List of questions
Related questions
Question 162 - CCAK discussion
An auditor is reviewing an organization's virtual machines (VMs) hosted in the cloud. The organization utilizes a configuration management (CM) tool to enforce password policies on its VMs. Which of the following is the BEST approach for the auditor to use to review the operating effectiveness of the password requirement?
The auditor should not rely on the CM tool and its settings, and for thoroughness should review the password configuration on the set of sample VMs.
Review the relevant configuration settings on the CM tool and check whether the CM tool agents are operating effectively on the sample VMs.
As it is an automated environment, reviewing the relevant configuration settings on the CM tool would be sufficient.
Review the incident records for any incidents relating to brute force attacks or password compromise in the last 12 months and investigate whether the root cause of the incidents was due to in appropriate password policy configured on the VMs.
0 comments
Leave a comment first