
Start your CCAK Exam Questions Preparation with Updated 128 Questions
A Fully Updated 2023 CCAK Exam Dumps - PDF Questions and Testing Engine
NEW QUESTION 43
An organization deploying the Cloud Control Matrix (CCM) to perform a compliance assessment will encompass the use of the "Corporate Governance Relevance" feature to filter out those controls:
- A. that can be either of an administrative or of a technical nature, therefore requiring an approval from the Change Advisory Board.
- B. that can be either of a management or of a legal nature, therefore requiring an approval from the Change Advisory Board.
- C. that require the prior approval from the Board of Directors to be funded (for either make or buy), implemented, and reported on.
- D. relating to policies, processes, laws, regulations, and institutions conditioning the way an organization is managed, directed, or controlled.
Answer: D
NEW QUESTION 44
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.
- A. risk framework
- B. value chain analysis
- C. control self-assessment (CSA)
- D. balanced scorecard
Answer: D
NEW QUESTION 45
To ensure that cloud audit resources deliver the best value to the organization, the PRIMARY step would be to:
- A. monitor progress of audits and initiate cost control measures.
- B. train the cloud audit staff on current technology used in the organization.
- C. develop a cloud audit plan on the basis of a detailed risk assessment.
- D. schedule the audits and monitor the time spent on each audit.
Answer: C
Explanation:
Explanation
It delivers value to the organization are the resources and efforts being dedicated to, and focused on, the higher-risk areas.
NEW QUESTION 46
Which of the following data destruction methods is the MOST effective and efficient?
- A. Multi-pass wipes
- B. Crypto-shredding
- C. Degaussing
- D. Physical destruction
Answer: C
NEW QUESTION 47
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.
- A. False
- B. True
Answer: B
NEW QUESTION 48
Which of the following has the MOST substantial impact on how aggressive or conservative the cloud approach of an organization will be?
- A. Applicable laws and regulations
- B. Internal policies and technical standards
- C. Risk scoring criteria
- D. Risk appetite and budget constraints
Answer: A
NEW QUESTION 49
Which of the following standards is designed to be used by organizations for cloud services that intend to select controls within the process of implementing an Information Security Management System based on ISO/IEC 27001?
- A. ISO/IEC 27017:2015
- B. ISO/IEC 27002
- C. CSA Cloud Control Matrix (CCM)
- D. NIST SP 800-146
Answer: B
NEW QUESTION 50
How can virtual machine communications bypass network security controls?
- A. The guest OS can invoke stealth mode
- B. Most network security systems do not recognize encrypted VM traffic
- C. VM communications may use a virtual network on the same hardware host
- D. VM images can contain rootkits programmed to bypass firewalls
- E. Hypervisors depend upon multiple network interfaces
Answer: C
NEW QUESTION 51
Which of the following is the MOST important audit scope document when conducting a review of a cloud service provider?
- A. Updated audit/work program
- B. Processes and systems to be audited
- C. Testing procedure to be performed
- D. Documentation criteria for the audit evidence
Answer: D
NEW QUESTION 52
What data center and physical security measures should a cloud customer consider when assessing a cloud service provider?
- A. Assess use of monitoring systems to control ingress and egress points of entry to the data center.
- B. Conduct a due diligence to verify the cloud provider applies adequate physical security measures.
- C. Review internal policies and procedures for relocation of hardware and software to an offsite location.
- D. Implement physical security perimeters to safeguard personnel, data and information systems.
Answer: B
NEW QUESTION 53
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?
- A. Expected Engineering
- B. Resiliency Planning
- C. Organized Downtime
- D. PlannedOutages
- E. Chaos Engineering
Answer: E
NEW QUESTION 54
Within an organization, which of the following functions should be responsible for defining the cloud adoption approach?
- A. Compliance manager
- B. Audit committee
- C. IT manager
- D. Senior management
Answer: D
NEW QUESTION 55
What type of termination occurs at the initiative of one party, and without the fault of the other party?
- A. Termination without the fault
- B. Termination at the end of the term
- C. Termination for convenience
- D. Termination for cause
Answer: B
NEW QUESTION 56
To identify key actors and requirements, which of the following MUST be considered when designing a cloud compliance program?
- A. Key stakeholders, enterprise risk management, and Internal audit perspectives
- B. Business/organizational, governance, cloud and risk perspectives
- C. Enterprise risk management, data protection, privacy and legal perspectives
- D. Cloud service provider, internal and external audit perspectives
Answer: B
NEW QUESTION 57
Which of the following is the GREATEST security risk associated with data migration from a legacy human resources (HR) system to a cloud-based system''
- A. System performance may be impacted by the migration
- B. Records past their retention period may not be migrated to the new system
- C. Data from the source and target system may have different data formats
- D. Data from the source and target system may be intercepted
Answer: D
NEW QUESTION 58
What is the advantage of using dynamic application security testing (DAST) over static application security testing (SAST) methodology?
- A. DAST delivers more false positives than SAST.
- B. DAST can dynamically integrate with most CI/CD tools.
- C. Unlike SAST, DAST is a blackbox and programming language agnostic.
- D. DAST is slower but thorough.
Answer: C
NEW QUESTION 59
Prioritizing assurance activities for an organization's cloud services portfolio depends PRIMARILY on an organization's ability to:
- A. develop plans using a standardized risk-based approach.
- B. maintain a comprehensive cloud service inventory.
- C. collate views from various business functions using cloud services.
- D. schedule frequent reviews with high-risk cloud service providers.
Answer: D
NEW QUESTION 60
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
- A. Allowing the cloud provider to manage your keys so that they have the ability to access and delete the data from the main and back-up storage.
- B. Maintaining customer managed key management and revoking ordeleting keys from the key management system to prevent the data from being accessed again.
- C. Practice Integration of Duties (IOD) so that everyone is able to delete the encrypted data.
- D. Both B and D.
- E. Keep the keys stored on the client side so that they are secure and so that the users have the ability to delete their own data.
Answer: B
NEW QUESTION 61
Which of the following aspects of risk management involves identifying the potential reputational harm and/or financial harm when an incident occurs?
- A. Impact Analysis
- B. Mitigations
- C. Residual risk
- D. Likelihood
Answer: A
NEW QUESTION 62
Which best describes the difference between a type 1 and a type 2 SOC report?
- A. There is no difference between a type 2 and type 1 SOC report.
- B. A type 1 SOC report provides an attestation whereas a type 2 SOC report offers a certification.
- C. A type 2 SOC report validates the operating effectiveness of controls whereas a type 1 SOC report validates the suitability of the design of the controls.
- D. A type 2 SOC report validates the suitability of the design of the controls whereas a type 1 SOC report validates the operating effectiveness of controls.
Answer: B
NEW QUESTION 63
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
- A. Inspect and account for risksinherited from other members of the cloud supply chain and take active measures to mitigate and contain risks through operational resiliency.
- B. Negotiate long-term contracts with companies who use well-vetted software application to avoid the transient nature of the cloud environment.
- C. Provide transparency to stakeholders and shareholders demonstrating fiscal solvency and organizational transparency.
- D. Both B and C.
- E. Respect the interdependency of the risks inherent in the cloud supply chain and communicate the corporate riskposture and readiness to consumers and dependent parties.
Answer: B
NEW QUESTION 64
To qualify for CSA STAR attestation for a particular cloud system, the SOC 2 report must cover:
- A. all Cloud Control Matrix (CCM) controls and TSPC security principles.
- B. ISO/IEC 27001: 2013 controls.
- C. Cloud Control Matrix (CCM) and ISO/IEC 27001:2013 controls.
- D. maturity model criteria.
Answer: A
NEW QUESTION 65
Which of the following is a cloud-specific security standard?
- A. ISO22301
- B. ISO14001
- C. ISO27017
- D. ISO27701
Answer: C
NEW QUESTION 66
An audit has identified that business units have purchased cloud-based applications without ITs support. What is the GREATEST risk associated with this situation?
- A. The applications could be modified without advanced notice.
- B. The application purchases did not follow procurement policy.
- C. The applications are not included in business continuity plans (BCPs).
- D. The applications may not reasonably protect data.
Answer: C
NEW QUESTION 67
......
What is the test format of the ISACA CCAK Exam?
Exam Length: 76
Exam Format: Multiple Choice
Passing score: 70%
Language: English
Exam Duration: 120 minutes
What if there is a better way to prepare yourself for the ISACA CCAK Exam?
Will it have enough substance and rigor to help you pass on your first try? Fortunately, there is such a thing. Considering the nature of the ISACA CCAK Exam, you can expect that the test will cover three main areas: cloud fundamentals, auditing practices, and risk management. You need to be acquainted with all of these topics if you want to pass the exam on your first try, and you can achieve easily with our CCAK Dumps. The good thing about this guide is that it covers all of these areas comprehensively. You can expect that it delivers what it promises; unlike most other guides out there in the market today, this one is known for its quality content and reliability.
Easy Success ISACA CCAK Exam in First Try: https://www.dumps4pdf.com/CCAK-valid-braindumps.html
Best CCAK Exam Dumps for the Preparation of Latest Exam Questions: https://drive.google.com/open?id=1wOLY_q4AQAF8h99Coc0EmN99116rTmQh