Isaca CCAK Practice Test - Questions Answers, Page 5
List of questions
Question 41

What areas should be reviewed when auditing a public cloud?
Question 42

A Dot Release of Cloud Control Matrix (CCM) indicates what?
Question 43

What aspect of SaaS functionality and operations would the cloud customer be responsible for and should be audited?
Reference: https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=919233
Question 44

To support customer's verification of the CSP claims regarding their responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?
Question 45

Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization's SaaS vendor?
Reference: https://assets.kpmg/content/dam/kpmg/ch/pdf/key-risks-internal-audit-2018.pdf
Question 46

The Cloud Octagon Model was developed to support organizations:
Question 47

To ensure that integration of security testing is implemented on large code sets in environments where time to completion is critical, what form of validation should an auditor expect?
Reference: https://www.sciencedirect.com/topics/computer-science/black-box-testing
Question 48

When performing audits in relation to Business Continuity Management and Operational Resilience strategy, what would be the MOST critical aspect to audit in relation to the strategy of the cloud customer that should be formulated jointly with the cloud service provider?
Question 49

Which of the following standards is designed to be used by organizations for cloud services that intend to select controls within the process of implementing an
Information Security Management System based on ISO/IEC 27001?
Reference: https://cyber.gc.ca/en/guidance/guidance-cloud-security-assessment-and-authorization-itsp50105
Question 50

Which of the following aspects of risk management involves identifying the potential reputational harm and/or financial harm when an incident occurs?
Reference: https://compliancecosmos.org/chapter-5-step-three-determining-impact-occurrence
Question