Isaca CCAK Practice Test - Questions Answers, Page 4

List of questions
Question 31

As a developer building codes into a container in a DevSecOps environment, which of the following is the appropriate place(s) to perform security tests?
Question 32

In which control should a cloud service provider, upon request, inform customers of compliance impact and risk, especially if customer data is used as part of the services?
Reference: https://rmas.fad.harvard.edu/cloud-service-providers
Question 33

With regard to the Cloud Control Matrix (CCM), the 'Architectural Relevance' is a feature that enables the filtering of security controls by:
Reference: https://downloads.cloudsecurityalliance.org/initiatives/ccm/CSA_CCM_v3.0.xlsx
Question 34

What should be the control audit frequency for Business Continuity Management?
Reference: https://repository.stcloudstate.edu/cgi/viewcontent.cgi?article=1068&context=msia_etds
Question 35

The PRIMARY objective of an audit initiation meeting with a cloud audit client is to:
Question 36

Which of the following key stakeholders should be identified the earliest when an organization is designing a cloud compliance program?
Question 37

Customer management interface, if compromised over public internet, can lead to:
Question 38

Which of the following is the BEST recommendation to offer an organization's HR department planning to adopt a new public SaaS application to ease the recruiting process?
Reference: https://www.mcafee.com/enterprise/en-us/security-awareness/cloud/what-is-a-casb.html
Question 39

Within an organization, which of the following functions should be responsible for defining the cloud adoption approach?
Question 40

An organization is in the initial phases of cloud adoption. It is not very knowledgeable about cloud security and cloud shared responsibility models. Which of the following approaches is BEST suited for such an organization to evaluate its cloud security?
Question