Isaca CCAK Practice Test - Questions Answers, Page 4
List of questions
Question 31
As a developer building codes into a container in a DevSecOps environment, which of the following is the appropriate place(s) to perform security tests?
Question 32
In which control should a cloud service provider, upon request, inform customers of compliance impact and risk, especially if customer data is used as part of the services?
Reference: https://rmas.fad.harvard.edu/cloud-service-providers
Question 33
With regard to the Cloud Control Matrix (CCM), the 'Architectural Relevance' is a feature that enables the filtering of security controls by:
Reference: https://downloads.cloudsecurityalliance.org/initiatives/ccm/CSA_CCM_v3.0.xlsx
Question 34
What should be the control audit frequency for Business Continuity Management?
Reference: https://repository.stcloudstate.edu/cgi/viewcontent.cgi?article=1068&context=msia_etds
Question 35
The PRIMARY objective of an audit initiation meeting with a cloud audit client is to:
Question 36
Which of the following key stakeholders should be identified the earliest when an organization is designing a cloud compliance program?
Question 37
Customer management interface, if compromised over public internet, can lead to:
Question 38
Which of the following is the BEST recommendation to offer an organization's HR department planning to adopt a new public SaaS application to ease the recruiting process?
Reference: https://www.mcafee.com/enterprise/en-us/security-awareness/cloud/what-is-a-casb.html
Question 39
Within an organization, which of the following functions should be responsible for defining the cloud adoption approach?
Question 40
An organization is in the initial phases of cloud adoption. It is not very knowledgeable about cloud security and cloud shared responsibility models. Which of the following approaches is BEST suited for such an organization to evaluate its cloud security?
Question