[Q21-Q44] Real ISACA CCAK Exam Questions [Updated 2021]

Share

Real ISACA CCAK Exam Questions [Updated 2021]

CCAK Exam Dumps Pass with Updated 2021 Certificate of Cloud Auditing Knowledge

NEW QUESTION 21
What is true of security as it relates to cloud network infrastructure?

  • A. You should always open traffic between workloads in the same virtual subnet for better visibility.
  • B. You should applycloud firewalls on a per-network basis.
  • C. You should implement a default allow with cloud firewalls and then restrict as necessary.
  • D. You should implement a default deny with cloud firewalls.
  • E. You should deploy your cloud firewalls identical to the existing firewalls.

Answer: D

 

NEW QUESTION 22
ENISA: Lock-in is ranked as a high risk in ENISA research, a key underlying vulnerability causing lock in is:

  • A. Lack of information onjurisdictions
  • B. Unclear asset ownership
  • C. Lack of completeness and transparency in terms of use
  • D. Audit or certification not available to customers
  • E. No source escrow agreement

Answer: C

 

NEW QUESTION 23
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?

  • A. None of the above.
  • B. More physical control over assets and processes.
  • C. Decreased requirement for proactive management of relationship and adherence to contracts.
  • D. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
  • E. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.

Answer: E

 

NEW QUESTION 24
Who is responsible for the security of the physical infrastructure and virtualization platform?

  • A. Itdepends on the agreement
  • B. The responsibility is split equally
  • C. The majority is covered by the consumer
  • D. The cloud consumer
  • E. The cloud provider

Answer: E

 

NEW QUESTION 25
Which of the following cloud deployment models would BEST meet the needs of a startup software development organization with limited initial capital?

  • A. Community
  • B. Private
  • C. Hybrid
  • D. Public

Answer: D

 

NEW QUESTION 26
Which of the following is the GREATEST concern associated with migrating computing resources to a cloud virtualized environment?

  • A. An increase in the number of e-discovery requests
  • B. An increase in the potential for data leakage
  • C. An increase in residual risk
  • D. An increase in inherent vulnerability

Answer: B

 

NEW QUESTION 27
Which statement best describes the impact of Cloud Computing on business continuity management?

  • A. A general lack of interoperability standards means that extra focus must be placed on the security aspects of migration between Cloud providers.
  • B. The size of data sets hosted at a Cloud provider can present challenges if migration to another provider becomesnecessary.
  • C. Customers of SaaS providers in particular need to mitigate the risks of application lock-in.
  • D. Clients need to do business continuity planning due diligence in case they suddenly need to switch providers.
  • E. Geographic redundancyensures that Cloud Providers provide highly available services.

Answer: E

 

NEW QUESTION 28
Big data includes high volume, high variety, and high velocity.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 29
An internal audit department recently established a quality assurance (QA) program as part of its overall audit program. Which of the following activities is MOST important to include as part of the QA program requirements?

  • A. Reporting OA program results to the audit committee
  • B. Analyzing user satisfaction reports from business lines
  • C. Benchmarking the QA framework to international standards
  • D. Conducting long-term planning for internal audit staffing

Answer: B

 

NEW QUESTION 30
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services fortracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document topotential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?

  • A. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
  • B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
  • C. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.

Answer: C

 

NEW QUESTION 31
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?

  • A. Resiliency Planning
  • B. Expected Engineering
  • C. Organized Downtime
  • D. Chaos Engineering
  • E. PlannedOutages

Answer: D

 

NEW QUESTION 32
ENISA: A reason for risk concerns of a cloud provider being acquired is:

  • A. Resource isolation may fail
  • B. Non-binding agreements put at risk
  • C. Arbitrary contract termination by acquiring company
  • D. Provider may change physical location
  • E. Mass layoffs may occur

Answer: B

 

NEW QUESTION 33
Which data security control is the LEAST likely to be assigned to an IaaSprovider?

  • A. Application logic
  • B. Encryption solutions
  • C. Access controls
  • D. Physical destruction
  • E. Asset management and tracking

Answer: A

 

NEW QUESTION 34
Which of the following should be the PRIMARY concern of an IS auditor during a review of an external IT service level agreement (SLA) for computer operations?

  • A. Lack of software escrow provisions
  • B. Changes in services are not tracked
  • C. Vendor has exclusive control of IT resources
  • D. No employee succession plan

Answer: B

 

NEW QUESTION 35
Select the best definition of"compliance" from the options below.

  • A. The awareness and adherence to obligations, including the assessment and prioritization of corrective actions deemed necessary and appropriate.
  • B. The timely and efficient filing of security reports.
  • C. The diligent habits of good security practices and recording of the same.
  • D. The development of a routine that covers all necessary security measures.
  • E. The process of completing all forms and paperwork necessary to develop a defensible paper trail.

Answer: A

 

NEW QUESTION 36
Which attack surfaces, if any, does virtualization technology introduce?

  • A. All of the above
  • B. The hypervisor
  • C. Configuration and VM sprawl issues
  • D. Virtualization management components apart from the hypervisor

Answer: A

 

NEW QUESTION 37
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?

  • A. Applistructure
  • B. Infostructure
  • C. Metastructure
  • D. Infrastructure
  • E. Datastructure

Answer: D

 

NEW QUESTION 38
If there are gaps in network logging data,what can you do?

  • A. Ask the cloud provider to open more ports.
  • B. Nothing. There are simply limitations around the data that can be logged in the cloud.
  • C. You can instrument the technology stack with your own logging.
  • D. Nothing. The cloud provider must make the information available.
  • E. Ask the cloud provider to close more ports.

Answer: C

 

NEW QUESTION 39
In which type of environment is it impractical to allow the customer to conduct their own audit, making it important that the data center operators are required to provide auditing for the customers?

  • A. Distributed computing arrangements
  • B. Long distance relationships
  • C. Multi-application, single tenant environments
  • D. Single tenantenvironments
  • E. Multi-tenant environments

Answer: E

 

NEW QUESTION 40
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 41
How does running applications on distinct virtual networks and only connecting networksas needed help?

  • A. It reduces hardware costs
  • B. It provides dynamic and granular policies with less management overhead
  • C. It enables you to configure applications around business groups
  • D. It reduces the blast radius of a compromised system
  • E. It locks down access and provides stronger data security

Answer: D

 

NEW QUESTION 42
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:

  • A. Infrastructure as a Service (laaS).
  • B. Platform as a Service (PaaS).
  • C. Identity as a Service (IDaaS).
  • D. Software as a Service (SaaS).

Answer: B

 

NEW QUESTION 43
Which of thefollowing items is NOT an example of Security as a Service (SecaaS)?

  • A. Intrusion detection
  • B. Provisioning
  • C. Web filtering
  • D. Authentication
  • E. Spam filtering

Answer: B

 

NEW QUESTION 44
......

CCAK Exam Dumps, CCAK Practice Test Questions: https://www.examslabs.com/ISACA/Cloud-Security-Alliance/best-CCAK-exam-dumps.html

Free CCAK Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=150XFAtzCXV1MrBi6wEp2GapFnMDgUkp3