01. In a SaaS service model, the tenant transfers technical control of the computing environment to the cloud service provider. Which of the following responsibilities does the tenant retain?
a) Backing up the data to a remote location
b) Liability and legal responsibility for securing data
c) Configuration of the underlying virtualization platform
d) Patching the operating systems
02. Which deployment model BEST meets the business requirements for cloud bursting?
a) Private cloud
b) Public cloud
c) Hybrid cloud
d) Community cloud
03. An organization is moving one business process, data storage, to a cloud service provider (CSP). On reviewing the CSP’s data storage strategy, you identify that it uses shared storage. Which of the following provides the BEST protection for your company’s data from other tenants?
a) Utilize a hybrid cloud strategy—utilizing the CSP’s application and storing the data locally
b) Require company data be stored on separate storage
c) Access control rules based on pre-defined business rules
d) Ensure company data is encrypted
04. Your company utilizes a custom application that services many financial clients. The application is hosted on company servers within their private data center. All company servers run specific configurations and a software firewall.
They want a test environment that offers as much control over the environment as possible, to ensure configuration settings of both environments are alike, but want to minimize the costs and time involved with setting up the environment.
Which service model BEST meets the business requirements?
a) SaaS/Public
b) PaaS/Hybrid
c) PaaS/Public
d) IaaS/Private
e) IaaS/Public
f) SaaS/Private
05. Part of your company’s risk management strategy is to ensure risk is properly addressed when moving processes to the cloud. Which of the following questions should NOT be part of that risk assessment?
a) If the process became unavailable, how would that affect the business?
b) Would the business be impacted if the information became publicly available?
c) What negative consequences would the business encounter if the process was manipulated by an unauthorized person?
d) What costs are associated with moving the business process to the cloud?
06. You work for a startup company that wants to be a SaaS provider. Your company wants to develop and sell the use of an application while minimizing capital expenditure costs. Which service model BEST meets these requirements?
a) PaaS
b) SaaS
c) IaaS
d) On-premises
07. The company only wants to pay for the resources they utilize; however, they want to ensure they are able to support high-demand periods, such as holiday times where resource demand increases quickly. Which concept would meet the business requirements?
a) Load balancing
b) High availability
c) Quad processors
d) Cloud bursting
08. Your company wants to move a business process to the cloud. The business process and associated data are heavily regulated. The company needs to ensure it retains ownership of the governing controls and has assurance the data will reside within a certain geographic location.
Which deployment model best meets the business requirements?
a) Community
b) Hybrid
c) Private
d) Public
09. After researching the various cloud deployment models, your company decides purchasing a dedicated cloud deployment model isn’t cost effective; however, they want to ensure that all companies utilizing the cloud deployment model are a known quantity and adhere to the same PCI-DSS requirements.
Which deployment model BEST meets these requirements?
a) Private
b) Community
c) Public
d) Hybrid
10. The second business process your company wishes to migrate to the cloud is the human resources system. They have selected a SaaS cloud service model. When using a SaaS cloud service model, what tool is MOST effective at ensuring the security of a company’s data?
a) Developing a contract that defines the roles and responsibilities of the CSP and the company
b) Defining the geographic restrictions where your company’s data is authorized to reside
c) Ensuring your company has the right to audit
d) Ensuring all company data is encrypted