Easily To Pass New ISACA CCAK Dumps with 128 Questions [Q42-Q64]

Share

Easily To Pass New ISACA CCAK Dumps with 128 Questions

Latest CCAK Study Guides 2023 - With Test Engine PDF

NEW QUESTION 42
Sending data to a provider's storage over an API is likely as much morereliable and secure than setting up your own SFTP server on a VM in the same provider

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 43
Which data security control is the LEAST likely to be assigned to an IaaSprovider?

  • A. Encryption solutions
  • B. Physical destruction
  • C. Asset management and tracking
  • D. Access controls
  • E. Application logic

Answer: E

 

NEW QUESTION 44
Due to cloud audit team resource constraints, an audit plan as initially approved cannot be completed. Assuming that the situation is communicated in the cloud audit report which course of action is MOST relevant?

  • A. Relying on management testing of cloud controls
  • B. Testing the operational effectiveness of cloud controls
  • C. Focusing on auditing high-risk areas
  • D. Testing the adequacy of cloud controls design

Answer: C

 

NEW QUESTION 45
Which of the following is an example of integrity technical impact?

  • A. An administrator inadvertently click on Phish bait exposing his company to a ransomware attack.
  • B. A hacker using a stolen administrator identity alerts the discount percentage in the product database.
  • C. A DDoS attack renders the customer's cloud inaccessible for 24 hours.
  • D. The cloud provider reports a breach of customer personal data from an unsecured server.

Answer: A

 

NEW QUESTION 46
Which of the following CSP activities requires a client's approval?

  • A. Delete the guest account or test accounts
  • B. Delete the guest account or destroy test data
  • C. Delete the test accounts or destroy test data
  • D. Delete the master account or subscription owner accounts

Answer: C

 

NEW QUESTION 47
When migrating to a cloud environment, which of the following should be the PRIMARY driver for the use of encryption?

  • A. Organizational security policies
  • B. Cost-benefit analysis
  • C. Cloud Service Provider encryption capabilities
  • D. The presence of PII

Answer: C

 

NEW QUESTION 48
To ensure that cloud audit resources deliver the best value to the organization, the PRIMARY step would be to:

  • A. schedule the audits and monitor the time spent on each audit.
  • B. monitor progress of audits and initiate cost control measures.
  • C. train the cloud audit staff on current technology used in the organization.
  • D. develop a cloud audit plan on the basis of a detailed risk assessment.

Answer: D

Explanation:
It delivers value to the organization are the resources and efforts being dedicated to, and focused on, the higher-risk areas.

 

NEW QUESTION 49
Which of the following defines the criteria designed by the American Institute of Certified Public Accountants (AICPA) to specify trusted services?

  • A. Security, confidentiality, availability, privacy and trustworthiness
  • B. Security, data integrity, availability, privacy and processing integrity
  • C. Security, confidentiality, availability, privacy and processing integrity
  • D. Security, applicability, availability, privacy and processing integrity

Answer: C

 

NEW QUESTION 50
Which of the following is the common cause of misconfiguration in a cloud environment?

  • A. Using multiple cloud service providers
  • B. Absence of effective change control
  • C. New cloud computing techniques
  • D. Traditional change process mechanisms

Answer: B

 

NEW QUESTION 51
How is encryption managed on multi-tenant storage?

  • A. C for data subject to the EU Data Protection Directive; B for all others
  • B. One key per data owner
  • C. The answer could be A, B, or C depending on the provider
  • D. Multiple keys per data owner
  • E. Single key for all data owners

Answer: B

 

NEW QUESTION 52
APIs and web services require extensive hardening and must assume attacks from authenticated and unauthenticated adversaries.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 53
What should be the control audit frequency for Business Continuity Management?

  • A. Annually
  • B. Monthly
  • C. Quarterly
  • D. Semi-annually

Answer: A

 

NEW QUESTION 54
A certification target helps in the formation of a continuous certification framework by incorporating:

  • A. frequency of evaluating security attributes.
  • B. scope description and security attributes to be tested.
  • C. service level objective and service qualitative objective.
  • D. CSA STAR level 2 attestation.

Answer: C

 

NEW QUESTION 55
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?

  • A. An image copy of the attacked system was not taken.
  • B. The handling procedures of the attacked system are not documented.
  • C. The proper authorities were not notified.
  • D. The investigation report does not indicate a conclusion.

Answer: C

 

NEW QUESTION 56
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what?

  • A. A validation process
  • B. An entrylog
  • C. A support table
  • D. An entitlement matrix
  • E. An access log

Answer: A

 

NEW QUESTION 57
Which of the following would be a logical starting point for an auditor who has been engaged to assess the security of an organization's DevOps pipeline?

  • A. Review the CI/CD pipeline audit logs.
  • B. Verify separation of development and production pipelines.
  • C. Conduct an architectural assessment.
  • D. Verify the inclusion of security gates in the pipeline.

Answer: A

 

NEW QUESTION 58
Which of the following is a fundamental concept of FedRAMP that intends to save costs, time, and staff conducting superfluous agency security assessments?

  • A. Use existing, provide many times
  • B. Do once, use many times
  • C. Use often, provide many times
  • D. Be economical, act deliberately

Answer: B

 

NEW QUESTION 59
Which of the following should be an IS auditor's GREATEST concern when reviewing an outsourcing arrangement with a third-party cloud service provider to host personally identifiable data?

  • A. The data is not adequately segregated on the host platform.
  • B. The outsourcing contract does not contain a right-to-audit clause.
  • C. Fees are charged based on the volume of data stored by the host.
  • D. The organization's servers are not compatible with the third party's infrastructure

Answer: A

 

NEW QUESTION 60
Which statement best describes why it is important to know how data is being accessed?

  • A. The devices used to access data use a variety of operating systems and may have different programs installed on them.
  • B. The devices used to access data have different storage formats.
  • C. The devices used to access data may have differentownership characteristics.
  • D. The devices used to access data use a variety of applications or clients and may have different security characteristics.
  • E. The device may affect data dispersion.

Answer: D

 

NEW QUESTION 61
The MAIN difference between Cloud Control Matrix (CCM) and Consensus Assessment Initiative Questionnaire (CAIQ) is that:

  • A. CCM has a set of security questions, whereas CAIQ has a set of security controls.
  • B. CCM has 14 domains and CAIQ has 16 domains.
  • C. CCM assesses the presence of controls, whereas CAIQ assesses overall security of a service.
  • D. CCM provides a controls framework, whereas CAIQ provides industry-accepted ways to document which security controls exist in IaaS, PaaS, and SaaS offerings.

Answer: D

 

NEW QUESTION 62
Which of the following is an example of financial business impact?

  • A. While the breach was reported in a timely manner to the CEO, the CFO and CISO blamed each other in public, resulting in a loss of public confidence that led the board to replace all three.
  • B. The cloud provider fails to report a breach of customer personal data from an unsecured server, resulting in GDPR fines of 10 million euro.
  • C. A DDoS attack renders the customer's cloud inaccessible for 24 hours resulting in millions in lost sales.
  • D. A hacker using a stolen administrator identity brings down the SaaS sales and marketing systems, resulting in the inability to process customer orders or manage customer relationships.

Answer: C

 

NEW QUESTION 63
Which of the following is the GREATEST security risk associated with data migration from a legacy human resources (HR) system to a cloud-based system''

  • A. Records past their retention period may not be migrated to the new system
  • B. Data from the source and target system may have different data formats
  • C. System performance may be impacted by the migration
  • D. Data from the source and target system may be intercepted

Answer: D

 

NEW QUESTION 64
......

CCAK Dumps and Exam Test Engine: https://surepass.free4dump.com/CCAK-real-dump.html