Free CCAK Exam Braindumps (page: 15)

Page 15 of 78

How should controls be designed by an organization?

  1. By the internal audit team
  2. Using the ISO27001 framework
  3. By the cloud provider
  4. Using the organization’s risk management framework

Answer(s): A


Reference:

https://www.isaca.org/resources/news-and-trends/isaca-now-blog/2016/internal-control-key-todelivering-stakeholder-value



Which of the following quantitative measures is KEY for an auditor to review when assessing the implementation of continuous auditing of performance on a cloud system?

  1. Service Level Objective (SLO)
  2. Recovery Point Objectives (RPO)
  3. Service Level Agreement (SLA)
  4. Recovery Time Objectives (RTO)

Answer(s): C



Your company is purchasing an application from a vendor. They do not allow you to perform an on-site audit on their information system. However, they say, they will provide the third-party audit attestation on the adequate control design within their environment. Which report is the vendor providing you?

  1. SOC 3
  2. SOC 2, TYPE 2
  3. SOC 1
  4. SOC 2, TYPE 1

Answer(s): B


Reference:

https://www.isaca.org/resources/isaca-journal/issues/2019/volume-6/soc-reports-for-cloud-securityand-privacy



Which of the following activities are part of the implementation phase of a cloud assurance program during a cloud migration?

  1. Development of the monitoring goals and requirements
  2. Identification of processes, functions, and systems
  3. Identification of the relevant laws, regulations, and standards
  4. Identification of roles and responsibilities

Answer(s): B


Reference:

https://www.isaca.org/resources/isaca-journal/past-issues/2012/cloud-risk-10-principles-and-aframework-for-assessment



Page 15 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote