Free CCAK Exam Braindumps (page: 32)

Page 32 of 78

Account design in the cloud should be driven by:

  1. security requirements.
  2. organizational structure.
  3. business continuity policies.
  4. management structure.

Answer(s): A



What should be the control audit frequency for Business Continuity Management?

  1. Quarterly
  2. Annually
  3. Monthly
  4. Semi-annually

Answer(s): B


Reference:

https://repository.stcloudstate.edu/cgi/viewcontent.cgi?article=1068&context=msia_etds



Which of the following should be an assurance requirement when an organization is migrating to a Software as a Service (SaaS) provider?

  1. Location of data
  2. Amount of server storage
  3. Access controls
  4. Type of network technology

Answer(s): C

Explanation:

Access controls are an assurance requirement when an organization is migrating to a SaaS provider because they ensure that only authorized users can access the cloud services and data. Access controls also help to protect the confidentiality, integrity and availability of the cloud resources. Access controls are part of the Cloud Control Matrix (CCM) domain IAM-01: Identity and Access Management Policy and Procedures, which states that "The organization should have a policy and procedures to manage user identities and access to cloud services and data."


Reference:

CCAK Study Guide, Chapter 4: A Threat Analysis Methodology for Cloud Using CCM, page 751



In a multi-level supply chain structure where cloud service provider A relies on other sub cloud services, the provider should ensure that any compliance requirements relevant to the provider are:

  1. passed to the sub cloud service providers based on the sub cloud service providers' geographic location.
  2. passed to the sub cloud service providers.
  3. treated as confidential information and withheld from all sub cloud service providers.
  4. treated as sensitive information and withheld from certain sub cloud service providers.

Answer(s): B

Explanation:

In a multi-level supply chain structure, the cloud service provider should ensure that any compliance requirements relevant to the provider are passed to the sub cloud service providers, regardless of their geographic location. This is because the sub cloud service providers may have access to or process the data of the provider's customers, and thus may affect the compliance status of the provider. The provider should also monitor and verify the compliance of the sub cloud service providers on a regular basis. This is part of the Cloud Control Matrix (CCM) domain COM-01:
Regulatory Frameworks, which states that "The organization should identify and comply with applicable regulatory frameworks, contractual obligations, and industry standards."1 Reference :
CCAK Study Guide, Chapter 3: Cloud Compliance Program, page 51



Page 32 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote