Isaca CCAK Practice Test - Questions Answers, Page 12
List of questions
Question 111
What is the advantage of using dynamic application security testing (DAST) over static application security testing (SAST) methodology?
Question 112
Which of the following is a cloud-specific security standard?
Question 113
Cloud Control Matrix (CCM) controls can be used by cloud customers to:
Question 114
Account design in the cloud should be driven by:
Question 115
In the context of Infrastructure as a Service (IaaS), a vulnerability assessment will scan virtual machines to identify vulnerabilities in:
Question 116
When using a SaaS solution, who is responsible for application security?
Question 117
The PRIMARY objective for an auditor to understand the organization's context for a cloud audit is to:
Question 118
A cloud service provider does not allow audits using automated tools as these tools could be considered destructive techniques for the cloud environment. Which of the following aspects of the audit will be constrained?
Question 119
When establishing cloud governance, an organization should FIRST test by migrating:
Question 120
When building a cloud governance model, which of the following requirements will focus more on the cloud service provider's evaluation and control checklist?
Question