Free CCSP Exam Braindumps (page: 26)

Page 25 of 129

Which of the following roles involves the connection and integration of existing systems and services to a cloud environment?

  1. Cloud service business manager
  2. Cloud service user
  3. Cloud service administrator
  4. Cloud service integrator

Answer(s): D

Explanation:

The cloud service integrator is the official role that involves connecting and integrating existing systems and services with a cloud environment. This may involve moving services into a cloud environment, or connecting to external cloud services and capabilities from traditional data center-hosted services.



Which technique involves replacing values within a specific data field to protect sensitive data?

  1. Anonymization
  2. Masking
  3. Tokenization
  4. Obfuscation

Answer(s): B

Explanation:

Masking involves replacing specific data within a data set with new values. For example, with credit card fields, as most who have ever purchased anything online can attest, nearly the entire credit card number is masked with a character such as an asterisk, with the last four digits left visible for identification and confirmation.



What expectation of data custodians is made much more challenging by a cloud implementation, especially with PaaS or SaaS?

  1. Data classification
  2. Knowledge of systems
  3. Access to data
  4. Encryption requirements

Answer(s): B

Explanation:

Under the Federal Rules of Civil Procedure, data custodians are assumed and expected to have full and comprehensive knowledge of the internal design and architecture of their systems. In a cloud environment, especially with PaaS and SaaS, it is impossible for the data custodian to have this knowledge because those systems are controlled by the cloud provider and protected as proprietary knowledge.



What type of PII is controlled based on laws and carries legal penalties for noncompliance with requirements?

  1. Contractual
  2. Regulated
  3. Specific
  4. Jurisdictional

Answer(s): B

Explanation:

Regulated PII involves those requirements put forth by specific laws or regulations, and unlike contractual PII, where a violation can lead to contractual penalties, a violation of regulated PII can lead to fines or even criminal charges in some jurisdictions. PII regulations can depend on either the jurisdiction that applies to the hosting location or application or specific legislation based on the industry or type of data used.






Post your Comments and Discuss ISC CCSP exam with other Community members:

CCSP Exam Discussions & Posts