<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Checking some answers to a practice test in Exam Preparation</title>
    <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23503#M1830</link>
    <description>&lt;P&gt;I just took a practice test and I don't understand some of the answers they say are correct. Can anyone explain them? Or are the questions broken?&lt;/P&gt;&lt;P&gt;17. Cloud computing is based on which approach to service delivery: the answer was "Virtualization or thin client technology." My answer "virtualization" was wrong. I wasn't aware the thin client technology was part of it. Not mentioned in anything I read (that I remember) or in the class.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;32. Information Rights management (IRM) is generally associated with the following attributes: (notice it said "attributes.")&lt;/P&gt;&lt;P&gt;Right answer: Data rights management, the use of role-based access control, the installation of a local client agent, and the ability to integrate with the data loss prevention (DLP) solutions&lt;/P&gt;&lt;P&gt;My selected answer was: Role-based access control, the installation of a local client agent, and the ability to integrate with the data loss prevention (DLP) solutions&lt;/P&gt;&lt;P&gt;It had everything that the "right" answer had except "data rights management." Is drm an attribute or a technology?&amp;nbsp; And besides, isn't IRM the same term as DRM?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;65. A risk assessment is based on the following, in order:&lt;/P&gt;&lt;P&gt;The right answer is: Threat, vulnerability, probability, impact and risk determination.&lt;/P&gt;&lt;P&gt;My answer was: Vulnerability, threat, impact, probability and risk determination.&lt;/P&gt;&lt;P&gt;My class notes and the photo of the instructor's drawing clearly says:&lt;/P&gt;&lt;P&gt;Identify assets&lt;/P&gt;&lt;P&gt;Identify vulnerabilities&lt;/P&gt;&lt;P&gt;Identify threats&lt;/P&gt;&lt;P&gt;Identify exposure factor (impact)&lt;/P&gt;&lt;P&gt;Identify Likelihood (probability)&lt;/P&gt;&lt;P&gt;Perform qualitative risk analysis&lt;/P&gt;&lt;P&gt;perform quantitative risk analysis.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; which means that my selected answer was correct. Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;135: Generally, there are two types of cooling, and the return air temperature is based on:&lt;/P&gt;&lt;P&gt;The right answer: Latent cooling (remove moisture) and sensible cooling (remove heat),and the temperature is measured at the inlet point.&lt;/P&gt;&lt;P&gt;Well that's just wrong. The air temperature is measured as it exits the room, not as it enters the room. My selected answer was: Latent cooling (remove moisture) and sensible cooling (remove heat),and the temperature is measured at the exhaust point.&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2019 22:04:23 GMT</pubDate>
    <dc:creator>altoflyer</dc:creator>
    <dc:date>2019-06-10T22:04:23Z</dc:date>
    <item>
      <title>Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23503#M1830</link>
      <description>&lt;P&gt;I just took a practice test and I don't understand some of the answers they say are correct. Can anyone explain them? Or are the questions broken?&lt;/P&gt;&lt;P&gt;17. Cloud computing is based on which approach to service delivery: the answer was "Virtualization or thin client technology." My answer "virtualization" was wrong. I wasn't aware the thin client technology was part of it. Not mentioned in anything I read (that I remember) or in the class.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;32. Information Rights management (IRM) is generally associated with the following attributes: (notice it said "attributes.")&lt;/P&gt;&lt;P&gt;Right answer: Data rights management, the use of role-based access control, the installation of a local client agent, and the ability to integrate with the data loss prevention (DLP) solutions&lt;/P&gt;&lt;P&gt;My selected answer was: Role-based access control, the installation of a local client agent, and the ability to integrate with the data loss prevention (DLP) solutions&lt;/P&gt;&lt;P&gt;It had everything that the "right" answer had except "data rights management." Is drm an attribute or a technology?&amp;nbsp; And besides, isn't IRM the same term as DRM?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;65. A risk assessment is based on the following, in order:&lt;/P&gt;&lt;P&gt;The right answer is: Threat, vulnerability, probability, impact and risk determination.&lt;/P&gt;&lt;P&gt;My answer was: Vulnerability, threat, impact, probability and risk determination.&lt;/P&gt;&lt;P&gt;My class notes and the photo of the instructor's drawing clearly says:&lt;/P&gt;&lt;P&gt;Identify assets&lt;/P&gt;&lt;P&gt;Identify vulnerabilities&lt;/P&gt;&lt;P&gt;Identify threats&lt;/P&gt;&lt;P&gt;Identify exposure factor (impact)&lt;/P&gt;&lt;P&gt;Identify Likelihood (probability)&lt;/P&gt;&lt;P&gt;Perform qualitative risk analysis&lt;/P&gt;&lt;P&gt;perform quantitative risk analysis.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; which means that my selected answer was correct. Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;135: Generally, there are two types of cooling, and the return air temperature is based on:&lt;/P&gt;&lt;P&gt;The right answer: Latent cooling (remove moisture) and sensible cooling (remove heat),and the temperature is measured at the inlet point.&lt;/P&gt;&lt;P&gt;Well that's just wrong. The air temperature is measured as it exits the room, not as it enters the room. My selected answer was: Latent cooling (remove moisture) and sensible cooling (remove heat),and the temperature is measured at the exhaust point.&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 22:04:23 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23503#M1830</guid>
      <dc:creator>altoflyer</dc:creator>
      <dc:date>2019-06-10T22:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23505#M1831</link>
      <description>&lt;P&gt;So this is hard to answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First whose practice test is it?&amp;nbsp; Is it on the internet, from the course provider?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second what were all the answers? to the questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Whose training did you take.......what references did they provide?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry for so many questions, but I cannot answer your questions without some information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 23:58:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23505#M1831</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-06-10T23:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23506#M1832</link>
      <description>&lt;P&gt;Thanks, I got the practice test from Training Camp. Training camp was offered to me by my employer, so I didn't inquire about their references. (or did you mean what materials did they reference?) The material we used was the official ISC2 publication "Certified Cloud Security Professional Official (ISC)2 Student Guide." IMHO, this guide is very poorly written. But that's the subject for another thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;17. Cloud computing is based on which approach to service delivery:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a) virtualization&lt;/P&gt;&lt;P&gt;b) thin client technology&lt;/P&gt;&lt;P&gt;c) Virtualization or thin client technology&lt;/P&gt;&lt;P&gt;d) Tightly coupled architectural models&lt;/P&gt;&lt;P&gt;I answered "a," but the correct answer was "c." Really?Just the fact that they have "or" in the answer made it not seem correct. That combined with not having heard about thin clients since the early days of the internet made that answer seem wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;32. Information Rights management (IRM) is generally associated with the following attributes:&lt;/P&gt;&lt;P&gt;a) Data rights management, the use of role-based access control, the installation of a local client agent, and the ability to integrate with the data loss prevention (DLP) solutions.&lt;/P&gt;&lt;P&gt;b) Data rights management, the use of rule based access control, the installation of a local client agent, and the ability to integrate with data loss prevention (DLP) solutions&lt;/P&gt;&lt;P&gt;c) role-based access control, the installation of a local client agent, and problems with interoperability with solutions such as data loss prevention (DLP) solutions.&lt;/P&gt;&lt;P&gt;d) Role-based access control, the installation of a local client agent, and the ability to integrate with data loss prevention (DLP) solutions.&lt;/P&gt;&lt;P&gt;I answered "d" because they said they were looking for attributes. The only difference between "d" and the right answer "a" is it mentions data rights management, which is a technology not an attribute.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;65. A risk assessment is based on the following, in order:&lt;/P&gt;&lt;P&gt;a) vulnerability, threat, probability, impact, existing controls, and risk determination.&lt;/P&gt;&lt;P&gt;b) vulnerability, threat, impact, probability, and risk de3termination&lt;/P&gt;&lt;P&gt;c) threat, vulnerability, existing controls, probability, impact and risk determination&lt;/P&gt;&lt;P&gt;d) threat, vulnerability, probability, impact, and risk determination&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I answer b, which matches my instructor's drawing in class. The correct answer is D.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My class notes and the photo of the instructor's drawing clearly says:&lt;/P&gt;&lt;P&gt;Identify assets&lt;/P&gt;&lt;P&gt;Identify vulnerabilities&lt;/P&gt;&lt;P&gt;Identify threats&lt;/P&gt;&lt;P&gt;Identify exposure factor (impact)&lt;/P&gt;&lt;P&gt;Identify Likelihood (probability)&lt;/P&gt;&lt;P&gt;Perform qualitative risk analysis&lt;/P&gt;&lt;P&gt;perform quantitative risk analysis. which means that my selected answer was correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HOWEVER ... between when I wrote that and now, I found this in the Student Guide:&lt;/P&gt;&lt;P&gt;Risk Management Process&lt;/P&gt;&lt;P&gt;An organization will conduct a risk assessment (the term risk analysis is sometimes intercahgned with risk assessment) to evaluate:&lt;/P&gt;&lt;P&gt;- threats to its assets&lt;/P&gt;&lt;P&gt;- vulnerabilities present in the envrionmnet&lt;/P&gt;&lt;P&gt;- the likelihood that a threat will be realized ...&lt;/P&gt;&lt;P&gt;- the impact that the exposure being realized will have on the organization&lt;/P&gt;&lt;P&gt;- Countermeasures available ...&lt;/P&gt;&lt;P&gt;- the residual risk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So that matches the right answer, D. So I guess that one is now answered. Go with the official ISC2 guidebook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;135: Generally, there are two types of cooling, and the return air temperature is based on:&lt;/P&gt;&lt;P&gt;a) latent cooling (remove moisture) and sensible cooling (remove heat), and the temperature is measured at the inlet point.&lt;/P&gt;&lt;P&gt;b) latent cooling (remove moisture) and sensible cooling (remove heat), and the temperature is measured at the server exhaust point&lt;/P&gt;&lt;P&gt;c) latent cooling (remove heat), and sensible cooling (remove moisture), and the temperature is measured at the inlet point.&lt;/P&gt;&lt;P&gt;d) latent cooling (remove heat) and sensible cooling (remove moisture), and the temperature is measured at the server exhaust point.&lt;/P&gt;&lt;P&gt;Well that's just wrong. The air temperature is measured as it exits the room, not as it enters the room. My selected answer was: Latent cooling (remove moisture) and sensible cooling (remove heat),and the temperature is measured at the exhaust point.&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your help!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 00:22:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23506#M1832</guid>
      <dc:creator>altoflyer</dc:creator>
      <dc:date>2019-06-11T00:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23509#M1833</link>
      <description>&lt;P&gt;And here is another one that I don't understand:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cloud environment can be separated into three layers, which are referred to as the:&lt;/P&gt;&lt;P&gt;a) compute layer, the management plane, and the infrastructure layer&lt;/P&gt;&lt;P&gt;b) application layer, the management plane, and the infrastructure layer&lt;/P&gt;&lt;P&gt;c) application layer, the control plane, and the infrastructure layer&lt;/P&gt;&lt;P&gt;d) service layer, the platform layer, and the infrastructure layer.&lt;/P&gt;&lt;P&gt;My answer was d, the right answer was a.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now this confuses the heck out of me because of a few things. First, a layer is an architectural component and a plane is traffic. (or so I've been told). So the only suitable answer was d. But even if you let that go ... second, they mix up plane and layer in answers a, b, and c. That seems inconsistent. Third, what i'd personally say was the right answer would be&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application (or compute) layer | Control Layer | Infrastructure Layer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The management plane runs on the control layer, sometimes also called the management layer. The control plane runs on the infrastructure layer and makes the connection to the control layer. The data plane (also called the forwarding plane, also called the data forwarding plane) runs on the infrastructure layer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So by what I know, none of the answers is correct. But even if you try to figure out which one is least wrong, and you accept that management plane is the central layer (since it does run there after all), then a and b are identical because application layer and compute layer are the same. And, given that my class drawing says "application layer," i would have chosen b. Which is wrong. Anyway, here's a screen shot of the information I've been referencing. &lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-06-10 at 8.37.50 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/3262i4F04EEEAA9709D2D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-06-10 at 8.37.50 PM.png" alt="Screen Shot 2019-06-10 at 8.37.50 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 00:40:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23509#M1833</guid>
      <dc:creator>altoflyer</dc:creator>
      <dc:date>2019-06-11T00:40:29Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23511#M1834</link>
      <description>For your query on Cloud Computing&lt;BR /&gt;Always remember this,&lt;BR /&gt;- Cloud Applications (SAAS)&lt;BR /&gt;- Cloud Software Environment (PAAS)&lt;BR /&gt;- Cloud Software Infrastructure&lt;BR /&gt;— Computation Resources (IAAS)&lt;BR /&gt;— Storage (DAAS)&lt;BR /&gt;— Communications (CAAS)&lt;BR /&gt;- Then comes Software Kernel which sits on&lt;BR /&gt;- Firmware /Hardware&lt;BR /&gt;&lt;BR /&gt;Now, looking at above, just try answering&lt;BR /&gt;1.the definition of Platform?&lt;BR /&gt;2. Is Infrastructure part of Platform? If not then why ?&lt;BR /&gt;3. Now relate this &amp;gt;&amp;gt; Computational Resources ( Processing, Memory ,etc ) sits on Infrastructure components and it’s controlled by administration or management&lt;BR /&gt;&lt;BR /&gt;Their answer is right definitely because a Platform is whole set of everything including Infrastructure and compute layers while management is being referred as a plane.&lt;BR /&gt;&lt;BR /&gt;Hope this clarifies&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Jun 2019 02:02:09 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23511#M1834</guid>
      <dc:creator>TheWhiteKnight</dc:creator>
      <dc:date>2019-06-11T02:02:09Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23514#M1835</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/588595801"&gt;@altoflyer&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Thanks, I got the practice test from Training Camp. Training camp was offered to me by my employer, so I didn't inquire about their references. (or did you mean what materials did they reference?) The material we used was the official ISC2 publication "Certified Cloud Security Professional Official (ISC)2 Student Guide." IMHO, this guide is very poorly written. But that's the subject for another thread.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;17. Cloud computing is based on which approach to service delivery:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a) virtualization&lt;/P&gt;&lt;P&gt;b) thin client technology&lt;/P&gt;&lt;P&gt;c) Virtualization or thin client technology&lt;/P&gt;&lt;P&gt;d) Tightly coupled architectural models&lt;/P&gt;&lt;P&gt;I answered "a," but the correct answer was "c." Really?Just the fact that they have "or" in the answer made it not seem correct. That combined with not having heard about thin clients since the early days of the internet made that answer seem wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;So my take on this one:&amp;nbsp; Not sure who wrote this question but I agree it is poorly written and in some ways what I would call a trick question.&amp;nbsp; I am not a CCSP but I do not think you should find any questions on the exam like this one.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/588595801"&gt;@altoflyer&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;65. A risk assessment is based on the following, in order:&lt;/P&gt;&lt;P&gt;a) vulnerability, threat, probability, impact, existing controls, and risk determination.&lt;/P&gt;&lt;P&gt;b) vulnerability, threat, impact, probability, and risk de3termination&lt;/P&gt;&lt;P&gt;c) threat, vulnerability, existing controls, probability, impact and risk determination&lt;/P&gt;&lt;P&gt;d) threat, vulnerability, probability, impact, and risk determination&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I answer b, which matches my instructor's drawing in class. The correct answer is D.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My class notes and the photo of the instructor's drawing clearly says:&lt;/P&gt;&lt;P&gt;Identify assets&lt;/P&gt;&lt;P&gt;Identify vulnerabilities&lt;/P&gt;&lt;P&gt;Identify threats&lt;/P&gt;&lt;P&gt;Identify exposure factor (impact)&lt;/P&gt;&lt;P&gt;Identify Likelihood (probability)&lt;/P&gt;&lt;P&gt;Perform qualitative risk analysis&lt;/P&gt;&lt;P&gt;perform quantitative risk analysis. which means that my selected answer was correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HOWEVER ... between when I wrote that and now, I found this in the Student Guide:&lt;/P&gt;&lt;P&gt;Risk Management Process&lt;/P&gt;&lt;P&gt;An organization will conduct a risk assessment (the term risk analysis is sometimes intercahgned with risk assessment) to evaluate:&lt;/P&gt;&lt;P&gt;- threats to its assets&lt;/P&gt;&lt;P&gt;- vulnerabilities present in the envrionmnet&lt;/P&gt;&lt;P&gt;- the likelihood that a threat will be realized ...&lt;/P&gt;&lt;P&gt;- the impact that the exposure being realized will have on the organization&lt;/P&gt;&lt;P&gt;- Countermeasures available ...&lt;/P&gt;&lt;P&gt;- the residual risk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So that matches the right answer, D. So I guess that one is now answered. Go with the official ISC2 guidebook.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;So I would have gone with D.&amp;nbsp; Rationale:&amp;nbsp; Patch Tuesday example:&amp;nbsp; a threat is announced, you check to see if you are vulnerable (does it exist in your environment), then evaluate the likely hood (impact), and then determine what to do.&amp;nbsp; The problem is that several of these steps happen at the same time.&amp;nbsp; I am not a fan of questions that are lists that require memory work......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/588595801"&gt;@altoflyer&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;135: Generally, there are two types of cooling, and the return air temperature is based on:&lt;/P&gt;&lt;P&gt;a) latent cooling (remove moisture) and sensible cooling (remove heat), and the temperature is measured at the inlet point.&lt;/P&gt;&lt;P&gt;b) latent cooling (remove moisture) and sensible cooling (remove heat), and the temperature is measured at the server exhaust point&lt;/P&gt;&lt;P&gt;c) latent cooling (remove heat), and sensible cooling (remove moisture), and the temperature is measured at the inlet point.&lt;/P&gt;&lt;P&gt;d) latent cooling (remove heat) and sensible cooling (remove moisture), and the temperature is measured at the server exhaust point.&lt;/P&gt;&lt;P&gt;Well that's just wrong. The air temperature is measured as it exits the room, not as it enters the room. My selected answer was: Latent cooling (remove moisture) and sensible cooling (remove heat),and the temperature is measured at the exhaust point.&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I know nothing about heating but as a casual user, I would rule out A and C and look to B or D as being the answer.&amp;nbsp; I would probably go with B.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Others?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 15:56:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23514#M1835</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2019-06-11T15:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23518#M1836</link>
      <description>&lt;P&gt;For 17, if you consider IaaS, PaaS and SaaS than c) is probably more correct answer.&amp;nbsp; Virtualisation is an enabler for cloud services, but thin client i.e. standard web browser, provides the universal access that make it usable.&amp;nbsp; If you look at the NIST definition in SP800-145 that should explain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;32 seems to be a poorly worded question and set of answers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For 65 if you look up 27005 or look at the links below, by convention you start with the threat source, then the threat actor who targets a vulnerability in an asset .....&lt;/P&gt;&lt;P&gt;&lt;A href="https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf" target="_blank"&gt;https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/IT_risk_management#/media/File:2010-T10-ArchitectureDiagram.png" target="_blank"&gt;https://en.wikipedia.org/wiki/IT_risk_management#/media/File:2010-T10-ArchitectureDiagram.png&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You've got all the right elements.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 10:08:12 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23518#M1836</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-06-11T10:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23535#M1837</link>
      <description>&amp;gt; altoflyer (Viewer) posted a new reply in Certifications on 06-10-2019 08:22 PM&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I got the practice test from Training Camp.&lt;BR /&gt;&lt;BR /&gt;I taught for Training Camp several times, and I often had trouble justifying the&lt;BR /&gt;"correct" answers on *their* practice exams from *their* material ... (Training&lt;BR /&gt;Camp *used* to have some agreement to use ISC2 facilitators and material, along&lt;BR /&gt;with their own stuff, but I don't know what the current situation is ...)&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;The sun, with all those planets revolving around it and&lt;BR /&gt;dependent upon it, can still ripen a bunch of grapes as if it had&lt;BR /&gt;nothing else in the universe to do. - Galileo Galilei&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Tue, 11 Jun 2019 15:54:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23535#M1837</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-06-11T15:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23575#M1838</link>
      <description>&lt;P&gt;I think it helps to stick to the official CBK materials rather than use secondary sources.&amp;nbsp;&amp;nbsp;The applies to the CISSP and CISSP concentrations (follow the references at the end of the chapters).&amp;nbsp;&amp;nbsp;Depending on reworked secondary sources, both in academia and in professional life is unlikely to be a useful shortcut.&amp;nbsp; So if you need to read the SP800 series, IETF RFCs, CoBIT ISO 27000 series or whatever, go read the original.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 07:08:05 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23575#M1838</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-06-12T07:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23595#M1839</link>
      <description>Yes, that does make sense. Thanks! I passed my test yesterday. Yay!</description>
      <pubDate>Wed, 12 Jun 2019 16:15:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23595#M1839</guid>
      <dc:creator>altoflyer</dc:creator>
      <dc:date>2019-06-12T16:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23596#M1840</link>
      <description>Thanks for your time to look at and think about these questions I had. I do understand and agree with the process for risk management. I'm just irritated that what we were taught is not what was in the ISC2 materials. These questions are binary: they are right or wrong. So we need to learn it the way it will be asked on the test.&lt;BR /&gt;&lt;BR /&gt;But hey, I passed my test! So, yay. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Wed, 12 Jun 2019 16:18:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23596#M1840</guid>
      <dc:creator>altoflyer</dc:creator>
      <dc:date>2019-06-12T16:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23597#M1841</link>
      <description>I completely agree. Unfortunately I had assumed that the class material was aligned with ISC2 material and had learned that. The book was very difficult to read since it was way too wordy and repetitive. They could use a very good copy editor. Think of Hemingway's sparse prose style, or of Edith Wharton going through her manuscripts and deleting the adjectives.&lt;BR /&gt;&lt;BR /&gt;Thank you for your time to look at my questions and provide your thoughts; I really appreciate it.&lt;BR /&gt;&lt;BR /&gt;And hey, I passed the test!!! YAY!</description>
      <pubDate>Wed, 12 Jun 2019 16:22:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23597#M1841</guid>
      <dc:creator>altoflyer</dc:creator>
      <dc:date>2019-06-12T16:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23619#M1842</link>
      <description>&lt;P&gt;Congratulations and welcome to the CCSP club!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I agree with what the others are saying in that these questions in the original post are badly written.&amp;nbsp;For anyone else looking at CCSP practice tests, I'd highly recommend the CCSP Official (ISC)2 Practice Tests:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.isc2.org/Training/Self-Study-Resources#accordion-64c669e893ce4e1ea9eb5ea78312cfec" target="_blank"&gt;https://www.isc2.org/Training/Self-Study-Resources#accordion-64c669e893ce4e1ea9eb5ea78312cfec&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These were written by&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/197341075"&gt;@Ben_Malisow&lt;/a&gt;&amp;nbsp;who is an active member on here and responds to queries you might have about the book or specific questions in the book in this thread:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.isc2.org/t5/Certifications/CCSP-Practice-Questions/m-p/5891#M1029" target="_blank"&gt;https://community.isc2.org/t5/Certifications/CCSP-Practice-Questions/m-p/5891#M1029&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 10:59:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23619#M1842</guid>
      <dc:creator>AlecTrevelyan</dc:creator>
      <dc:date>2019-06-13T10:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23622#M1843</link>
      <description>&lt;P&gt;Thanks for the kind words, Alec! Yes, I'd be glad to offer any insight to issues that you might have with any of the questions from the book.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 11:51:51 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23622#M1843</guid>
      <dc:creator>Ben_Malisow</dc:creator>
      <dc:date>2019-06-13T11:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Checking some answers to a practice test</title>
      <link>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23688#M1844</link>
      <description>&lt;P&gt;I'm afraid that's the trick to passing these tests, like all recall based testing.&amp;nbsp; Personally I think it'd be far more valuable if the tests were applied to more typical real world scenarios, rather than being a case of selecting the best or least worst answers, but that'd require a lot of human judgement in assessing, so I can't see it happening.&amp;nbsp; There are other InfoSec professional bodies you can join that do require written exams and face to face interview in which you are grilled about your experience.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 12:06:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Exam-Preparation/Checking-some-answers-to-a-practice-test/m-p/23688#M1844</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-06-14T12:06:10Z</dc:date>
    </item>
  </channel>
</rss>

