Isaca CCAK Practice Test - Questions Answers, Page 13
List of questions
Related questions
Which of the following would be considered as a factor to trust in a cloud service provider?
Which of the following quantitative measures is KEY for an auditor to review when assessing the implementation of continuous auditing of performance on a cloud system?
In cloud computing, with whom does the responsibility and accountability for compliance lie?
A certification target helps in the formation of a continuous certification framework by incorporating:
Which of the following are the three MAIN phases of the cloud controls matrix (CCM) mapping methodology?
Which of the following activities are part of the implementation phase of a cloud assurance program during a cloud migration?
The three layers of Open Certification Framework (OCF) PRIMARILY help cloud service providers and cloud clients improve the level of:
legal and regulatory compliance.
risk and controls.
audit structure and formats.
transparency and assurance.
While using Software as a Service (SaaS) to store secret customer information, an organization identifies a risk of disclosure to unauthorized parties. Although the SaaS service continues to be used, secret customer data is not processed. Which of the following risk treatment methods is being practiced?
Risk acceptance
Risk transfer
Risk mitigation
Risk reduction
A business unit introducing cloud technologies to the organization without the knowledge or approval of the appropriate governance function is an example of:
IT exception
Threat
Shadow IT
Vulnerability
Which industry organization offers both security controls and cloud-relevant benchmarking?
Cloud Security Alliance (CSA)
SANS Institute
International Organization for Standardization (ISO)
Center for Internet Security (CIS)
Question