ExamGecko
Question list
Search
Search

List of questions

Search

Question 129 - CCAK discussion

Report
Export

A business unit introducing cloud technologies to the organization without the knowledge or approval of the appropriate governance function is an example of:

A.

IT exception

Answers
A.

IT exception

B.

Threat

Answers
B.

Threat

C.

Shadow IT

Answers
C.

Shadow IT

D.

Vulnerability

Answers
D.

Vulnerability

Suggested answer: C

Explanation:

Shadow IT refers to the use of IT resources (hardware, software, or cloud services) within an organization without the explicit approval of the IT or governance team. This practice is often flagged in cloud audits due to potential risks of compliance violations and security threats. The CCAK documentation from ISACA highlights the need for visibility and governance over all IT assets, with specific controls listed in the CSA CCM for Cloud Governance (GOV-09). Shadow IT poses risks to data security, compliance, and can introduce vulnerabilities, as systems are not subject to organizational standards and oversight.

asked 17/11/2024
Calvin Bolico
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first