Loading provider exams...
Loading provider exams...
In large distributed systems that use pooled resources, cloud computing depends on extensive orchestration to maintain the environment and on continual resource provisioning.
Which of the following is essential for orchestrating and automating networking resources in a cloud?
Which data state is most likely to use TLS as its protection mechanism?
During which stage of the BCDR plan-creation process should security be part of the discussions?
Which of the following can serve as a second multifactor-authentication component when a user has an RSA token?
Your newly appointed CISO is putting greater emphasis and attention on regulatory compliance as your applications and systems move to cloud environments.
Which of the following would NOT be a major focus as you create a project plan centered on regulatory compliance?
Go ad-free and unlock Learn Mode, Exam Mode, AstroTutor AI and every premium tool — everything you need to walk in prepared, and confident.
Three core concepts determine the type of data and information for which an organization has responsibility in eDiscovery.
Which of the following are the three components that make up required disclosure?
When seeking to provide a layered defense, which type of security controls should the security practitioner persuade senior management to include?
For a cloud service category in which the cloud customer is responsible for deploying all services, systems, and components required for their applications, which storage types are MOST likely to be available?
Which of the following terms is not a commonly used category of risk acceptance?
Various security systems can be integrated into a network—some only monitor for threats and generate alerts, while others act on signatures, behavior, and other rule types to actively prevent potential threats.
Which of the following technology types are best described?
When an organization is evaluating a cloud environment to host BCDR solutions, which of the following is the greatest concern?
In the STRIDE threat model, what concept does the “I” stand for?
Which of the following is not an application or utility used to apply and enforce baselines on a system?
During which phase of the cloud data lifecycle is the data’s classification determined?
Which of the following is not a risk-management framework?
Each of the following are dependencies that must be considered when reviewing the BIA following cloud migration, except:
What is the lowest level in the CSA STAR program?
Which technology is not commonly used to secure data in transit?
Which option best characterizes the Organizational Normative Framework (ONF)?
Many common threats target web-exposed services and applications. One attack attempts to exploit input fields to run nested queries in a way the developers did not intend.
What type of attack is this?
From a security standpoint, which component of a cloud-computing infrastructure presents the greatest concern?
DLP solutions can help deter loss resulting from which of the following?
Which threat type involves submitting commands or arbitrary data through an application's input fields in an effort to have that code executed during normal processing?
Identity and access management (IAM) is a security discipline that ensures which of the following?
Every company must make an important decision about where to host the data systems on which it relies. There is debate over whether it is preferable to lease space in a data center, build an in-house data center, or, with cloud computing, purchase cloud resources.
What is the greatest advantage of leasing space in a data center rather than obtaining cloud services?
Community Discussion