📘 Free CCSP Sample Questions
Which of the following roles is responsible for creating cloud components and the testing and validation of
services?
A
A.Cloud auditor
B
B.Inter-cloud provider
C
C.Cloud service broker
D
D.Cloud service developer
Correct Answer:
D. D.Cloud service developer
Explanation:
The cloud service developer is responsible for developing and creating cloud components and services, as
well as for testing and validating services.
What is the best source for information about securing a physical asset's BIOS?
A
A. Security policies
B
B. Manual pages
C
C. Vendor documentation
D
D.Regulations
Correct Answer:
C. C. Vendor documentation
Explanation:
Vendor documentation from the manufacturer of the physical hardware is the best source of best practices
for securing the BIOS.
Which of the following is not a component of contractual PII?
A
A.Scope of processing
B
B.Value of data
C
C.Location of data
D
D.Use of subcontractors
Correct Answer:
B. B.Value of data
Which of the following concepts refers to a cloud customer paying only for the resources and offerings they use
within a cloud environment, and only for the duration that they are consuming them?
A
A.Consumable service
B
B.Measured service
C
C.Billable service
D
D.Metered service
Correct Answer:
B. B.Measured service
Explanation:
Measured service is where cloud services are delivered and billed in a metered way, where the cloud customer
only pays for those that they actually use, and for the duration of time that they use them.
Which of the following roles involves testing, monitoring, and securing cloud services for an organization?
A
A.Cloud service integrator
B
B.Cloud service business manager
C
C.Cloud service administrator
Correct Answer:
C. C.Cloud service administrator
Explanation:
The cloud service administrator is responsible for testing cloud services, monitoring services, administering
security for services, providing usage reports on cloud services, and addressing problem reports
What is the only data format permitted with the SOAP API?
A
A.HTML
B
B.SAML
C
C.XSML
D
D.XML
Correct Answer:
D. D.XML
Explanation:
The SOAP protocol only supports the XML data format.
Which data formats are most commonly used with the REST API?
A
A.JSON and SAML
B
B. XML and SAML
C
C. XML and JSON
D
D. SAML and HTML
Correct Answer:
C. C. XML and JSON
Explanation:
JavaScript Object Notation (JSON) and Extensible Markup Language (XML) are the most commonly used data
formats for the Representational State Transfer
(REST) API, and are typically implemented with caching for increased scalability and performance.
Which of the following threat types involves an application that does not validate authorization for portions of
itself after the initial checks?
A
A.Injection
B
B.Missing function-level access control
C
C.Cross-site request forgery
D
D.Cross-site scripting
Correct Answer:
B. B.Missing function-level access control
Explanation:
It is imperative that an application perform checks when each function or portion of the application is
accessed, to ensure that the user is properly authorized to access it. Without continual checks each time a
function is accessed, an attacker could forge requests to access portions of the application where
authorization has not been granted.
Which of the following roles involves overseeing billing, purchasing, and requesting audit reports for an
organization within a cloud environment?
A
A. Cloud service user
B
B. Cloud service business manager
C
C. Cloud service administrator
D
D. Cloud service integrator
Correct Answer:
B. B. Cloud service business manager
Explanation:
The cloud service business manager is responsible for overseeing business and billing administration,
purchasing cloud services, and requesting audit reports when necessary
What is the biggest concern with hosting a key management system outside of the cloud environment?
A
A.Confidentiality
B
B.Portability
C
C.Availability
D
D.Integrity
Correct Answer:
C. C.Availability
Explanation:
When a key management system is outside of the cloud environment hosting the application, availability is a
primary concern because any access issues with the encryption keys will render the entire application unusable.
Questions: 1-10 out of 507
Continue Full Practice..
GET ALL 507 QUESTIONS