exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 460 discussion

Actual exam question from ISC's CCSP
Question #: 460
Topic #: 1
[All CCSP Questions]

Countermeasures for protecting cloud operations against internal threats include all of the following except:

  • A. Extensive and comprehensive training programs, including initial, recurring, and refresher sessions
  • B. Skills and knowledge testing
  • C. Hardened perimeter devices
  • D. Aggressive background checks
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Hardened perimeter devices are more useful at attenuating the risk of external attack.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
gavbam
Highly Voted 2 years, 8 months ago
Answer C is correct try whittle the other ones away you will see defo not D so A, B or C B incorrect an attacker doenst care so left with A or C A is a distractor c is left
upvoted 5 times
...
bdfb8cf
Most Recent 3 weeks, 2 days ago
Selected Answer: C
An unskilled internal actor is a threat Perimeter security is defense vs external threat
upvoted 1 times
...
MaciekMT
1 month ago
Selected Answer: C
Countermeasures for internal threats focus on personnel security, training, and monitoring to prevent malicious or accidental insider threats. While hardened perimeter devices (e.g., firewalls, intrusion prevention systems) are crucial for external security, they do not specifically address internal threats. 🔹 Effective Internal Threat Countermeasures: A. Extensive and comprehensive training programs → Educates employees on security best practices and how to avoid insider threats. B. Skills and knowledge testing → Ensures employees understand security policies and can apply them correctly. D. Aggressive background checks → Helps identify potentially risky employees before hiring. 🔹 Why Not "Hardened Perimeter Devices"? Perimeter security is designed to block external attackers, not to monitor or prevent insider threats. Insider threats often bypass perimeter security because they originate from within the organization.
upvoted 1 times
...
lolanczos
3 months, 1 week ago
It's C. The context is EXTERNAL attack. Hardened perimeter devices are primarily a countermeasure against external threats, not internal threats. Internal threats require measures that focus on personnel, access controls, and monitoring of insider activity. The others are all internal measures.
upvoted 1 times
...
Alex_2169
7 months, 3 weeks ago
C is the best answer
upvoted 3 times
...
data304
11 months, 4 weeks ago
Selected Answer: B
I personally don't agree to C, because in large enterprises you may have several internal network zones which some of these may have a perimeter control. So from my perspective B makes no sense and is not a formal control.
upvoted 2 times
lolanczos
3 months, 1 week ago
C is objectively correct.
upvoted 1 times
...
...
Sa007788
2 years, 8 months ago
answer not true, most attck come from internal staff.When we use a lapotop we don't access with admin account.
upvoted 1 times
Ahbey_911
2 years, 8 months ago
Hardened perimeter defense mitigates against external threats, not internal threat actor that already have access to the internal network. The selected answer is correct.
upvoted 7 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago