ExamGecko
Question list
Search
Search

List of questions

Search

Question 161 - CCAK discussion

Report
Export

Which of the following provides the BEST evidence that a cloud service provider's continuous integration and continuous delivery (CI/CD) development pipeline includes checks for compliance as new features are added to its Software as a Service (SaaS) applications?

A.

Compliance tests are automated and integrated within the Cl tool.

Answers
A.

Compliance tests are automated and integrated within the Cl tool.

B.

Developers keep credentials outside the code base and in a secure repository.

Answers
B.

Developers keep credentials outside the code base and in a secure repository.

C.

Frequent compliance checks are performed for development environments.

Answers
C.

Frequent compliance checks are performed for development environments.

D.

Third-party security libraries are continuously kept up to date.

Answers
D.

Third-party security libraries are continuously kept up to date.

Suggested answer: A

Explanation:

A centralized risk and controls dashboard is the best option for ensuring a coordinated approach to risk and control processes when duties are split between an organization and its cloud service providers. This dashboard provides a unified view of risk and control status across the organization and the cloud services it utilizes. It enables both parties to monitor and manage risks effectively and ensures that control activities are aligned and consistent. This approach supports proactive risk management and facilitates communication and collaboration between the organization and the cloud service provider.

Reference The concept of a centralized risk and controls dashboard is supported by the Cloud Security Alliance (CSA) and ISACA, which emphasize the importance of visibility and coordination in cloud risk management.The CCAK materials and the Cloud Controls Matrix (CCM) provide guidance on establishing such dashboards as a means to manage and mitigate risks in a cloud environment12.

asked 17/11/2024
Alonzo M. Carr Sr.
24 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first