exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 2 discussion

Actual exam question from CompTIA's CAS-004
Question #: 2
Topic #: 1
[All CAS-004 Questions]

An organization is preparing to migrate its production environment systems from an on-premises environment to a cloud service. The lead security architect is concerned that the organization's current methods for addressing risk may not be possible in the cloud environment.
Which of the following BEST describes the reason why traditional methods of addressing risk may not be possible in the cloud?

  • A. Migrating operations assumes the acceptance of all risk.
  • B. Cloud providers are unable to avoid risk.
  • C. Specific risks cannot be transferred to the cloud provider.
  • D. Risks to data in the cloud cannot be mitigated.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BiteSize
Highly Voted 1 year, 9 months ago
Selected Answer: C
A = wouldn't make sense since the CSP isn't the data owner B = Cloud providers could avoid the risk via contract C = Cloud migrations are always a shared risk responsibility but ultimately the data owner/user has the most risk because they have the most to lose. D = You can mitigate risks with technical and administrative controls in both cloud and on-premises Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 12 times
...
ASH1776
Highly Voted 2 years, 2 months ago
Selected Answer: C
C is the correct answer.
upvoted 5 times
...
blacksheep6r
Most Recent 2 months, 3 weeks ago
Selected Answer: C
C. Specific risks cannot be transferred to the cloud provider: While cloud providers can handle certain security and risk aspects (like physical infrastructure and network security), some risks—especially related to data privacy, compliance, and specific application security—still remain the responsibility of the organization. So, these risks cannot be entirely transferred to the provider.
upvoted 1 times
...
Delab202
7 months ago
Selected Answer: C
C. Specific risks cannot be transferred to the cloud provider. Explanation: In a cloud environment, there is a shared responsibility model between the cloud service provider (CSP) and the customer. While the CSP is responsible for the security of the cloud infrastructure (e.g., physical data centers, networking, and hypervisors), customers are responsible for securing their data, applications, identity management, access controls, and configurations. Traditional methods of addressing risk often involved transferring certain risks to external entities, such as insurance providers or third-party service providers. However, in the cloud, specific risks related to the customer's data and applications cannot be entirely transferred to the cloud provider. The customer retains responsibility for aspects such as data protection, access management, and application security.
upvoted 3 times
...
23169fd
9 months, 2 weeks ago
Selected Answer: C
Shared Responsibility Model. Client: Encryption, OS, Apps and Data CSP: IaaS.
upvoted 2 times
...
Garrisonpro
11 months, 2 weeks ago
Hi, I hope all is well. I'll reveal to you how to get a score of at least 90% on your CAS-004 exam. First, you'll want to find a reliable source of knowledge regarding the exam and techniques for succeeding on it. This is my personal experience with Realexamcollection, where I received instruction for various tests and received perfect scores on all of them.
upvoted 1 times
...
rvv1978
1 year, 10 months ago
C. Specific risks cannot be transferred to the cloud provider. In a cloud environment, the responsibility for managing and mitigating risks is shared between the cloud service provider and the organization. While the cloud service provider takes on certain responsibilities related to the security and infrastructure of the cloud platform, it does not assume all risks associated with the organization's data and operations.
upvoted 5 times
...
CASP_Master
1 year, 11 months ago
The BEST answer is C.
upvoted 4 times
...
user009
2 years ago
The correct answer is C. Specific risks cannot be transferred to the cloud provider. Explanation: Traditional methods of addressing risk may not be possible in the cloud because specific risks cannot always be transferred to the cloud provider. Cloud providers may offer some security controls and features, but the organization is still responsible for ensuring its data and systems are secure. Cloud providers offer shared responsibility models where the provider is responsible for the security of the cloud infrastructure while the organization is responsible for securing its applications and data.
upvoted 3 times
...
xaliq
2 years, 4 months ago
the answer is C
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago