on its share value to determine which hosts get access to the limited resources still available. The higher the value a particular host has, the more resources it will be allowed to utilize.
質問 # 384
Which OSI layer does IPsec operate at?
- A. Network
- B. transport
- C. Application
- D. Presentation
正解:A
解説:
Explanation
A major difference between IPsec and other protocols such as TLS is that IPsec operates at the Internet network layer rather than the application layer, allowing for complete end-to-end encryption of all communications and traffic.
質問 # 385
Which of the following may unilaterally deem a cloud hosting model inappropriate for a system or application?
- A. Certification
- B. Multitenancy
- C. Virtualization
- D. Regulation
正解:D
解説:
Explanation/Reference:
Explanation:
Some regulations may require specific security controls or certifications be used for hosting certain types of data or functions, and in some circumstances they may be requirements that are unable to be met by any cloud provider.
質問 # 386
Your company has just been served with an eDiscovery order to collect event data and other pertinent information from your application during a specific period of time, to be used as potential evidence for a court proceeding.
Which of the following, apart from ensuring that you collect all pertinent data, would be the MOST important consideration?
Response:
- A. Confidentiality
- B. Compression
- C. Chain of custody
- D. Encryption
正解:C
質問 # 387
Which protocol does the REST API depend on?
- A. XML
- B. SSH
- C. SAML
- D. HTTP
正解:D
解説:
Representational State Transfer (REST) is a software architectural scheme that applies the components, connectors, and data conduits for many web applications used on the Internet. It uses and relies on the HTTP protocol and supports a variety of data formats.
質問 # 388
The Open Web Application Security Project (OWASP) Top Ten is a list of web application security threats that is composed by a member-driven OWASP committee of application development experts and published approximately every 24 months. The 2013 OWASP Top Ten list includes "using components with known vulnerabilities." Why would an organization ever use components with known vulnerabilities to create software?
- A. A component might have a hidden vulnerability.
- B. The organization is insured.
- C. Some vulnerabilities only exist in foreign countries.
- D. The particular vulnerabilities only exist in a context not being used by developers.
正解:D
質問 # 389
When using a PaaS solution, what is the capability provided to the customer?
- A. To deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages, libraries, services, and tools that the provider supports. The consumer does not manage or control the underlying cloud infrastructure, including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment.
- B. To deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages, libraries, services, and tools that the consumer supports. The consumer does not manage or control the underlying cloud infrastructure, including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment.
- C. To deploy onto the cloud infrastructure provider-created or acquired applications created using programming languages, libraries, services, and tools that the provider supports. The consumer does not manage or control the underlying cloud infrastructure, including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment.
- D. To deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages, libraries, services, and tools that the provider supports. The provider does not manage or control the underlying cloud infrastructure, including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment.
正解:A
解説:
Explanation/Reference:
Explanation:
According to "The NIST Definition of Cloud Computing," in PaaS, "the capability provided to the consumer is to deploy onto the cloud infrastructure consumer-created or acquired applications created using programming languages, libraries, services, and tools supported by the provider. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, or storage, but has control over the deployed applications and possibly configuration settings for the application-hosting environment.
質問 # 390
Data center and operations design traditionally takes a tiered, topological approach.
Which of the following standards is focused on that approach and is prevalently used throughout the industry?
- A. BICSI
- B. IDCA
- C. NFPA
- D. Uptime Institute
正解:D
解説:
The Uptime Institute publishes the most widely known and used standard for data center topologies and tiers.
The National Fire Protection Association (NFPA) publishes a broad range of fire safety and design standards for many different types of facilities. Building Industry Consulting Services International (BICSI) issues certifications for data center cabling. The International Data Center Authority (IDCA) offers the Infinity Paradigm, which takes a macro-level approach to data center design.
質問 # 391
Which of the following methods of addressing risk is most associated with insurance?
- A. Transference
- B. Acceptance
- C. Mitigation
- D. Avoidance
正解:A
解説:
Explanation
Avoidance halts the business process, mitigation entails using controls to reduce risk, acceptance involves taking on the risk, and transference usually involves insurance.
質問 # 392
Firewalls are used to provide network security throughout an enterprise and to control what information can be accessed--and to a certain extent, through what means.
Which of the following is NOT something that firewalls are concerned with?
- A. IP address
- B. Protocol
- C. Port
- D. Encryption
正解:D
解説:
Explanation
Firewalls work at the network level and control traffic based on the source, destination, protocol, and ports.
Whether or not the traffic is encrypted is not a factor with firewalls and their decisions about routing traffic.
Firewalls work primarily with IP addresses, ports, and protocols.
質問 # 393
DLP solutions can aid in deterring loss due to which of the following?
- A. Natural disaster
- B. Randomization
- C. Inadvertent disclosure
- D. Device failure
正解:C
解説:
Explanation/Reference:
Explanation:
DLP solutions may protect against inadvertent disclosure. Randomization is a technique for obscuring data, not a risk to data. DLP tools will not protect against risks from natural disasters, or against impacts due to device failure.
質問 # 394
With a federated identity system, where would a user perform their authentication when requesting services or application access?
- A. The application
- B. Cloud provider
- C. Third-party authentication system
- D. Their home organization
正解:D
解説:
Explanation
With a federated identity system, a user will perform authentication with their home organization, and the application will accept the authentication tokens and user information from the identity provider in order to grant access. The purpose of a federated system is to allow users to authenticate from their home organization.
Therefore, using the application or a third-party authentication system would be contrary to the purpose of a federated system because it necessitates the creation of additional accounts. The use of a cloud provider would not be relevant to the operations of a federated system.
質問 # 395
Which of the following roles would be responsible for managing memberships in federations and the use and integration of federated services?
- A. Cloud service administrator
- B. Inter-cloud provider
- C. Cloud service integrator
- D. Cloud service business manager
正解:B
解説:
The inter-cloud provider is responsible for peering with other cloud services and providers, as well as overseeing and managing federations and federated services. A cloud service administrator is responsible for testing, monitoring, and securing cloud services, as well as providing usage reporting and dealing with service problems. The cloud service integrator is responsible for connecting existing systems and services with a cloud. The cloud service business manager is responsible for overseeing the billing, auditing, and purchasing of cloud services.
質問 # 396
The BCDR plan/process should be written and documented in such a way that it can be used by ____________.
Response:
- A. Essential BCDR team members
- B. Someone with the requisite skills
- C. Users
- D. Regulators
正解:B
質問 # 397
......
ISC Cloud Security無料認定試験材料はGoShikenが提供された830問題:https://www.goshiken.com/ISC/CCSP-mondaishu.html
CCSP問題集完全版問題試験学習ガイド:https://drive.google.com/open?id=17QGCV4-YnklRzZz1BRbk5Hq9lsN77HxJ