[Feb 05, 2022] Passing Key To Getting CCAK Certified Exam Engine PDF [Q38-Q58]

Share

[Feb 05, 2022] Passing Key To Getting CCAK Certified Exam Engine PDF

CCAK Exam Dumps Pass with Updated Feb-2022 Tests Dumps


ISACA CCAK Exam Syllabus Topics:

TopicDetails
Topic 1
  • Evaluating a Cloud Compliance Program
  • Cloud Auditing
Topic 2
  • CCM and CAIQ: Goals, Objectives, and Structure
  • CCM: Auditing Controls
Topic 3
  • Continuous Assurance and Compliance
  • Cloud Compliance Program
Topic 4
  • A Threat Analysis Methodology for Cloud Using CCM
  • Cloud Governance

 

NEW QUESTION 38
Which statement best describes the impact of Cloud Computing on business continuity management?

  • A. Clients need to do business continuity planning due diligence in case they suddenly need to switch providers.
  • B. Customers of SaaS providers in particular need to mitigate the risks of application lock-in.
  • C. A general lack of interoperability standards means that extra focus must be placed on the security aspects of migration between Cloud providers.
  • D. Geographic redundancyensures that Cloud Providers provide highly available services.
  • E. The size of data sets hosted at a Cloud provider can present challenges if migration to another provider becomesnecessary.

Answer: D

 

NEW QUESTION 39
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?

  • A. Negotiate long-term contracts with companies who use well-vetted software application to avoid the transient nature of the cloud environment.
  • B. Respect the interdependency of the risks inherent in the cloud supply chain and communicate the corporate riskposture and readiness to consumers and dependent parties.
  • C. Inspect and account for risksinherited from other members of the cloud supply chain and take active measures to mitigate and contain risks through operational resiliency.
  • D. Provide transparency to stakeholders and shareholders demonstrating fiscal solvency and organizational transparency.
  • E. Both B and C.

Answer: A

 

NEW QUESTION 40
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?

  • A. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
  • B. More physical control over assets and processes.
  • C. None of the above.
  • D. Decreased requirement for proactive management of relationship and adherence to contracts.
  • E. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.

Answer: E

 

NEW QUESTION 41
ENISA: Lock-in is ranked as a high risk in ENISA research, a key underlying vulnerability causing lock in is:

  • A. Audit or certification not available to customers
  • B. No source escrow agreement
  • C. Unclear asset ownership
  • D. Lack of completeness and transparency in terms of use
  • E. Lack of information onjurisdictions

Answer: D

 

NEW QUESTION 42
Which of the following CSP activities requires a client's approval?

  • A. Delete the guest account or test accounts
  • B. Delete the test accounts or destroy test data
  • C. Delete the master account or subscription owner accounts
  • D. Delete the guest account or destroy test data

Answer: B

 

NEW QUESTION 43
In volume storage, what method is often used to support resiliency and security?

  • A. data rights management
  • B. random placement
  • C. hypervisor agents
  • D. data dispersion
  • E. proxy encryption

Answer: D

 

NEW QUESTION 44
Which of the following should be an IS auditor's GREATEST concern when reviewing an outsourcing arrangement with a third-party cloud service provider to host personally identifiable data?

  • A. The organization's servers are not compatible with the third party's infrastructure
  • B. The outsourcing contract does not contain a right-to-audit clause.
  • C. The data is not adequately segregated on the host platform.
  • D. Fees are charged based on the volume of data stored by the host.

Answer: C

 

NEW QUESTION 45
CCM: In the CCM tool, ais a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.

  • A. Risk Impact
  • B. Domain
  • C. Control Specification

Answer: C

 

NEW QUESTION 46
To assist an organization with planning a cloud migration strategy to execution, an auditor should recommend the use of:

  • A. object-oriented architecture.
  • B. software architecture.
  • C. service-oriented architecture.
  • D. enterprise architecture.

Answer: C

 

NEW QUESTION 47
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?

  • A. Control Specification
  • B. Domain
  • C. Risk Impact

Answer: B

 

NEW QUESTION 48
From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps concept?

  • A. Development standards for addressing integration, testing, and deployment issues
  • B. Operational framework that promotes software consistency through automation
  • C. Making software development simpler, faster, and easier using automation
  • D. Process of security integration using automation in software development

Answer: A

 

NEW QUESTION 49
Organizations maintain mappings between the different control frameworks they adopt to:

  • A. help identify controls with common assessment status.
  • B. start a compliance assessment using latest assessment.
  • C. help identify controls with different assessment status.
  • D. avoid duplication of work when assessing compliance.

Answer: C

 

NEW QUESTION 50
When deploying Security as a Service in a highly regulated industry or environment, what should bothparties agree on in advance and include in the SLA?

  • A. The type of security software which meets regulations and the number of licenses that will be needed.
  • B. The cost per incident for security breaches of regulated information.
  • C. The duration of time that a security violation can occur before the client begins assessing regulatory fines.
  • D. The metrics defining the service level required to achieve regulatory objectives.
  • E. The regulations that are pertinent to the contract and how to circumvent them.

Answer: D

 

NEW QUESTION 51
A third-party service provider is hosting a private cloud for an organization. Which of the following findings during an audit of the provider poses the GREATEST risk to the organization?

  • A. 2% of backups had to be rescheduled due to backup media failures.
  • B. The organization's virtual machines share the same hypervisor with virtual machines of other clients.
  • C. 5% of detected incidents exceeded the defined service level agreement (SLA) for escalation.
  • D. Two different hypervisor versions are used due to the compatibility restrictions of some virtual machines.

Answer: B

 

NEW QUESTION 52
Which of the following would be the GREATEST governance challenge to an organization where production is hosted in a public cloud and backups are held on the premises?

  • A. Aligning shared responsibilities between provider and customer
  • B. Aligning the cloud provider's SLA with the organization's policy
  • C. Aligning the organization's activity with the cloud provider's policy
  • D. Aligning the cloud service delivery with the organization's objective

Answer: D

 

NEW QUESTION 53
When performing audits in relation to Business Continuity Management and Operational Resilience strategy, what would be the MOST critical aspect to audit in relation to the strategy of the cloud customer that should be formulated jointly with the cloud service provider?

  • A. Validate if the strategy covers unavailability of all components required to operate the business-as-usual or in disrupted mode, in parts or total- when impacted by a disruption.
  • B. Validate if the strategy covers all activities required to continue and recover prioritized activities within identified time frames and agreed capacity, aligned to the risk appetite of the organization including the invocation of continuity plans and crisis management capabilities.
  • C. Validate if the strategy covers all aspects of Business Continuity and Resilience planning, taking inputs from the assessed impact and risks, to consider activities for before, during, and after a disruption.
  • D. Validate if the strategy is developed by both cloud service providers and cloud service consumers within the acceptable limits of their risk appetite.

Answer: C

 

NEW QUESTION 54
While performing the audit, the auditor found that an object storage bucket containing PII could be accessed by anyone on the Internet. Given this discovery, what should be the most appropriate action for the auditor to perform?

  • A. Highlighting the gap to the audit sponsor at the sponsor's earliest possible availability
  • B. Informing the organization's internal audit manager immediately about the gap
  • C. Asking the organization's cloud administrator to immediately close the gap by updating the configuration settings and making the object storage bucket private and hence inaccessible from the Internet
  • D. Documenting the finding in the audit report and sharing the gap with the relevant stakeholders

Answer: D

 

NEW QUESTION 55
Which communication methods within a cloud environment must be exposed for partners or consumers to access database information using a web application?

  • A. Extensible Markup Language (XML)
  • B. Resource Description Framework (RDF)
  • C. Software Development Kits (SDKs)
  • D. Application Programming Interface (API)
  • E. Application Binary Interface (ABI)

Answer: D

 

NEW QUESTION 56
APIs and web services require extensive hardening and must assume attacks from authenticated and unauthenticated adversaries.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 57
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 58
......

CCAK exam questions for practice in 2022 Updated 78 Questions: https://www.pass4surequiz.com/CCAK-exam-quiz.html

Updated Premium CCAK Exam Engine pdf: https://drive.google.com/open?id=1juIhrt_DKuIPjx7hsvmN-TkyV4vbF0Yg