
CCAK Dumps 2022 - New ISACA CCAK Exam Questions
Free CCAK Braindumps Download Updated on Jun 08, 2022 with 128 Questions
NEW QUESTION 22
Which of the following is the GREATEST concern associated with migrating computing resources to a cloud virtualized environment?
- A. An increase in the potential for data leakage
- B. An increase in inherent vulnerability
- C. An increase in residual risk
- D. An increase in the number of e-discovery requests
Answer: A
NEW QUESTION 23
When building a cloud governance model, which of the following requirements will focus more on the cloud service provider's evaluation and control checklist?
- A. Operational requirements
- B. Compliance requirements
- C. Security requirements
- D. Legal requirements
Answer: A
NEW QUESTION 24
When developing a cloud compliance program, what is the PRIMARY reason for a cloud customer to review which cloud services will be deployed?
- A. To confirm if the compensating controls implemented are sufficient for the cloud
- B. To determine how those services will fit within its policies and procedures
- C. To determine the total cost of the cloud services to be deployed
- D. To confirm which vendor will be selected based on the compliance with security requirements
Answer: B
NEW QUESTION 25
To ensure that integration of security testing is implemented on large code sets in environments where time to completion is critical, what form of validation should an auditor expect?
- A. Functional verification
- B. Parallel testing
- C. Full application stack unit testing
- D. Regression testing
Answer: C
NEW QUESTION 26
Which of the following attestation allows for immediate adoption of the Cloud Control Matrix (CCM) as additional criteria to AICPA Trust Service Criteria and provides the flexibility to update the criteria as technology and market requirements change?
- A. BSI Criteria Catalogue C5
- B. PC-IDSS
- C. MTCS
- D. CSA STAR Attestation
Answer: D
NEW QUESTION 27
Which of the following cloud models prohibits penetration testing?
- A. Public Cloud
- B. Community Cloud
- C. Private Cloud
- D. Hybrid Cloud
Answer: C
NEW QUESTION 28
Under GDPR, an organization should report a data breach within what time frame?
- A. 2 weeks
- B. 72 hours
- C. 1 week
- D. 48 hours
Answer: B
NEW QUESTION 29
Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization's SaaS vendor?
- A. Board oversight
- B. Risk appetite
- C. Risk exceptions policy
- D. Contractual requirements
Answer: B
NEW QUESTION 30
Which attack surfaces, if any, does virtualization technology introduce?
- A. Virtualization management components apart from the hypervisor
- B. The hypervisor
- C. All of the above
- D. Configuration and VM sprawl issues
Answer: C
NEW QUESTION 31
Which of the following BEST ensures adequate restriction on the number of people who can access the pipeline production environment?
- A. Separation of production and development pipelines.
- B. Ensuring segregation of duties in the production and development pipelines.
- C. Periodic review of the Cl/CD pipeline audit logs to identify any access violations.
- D. Role-based access controls in the production and development pipelines.
Answer: A
NEW QUESTION 32
Which governance domain deals with evaluating how cloudcomputing affects compliance with internal security policies and various legal requirements, such as regulatory and legislative?
- A. Governance and Enterprise Risk Management
- B. Information Governance
- C. Compliance and Audit Management
- D. Infrastructure Security
- E. Legal Issues: Contracts and Electronic Discovery
Answer: C
NEW QUESTION 33
In which control should a cloud service provider, upon request, inform customers of compliance impact and risk, especially if customer data is used as part of the services?
- A. Service Provider control
- B. Compliance control
- C. Impact and Risk control
- D. Data Inventory control
Answer: A
NEW QUESTION 34
The criteria for limiting services allowing non-critical services or services requiring high availability and resilience to be moved to the cloud is an important consideration to be included PRIMARILY in the:
- A. risk management policy.
- B. information security standard for cloud technologies.
- C. business continuity plan.
- D. cloud policy.
Answer: C
NEW QUESTION 35
When using a SaaS solution, who is responsible for application security?
- A. The cloud service consumer only
- B. Both cloud provider and the consumer
- C. Both cloud consumer and the enterprise
- D. The cloud service provider only
Answer: D
NEW QUESTION 36
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?
- A. An image copy of the attacked system was not taken.
- B. The investigation report does not indicate a conclusion.
- C. The handling procedures of the attacked system are not documented.
- D. The proper authorities were not notified.
Answer: D
NEW QUESTION 37
......
ISACA CCAK Exam Practice Test Questions: https://www.testkingpass.com/CCAK-testking-dumps.html
Updated Certification Exam CCAK Dumps - Practice Test Questions: https://drive.google.com/open?id=1n4MPbsbNJ_m0yz3yxYTLkKg0gz-HCAex