Free CCAK Exam Braindumps (page: 8)

Page 8 of 78

What is a sign of an organization that has adopted a shift-left concept of code release cycles?

  1. A waterfall model to move resources through the development to release phases
  2. Incorporation of automation to identify and address software code problems early
  3. Maturity of start-up entities with high-iteration to low-volume code commits
  4. Large entities with slower release cadences and geographical dispersed systems

Answer(s): B


Reference:

https://www.ibm.com/cloud/learn/devsecops



Cloud Control Matrix (CCM) controls can be used by cloud customers to:

  1. develop new security baselines for the industry.
  2. define different control frameworks for different cloud service providers.
  3. facilitate communication with their legal department.
  4. build an operational cloud risk management program.

Answer(s): B

Explanation:


Reference:

https://cloudsecurityalliance.org/blog/2020/10/16/what-is-the-cloud-controls-matrix-ccm/



Within an organization, which of the following functions should be responsible for defining the cloud adoption approach?

  1. Audit committee
  2. Compliance manager
  3. IT manager
  4. Senior management

Answer(s): D


Reference:

https://www.coso.org/documents/cloud-computing-thought-paper.pdf



An independent contractor is assessing security maturity of a SaaS company against industry standards. The SaaS company has developed and hosted all their products using the cloud services provided by a third-party cloud service provider (CSP). What is the optimal and most efficient mechanism to assess the controls CSP is responsible for?

  1. Review third-party audit reports.
  2. Review CSP?s published questionnaires.
  3. Directly audit the CSP.
  4. Send supplier questionnaire to the CSP.

Answer(s): B


Reference:

https://www.sapidata.sm/img/cms/CAIQ_v3-1_2020-01-13.pdf



Page 8 of 78



Post your Comments and Discuss ISACA CCAK exam with other Community members:

ccak commented on June 08, 2023
ccak is hard
Anonymous
upvote