ISACA CCAK Exam Practice Questions (P. 4)
- Full Access (265 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #16
When performing audits in relation to Business Continuity Management and Operational Resilience strategy, what would be the MOST critical aspect to audit in relation to the strategy of the cloud customer that should be formulated jointly with the cloud service provider?
- AValidate if the strategy covers unavailability of all components required to operate the business-as-usual or in disrupted mode, in parts or total- when impacted by a disruption.
- BValidate if the strategy covers all aspects of Business Continuity and Resilience planning, taking inputs from the assessed impact and risks, to consider activities for before, during, and after a disruption.
- CValidate if the strategy covers all activities required to continue and recover prioritized activities within identified time frames and agreed capacity, aligned to the risk appetite of the organization including the invocation of continuity plans and crisis management capabilities.Most Voted
- DValidate if the strategy is developed by both cloud service providers and cloud service consumers within the acceptable limits of their risk appetite.
Correct Answer:
B
B
send
light_mode
delete
Question #17
Which of the following metrics are frequently immature?
- AMetrics around Infrastructure as a Service (IaaS) storage and network environments
- BMetrics around Platform as a Service (PaaS) development environments
- CMetrics around Infrastructure as a Service (IaaS) computing environments
- DMetrics around specific Software as a Service (SaaS) application servicesMost Voted
Correct Answer:
A
A
send
light_mode
delete
Question #18
The MAIN difference between Cloud Control Matrix (CCM) and Consensus Assessment Initiative Questionnaire (CAIQ) is that:
- ACCM assesses the presence of controls, whereas CAIQ assesses overall security of a service.
- BCCM has a set of security questions, whereas CAIQ has a set of security controls.
- CCCM has 14 domains and CAIQ has 16 domains.
- DCCM provides a controls framework, whereas CAIQ provides industry-accepted ways to document which security controls exist in IaaS, PaaS, and SaaS offerings.
Correct Answer:
D
D
send
light_mode
delete
Question #19
Which of the following is an example of financial business impact?
- AA hacker using a stolen administrator identity brings down the SaaS sales and marketing systems, resulting in the inability to process customer orders or manage customer relationships.
- BWhile the breach was reported in a timely manner to the CEO, the CFO and CISO blamed each other in public, resulting in a loss of public confidence that led the board to replace all three.
- CA DDoS attack renders the customer's cloud inaccessible for 24 hours resulting in millions in lost sales.Most Voted
- DThe cloud provider fails to report a breach of customer personal data from an unsecured server, resulting in GDPR fines of 10 million euro.
Correct Answer:
C
C
send
light_mode
delete
Question #20
From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps concept?
- AProcess of security integration using automation in software developmentMost Voted
- BDevelopment standards for addressing integration, testing, and deployment issues
- COperational framework that promotes software consistency through automation
- DMaking software development simpler, faster, and easier using automation
Correct Answer:
B
B
send
light_mode
delete
All Pages