Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 393 discussion

Actual exam question from ISC's CISSP
Question #: 393
Topic #: 1
[All CISSP Questions]

What is the MOST effective way to ensure that a cloud service provider does not access a customer’s data stored within its infrastructure?

  • A. Use the organization’s encryption tools and data management controls.
  • B. Ensure that the cloud service provider will contractually not access data unless given explicit authority.
  • C. Request audit logs on a regular basis.
  • D. Utilize the cloud provider’s key management and elastic hardware security module (HSM) support.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
JohnyDal
Highly Voted 1 year, 9 months ago
Selected Answer: A
Most secure is to avoid the use and reliance of CSP's key infrastructure and only use internal one.
upvoted 7 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
GuardianAngel
Most Recent 9 months, 3 weeks ago
Usually the CLOUD service providers have the digital key to the encryption so that they can process a user’s data—for example, by indexing the data for future searches. I'm not sure if that means they have a key to ANY encryption used or only if their cloud native processes are used for encryption. I'm still going with answer A. (encryption), but this article could indicate B is the correct answer. https://thesciencebehindit.org/how-secure-is-data-stored-in-the-cloud/#:~:text=Can%20the%20cloud%20computing%20company,the%20data%20for%20future%20searches.
upvoted 1 times
...
Woo7
9 months, 3 weeks ago
Selected Answer: B
most effective on a cloud provider would be through contract.
upvoted 1 times
Woo7
9 months, 3 weeks ago
changing to b
upvoted 1 times
Woo7
9 months, 3 weeks ago
I mean A
upvoted 2 times
...
...
...
YesPlease
11 months, 1 week ago
Selected Answer: A
Answer A) https://cpl.thalesgroup.com/faq/data-security-in-the-cloud/how-do-i-ensure-the-cloud-provider-does-not-access-my-data
upvoted 1 times
...
Voxycs
1 year, 1 month ago
I don't like this question. If you have to think like a manager then you go with B since you're concerned with processes and cost. However, A makes more operational sense. ChatGPT says to go with A but I believe the answer is B...
upvoted 1 times
...
benllp_sst
1 year, 3 months ago
Selected Answer: B
B is more effective way, because A will generate extra cost on that and I think the exam more focus on high level consideration.
upvoted 2 times
...
[Removed]
1 year, 7 months ago
Selected Answer: A
I prefer a technical Computer Says No, thus A. If one could make a case that the CSP can easily access the data (i.e. via self-generated user accounts), I probably would go for B.
upvoted 1 times
...
Rollingalx
1 year, 9 months ago
A is correct
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...