Free CCAK Exam Braindumps (page: 3)

Page 3 of 78

SAST testing is performed by:

  1. scanning the application source code.
  2. scanning the application interface.
  3. scanning all infrastructure components.
  4. performing manual actions to gain control of the application.

Answer(s): A

Explanation:

SAST analyzes application code offline. SAST is generally a rules-based test that will scan software code for items such as credentials embedded into application code and a test of input validation, both of which are major concerns for application security.



When a client’s business process changes, the CSP SLA should:

  1. be reviewed, but the SLA cannot be updated.
  2. not be reviewed, but the cloud contract should be cancelled immediately.
  3. not be reviewed as the SLA cannot be updated.
  4. be reviewed and updated if required.

Answer(s): D


Reference:

http://www.diva-portal.org/smash/get/diva2:1312384/FULLTEXT01.pdf



The PRIMARY objective of an audit initiation meeting with a cloud audit client is to:

  1. select the methodology of the audit.
  2. review requested evidence provided by the audit client.
  3. discuss the scope of the cloud audit.
  4. identify resource requirements of the cloud audit.

Answer(s): C



Policies and procedures shall be established, and supporting business processes and technical measures implemented, for maintenance of several items ensuring continuity and availability of operations and support personnel. Which of the following controls BEST matches this control description?

  1. Operations Maintenance
  2. System Development Maintenance
  3. Equipment Maintenance
  4. System Maintenance

Answer(s): A


Reference:

https://www.sapidata.sm/img/cms/CAIQ_v3-1_2020-01-13.pdf (2)



Page 3 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote