Latest CCAK Actual Free Exam Questions Updated 78 Questions [Q38-Q59]

Share

Latest CCAK Actual Free Exam Questions Updated 78 Questions

Free CCAK Exam Braindumps certification guide Q&A

NEW QUESTION 38
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:

  • A. Infrastructure as a Service (laaS).
  • B. Platform as a Service (PaaS).
  • C. Identity as a Service (IDaaS).
  • D. Software as a Service (SaaS).

Answer: B

 

NEW QUESTION 39
A client/server configuration will:

  • A. enhance system performance through the separation of front-end and back-end processes.
  • B. limit the clients and servers relationship by limiting the IS facilities to a single hardware system.
  • C. optimize system performance by having a server on a front-end and clients on a host.
  • D. keep track of all the clients using the IS facilities of a service organization.

Answer: A

 

NEW QUESTION 40
An important consideration when performing a remote vulnerability test of a cloud-based application is to

  • A. Use techniques to evade cloud provider's detection systems
  • B. Schedule vulnerability test at night
  • C. Obtain provider permission for test
  • D. Use network layer testing tools exclusively
  • E. Use application layer testing tools exclusively

Answer: C

 

NEW QUESTION 41
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework

  • A. Governance and Retention Management
  • B. Governance and Risk Management
  • C. Governing and Risk Metrics

Answer: B

 

NEW QUESTION 42
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?

  • A. Resiliency Planning
  • B. Expected Engineering
  • C. Organized Downtime
  • D. Chaos Engineering
  • E. PlannedOutages

Answer: D

 

NEW QUESTION 43
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?

  • A. Domain
  • B. Risk Impact
  • C. Control Specification

Answer: A

 

NEW QUESTION 44
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?

  • A. Inspect and account for risksinherited from other members of the cloud supply chain and take active measures to mitigate and contain risks through operational resiliency.
  • B. Negotiate long-term contracts with companies who use well-vetted software application to avoid the transient nature of the cloud environment.
  • C. Provide transparency to stakeholders and shareholders demonstrating fiscal solvency and organizational transparency.
  • D. Respect the interdependency of the risks inherent in the cloud supply chain and communicate the corporate riskposture and readiness to consumers and dependent parties.
  • E. Both B and C.

Answer: B

 

NEW QUESTION 45
Which communication methods within a cloud environment must be exposed for partners or consumers to access database information using a web application?

  • A. Resource Description Framework (RDF)
  • B. Software Development Kits (SDKs)
  • C. Application Binary Interface (ABI)
  • D. Application Programming Interface (API)
  • E. Extensible Markup Language (XML)

Answer: D

 

NEW QUESTION 46
An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?

  • A. verifying the weighting of each selection criteria
  • B. Witnessing the vendor selection process
  • C. Approving the vendor selection methodology
  • D. Reviewing the request for proposal (RFP)

Answer: C

 

NEW QUESTION 47
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?

  • A. Applistructure
  • B. Infostructure
  • C. Metastructure
  • D. Infrastructure
  • E. Datastructure

Answer: D

 

NEW QUESTION 48
To understand their compliance alignments and gaps with a cloud provider, what must cloud customers rely on?

  • A. Provider run audits and reports
  • B. Provider and consumer contracts
  • C. Third-party attestations
  • D. EDiscovery tools
  • E. Provider documentation

Answer: C

 

NEW QUESTION 49
Your SLA with your cloudprovider ensures continuity for all services.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 50
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what?

  • A. An entitlement matrix
  • B. A support table
  • C. An entrylog
  • D. An access log
  • E. A validation process

Answer: E

 

NEW QUESTION 51
Who is responsible for the security of the physical infrastructure and virtualization platform?

  • A. Itdepends on the agreement
  • B. The responsibility is split equally
  • C. The majority is covered by the consumer
  • D. The cloud consumer
  • E. The cloud provider

Answer: E

 

NEW QUESTION 52
What factors should you understand about the data specifically due to legal, regulatory, and jurisdictional factors?

  • A. The actualsize of the data and the storage format
  • B. The language of the data and how it affects the user
  • C. The fragmentation and encryption algorithms employed
  • D. The implications of storing complex information on simple storage systems
  • E. Thephysical location of the data and how it is accessed

Answer: D

 

NEW QUESTION 53
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?

  • A. Infrastructure-as-a-service (IaaS)
  • B. Identity-as-a-service (IDaaS)
  • C. Software-as-a-service (SaaS)
  • D. Platform-as-a-service (PaaS)
  • E. Desktop-as-a-service (DaaS)

Answer: D

 

NEW QUESTION 54
Which of the following would be MOST important to update once a decision has been made to outsource a critical application to a cloud service provider?

  • A. Project portfolio
  • B. IT resource plan
  • C. Business impact analysis (BIA)
  • D. IT budget

Answer: C

 

NEW QUESTION 55
An internal audit department recently established a quality assurance (QA) program as part of its overall audit program. Which of the following activities is MOST important to include as part of the QA program requirements?

  • A. Reporting OA program results to the audit committee
  • B. Analyzing user satisfaction reports from business lines
  • C. Benchmarking the QA framework to international standards
  • D. Conducting long-term planning for internal audit staffing

Answer: B

 

NEW QUESTION 56
CCM: In the CCM tool, ais a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.

  • A. Control Specification
  • B. Risk Impact
  • C. Domain

Answer: A

 

NEW QUESTION 57
How does running applications on distinct virtual networks and only connecting networksas needed help?

  • A. It reduces hardware costs
  • B. It provides dynamic and granular policies with less management overhead
  • C. It enables you to configure applications around business groups
  • D. It reduces the blast radius of a compromised system
  • E. It locks down access and provides stronger data security

Answer: D

 

NEW QUESTION 58
Which of the following should be the PRIMARY concern of an IS auditor during a review of an external IT service level agreement (SLA) for computer operations?

  • A. Lack of software escrow provisions
  • B. Changes in services are not tracked
  • C. Vendor has exclusive control of IT resources
  • D. No employee succession plan

Answer: B

 

NEW QUESTION 59
......

CCAK Certification Overview Latest CCAK PDF Dumps: https://www.pass4surequiz.com/CCAK-exam-quiz.html

Top ISACA CCAK Exam Audio Study Guide! Practice Questions Edition: https://drive.google.com/open?id=1xbHnqb76QZ_wOVt0yHxPfBaDRNfiUAoT