Isaca CCAK Practice Test - Questions Answers, Page 2
List of questions
Related questions
Which of the following is the BEST tool to perform cloud security control audits?
Which of the following is an example of a corrective control?
When developing a cloud compliance program, what is the PRIMARY reason for a cloud customer to review which cloud services will be deployed?
The Cloud Computing Compliance Controls Catalogue (C5) framework is maintained by which of the following agencies?
Which of the following is the MOST feasible way to validate the performance of CSPs for the delivery of technology resources?
Which of the following would be the MOST critical finding of an application security and DevOps audit?
During an audit it was identified that a critical application hosted in an off-premises cloud is not part of the organization's DRP (Disaster Recovery Plan).
Management stated that it is responsible for ensuring that the cloud service provider (CSP) has a plan that is tested annually. What should be the auditor's NEXT course of action?
Organizations maintain mappings between the different control frameworks they adopt to:
Which of the following defines the criteria designed by the American Institute of Certified Public Accountants (AICPA) to specify trusted services?
While performing the audit, the auditor found that an object storage bucket containing PII could be accessed by anyone on the Internet. Given this discovery, what should be the most appropriate action for the auditor to perform?
Question