Free CCAK Exam Braindumps (page: 20)

Page 20 of 78

Which of the following is the BEST way for a client to enforce a policy violation committed by a cloud service provider (CSP)?

  1. The violation is agreed upon and documented.
  2. Nothing can be done to enforce violations as this is a cloud service.
  3. The violation is agreed to verbally by the CSP.
  4. Violations will be automatically enforced so no action is needed.

Answer(s): A


Reference:

https://www.omg.org/cloud/deliverables/CSCC-Security-for-Cloud-Computing-10-Steps-to-Ensure-Success.pdf



Which of the following is a corrective control that may be identified in a SaaS service provider?

  1. Log monitoring
  2. Penetration testing
  3. Incident response plans
  4. Vulnerability scan

Answer(s): D



Which of the following configuration change controls is acceptable to a cloud auditor?

  1. Development, test and production are hosted in the same network environment.
  2. Programmers have permanent access to production software.
  3. The Head of Development approves changes requested to production.
  4. Programmers cannot make uncontrolled changes to the source code production version.

Answer(s): D



In cloud computing, with whom does the responsibility and accountability for compliance lie?

  1. The cloud service provider is responsible and accountable for compliance.
  2. The cloud service provider is responsible for compliance, and the cloud service customer is accountable.
  3. The cloud service customer is responsible and accountable for compliance.
  4. The cloud service customer is responsible for compliance, and the cloud service provider is accountable.

Answer(s): D



Page 20 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote