Isaca CCAK Practice Test - Questions Answers, Page 12

List of questions
Question 111

What is the advantage of using dynamic application security testing (DAST) over static application security testing (SAST) methodology?
Question 112

Which of the following is a cloud-specific security standard?
Question 113

Cloud Control Matrix (CCM) controls can be used by cloud customers to:
Question 114

Account design in the cloud should be driven by:
Question 115

In the context of Infrastructure as a Service (IaaS), a vulnerability assessment will scan virtual machines to identify vulnerabilities in:
Question 116

When using a SaaS solution, who is responsible for application security?
Question 117

The PRIMARY objective for an auditor to understand the organization's context for a cloud audit is to:
Question 118

A cloud service provider does not allow audits using automated tools as these tools could be considered destructive techniques for the cloud environment. Which of the following aspects of the audit will be constrained?
Question 119

When establishing cloud governance, an organization should FIRST test by migrating:
Question 120

When building a cloud governance model, which of the following requirements will focus more on the cloud service provider's evaluation and control checklist?
Question