ISACA CCAK Exam Practice Questions (P. 5)
- Full Access (325 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #41
When using a SaaS solution, who is responsible for application security?
- AThe cloud service provider only
- BThe cloud service consumer only
- CBoth cloud consumer and the enterprise
- DBoth cloud provider and the consumerMost Voted
send
light_mode
delete
Question #42
Which of the following would be the GREATEST governance challenge to an organization where production is hosted in a public cloud and backups are held on the premises?
- AAligning the cloud service delivery with the organization’s objective
- BAligning the cloud provider’s SLA with the organization’s policy
- CAligning shared responsibilities between provider and customerMost Voted
- DAligning the organization’s activity with the cloud provider’s policy
send
light_mode
delete
Question #43
What aspect of SaaS functionality and operations would the cloud customer be responsible for and should be audited?
- AAccess controls
- BVulnerability management
- CSource code reviews
- DPatching
Correct Answer:
A
A
send
light_mode
delete
Question #44
The Open Certification Framework is structured on three levels of trust. Those three levels of trust are:
- ACSA STAR Self-Assessment, STAR Certification & Attestation (Third-party Assessment), STAR Compliance
- BCSA STAR Audit, STAR Certification & Attestation (Third-party Assessment), STAR Continuous
- CCSA STAR Self-Assessment, STAR Certification & Attestation (Third-party Assessment), STAR Monitoring and Control
- DCSA STAR Self-Assessment, STAR Certification & Attestation (Third-party Assessment), STAR Continuous
Correct Answer:
D
D
send
light_mode
delete
Question #45
Which of the following is a fundamental concept of FedRAMP that intends to save costs, time, and staff conducting superfluous agency security assessments?
- AUse often, provide many times
- BBe economical, act deliberately
- CUse existing, provide many times
- DDo once, use many times
Correct Answer:
D
D
send
light_mode
delete
Question #46
Which of the following is the risk associated with storing data in a cloud that crosses jurisdictions?
- ACompliance risk
- BProvider administration risk
- CAudit risk
- DVirtualization risk
Correct Answer:
A
A
send
light_mode
delete
Question #47
Since CCM allows cloud customers to build a detailed list of requirements and controls to be implemented by the CSP as part of their overall third-party risk management and procurement program, will CCM alone be enough to define all the items to be considered when operating/using cloud services?
- ANo. CCM must be completed with definitions established by the CSP because of its relevance to service continuity.
- BYes. CCM suffices since it maps a huge library of widely accepted frameworks.
- CYes. When implemented in the right manner, CCM alone can help to measure, assess and monitor the risk associated with a CSP or a particular service.
- DNo. CCM can serve as a foundation for a cloud assessment program, but it needs to be completed with requirements applicable to each company.Most Voted
send
light_mode
delete
Question #48
During an audit it was identified that a critical application hosted in an off-premises cloud is not part of the organization’s DRP (Disaster Recovery Plan). Management stated that it is responsible for ensuring that the cloud service provider (CSP) has a plan that is tested annually. What should be the auditor’s NEXT course of action?
- AReview the CSP audit reports.
- BReview the security white paper of the CSP.
- CReview the contract and DR capability.Most Voted
- DPlan an audit of the CSP.
send
light_mode
delete
Question #49
Which of the following is the BEST recommendation to offer an organization’s HR department planning to adopt a new public SaaS application to ease the recruiting process?
- AEnsure HIPAA compliance
- BImplement a cloud access security broker
- CConsult the legal departmentMost Voted
- DDo not allow data to be in cleratext
send
light_mode
delete
Question #50
In which control should a cloud service provider, upon request, inform customers of compliance impact and risk, especially if customer data is used as part of the services?
- AService Provider control
- BImpact and Risk control
- CData Inventory control
- DCompliance controlMost Voted
send
light_mode
delete
All Pages