Free CCAK Exam Braindumps (page: 31)

Page 31 of 78

Which of the following is a cloud-specific security standard?

  1. ISO27017
  2. ISO27701
  3. ISO22301
  4. ISO14001

Answer(s): A


Reference:

https://en.wikipedia.org/wiki/ISO/IEC_27017#:~:text=ISO%2FIEC%2027017%20is%20a,the%20risk%20of%20security%20problems



The PRIMARY objective for an auditor to understand the organization’s context for a cloud audit is to:

  1. determine whether the organization has carried out control self-assessment and validated audit reports of the cloud service providers (CSP).
  2. validate an understanding of the organization’s current state and how the cloud audit plan fits into the existing audit approach.
  3. validate whether an organization has a cloud audit plan in place.
  4. validate the organization’s performance effectiveness utilizing cloud service providers (CSP) solutions.

Answer(s): B



Which of the following defines the criteria designed by the American Institute of Certified Public Accountants (AICPA) to specify trusted services?

  1. Security, confidentiality, availability, privacy and processing integrity
  2. Security, applicability, availability, privacy and processing integrity
  3. Security, confidentiality, availability, privacy and trustworthiness
  4. Security, data integrity, availability, privacy and processing integrity

Answer(s): A

Explanation:


Reference:

https://us.aicpa.org/content/dam/aicpa/interestareas/frc/assuranceadvisoryservices/downloadabledocuments/trust-services-criteria.pdf



Which of the following is the BEST control framework for a European manufacturing corporation that is migrating to the cloud?

  1. NIST SP 800-53
  2. CSA?s GDPR CoC
  3. PCI-DSS
  4. EU GDPR

Answer(s): D


Reference:

https://ec.europa.eu/info/sites/default/files/ec_cloud_strategy.pdf



Page 31 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote