All of the following are techniques to enhance the portability of cloud data, in order to minimize the potential of vendor lock-in except:
What concept does the D represent within the STRIDE threat model?
Legal controls refer to which of the following?
Which of the following is NOT one of the official risk rating categories?
What is the correct order of the phases of the data life cycle?
Identity and access management (IAM) is a security discipline that ensures which of the following?
Which of the following best describes the Organizational Normative Framework (ONF)?
Which of the following types of data would fall under data rights management (DRM) rather than information rights management (IRM)?
Because cloud providers will not give detailed information out about their infrastructures and practices to the general public, they will often use established auditing reports to ensure public trust, where the reputation of the auditors serves for assurance.
Which type of audit reports can be used for general public trust assurances?
Which of the following components are part of what a CCSP should review when looking at contracting with a cloud service provider?
Being in a cloud environment, cloud customers lose a lot of insight and knowledge as to how their data is stored and their systems are deployed.
Which concept from the ISO/IEC cloud standards relates to the necessity of the cloud provider to inform the cloud customer on these issues?
What type of masking would you employ to produce a separate data set for testing purposes based on production data without any sensitive information?
The GAPP framework was developed through a joint effort between the major Canadian and American professional accounting associations in order to assist their members with managing and preventing risks to the privacy of their data and customers.
Which of the following is the meaning of GAPP?
All of these are methods of data discovery, except:
Which of the following areas of responsibility always falls completely under the purview of the cloud provider, regardless of which cloud service category is used?