[Oct 18, 2021] Step by Step Guide to Prepare for CCAK Exam BrainDumps [Q46-Q61]

Share

Oct 18, 2021 Step by Step Guide to Prepare for CCAK Exam BrainDumps

Cloud Security Alliance CCAK Real Exam Questions and Answers FREE Updated on 2021

NEW QUESTION 46
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services fortracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document topotential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?

  • A. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.
  • B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
  • C. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.

Answer: A

 

NEW QUESTION 47
Select the best definition of"compliance" from the options below.

  • A. The development of a routine that covers all necessary security measures.
  • B. The diligent habits of good security practices and recording of the same.
  • C. The awareness and adherence to obligations, including the assessment and prioritization of corrective actions deemed necessary and appropriate.
  • D. The timely and efficient filing of security reports.
  • E. The process of completing all forms and paperwork necessary to develop a defensible paper trail.

Answer: C

 

NEW QUESTION 48
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.

  • A. control self-assessment (CSA)
  • B. value chain analysis
  • C. risk framework
  • D. balanced scorecard

Answer: D

 

NEW QUESTION 49
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?

  • A. Risk Impact
  • B. Domain
  • C. Control Specification

Answer: B

 

NEW QUESTION 50
What is known as a code execution environment running within an operating system that shares and uses the resources of the operating system?

  • A. Abstraction
  • B. Container
  • C. Platform-basedWorkload
  • D. Pod
  • E. Virtual machine

Answer: B

 

NEW QUESTION 51
Sending data to a provider's storage over an API is likely as much morereliable and secure than setting up your own SFTP server on a VM in the same provider

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 52
Which of the following is the GREATEST security risk associated with data migration from a legacy human resources (HR) system to a cloud-based system''

  • A. Data from the source and target system may have different data formats
  • B. Records past their retention period may not be migrated to the new system
  • C. System performance may be impacted by the migration
  • D. Data from the source and target system may be intercepted

Answer: D

 

NEW QUESTION 53
Which attack surfaces, if any, does virtualization technology introduce?

  • A. All of the above
  • B. The hypervisor
  • C. Configuration and VM sprawl issues
  • D. Virtualization management components apart from the hypervisor

Answer: A

 

NEW QUESTION 54
Network logs from cloud providers are typically flow records, not full packet captures.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 55
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?

  • A. Applistructure
  • B. Datastructure
  • C. Infostructure
  • D. Infrastructure
  • E. Metastructure

Answer: D

 

NEW QUESTION 56
ENISA: "VMhopping" is:

  • A. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
  • B. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.
  • C. Looping within virtualized routing systems.
  • D. Lack of vulnerability management standards.
  • E. Instability in VM patch management causing VM routing errors.

Answer: B

 

NEW QUESTION 57
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?

  • A. Application
  • B. Object storage
  • C. Platform
  • D. Database
  • E. Volume storage

Answer: E

 

NEW QUESTION 58
Which of the following would be MOST important to update once a decision has been made to outsource a critical application to a cloud service provider?

  • A. IT budget
  • B. Business impact analysis (BIA)
  • C. Project portfolio
  • D. IT resource plan

Answer: B

 

NEW QUESTION 59
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework

  • A. Governance and Risk Management
  • B. Governing and Risk Metrics
  • C. Governance and Retention Management

Answer: A

 

NEW QUESTION 60
What is true of searching data across cloud environments?

  • A. You might not have the ability oradministrative rights to search or access all hosted data.
  • B. The cloud provider must conduct the search with the full administrative controls.
  • C. Search and discovery time is alwaysfactored into a contract between the consumer and provider.
  • D. You can easily search across your environment using any E-Discovery tool.
  • E. All cloud-hosted email accounts are easily searchable.

Answer: A

 

NEW QUESTION 61
......

Ultimate Guide to Prepare CCAK Certification Exam for Cloud Security Alliance: https://www.examslabs.com/ISACA/Cloud-Security-Alliance/best-CCAK-exam-dumps.html

CCAK Ultimate Study Guide: https://drive.google.com/open?id=1y0OEsM8UiuyFXHsdK1916zPSum6WVgS2