ExamGecko
Question list
Search
Search

List of questions

Search

Question 20 - CCAK discussion

Report
Export

While performing the audit, the auditor found that an object storage bucket containing PII could be accessed by anyone on the Internet. Given this discovery, what should be the most appropriate action for the auditor to perform?

A.
Highlighting the gap to the audit sponsor at the sponsor's earliest possible availability
Answers
A.
Highlighting the gap to the audit sponsor at the sponsor's earliest possible availability
B.
Asking the organization's cloud administrator to immediately close the gap by updating the configuration settings and making the object storage bucket private and hence inaccessible from the Internet
Answers
B.
Asking the organization's cloud administrator to immediately close the gap by updating the configuration settings and making the object storage bucket private and hence inaccessible from the Internet
C.
Documenting the finding in the audit report and sharing the gap with the relevant stakeholders
Answers
C.
Documenting the finding in the audit report and sharing the gap with the relevant stakeholders
D.
Informing the organization's internal audit manager immediately about the gap
Answers
D.
Informing the organization's internal audit manager immediately about the gap
Suggested answer: C

Explanation:

Reference: https://www.isaca.org/resources/isaca-journal/issues/2020/volume-1/is-audit-basics-the-components-of-the-itaudit-report

asked 18/09/2024
mostafa khalaf
53 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first