Free CCAK Exam Braindumps (page: 24)

Page 24 of 78

The BEST way to deliver continuous compliance in a cloud environment is to:

  1. decrease the interval between attestations of compliance.
  2. combine point-in-time assurance approaches with continuous monitoring.
  3. increase the frequency of external audits from annual to quarterly.
  4. combine point-in-time assurance approaches with continuous auditing.

Answer(s): B



To identify key actors and requirements, which of the following MUST be considered when designing a cloud compliance program?

  1. Cloud service provider, internal and external audit perspectives
  2. Business/organizational, governance, cloud and risk perspectives
  3. Enterprise risk management, data protection, privacy and legal perspectives
  4. Key stakeholders, enterprise risk management, and Internal audit perspectives

Answer(s): B



Which of the following standards is designed to be used by organizations for cloud services that intend to select controls within the process of implementing an Information Security Management System based on ISO/ IEC 27001?

  1. ISO/IEC 27017:2015
  2. CSA Cloud Control Matrix (CCM)
  3. NIST SP 800-146
  4. ISO/IEC 27002

Answer(s): D


Reference:

https://cyber.gc.ca/en/guidance/guidance-cloud-security-assessment-and-authorization-itsp50105



Which of the following is the common cause of misconfiguration in a cloud environment?

  1. Absence of effective change control
  2. Using multiple cloud service providers
  3. New cloud computing techniques
  4. Traditional change process mechanisms

Answer(s): A

Explanation:


Reference:

https://businessinsights.bitdefender.com/the-top-5-cloud-threats-that-smbs-need-to-address



Page 24 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote