Free CCAK Exam Braindumps (page: 18)

Page 18 of 78

Which of the following BEST ensures adequate restriction on the number of people who can access the pipeline production environment?

  1. Ensuring segregation of duties in the production and development pipelines.
  2. Role-based access controls in the production and development pipelines.
  3. Separation of production and development pipelines.
  4. Periodic review of the Cl/CD pipeline audit logs to identify any access violations.

Answer(s): C


Reference:

https://www.isaca.org/-/media/files/isacadp/project/isaca/articles/journal/2016/volume- 2/journalvolume-2-2016



A cloud customer configured and developed a solution on top of the certified cloud services. Building on top of a compliant CSP:

  1. means that the cloud customer is also compliant.
  2. means that the cloud customer and client are both compliant.
  3. means that the cloud customer is compliant but their client is not compliant.
  4. does not necessarily mean that the cloud customer is also compliant.

Answer(s): D



The rapid and dynamic rate of changes found in a cloud environment affects the organization’s:

  1. risk profile.
  2. risk appetite.
  3. risk scoring.
  4. risk communication.

Answer(s): B



A CSP providing cloud services currently being used by the United States federal government should obtain which of the following to assure compliance to stringent government standards?

  1. Multi-Tier Cloud Security (MTCS) Attestation
  2. FedRAMP Authorization
  3. ISO/IEC 27001:2013 Certification
  4. CSA STAR Level Certificate

Answer(s): B

Explanation:


Reference:

https://www.ftptoday.com/blog/benefits-using-fedramp-authorized-cloud-service-provider



Page 18 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote