exam questions

Exam PT0-002 All Questions

View all questions & answers for the PT0-002 exam

Exam PT0-002 topic 1 question 7 discussion

Actual exam question from CompTIA's PT0-002
Question #: 7
Topic #: 1
[All PT0-002 Questions]

A company obtained permission for a vulnerability scan from its cloud service provider and now wants to test the security of its hosted data.
Which of the following should the tester verify FIRST to assess this risk?

  • A. Whether sensitive client data is publicly accessible
  • B. Whether the connection between the cloud and the client is secure
  • C. Whether the client's employees are trained properly to use the platform
  • D. Whether the cloud applications were developed using a secure SDLC
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
RRabbit_111
Highly Voted 2 years, 3 months ago
Selected Answer: A
A. Whether sensitive client data is publicly accessible When assessing the security of hosted data in a cloud environment, the first thing that should be verified is whether sensitive client data is publicly accessible. This includes checking for any misconfigurations or vulnerabilities that could allow an unauthorized person to access the data. This could be accomplished by performing web application scans, network scans, and manual testing to check for any vulnerabilities that could allow for data exfiltration or unauthorized access. It's also important to check whether the connection between the cloud and the client is secure, whether the client's employees are trained properly to use the platform, and whether the cloud applications were developed using a secure SDLC, but verifying whether sensitive client data is publicly accessible should be the primary focus.
upvoted 10 times
...
petercorn
Highly Voted 2 years, 6 months ago
Selected Answer: A
Answer is A as question is asking 'data'
upvoted 5 times
...
DoomChicken
Most Recent 3 months, 2 weeks ago
Selected Answer: A
A would be your first step to see if there is any security at all on the hosted data itself. The connection to the cloud is less relevant as the question asks specifically about the hosted data itself.
upvoted 2 times
...
Etc_Shadow28000
10 months ago
Selected Answer: A
The tester should verify FIRST: A. Whether sensitive client data is publicly accessible Ensuring that sensitive client data is not publicly accessible is the most immediate and critical check. If such data is exposed, it represents a significant risk to the company and its clients. This verification will help identify any obvious and severe vulnerabilities that could be exploited by attackers.
upvoted 2 times
...
j904
1 year ago
Selected Answer: B
B. makes the most sense in a cloud scenario
upvoted 1 times
...
surfuganda
1 year, 1 month ago
Selected Answer: B
Too much groupthink in these forums. Do some research, and use some tools. Get practical experience, and stop copy/pasting ChatGPT (It's just not that reliable). MY OPINION (sure, I could be wrong): The COMPANY is going to scan the CSP. The FIRST thing to do is [B]. Because if the COMPANY's connection is unsecured and intercepted, the intercepting party may have live access to the vulnerability results, and can attack before the scan is complete or before vulnerability mitigations are implemented (because mitigations can take time to implement). NOT DOING SO: creates a situation where the COMPANY introduces greater risk. After [B] is implemented, the vulnerability scan may inform whether [A] is a concern.
upvoted 3 times
...
J0hnn13
1 year, 5 months ago
Selected Answer: B
Ensuring the security of the connection between the client and the cloud is a fundamental aspect of cloud security. This includes assessing the encryption protocols, data in transit protection, and the overall security of the network connection.
upvoted 3 times
...
[Removed]
1 year, 5 months ago
Selected Answer: B
When assessing the security of hosted data in a cloud environment, one of the first things to verify is the security of the connection between the cloud and the client. Therefore, the correct answer is: B. Whether the connection between the cloud and the client is secure
upvoted 3 times
...
Mr_BuCk3th34D
2 years, 4 months ago
B should be the first thing you do when assessing a cloud environment. Before anything else, you need to make sure that the connection between you (as a customer) and the cloud (as the provider), is secure, if not, there's no guarantee of the confidentiality and integrity of the information later, you can already assume that data might be exposed, eliminating alternative A as the answer.
upvoted 2 times
...
bieecop
2 years, 5 months ago
Selected Answer: A
A That's correct.
upvoted 4 times
...
ma3ks
2 years, 5 months ago
Selected Answer: A
should be a
upvoted 4 times
...
lordguck
2 years, 5 months ago
A: as not all cloud services require a client (B)
upvoted 3 times
...
dcyberguy
2 years, 6 months ago
Selected Answer: A
I’ll go with A, since the company is conducting “Security in the Cloud”. Whether it’s data is publicly exposed is paramount
upvoted 4 times
...
Neolot
2 years, 6 months ago
Selected Answer: B
i think B is the correct answer.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago