โ† All CCSK Flashcard Decks

Cloud Data Security and Governance Flashcards

6 cards from real CCSK practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Data Security and Governance flashcards as text
  1. What is 'tokenization' and how does it differ from encryption in cloud data protection?

    Answer: Tokenization replaces sensitive data with a non-sensitive placeholder; encryption transforms data using a mathematical algorithm and key

    Tokenization substitutes sensitive data with a token that has no intrinsic value, while encryption transforms data mathematically and can be reversed with the key.

  2. Which CCSK concept describes ensuring data integrity throughout its lifecycle in the cloud?

    Answer: Data lineage

    Data lineage tracks how data moves, transforms, and is used throughout its lifecycle, ensuring accountability and integrity verification.

  3. What is a 'cloud access security broker' (CASB) primarily used for?

    Answer: Enforcing security policies between cloud users and cloud services

    A CASB sits between users and cloud services to enforce security policies including visibility, compliance, data security, and threat protection.

  4. According to CCSK, what should organizations do before terminating a cloud provider contract to address data security?

    Answer: Ensure all data is exported, verify deletion by the provider, and obtain written confirmation

    Before contract termination, organizations should export all data, confirm its deletion from provider systems, and obtain written assurance of secure disposal.

  5. What is the role of metadata in cloud data governance according to CCSK?

    Answer: Metadata describes data attributes enabling classification, discovery, and access control decisions

    Metadata describes data characteristics (type, owner, sensitivity) and enables automated classification, discovery, and enforcement of governance policies.

  6. Which approach does CCSK recommend for managing encryption keys in a multi-cloud environment?

    Answer: Use a centralized, customer-controlled key management system (KMS) or HSM

    A centralized customer-controlled KMS or hardware security module (HSM) ensures consistent key governance across multiple cloud providers.