ExamGecko
Home / Isaca / CCAK / List of questions
Ask Question

Isaca CCAK Practice Test - Questions Answers, Page 17

Add to Whishlist

List of questions

Question 161

Report Export Collapse

Which of the following provides the BEST evidence that a cloud service provider's continuous integration and continuous delivery (CI/CD) development pipeline includes checks for compliance as new features are added to its Software as a Service (SaaS) applications?

Become a Premium Member for full access
  Unlock Premium Member

Question 162

Report Export Collapse

An auditor is reviewing an organization's virtual machines (VMs) hosted in the cloud. The organization utilizes a configuration management (CM) tool to enforce password policies on its VMs. Which of the following is the BEST approach for the auditor to use to review the operating effectiveness of the password requirement?

Become a Premium Member for full access
  Unlock Premium Member

Question 163

Report Export Collapse

Which of the following is the MOST important strategy and governance documents to provide to the auditor prior to a cloud service provider review?

Become a Premium Member for full access
  Unlock Premium Member

Question 164

Report Export Collapse

What should be the control audit frequency for an organization's business continuity management and operational resilience strategy?

Become a Premium Member for full access
  Unlock Premium Member

Question 165

Report Export Collapse

From the perspective of a senior cloud security audit practitioner in an organization with a mature security program and cloud adoption, which of the following statements BEST describes the DevSecOps concept?

Become a Premium Member for full access
  Unlock Premium Member

Question 166

Report Export Collapse

Which of the following BEST describes the difference between a Type 1 and a Type 2 SOC report?

Become a Premium Member for full access
  Unlock Premium Member

Question 167

Report Export Collapse

Which of the following is a KEY benefit of using the Cloud Controls Matrix (CCM)?

Become a Premium Member for full access
  Unlock Premium Member

Question 168

Report Export Collapse

A cloud service customer is looking to subscribe to a finance solution provided by a cloud service provider. The provider has clarified that the audit logs cannot be taken out of the cloud environment by the customer to its security information and event management (SIEM) solution for monitoring purposes. Which of the following should be the GREATEST concern to the auditor?

Become a Premium Member for full access
  Unlock Premium Member

Question 169

Report Export Collapse

As Infrastructure as a Service (laaS) cloud service providers often do not allow the cloud service customers to perform on-premise audits, the BEST approach for the auditor should be to:

Become a Premium Member for full access
  Unlock Premium Member

Question 170

Report Export Collapse

Which of the following is MOST important to ensure effective cloud application controls are maintained in an organization?

Become a Premium Member for full access
  Unlock Premium Member
Total 195 questions
Go to page: of 20
Search