
Mar-2023 CCAK Study Material, Preparation Guide and PDF Download
Free CCAK Certification Sample Questions with Online Practice Test
ISACA CCAK Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
NEW QUESTION 20
Which statement best describes why it is important to know how data is being accessed?
- A. The devices used to access data use a variety of applications or clients and may have different security characteristics.
- B. The device may affect data dispersion.
- C. The devices used to access data may have differentownership characteristics.
- D. The devices used to access data use a variety of operating systems and may have different programs installed on them.
- E. The devices used to access data have different storage formats.
Answer: A
NEW QUESTION 21
An independent contractor is assessing security maturity of a SaaS company against industry standards. The SaaS company has developed and hosted all their products using the cloud services provided by a third-party cloud service provider (CSP). What is the optimal and most efficient mechanism to assess the controls CSP is responsible for?
- A. Review third-party audit reports.
- B. Send supplier questionnaire to the CSP.
- C. Review CSP's published questionnaires.
- D. Directly audit the CSP.
Answer: C
NEW QUESTION 22
While performing the audit, the auditor found that an object storage bucket containing PII could be accessed by anyone on the Internet. Given this discovery, what should be the most appropriate action for the auditor to perform?
- A. Informing the organization's internal audit manager immediately about the gap
- B. Asking the organization's cloud administrator to immediately close the gap by updating the configuration settings and making the object storage bucket private and hence inaccessible from the Internet
- C. Highlighting the gap to the audit sponsor at the sponsor's earliest possible availability
- D. Documenting the finding in the audit report and sharing the gap with the relevant stakeholders
Answer: D
NEW QUESTION 23
Which of the following controls framework should the cloud customer use to assess the overall security risk of a cloud provider?
- A. Cloud Control Matrix (CCM)
- B. SOC3 - Type2
- C. SOC1 - Type1
- D. SOC2 - Type1
Answer: D
NEW QUESTION 24
Since CCM allows cloud customers to build a detailed list of requirements and controls to be implemented by the CSP as part of their overall third-party risk management and procurement program, will CCM alone be enough to define all the items to be considered when operating/using cloud services?
- A. Yes. CCM suffices since it maps a huge library of widely accepted frameworks.
- B. No. CCM must be completed with definitions established by the CSP because of its relevance to service continuity.
- C. No. CCM can serve as a foundation for a cloud assessment program, but it needs to be completed with requirements applicable to each company.
- D. Yes. When implemented in the right manner. CCM alone can help to measure, assess and monitor the risk associated with a CSP or a particular service.
Answer: B
NEW QUESTION 25
When deploying Security as a Service in a highly regulated industry or environment, what should bothparties agree on in advance and include in the SLA?
- A. The cost per incident for security breaches of regulated information.
- B. The regulations that are pertinent to the contract and how to circumvent them.
- C. The type of security software which meets regulations and the number of licenses that will be needed.
- D. The duration of time that a security violation can occur before the client begins assessing regulatory fines.
- E. The metrics defining the service level required to achieve regulatory objectives.
Answer: E
NEW QUESTION 26
An audit has identified that business units have purchased cloud-based applications without ITs support. What is the GREATEST risk associated with this situation?
- A. The application purchases did not follow procurement policy.
- B. The applications may not reasonably protect data.
- C. The applications are not included in business continuity plans (BCPs).
- D. The applications could be modified without advanced notice.
Answer: C
NEW QUESTION 27
Which of the following is MOST important to consider when an organization is building a compliance program for the cloud?
- A. The cloud is similar to the on-premise environment in terms of compliance.
- B. The rapidly changing service portfolio and architecture of the cloud.
- C. The fairly static nature of the service portfolio and architecture of the cloud.
- D. Cloud providers should not be part of the compliance program.
Answer: B
NEW QUESTION 28
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
- A. Inspect and account for risksinherited from other members of the cloud supply chain and take active measures to mitigate and contain risks through operational resiliency.
- B. Negotiate long-term contracts with companies who use well-vetted software application to avoid the transient nature of the cloud environment.
- C. Respect the interdependency of the risks inherent in the cloud supply chain and communicate the corporate riskposture and readiness to consumers and dependent parties.
- D. Provide transparency to stakeholders and shareholders demonstrating fiscal solvency and organizational transparency.
- E. Both B and C.
Answer: B
NEW QUESTION 29
A client/server configuration will:
- A. keep track of all the clients using the IS facilities of a service organization.
- B. limit the clients and servers relationship by limiting the IS facilities to a single hardware system.
- C. optimize system performance by having a server on a front-end and clients on a host.
- D. enhance system performance through the separation of front-end and back-end processes.
Answer: D
NEW QUESTION 30
Prioritizing assurance activities for an organization's cloud services portfolio depends PRIMARILY on an organization's ability to:
- A. schedule frequent reviews with high-risk cloud service providers.
- B. collate views from various business functions using cloud services.
- C. develop plans using a standardized risk-based approach.
- D. maintain a comprehensive cloud service inventory.
Answer: A
NEW QUESTION 31
Which data security control is the LEAST likely to be assigned to an IaaSprovider?
- A. Application logic
- B. Asset management and tracking
- C. Physical destruction
- D. Encryption solutions
- E. Access controls
Answer: A
NEW QUESTION 32
Use elastic servers when possible and move workloads to new instances.
- A. True
- B. False
Answer: A
NEW QUESTION 33
SAST testing is performed by:
- A. scanning the application interface.
- B. scanning the application source code.
- C. scanning all infrastructure components.
- D. performing manual actions to gain control of the application.
Answer: B
Explanation:
SAST analyzes application code offline. SAST is generally a rules-based test that will scan software code for items such as credentials embedded into application code and a test of input validation, both of which are major concerns for application security.
NEW QUESTION 34
Which of the following configuration change controls is acceptable to a cloud auditor?
- A. The Head of Development approves changes requested to production.
- B. Programmers cannot make uncontrolled changes to the source code production version.
- C. Development, test and production are hosted in the same network environment.
- D. Programmers have permanent access to production software.
Answer: B
NEW QUESTION 35
Big data includes high volume, high variety, and high velocity.
- A. True
- B. False
Answer: A
NEW QUESTION 36
......
CCAK Certification Study Guide Pass CCAK Fast: https://www.free4torrent.com/CCAK-braindumps-torrent.html
CCAK Dumps PDF 2023 Program Your Preparation EXAM SUCCESS: https://drive.google.com/open?id=1C1TA3QlON5pUhChBz7wGO-I9ZeV75Ev3