
New 2021 Guaranteed Success with Real4Prep CCAK Dumps ISACA PDF Questions
Exceptional Practice To Certificate of Cloud Auditing Knowledge Pass the First Time
NEW QUESTION 31
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services fortracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document topotential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?
- A. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.
- B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
- C. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
Answer: A
NEW QUESTION 32
How does virtualized storage help avoid data loss if a drive fails?
- A. Drives are backed up, swapped, and archived constantly
- B. Data loss is unavoidable with drive failures
- C. Full back ups weekly
- D. Multiple copies indifferent locations
- E. Incremental backups daily
Answer: D
NEW QUESTION 33
Which data security control is the LEAST likely to be assigned to an IaaSprovider?
- A. Application logic
- B. Encryption solutions
- C. Physical destruction
- D. Asset management and tracking
- E. Access controls
Answer: A
NEW QUESTION 34
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.
- A. control self-assessment (CSA)
- B. value chain analysis
- C. risk framework
- D. balanced scorecard
Answer: D
NEW QUESTION 35
Your SLA with your cloudprovider ensures continuity for all services.
- A. False
- B. True
Answer: A
NEW QUESTION 36
Which concept is a mapping of an identity, including roles, personas, and attributes, to an authorization?
- A. Access control
- B. Authentication
- C. Federated Identity Management
- D. Entitlement
- E. Authoritative source
Answer: D
NEW QUESTION 37
An important consideration when performing a remote vulnerability test of a cloud-based application is to
- A. Obtain provider permission for test
- B. Use application layer testing tools exclusively
- C. Schedule vulnerability test at night
- D. Use network layer testing tools exclusively
- E. Use techniques to evade cloud provider's detection systems
Answer: A
NEW QUESTION 38
Which statement best describes the impact of Cloud Computing on business continuity management?
- A. Geographic redundancyensures that Cloud Providers provide highly available services.
- B. Clients need to do business continuity planning due diligence in case they suddenly need to switch providers.
- C. The size of data sets hosted at a Cloud provider can present challenges if migration to another provider becomesnecessary.
- D. A general lack of interoperability standards means that extra focus must be placed on the security aspects of migration between Cloud providers.
- E. Customers of SaaS providers in particular need to mitigate the risks of application lock-in.
Answer: A
NEW QUESTION 39
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?
- A. More physical control over assets and processes.
- B. None of the above.
- C. Decreased requirement for proactive management of relationship and adherence to contracts.
- D. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
- E. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.
Answer: E
NEW QUESTION 40
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:
- A. Platform as a Service (PaaS).
- B. Infrastructure as a Service (laaS).
- C. Identity as a Service (IDaaS).
- D. Software as a Service (SaaS).
Answer: A
NEW QUESTION 41
Why is a service type of network typically isolated on different hardware?
- A. It manages resource pools for cloud consumers
- B. It manages the traffic between other networks
- C. It requires distinct access controls
- D. It has distinct functions from other networks
- E. It requires unique security
Answer: B
NEW QUESTION 42
Big data includes high volume, high variety, and high velocity.
- A. True
- B. False
Answer: A
NEW QUESTION 43
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
- A. URL filters
- B. Database Activity Monitoring
- C. Data Loss Prevention
- D. Cloud Access and Security Brokers (CASB)
- E. Intrusion Prevention System
Answer: E
NEW QUESTION 44
If there are gaps in network logging data,what can you do?
- A. Nothing. The cloud provider must make the information available.
- B. Ask the cloud provider to open more ports.
- C. You can instrument the technology stack with your own logging.
- D. Nothing. There are simply limitations around the data that can be logged in the cloud.
- E. Ask the cloud provider to close more ports.
Answer: C
NEW QUESTION 45
An organization recently implemented a cloud document storage solution and removed the ability for end users to save data to their local workstation hard drives Which of the following findings should be the IS auditor's GREATEST concern?
- A. Mobile devices are not encrypted.
- B. Users have not been trained on the new system.
- C. Users are not required to sign updated acceptable
- D. The business continuity plan (BCP) was not updated.
Answer: D
NEW QUESTION 46
Who is responsible for the security of the physical infrastructure and virtualization platform?
- A. The cloud provider
- B. The responsibility is split equally
- C. The majority is covered by the consumer
- D. Itdepends on the agreement
- E. The cloud consumer
Answer: A
NEW QUESTION 47
......
CCAK EXAM DUMPS WITH GUARANTEED SUCCESS: https://www.real4prep.com/CCAK-exam.html
Best Quality ISACA CCAK Exam Questions: https://drive.google.com/open?id=1rTghRZl6wGmw69R5rQr6UFW-oSUv4u9I