ExamGecko
Question list
Search
Search

List of questions

Search

Question 151 - CCAK discussion

Report
Export

Which of the following helps an organization to identify control gaps and shortcomings in the context of cloud computing?

A.

Walk-through peer review

Answers
A.

Walk-through peer review

B.

Periodic documentation review

Answers
B.

Periodic documentation review

C.

User security awareness training

Answers
C.

User security awareness training

D.

Monitoring effectiveness

Answers
D.

Monitoring effectiveness

Suggested answer: B

Explanation:

Periodic documentation review is a critical process that helps organizations identify control gaps and shortcomings, particularly in the context of cloud computing. This process involves regularly examining the documentation of processes, controls, and policies to ensure they are up-to-date and effective. It allows an organization to verify that the controls are operating as intended and to discover any areas where the controls may not fully address the organization's requirements or the unique risks associated with cloud services. By conducting these reviews, organizations can maintain compliance with relevant regulations and standards, and ensure continuous improvement in their cloud security posture.

Reference The significance of periodic documentation review is highlighted in cloud auditing and security best practices, as outlined by the Cloud Security Alliance (CSA) and the Certificate of Cloud Auditing Knowledge (CCAK) program12. These resources emphasize the importance of regular reviews as part of a comprehensive cloud governance and compliance strategy.

asked 17/11/2024
Jorge Pinto
30 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first