We provide CCSP Exam Questions in two formats. Download PDF & Practice Tests. Pass ISC2 CCSP Exam quickly & easily. The CCSP PDF type is available for reading and printing. You can print more and practice many times. With the help of our CCSP Dumps Questions product and material, you can easily pass the CCSP exam.

Check CCSP free dumps before getting the full version:

NEW QUESTION 1
What type of device is often leveraged to assist legacy applications that may not have the programmatic capability to process assertions from modern web services?

  • A. Web application firewall
  • B. XML accelerator
  • C. Relying party
  • D. XML firewall

Answer: B

NEW QUESTION 2
Which standards body depends heavily on contributions and input from its open membership base? Response:

  • A. NIST
  • B. ISO
  • C. ICANN
  • D. CSA

Answer: D

NEW QUESTION 3
In a cloud environment, encryption should be used for all the following, except: Response:

  • A. Long-term storage of data
  • B. Near-term storage of virtualized images
  • C. Secure sessions/VPN
  • D. Profile formatting

Answer: D

NEW QUESTION 4
What type of software is often considered secured and validated via community knowledge?
Response:

  • A. Proprietary
  • B. Object-oriented
  • C. Open source
  • D. Scripting

Answer: C

NEW QUESTION 5
Of the following, which is probably the most significant risk in a managed cloud environment? Response:

  • A. DDoS
  • B. Management plane breach
  • C. Guest escape
  • D. Physical attack on the utility service lines

Answer: B

NEW QUESTION 6
An audit against the ______ will demonstrate that an organization has a holistic, comprehensive security program.
Response:

  • A. SAS 70 standard
  • B. SSAE 16 standard
  • C. SOC 2, Type 2 report matrix
  • D. ISO 27001 certification requirements

Answer: D

NEW QUESTION 7
Which of the following is NOT one of the cloud computing activities, as outlined in ISO/IEC 17789? Response:

  • A. Cloud service provider
  • B. Cloud service partner
  • C. Cloud service administrator
  • D. Cloud service customer

Answer: C

NEW QUESTION 8
Which of the following is the correct name for Tier II of the Uptime Institute Data Center Site Infrastructure Tier Standard Topology?

  • A. Concurrently Maintainable Site Infrastructure
  • B. Fault-Tolerant Site Infrastructure
  • C. Basic Site Infrastructure
  • D. Redundant Site Infrastructure Capacity Components

Answer: D

NEW QUESTION 9
The Open Web Application Security Project (OWASP) Top Ten is a list of web application security threats that is composed by a member-driven OWASP committee of application development experts and published approximately every 24 months. The 2013 OWASP Top Ten list includes “cross-site scripting (XSS).”
Which of the following is not a method for reducing the risk of XSS attacks? Response:

  • A. Use an auto-escaping template system.
  • B. XML escape all identity assertions.
  • C. Sanitize HTML markup with a library designed for the purpose.
  • D. HTML escape JSON values in an HTML context and read the data with JSON.parse.

Answer: B

NEW QUESTION 10
You are the security manager of a small firm that has just purchased a DLP solution to implement in your cloud-based production environment.
Which of these activities should you perform before deploying the tool? Response:

  • A. Survey your company’s departments about the data under their control
  • B. Reconstruct your firewalls
  • C. Harden all your routers
  • D. Adjust the hypervisors

Answer: A

NEW QUESTION 11
Bob is staging an attack against Alice’s website. He is able to embed a link on her site that will execute malicious code on a visitor’s machine, if the visitor clicks on the link. This is an example of which type of attack?
Response:

  • A. Cross-site scripting
  • B. Broken authentication/session management
  • C. Security misconfiguration
  • D. Insecure cryptographic storage

Answer: A

NEW QUESTION 12
What is one of the benefits of implementing an egress monitoring solution? Response:

  • A. Preventing DDoS attacks
  • B. Inventorying data assets
  • C. Interviewing data owners
  • D. Protecting against natural disasters

Answer: B

NEW QUESTION 13
What are the six components that make up the STRIDE threat model? Response:

  • A. Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege
  • B. Spoofing, Tampering, Non-Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege
  • C. Spoofing, Tampering, Repudiation, Information Disclosure, Distributed Denial of Service, and Elevation of Privilege
  • D. Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Social Engineering

Answer: A

NEW QUESTION 14
You are the IT director for a small contracting firm. Your company is considering migrating to a cloud production environment.
Which service model would best fit your needs if you wanted an option that reduced the chance of vendor lock-in but also did not require the highest degree of administration by your own personnel?
Response:

  • A. IaaS
  • B. PaaS
  • C. SaaS
  • D. TanstaafL

Answer: B

NEW QUESTION 15
In general, a cloud BCDR solution will be ______ than a physical solution. Response:

  • A. Slower
  • B. Less expensive
  • C. Larger
  • D. More difficult to engineer

Answer: B

NEW QUESTION 16
Which of the following is perhaps the best method for reducing the risk of a specific application not delivering the proper level of functionality and performance when it is moved from the legacy environment into the cloud?
Response:

  • A. Remove the application from the organization’s production environment, and replace it with something else.
  • B. Negotiate and conduct a trial run in the cloud environment for that application before permanently migrating.
  • C. Make sure the application is fully updated and patched according to all vendor specifications.
  • D. Run the application in an emulator.

Answer: B

NEW QUESTION 17
Which kind of SSAE audit reviews controls dealing with the organization’s controls for assuring the confidentiality, integrity, and availability of data?
Response:

  • A. SOC 1
  • B. SOC 2
  • C. SOC 3
  • D. SOC 4

Answer: B

Recommend!! Get the Full CCSP dumps in VCE and PDF From Dumpscollection, Welcome to Download: http://www.dumpscollection.net/dumps/CCSP/ (New 353 Q&As Version)