ExamGecko
Question list
Search
Search

List of questions

Search

Question 168 - CCAK discussion

Report
Export

A cloud service customer is looking to subscribe to a finance solution provided by a cloud service provider. The provider has clarified that the audit logs cannot be taken out of the cloud environment by the customer to its security information and event management (SIEM) solution for monitoring purposes. Which of the following should be the GREATEST concern to the auditor?

A.

The audit logs are overwritten every 30 days, and all past audit trail is lost.

Answers
A.

The audit logs are overwritten every 30 days, and all past audit trail is lost.

B.

The audit trails are backed up regularly, but the backup is not encrypted.

Answers
B.

The audit trails are backed up regularly, but the backup is not encrypted.

C.

The provider does not maintain audit logs in their environment.

Answers
C.

The provider does not maintain audit logs in their environment.

D.

The customer cannot monitor its cloud subscription on its own and must rely on the provider for monitoring purposes.

Answers
D.

The customer cannot monitor its cloud subscription on its own and must rely on the provider for monitoring purposes.

Suggested answer: D

Explanation:

The greatest concern to the auditor should be that the customer cannot monitor its cloud subscription on its own and must rely on the provider for monitoring purposes. This situation can lead to a lack of transparency and control over the security and compliance posture of the cloud services being used. It is crucial for customers to have the ability to independently monitor their systems to ensure that they are secure and compliant with relevant regulations and standards.

Reference This concern is highlighted in the Cloud Security Alliance's (CSA) Cloud Controls Matrix (CCM) and the Certificate of Cloud Auditing Knowledge (CCAK) materials, which emphasize the importance of continuous monitoring and the customer's ability to audit and ensure the security of their cloud services1.

asked 17/11/2024
MARCONDES SANTOS
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first