Free CCAK Exam Braindumps (page: 12)

Page 12 of 78

Which of the following is a fundamental concept of FedRAMP that intends to save costs, time, and staff conducting superfluous agency security assessments?

  1. Use often, provide many times
  2. Be economical, act deliberately
  3. Use existing, provide many times
  4. Do once, use many times

Answer(s): D

Explanation:


Reference:

https://www.fedramp.gov/assets/resources/documents/FedRAMP_Security_Assessment_Framework.pdf (2)



Which of the following is the risk associated with storing data in a cloud that crosses jurisdictions?

  1. Compliance risk
  2. Provider administration risk
  3. Audit risk
  4. Virtualization risk

Answer(s): A


Reference:

http://webcache.googleusercontent.com/search?q=cache:9OK2cQSAR3oJ:www.aph.gov.au/DocumentStore.ashx%3Fid%3D88403640-14b5-4c3e-8dd7-315bb5067ba4+&cd=1&hl=en&ct=clnk&gl=pk



Since CCM allows cloud customers to build a detailed list of requirements and controls to be implemented by the CSP as part of their overall third-party risk management and procurement program, will CCM alone be enough to define all the items to be considered when operating/using cloud services?

  1. No. CCM must be completed with definitions established by the CSP because of its relevance to service continuity.
  2. Yes. CCM suffices since it maps a huge library of widely accepted frameworks.
  3. Yes. When implemented in the right manner, CCM alone can help to measure, assess and monitor the risk associated with a CSP or a particular service.
  4. No. CCM can serve as a foundation for a cloud assessment program, but it needs to be completed with requirements applicable to each company.

Answer(s): C



During an audit it was identified that a critical application hosted in an off-premises cloud is not part of the organization’s DRP (Disaster Recovery Plan). Management stated that it is responsible for ensuring that the cloud service provider (CSP) has a plan that is tested annually. What should be the auditor’s NEXT course of action?

  1. Review the CSP audit reports.
  2. Review the security white paper of the CSP.
  3. Review the contract and DR capability.
  4. Plan an audit of the CSP.

Answer(s): B



Page 12 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote