Free CCSP Exam Braindumps (page: 28)

Page 27 of 129

What is a standard configuration and policy set that is applied to systems and virtual machines called?

  1. Standardization
  2. Baseline
  3. Hardening
  4. Redline

Answer(s): B

Explanation:

The most common and efficient manner of securing operating systems is through the use of baselines. A baseline is a standardized and understood set of base configurations and settings. When a new system is built or a new virtual machine is established, baselines will be applied to a new image to ensure the base configuration meets organizational policy and regulatory requirements.



Which entity requires all collection and storing of data on their citizens to be done on hardware that resides within their borders?

  1. Russia
  2. France
  3. Germany
  4. United States

Answer(s): A

Explanation:

Signed into law and effective starting on September 1, 2015, Russian Law 526-FZ establishes that any collecting, storing, or processing of personal information or data on Russian citizens must be done from systems and databases that are physically located with the Russian Federation.



Which of the cloud cross-cutting aspects relates to the ability to easily move services and applications between different cloud providers?

  1. Reversibility
  2. Availability
  3. Portability
  4. Interoperability

Answer(s): C

Explanation:

Portability is the ease with which a service or application can be moved between different cloud providers. Maintaining portability gives an organization great flexibility between cloud providers and the ability to shop for better deals or offerings.



Which type of audit report is considered a "restricted use" report for its intended audience?

  1. SAS-70
  2. SSAE-16
  3. SOC Type 1
  4. SOC Type 2

Answer(s): C

Explanation:

SOC Type 1 reports are considered "restricted use" reports. They are intended for management and stakeholders of an organization, clients of the service organization, and auditors of the organization. They are not intended for release beyond those audiences.






Post your Comments and Discuss ISC CCSP exam with other Community members:

CCSP Exam Discussions & Posts