Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 83 discussion

Actual exam question from ISC's CISSP
Question #: 83
Topic #: 1
[All CISSP Questions]

As a design principle, which one of the following actors is responsible for identifying and approving data security requirement in a cloud ecosystem?

  • A. Cloud auditor
  • B. Cloud broker
  • C. Cloud provider
  • D. Cloud consumer
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
kptest12
Highly Voted 2 years, 1 month ago
Selected Answer: D
https://www.isc2.org/Articles/Responsibility-and-Accountability-in-the-Cloud Data Security - Customer responsibility
upvoted 12 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 2 times
...
...
sbear123
Most Recent 8 months, 1 week ago
Selected Answer: D
In all models of cloud, Data is always Customer's responsibility.
upvoted 2 times
...
Hongjun
8 months, 3 weeks ago
Selected Answer: D
Copy form chapter 3.4: Users often mistakenly assume that their CSP is responsible for all security, but users have responsibility for securing their own storage and processing capabilities. So clear that is D
upvoted 1 times
...
YesPlease
11 months, 3 weeks ago
Selected Answer: D
Answer D) Cloud Consumer is responsible for DATA SECURITY on IaaS - PaaS - SaaS https://www.isc2.org/insights/2021/02/responsibility-and-accountability-in-the-cloud
upvoted 1 times
...
Soleandheel
11 months, 3 weeks ago
D. is the correct answer. Think of it like this; Who ever owns the data, decides how they want the data they own identified, classified and secured. The data owner always has the ultimate say and in this case, the cloud consumer would be considered the data owner. Imagine if the data being stored contained important propriatory information, would you as the owner of the data (the clod consumer) want the cloud provider deciding on how to classify and secure your data? Absolutely not. So in a very logical way, you can see that the correct answer is undeniably D.
upvoted 1 times
...
AMANSUNAR
1 year ago
Selected Answer: D
The cloud consumer is the entity or organization that utilizes cloud services. In the context of data security, the cloud consumer plays a key role in identifying and specifying the security requirements for their data when using cloud services.
upvoted 1 times
...
Moose01
1 year, 1 month ago
D is correct - generally cloud provider is responsible for some level of security but the wording here is Requirements and Approval, that is requested and approved by the consumer. cloud providers will make more money by selling different security packages to consumers.
upvoted 2 times
...
BoyBastos
1 year, 2 months ago
Selected Answer: D
Cloud consumer
upvoted 1 times
...
Bach1968
1 year, 4 months ago
Selected Answer: C
the correct answer is C. Cloud provider. The Cloud provider is responsible for identifying and approving data security requirements in a cloud ecosystem. They are the ones who offer the cloud services and resources to the Cloud consumers. As part of their role, Cloud providers are expected to implement security measures and controls to protect the data and ensure compliance with applicable regulations and standards.
upvoted 2 times
...
Dee83
1 year, 10 months ago
D. Cloud consumer is responsible for identifying and approving data security requirements in a cloud ecosystem as a design principle. A cloud consumer is the organization or individual who utilizes the cloud services offered by a cloud provider. As such, it is the responsibility of the cloud consumer to identify and approve the data security requirements for their specific use case and business needs. This includes assessing the risks and vulnerabilities associated with their data and applications, and determining the appropriate controls and safeguards that are required to protect them. The cloud consumer must also ensure that the cloud provider is able to meet these requirements,
upvoted 4 times
...
rajkamal0
1 year, 11 months ago
Selected Answer: D
100% Cloud Consumer. The cloud service provider does not take any responsibility of security lapse on customer.
upvoted 2 times
...
oudmaster
1 year, 11 months ago
Data in any cloud model is always owned by the customer and they are responsible to identifying and approving data security requirement. ! Consumers must have security consultants who decide the security requirements. ! I go with D
upvoted 1 times
...
Toa
2 years ago
Answer D Page 12 of link explain : Because cloud Consumers retain ownership of the data residing in a cloud Ecosystem, they usually keep the security authorization in- house and are responsible for identifying all security requirements pertaining to the cloud Ecosystem’s hosting and processing of this data. Cloud Consumer A person or organization that maintains a business relationship with, and uses service from, Cloud Providers. Cloud Provider A person, organization, or entity responsible for making a service available to interested parties. Cloud Auditor A party that can conduct an independent assessment of cloud services, information system operations, performance and security of the cloud implementation. Cloud Broker An entity that manages the use, performance and delivery of cloud services, and negotiates relationships between Cloud Providers and Cloud Consumers. Cloud Carrier An intermediary that provides connectivity and transport of cloud services from Cloud Providers to Cloud Consumers. https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=919233
upvoted 1 times
...
rootic
2 years ago
Selected Answer: D
I with D.
upvoted 1 times
...
franbarpro
2 years, 1 month ago
Selected Answer: D
For data security I am thinking of "D" - No matter if we are in the cloud...... We are still responsible for our data. YES it is stored in the cloud but if anything happens to the data. It's "US" the company in the news - not the cloud provider.
upvoted 2 times
...
stickerbush1970
2 years, 2 months ago
Selected Answer: C
Cloud providers have multiple offerings that accommodate different information assurance levels.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...