Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CCSP Exam - Topic 3 Question 111 Discussion

To address shared monitoring and testing responsibilities in a cloud configuration, the provider might offer all these to the cloud customer except:
C) Security control administration
A) Access to audit logs and performance data
B) DLP solution results
D) SIM, SEIM. and SEM logs

ISC2 CCSP Exam - Topic 3 Question 111 Discussion

Actual exam question for ISC2's CCSP exam
Question #: 111
Topic #: 3
[All CCSP Questions]

To address shared monitoring and testing responsibilities in a cloud configuration, the provider might offer all these to the cloud customer except:

Show Suggested Answer Hide Answer
Suggested Answer: C

While the provider might share any of the other options listed, the provider will not share administration of security controls with the customer. Security controls are the sole province of the provider.


Contribute your Thoughts:

0/2000 characters
Nan
2 months ago
True, but I still feel C is the right choice. Providers focus on infrastructure, not security controls.
upvoted 0 times
...
Robt
2 months ago
But what about A? Access to audit logs is crucial for customers.
upvoted 0 times
...
Breana
3 months ago
I agree, C makes sense. Providers usually don’t handle that directly.
upvoted 0 times
...
Nichelle
3 months ago
I think the answer is C. Security control administration should be the customer's job.
upvoted 0 times
...
Paris
3 months ago
Yeah, I’m surprised they wouldn’t share audit logs.
upvoted 0 times
...
Wenona
3 months ago
I thought they might provide DLP results, but I guess not!
upvoted 0 times
...
Vi
3 months ago
Wait, are we sure about D? That seems important too.
upvoted 0 times
...
Jolene
3 months ago
I agree, C is the odd one out here!
upvoted 0 times
...
Dominque
4 months ago
Definitely not C, they usually don’t give that up.
upvoted 0 times
...
Lashon
4 months ago
I bet the provider is just trying to hide all the embarrassing security breaches in those DLP logs!
upvoted 0 times
...
Lai
4 months ago
Haha, the provider is like, "Sorry, that's our little secret. You don't get to see the DLP stuff!"
upvoted 0 times
...
Curt
5 months ago
Hmm, I'm not sure. Wouldn't the customer want to see the DLP results too? Seems like an important part of shared responsibilities.
upvoted 0 times
...
Thea
5 months ago
I agree, B is the odd one out here. The provider should give the customer access to the other monitoring and testing data.
upvoted 0 times
...
Hana
5 months ago
The correct answer is B) DLP solution results. The cloud provider would not provide that to the customer.
upvoted 0 times
...
Brandon
5 months ago
I feel like DLP solution results might not be shared, but I need to double-check my notes on that.
upvoted 0 times
...
Nickole
5 months ago
SIM, SEIM, and SEM logs sound like something the provider would provide, but I can't recall if they always do.
upvoted 0 times
...
Una
6 months ago
I remember a practice question that mentioned security control administration might be the customer's responsibility, so I'm leaning towards C.
upvoted 0 times
...
Marguerita
6 months ago
I think the provider would definitely offer access to audit logs and performance data, but I'm not sure about DLP results.
upvoted 0 times
...
Jamey
6 months ago
I feel pretty confident about this one. The provider would want to give the customer as much visibility as possible, so the exception is likely the DLP solution results.
upvoted 0 times
...
Shawnna
6 months ago
I've got a strategy - I'll eliminate the options I'm sure about first, then focus on the remaining two to decide which one the provider would not offer.
upvoted 0 times
...
Haydee
6 months ago
I'm a bit confused on the difference between those monitoring and logging solutions. I'll need to review my notes to make sure I understand them.
upvoted 0 times
...
Penney
6 months ago
Okay, let's see. The provider would likely offer access to audit logs, performance data, and security control administration, so that leaves DLP solution results or SIM/SIEM/SEM logs as the exception.
upvoted 0 times
...
William
7 months ago
Hmm, this one seems tricky. I'll need to think through the shared responsibilities carefully.
upvoted 0 times
Shantell
11 days ago
Yeah, that makes sense. They usually don’t provide those.
upvoted 0 times
...
Sheridan
16 days ago
I think DLP solution results might be the answer.
upvoted 0 times
...
Lashonda
2 months ago
I agree, it’s definitely a tricky question.
upvoted 0 times
...
...

Save Cancel