ExamGecko
Question list
Search
Search

List of questions

Search

Question 56 - CCAK discussion

Report
Export

Since CCM allows cloud customers to build a detailed list of requirements and controls to be implemented by the CSP as part of their overall third-party risk management and procurement program, will CCM alone be enough to define all the items to be considered when operating/using cloud services?

A.
No. CCM must be completed with definitions established by the CSP because of its relevance to service continuity.
Answers
A.
No. CCM must be completed with definitions established by the CSP because of its relevance to service continuity.
B.
Yes. CCM suffices since it maps a huge library of widely accepted frameworks.
Answers
B.
Yes. CCM suffices since it maps a huge library of widely accepted frameworks.
C.
Yes. When implemented in the right manner, CCM alone can help to measure, assess and monitor the risk associated with a CSP or a particular service.
Answers
C.
Yes. When implemented in the right manner, CCM alone can help to measure, assess and monitor the risk associated with a CSP or a particular service.
D.
No. CCM can serve as a foundation for a cloud assessment program, but it needs to be completed with requirements applicable to each company.
Answers
D.
No. CCM can serve as a foundation for a cloud assessment program, but it needs to be completed with requirements applicable to each company.
Suggested answer: C
asked 18/09/2024
Martin Simmons
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first