ExamGecko
Question list
Search
Search

List of questions

Search

Question 159 - CCAK discussion

Report
Export

From an auditor perspective, which of the following BEST describes shadow IT?

A.

An opportunity to diversify the cloud control approach

Answers
A.

An opportunity to diversify the cloud control approach

B.

A weakness in the cloud compliance posture

Answers
B.

A weakness in the cloud compliance posture

C.

A strength of disaster recovery (DR) planning

Answers
C.

A strength of disaster recovery (DR) planning

D.

A risk that jeopardizes business continuity planning

Answers
D.

A risk that jeopardizes business continuity planning

Suggested answer: D

Explanation:

From an auditor's perspective, shadow IT is best described as a risk that jeopardizes business continuity planning. Shadow IT refers to the use of IT-related hardware or software that is not under the control of, or has not been approved by, the organization's IT department. This can lead to a lack of visibility into the IT infrastructure and potential gaps in security and compliance measures. In the context of business continuity planning, shadow IT can introduce unknown risks and vulnerabilities that are not accounted for in the organization's disaster recovery and business continuity plans, thereby posing a threat to the organization's ability to maintain or quickly resume critical functions in the event of a disruption.

Reference The answer is based on general knowledge of shadow IT risks and their impact on business continuity planning. Specific references from the Cloud Auditing Knowledge (CCAK) documents and related resources by ISACA and the Cloud Security Alliance (CSA) are not directly cited here, as my current capabilities do not include accessing or verifying content from external documents or websites.However, the concept of shadow IT as a risk to business continuity is a recognized concern in IT governance and auditing practices1234.

asked 17/11/2024
Nelson Alvaro
49 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first