ExamGecko
Question list
Search
Search

List of questions

Search

Question 40 - CCAK discussion

Report
Export

An organization is in the initial phases of cloud adoption. It is not very knowledgeable about cloud security and cloud shared responsibility models. Which of the following approaches is BEST suited for such an organization to evaluate its cloud security?

A.
Use of an established standard/regulation to map controls and use as the audit criteria
Answers
A.
Use of an established standard/regulation to map controls and use as the audit criteria
B.
For efficiency reasons, use of its on-premises systems' audit criteria to audit the cloud environment
Answers
B.
For efficiency reasons, use of its on-premises systems' audit criteria to audit the cloud environment
C.
As this is the initial stage, the ISO/IEC 27001 certificate shared by the cloud service provider is sufficient for audit and compliance purposes.
Answers
C.
As this is the initial stage, the ISO/IEC 27001 certificate shared by the cloud service provider is sufficient for audit and compliance purposes.
D.
Development of the cloud security audit criteria based on its own internal audit test plans to ensure appropriate coverage
Answers
D.
Development of the cloud security audit criteria based on its own internal audit test plans to ensure appropriate coverage
Suggested answer: A
asked 18/09/2024
Eduardo Efren Flores Riofrio
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first