素晴らしいManaging-Cloud-Security試験問題集試そうManaging-Cloud-Security問題集PDF [Q110-Q132]

Share

素晴らしいManaging-Cloud-Security試験問題集試そうManaging-Cloud-Security問題集PDF

Managing-Cloud-Security問題集PDFでManaging-Cloud-Securityリアル試験問題解答

質問 # 110
An organization is implementing a new hybrid cloud deployment. Before granting access to any of the resources, the security team wants to ensure that all employees are checked against a database to see if they are allowed to access the requested resource. Which type of security control is the organization leveraging for its employees?

  • A. Authorization
  • B. Authentication
  • C. Antispyware program
  • D. Web application firewall (WAF)

正解:A

解説:
The described control isauthorization, which occurs after authentication. Authorization determines what resources a user can access based on their role, attributes, or policies stored in an access control database.
Authentication confirms identity, but authorization validates permissions. WAFs protect applications from malicious traffic, and antispyware tools detect malware. Neither applies to access decisions.
By checking users against a database of permissions, the organization enforces the principle of least privilege, ensuring employees only access the resources necessary for their role. This strengthens data protection, reduces insider threats, and aligns with compliance requirements for access governance.


質問 # 111
Which countermeasure should be taken during the containment, eradication, and recovery phase of the incident response lifecycle?

  • A. Build timeline of attack
  • B. Validate alerts
  • C. Identify training
  • D. Take systems offline

正解:D

解説:
During the containment, eradication, and recovery phase of the incident response lifecycle, immediate action is taken to limit damage, remove the threat, and restore normal operations. Managing Cloud guidance explains that isolating affected systems is a key containment activity.
Taking systems offline prevents attackers from continuing malicious activity, stops further data loss, and allows remediation to occur safely. Once contained, systems can be cleaned, patched, restored from backups, and securely returned to service.
Validating alerts occurs during detection and analysis, identifying training needs belongs to lessons learned, and building a timeline of attack supports forensic analysis. Therefore, taking systems offline is the correct countermeasure in this phase.


質問 # 112
What must be provided by a European Union (EU) citizen, according to the General Data Protection Regulation (GDPR), before a firm may process the personal data of that individual?

  • A. Specific consent for the processing of the data
  • B. Verification of the accuracy of the data
  • C. Statement about need for the data to be processed
  • D. Attestation on the legal purpose for processing the data

正解:A

解説:
Under the General Data Protection Regulation (GDPR), an EU citizen must provide specific consent before an organization may process their personal data, unless another lawful basis explicitly applies.
Managing Cloud principles explain that consent must be freely given, specific, informed, and unambiguous.
This ensures individuals retain control over how their personal information is collected and used.
Consent must clearly state the purpose of processing and cannot be implied or bundled with unrelated terms.
Organizations must also be able to demonstrate that consent was obtained and allow individuals to withdraw consent at any time. This requirement strengthens transparency and accountability in data handling practices.
The other options do not satisfy GDPR consent requirements. Legal purpose attestation is an organizational responsibility, data accuracy verification is a data quality obligation, and statements of need do not replace explicit consent. Therefore, specific consent is required before processing personal data.


質問 # 113
Which security issue may occur when application programming interfaces (APIs) without sufficient validation are used in cloud services?

  • A. Data breach
  • B. Crypto-shredding
  • C. Inefficient bandwidth utilization
  • D. Perimeter security breach

正解:A

解説:
A data breach may occur when APIs lack sufficient validation in cloud services. Managing Cloud documentation explains that APIs often serve as primary access points to cloud applications and data.
Without proper input validation, authentication, and authorization checks, APIs can be exploited to access sensitive data, bypass controls, or manipulate backend services. Attackers may inject malicious requests or abuse poorly secured endpoints to extract or alter data.
Inefficient bandwidth usage is a performance issue, perimeter breaches involve network defenses, and crypto- shredding is a data destruction technique. Therefore, data breach is the correct answer.


質問 # 114
An organization is concerned that it will be unable to recover or access data if the cloud provider goes into bankruptcy and leaves the market. How is this concern addressed in a business continuity and disaster recovery plan?

  • A. Enable multiple zones to mitigate service disruptions
  • B. Use best tools to securely connect to the cloud
  • C. Consider options for portability and interoperability
  • D. Revise contractual and personnel obligations

正解:C

解説:
This concern is addressed by considering portability and interoperability options. Managing Cloud guidance explains that organizations must plan for provider exit scenarios to avoid dependency risks.
Portability ensures data and workloads can be moved to another provider or on-premises environment, while interoperability supports compatibility across platforms. This may include standardized data formats, documented APIs, and offsite backups.
Multiple zones address outages, not provider bankruptcy. Contract revisions help legally but do not guarantee recovery. Therefore, portability and interoperability are the correct focus.


質問 # 115
Which key management option typically needs to be on-premises and delivers the keys to the cloud over a dedicated connection?

  • A. Cloud provider service
  • B. Hardware security appliance
  • C. Virtual appliance
  • D. Hybrid

正解:D

解説:
The Hybrid key management option typically requires key management infrastructure to remain on-premises while securely delivering cryptographic keys to the cloud through a dedicated and protected connection.
Managing Cloud guidance explains that hybrid key management models are designed for organizations that require maximum control over encryption keys while still leveraging cloud-based storage and processing.
In this model, encryption keys are generated, stored, and managed within the organization's own secure environment, reducing the risk of unauthorized access by external entities. Keys are provided to cloud services only when needed and often through secure channels such as private network connections. This approach supports strict compliance, regulatory, and data sovereignty requirements.
Other options do not meet this requirement. A hardware security appliance may be used on-premises but does not inherently define a hybrid cloud delivery model. Virtual appliances are typically cloud-resident, and cloud provider services manage keys entirely within the provider's infrastructure. Therefore, the hybrid option best aligns with on-premises key control combined with secure cloud integration.


質問 # 116
Which role in cloud computing provides products or services that interact with the primary offering of a cloud service provider?

  • A. Cloud service developer
  • B. Cloud service partner
  • C. Customer
  • D. Regulator

正解:B

解説:
A cloud service partner plays a complementary role by offering products or services that enhance or interact with the primary cloud provider's offerings. Examples include managed service providers, value-added resellers, or software vendors that integrate their solutions with the core infrastructure or platform of a cloud service provider.
The customer is the end user of cloud services, regulators ensure compliance with laws, and developers create applications but do not represent an independent ecosystem role. Partners, on the other hand, extend the value of the primary offering by providing additional tools, support, or integrations that enhance customer experience.
This ecosystem role is recognized by major cloud frameworks, such as the Cloud Security Alliance, which notes the importance of partners in ensuring interoperability, extending services, and supporting shared responsibility. For customers, this means greater flexibility and choice in tailoring cloud solutions to business needs.


質問 # 117
An organization's leadership team gathered managers and key team members in each division to help create a disaster recovery plan. They realize they lack a complete understanding of the infrastructure and software needed to formulate the plan. Which action should they take to correct this issue?

  • A. They should identify the key roles in a disaster.
  • B. They should determine the criteria of a disaster.
  • C. They should perform an inventory of assets.
  • D. They should create a checklist of the necessary tasks.

正解:C

解説:
Without a clear understanding of infrastructure and software, the leadership team must first conduct an inventory of assets. An asset inventory provides a comprehensive list of hardware, software, and services that support business operations.
Creating checklists, defining criteria, and assigning roles are important, but they rely on knowing what assets exist. Without an inventory, the disaster recovery plan would miss critical dependencies, making recovery incomplete or impossible.
Performing an inventory supports business impact analysis, risk assessments, and recovery prioritization. It ensures that all critical systems are accounted for and appropriate recovery strategies can be designed. Asset inventories are a foundational best practice for disaster recovery and continuity planning.


質問 # 118
Which term describes data elements that, when combined with other information, are used to single out an individual?

  • A. Personal details
  • B. Indirect identifiers
  • C. Data subjects
  • D. Direct identifiers

正解:B

解説:
Indirect identifiersare pieces of information that may not identify an individual on their own but, when combined with other data, can uniquely identify someone. Examples include birthdate, ZIP code, or gender.
Together, these can re-identify a person, even when names or direct identifiers are removed.
Direct identifiers (such as Social Security numbers) uniquely identify an individual alone. Data subjects are the individuals to whom the data refers, while personal details is too broad and not a formal term.
Understanding indirect identifiers is essential in privacy regulations like GDPR and HIPAA, where pseudonymization or anonymization must account for potential re-identification risks. Safeguarding indirect identifiers reduces the chance of privacy violations and unauthorized profiling.


質問 # 119
A user creates new financial documents that will be stored in the cloud. Which action should the user take before uploading the documents to protect them against threats such as packet capture and on-path attacks?

  • A. Hashing
  • B. Metadata labeling
  • C. Encryption
  • D. Change tracking

正解:C

解説:
Before transmitting sensitive financial data to the cloud, the best defense against interception threats like packet capture and man-in-the-middle attacks is encryption. Encryption protects data in transit by converting plain text into cipher text, which can only be deciphered with the correct keys.
Hashing provides integrity verification but does not secure confidentiality. Change tracking monitors modifications but does not prevent interception. Metadata labeling adds context but does not protect against on-path attackers.
Using strong encryption protocols (e.g., TLS) ensures that even if traffic is intercepted, the attacker cannot read the data. Encryption also aligns with compliance requirements such as PCI DSS, which mandates encryption for financial data during transmission. By encrypting before upload, the user ensures end-to-end confidentiality across potentially insecure networks.


質問 # 120
Which methodology encompasses conducting tests around the interaction of end users with new code that is intended for a patch?

  • A. Nonfunctional testing
  • B. Functional testing
  • C. Tabletop testing
  • D. Full testing

正解:B

解説:
Functional testingvalidates that new or updated code performs correctly from the end user's perspective.
This type of testing ensures that the patch delivers intended results without introducing errors. It focuses on verifying user interactions, workflows, and outputs.
Full testing may cover all aspects, but it is broader than necessary. Nonfunctional testing evaluates performance, scalability, or usability, not direct functionality. Tabletop testing is a discussion-based exercise, often used for incident response.
Functional testing ensures customer satisfaction by aligning patches with expected system behavior. It is a core component of Agile and DevOps pipelines, where user experience and rapid delivery are prioritized.


質問 # 121
A warning system identifies an impending disaster. When should failover occur to ensure continuity of operations?

  • A. During the crisis event
  • B. Prior to the crisis event
  • C. During the resumption of normal activities
  • D. Prior to the resumption of normal activities

正解:B

解説:
Failover should occur prior to the crisis event when an impending disaster is identified. Managing Cloud principles explain that proactive failover allows organizations to maintain service continuity by transitioning operations to alternate systems before disruption occurs.
Early failover reduces downtime, minimizes data loss, and avoids the risks associated with reactive responses during an active crisis. Cloud environments support automated or planned failover mechanisms that can be triggered by warning systems, ensuring seamless continuity.
Failover during or after the crisis increases the likelihood of service interruption. Therefore, initiating failover before the event is the correct approach.


質問 # 122
Which security device includes anti-distributed denial of service (DDoS) capabilities in order to protect cloud data storage?

  • A. Network-based database activity monitor (NDAM)
  • B. Extensible markup language (XML) gateway
  • C. Web application firewall (WAF)
  • D. Agent-based database activity monitor (ADAM)

正解:C

解説:
A Web Application Firewall (WAF) includes anti-distributed denial of service (DDoS) capabilities designed to protect cloud-hosted applications and underlying data storage from availability-based attacks. Managing Cloud principles state that WAFs sit in front of web applications and analyze incoming traffic to identify and block malicious requests, including high-volume attack patterns characteristic of DDoS attacks.
By filtering traffic at the application layer, a WAF prevents excessive or malicious requests from overwhelming backend services such as cloud storage systems and databases. Many WAF solutions implement rate limiting, traffic profiling, and behavioral analysis to distinguish legitimate users from attackers, ensuring continued access to cloud resources.
The other options do not provide DDoS protection. An XML gateway focuses on validating and securing XML-based messages. NDAM and ADAM solutions monitor database activity but do not mitigate network- level or application-layer flood attacks. Therefore, the Web Application Firewall is the correct security device for providing anti-DDoS protection in cloud environments.


質問 # 123
Which strategy provides the highest overall cost savings for an organization implementing a business continuity and disaster recovery (BCDR) plan?

  • A. Migrate local backups to tape.
  • B. Move all services to the cloud.
  • C. Deploy a hot cloud site.
  • D. Implement cross-site replication.

正解:B

解説:
Moving all services to the cloud provides the highest overall cost savings for organizations implementing BCDR. Managing Cloud guidance explains that cloud-based services reduce capital expenditures, eliminate the need for secondary physical data centers, and leverage on-demand scalability.
Cloud platforms offer built-in redundancy, geographic distribution, and automated recovery capabilities that significantly lower the cost of maintaining separate disaster recovery infrastructure. Pay-as-you-go pricing ensures organizations only pay for resources when needed, further reducing operational expenses.
Hot sites and cross-site replication incur ongoing costs, while tape backups offer lower cost but do not support rapid recovery. Therefore, migrating services to the cloud delivers the most comprehensive cost savings.


質問 # 124
Which item determines whether a server has the capacity and the instance allocation to meet a customer's requirements?

  • A. Instance provider
  • B. Cloud controller
  • C. UniFi controller
  • D. Cloud provider

正解:B

解説:
The cloud controller determines whether a server has sufficient capacity and appropriate instance allocation to meet customer requirements. Managing Cloud principles explain that the cloud controller manages resource scheduling, provisioning, and allocation across the cloud infrastructure.
It evaluates available compute, memory, storage, and network resources before assigning workloads to physical or virtual servers. This ensures that customer requests are fulfilled without overcommitting resources or degrading performance.
A cloud provider delivers services, an instance provider is not a standard cloud role, and a UniFi controller manages networking devices. Therefore, the cloud controller is the correct answer.


質問 # 125
An organization's security architects determined that all authentication and authorization requests need to be validated before any employee can access corporate resources. Because of this, the organization needs to implement a system that stores and manages the employees' credential information and then validates any requests sent. Which system would allow the organization to meet the architects' requirements?

  • A. Bastion host
  • B. Zero trust
  • C. Identity provider (IdP)
  • D. Hardware security module (HSM)

正解:C

解説:
AnIdentity Provider (IdP)is a system that stores and manages identity information and validates authentication and authorization requests. IdPs are critical in cloud and hybrid environments, supporting protocols such as SAML, OAuth, and OpenID Connect for federated access.
An HSM manages encryption keys, not identities. Zero Trust is a security philosophy requiring continuous verification, but the system that enforces authentication is the IdP. A bastion host provides secure administrative access but does not manage identity.
By using an IdP, organizations centralize credential management, enforce multifactor authentication, and integrate with Single Sign-On (SSO). This reduces password fatigue, increases security, and ensures consistent access control policies across applications and services.


質問 # 126
Which security device allows customers to redirect traffic?

  • A. Intrusion detection and prevention systems
  • B. Web application firewalls
  • C. Security information and event management
  • D. Cryptographic key management

正解:B

解説:
A Web Application Firewall (WAF) allows customers to redirect traffic as part of securing cloud-hosted applications. Managing Cloud principles explain that WAFs operate at the application layer and can inspect, filter, allow, block, or redirect HTTP and HTTPS traffic based on defined security rules.
Traffic redirection is commonly used to route suspicious or malicious requests away from protected applications, forward traffic to alternate services, or enforce secure communication paths. WAFs can also integrate with load balancers and content delivery networks to manage traffic flow efficiently while protecting applications from attacks such as SQL injection, cross-site scripting, and denial-of-service attempts.
The other options do not provide traffic redirection. SIEM systems aggregate and analyze logs, intrusion detection and prevention systems focus on detection and blocking, and cryptographic key management handles encryption keys. Therefore, a web application firewall is the correct answer.


質問 # 127
Which aspect of access management safeguards data by determining the user's rights to a certain resource?

  • A. Authorization
  • B. Authentication
  • C. Centralization
  • D. Provisioning

正解:A

解説:
Authorization is the access management aspect that safeguards data by determining a user's rights to specific resources. Managing Cloud principles describe authorization as the process of enforcing policies that define what actions an authenticated user is permitted to perform within a system.
Once a user's identity has been authenticated, authorization evaluates roles, permissions, and access rules to decide whether access to a particular resource should be granted or denied. This ensures that users can only access data and services necessary for their job functions, reducing the risk of unauthorized data exposure.
Authentication verifies who the user is, provisioning creates the identity, and centralization relates to identity architecture design. None of these directly determine access rights. Authorization is therefore the key mechanism that enforces least privilege and protects cloud data from improper access.


質問 # 128
Which risk relates to the removal of a person's information within the public cloud by legal authorities?

  • A. Remote wiping
  • B. Vendor lock-in
  • C. Data masking
  • D. Data seizure

正解:D

解説:
Data seizure is the risk associated with legal authorities removing or accessing a person's information stored in a public cloud. Managing Cloud guidance explains that cloud data is subject to the laws and legal processes of the jurisdiction in which it resides.
In some cases, government agencies may compel cloud service providers to disclose or seize data as part of legal investigations. This can occur without the data owner's direct involvement and may affect confidentiality, privacy, and business operations. Public cloud environments increase this risk because infrastructure is shared and often spans multiple jurisdictions.
Remote wiping is a data destruction technique, vendor lock-in relates to dependency on providers, and data masking protects sensitive data. Therefore, data seizure is the correct risk.


質問 # 129
As part of an e-discovery process, an employee needs to identify all documents that contain a specific phrase.
Which type of discovery method should the employee use to identify these documents?

  • A. Metadata-based
  • B. Location-based
  • C. Label-based
  • D. Content-based

正解:D

解説:
Content-based discoveryinvolves searching within the actual text or binary content of documents to find matches for keywords, phrases, or patterns. In e-discovery, when the requirement is to locate documents containing a specific phrase, searching based on content is the most direct and reliable method.
Other approaches, such as metadata-based discovery, only examine properties like creation date or author, which do not reveal the presence of specific text. Label-based discovery relies on pre-applied classification labels, which may not always be accurate. Location-based discovery limits searches to folders or storage locations but does not guarantee relevance.
Content-based discovery provides completeness in legal and regulatory investigations. It ensures that no relevant documents are overlooked simply because of inconsistent labeling or metadata, thus supporting compliance and defensibility in court proceedings.


質問 # 130
Which type of cloud security vulnerability is static application security testing (SAST) likely to find?

  • A. Embedded credentials
  • B. Software misconfiguration
  • C. Hypervisor vulnerabilities
  • D. Run-time vulnerabilities

正解:A

解説:
Static application security testing (SAST) is most likely to identify embedded credentials. Managing Cloud principles explain that SAST analyzes application source code, binaries, or bytecode without executing the program.
Because SAST inspects code structure and logic, it can detect hard-coded passwords, API keys, and secrets embedded directly in application files. These vulnerabilities pose significant risk if exposed in cloud environments.
Software misconfiguration and runtime vulnerabilities require execution context, and hypervisor vulnerabilities exist outside application code. Therefore, embedded credentials are best detected through SAST.


質問 # 131
Which cloud storage architecture enhances the opportunity for data policy enforcement such as data loss prevention (DLP)?

  • A. Database
  • B. Object
  • C. Ephemeral
  • D. Flash

正解:B

解説:
Object storage architecture enhances the opportunity for enforcing data policies such as data loss prevention (DLP). Managing Cloud principles explain that object storage supports extensive metadata tagging, which allows organizations to classify data, apply sensitivity labels, and enforce security policies directly at the storage level.
By leveraging metadata, DLP solutions can identify sensitive information, apply access restrictions, trigger alerts, or prevent unauthorized data movement. Policies can be consistently enforced across large-scale cloud environments without relying on application-level controls. This makes object storage particularly effective for managing unstructured data such as documents, media files, and backups.
The other options do not provide the same level of policy enforcement. Flash storage focuses on performance, databases rely on structured schemas, and ephemeral storage is temporary and unsuitable for persistent policy enforcement. Therefore, object storage is the most effective architecture for enabling strong data governance and DLP controls in cloud environments.


質問 # 132
......

有効なManaging-Cloud-Securityテスト解答とWGU Managing-Cloud-Security試験PDF:https://jp.fast2test.com/Managing-Cloud-Security-premium-file.html

実際に出るManaging-Cloud-Security試験問題集には正確で更新された問題:https://drive.google.com/open?id=13eVi7ixpxFoDdKjVFnRxQvGYPwohVewm


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어