Isaca CCAK Practice Test - Questions Answers, Page 15
List of questions
Related questions
Which of the following is the PRIMARY area for an auditor to examine in order to understand the criticality of the cloud services in an organization, along with their dependencies and risks?
Contractual documents of the cloud service provider
Heat maps
Data security process flow
Turtle diagram
Which of the following is the BEST method to demonstrate assurance in the cloud services to multiple cloud customers?
Provider's financial stability report and market value
Reputation of the service provider in the industry
Provider self-assessment and technical documents
External attestation and certification audit reports
What is the FIRST thing to define when an organization is moving to the cloud?
Goals of the migration
Internal service level agreements (SLAs)
Specific requirements
Provider evaluation criteria
To BEST prevent a data breach from happening, cryptographic keys should be:
distributed in public-facing repositories.
embedded in source code.
rotated regularly.
transmitted in clear text.
What type of termination occurs at the initiative of one party and without the fault of the other party?
Termination without the fault
Termination at the end of the term
Termination for cause
Termination for convenience
Which of the following types of risk is associated specifically with the use of multi-cloud environments in an organization?
Risk of supply chain visibility and validation
Risk of reduced visibility and control
Risk of service reliability and uptime
Risk of unauthorized access to customer and business data
Which of the following key stakeholders should be identified FIRST when an organization is designing a cloud compliance program?
Cloud strategy owners
Internal control function
Cloud process owners
Legal functions
is it important for the individuals in charge of cloud compliance to understand the organization's past?
To determine the current state of the organization's compliance
To determine the risk profile of the organization
To address any open findings from previous external audits
To verify whether the measures implemented from the lessons learned are effective
Market share and geolocation are aspects PRIMARILY related to:
business perspective.
cloud perspective.
risk perspective.
governance perspective.
organization should document the compliance responsibilities and ownership of accountability in a RACI chart or its informational equivalents in order to:
provide a holistic and seamless view of the cloud service provider's responsibility for compliance with prevailing laws and regulations.
provide a holistic and seamless view of the enterprise's responsibility for compliance with prevailing laws and regulations.
conform to the organization's governance model.
define the cloud compliance requirements and how they interplay with the organization's business strategy, goals, and other compliance requirements.
Question