Isaca CCAK Practice Test - Questions Answers, Page 16
List of questions
Related questions
Which of the following helps an organization to identify control gaps and shortcomings in the context of cloud computing?
Walk-through peer review
Periodic documentation review
User security awareness training
Monitoring effectiveness
What is below the waterline in the context of cloud operationalization?
The controls operated by the customer
The controls operated by both
The controls operated by the cloud access security broker (CASB)
The controls operated by the cloud service provider
Which of the following types of SOC reports BEST helps to ensure operating effectiveness of controls in a cloud service provider offering?
SOC 3 Type 2
SOC 2 Type 2
SOC 1 Type 1
SOC 2 Type 1
Which of the following is MOST important to ensure effective operationalization of cloud security controls?
Identifying business requirements
Comparing different control frameworks
Assessing existing risks
Training and awareness
Which of the following activities is performed outside information security monitoring?
Management review of the information security framework
Monitoring the effectiveness of implemented controls
Collection and review of security events before escalation
Periodic review of risks, vulnerabilities, likelihoods, and threats
Which of the following is a KEY benefit of using the Cloud Controls Matrix (CCM)?
CCM utilizes an ITIL framework to define the capabilities needed to manage the IT services and security services.
CCM maps to existing security standards, best practices, and regulations.
CCM uses a specific control for Infrastructure as a Service (laaS).
CCM V4 is an improved version from CCM V3.0.1.
Which of the following cloud environments should be a concern to an organization s cloud auditor?
The cloud service provider s data center is more than 100 miles away.
The technical team is trained on only one vendor Infrastructure as a Service (laaS) platform, but the organization has subscribed to another vendor's laaS platform as an alternative.
The organization entirely depends on several proprietary Software as a Service (SaaS) applications.
The failover region of the cloud service provider is on another continent
From a compliance perspective, which of the following artifacts should an assessor review when evaluating the effectiveness of Infrastructure as Code deployments?
Evaluation summaries
logs
SOC reports
Interviews
From an auditor perspective, which of the following BEST describes shadow IT?
An opportunity to diversify the cloud control approach
A weakness in the cloud compliance posture
A strength of disaster recovery (DR) planning
A risk that jeopardizes business continuity planning
In a situation where duties related to cloud risk management and control are split between an organization and its cloud service providers, which of the following would BEST help to ensure a coordinated approach to risk and control processes?
Establishing a joint security operations center
Automating reporting of risk and control compliance
Co-locating compliance management specialists
Maintaining a centralized risk and controls dashboard
Question