
2023 CCAK Question Bank: Free PDF Download Recently Updated Questions
CCAK Certification Exam Dumps with 128 Practice Test Questions
NEW QUESTION 63
Which of the following is the GREATEST security risk associated with data migration from a legacy human resources (HR) system to a cloud-based system''
- A. System performance may be impacted by the migration
- B. Data from the source and target system may have different data formats
- C. Records past their retention period may not be migrated to the new system
- D. Data from the source and target system may be intercepted
Answer: D
NEW QUESTION 64
Which of the following is the MOST important audit scope document when conducting a review of a cloud service provider?
- A. Updated audit/work program
- B. Documentation criteria for the audit evidence
- C. Testing procedure to be performed
- D. Processes and systems to be audited
Answer: B
NEW QUESTION 65
Which of thefollowing items is NOT an example of Security as a Service (SecaaS)?
- A. Spam filtering
- B. Provisioning
- C. Authentication
- D. Intrusion detection
- E. Web filtering
Answer: B
NEW QUESTION 66
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?
- A. Software-as-a-service (SaaS)
- B. Desktop-as-a-service (DaaS)
- C. Identity-as-a-service (IDaaS)
- D. Infrastructure-as-a-service (IaaS)
- E. Platform-as-a-service (PaaS)
Answer: E
NEW QUESTION 67
Which of the following is MOST important to consider when an organization is building a compliance program for the cloud?
- A. Cloud providers should not be part of the compliance program.
- B. The rapidly changing service portfolio and architecture of the cloud.
- C. The cloud is similar to the on-premise environment in terms of compliance.
- D. The fairly static nature of the service portfolio and architecture of the cloud.
Answer: B
NEW QUESTION 68
The Cloud Computing Compliance Controls Catalogue (C5) framework is maintained by which of the following agencies?
- A. Agence nationale de la securite des systemes d'information (ANSSI)
- B. National Security Agency (NSA)
- C. National Institute of Standards and Technology (NIST)
- D. Bundesamt fur Sicherheit in der Informationstechnik (BSI)
Answer: D
NEW QUESTION 69
Which of the following metrics are frequently immature?
- A. Metrics around Infrastructure as a Service (IaaS) computing environments
- B. Metrics around specific Software as a Service (SaaS) application services
- C. Metrics around Platform as a Service (PaaS) development environments
- D. Metrics around Infrastructure as a Service (IaaS) storage and network environments
Answer: D
NEW QUESTION 70
To qualify for CSA STAR attestation for a particular cloud system, the SOC 2 report must cover:
- A. all Cloud Control Matrix (CCM) controls and TSPC security principles.
- B. Cloud Control Matrix (CCM) and ISO/IEC 27001:2013 controls.
- C. maturity model criteria.
- D. ISO/I 27001: 2013 controls.
Answer: A
NEW QUESTION 71
Which concept provides the abstraction needed for resource pools?
- A. Virtualization
- B. Hypervisor
- C. Orchestration
- D. Metastructure
- E. Applistructure
Answer: A
NEW QUESTION 72
Which of the following approaches encompasses social engineering of staff, bypassing of physical access controls and penetration testing?
- A. Gray box
- B. Blue team
- C. Red team
- D. White box
Answer: D
NEW QUESTION 73
Which of the following has the MOST substantial impact on how aggressive or conservative the cloud approach of an organization will be?
- A. Risk appetite and budget constraints
- B. Applicable laws and regulations
- C. Risk scoring criteria
- D. Internal policies and technical standards
Answer: B
NEW QUESTION 74
What is defined as the process by which an opposing party may obtain private documents for use in litigation?
- A. Risk Assessment
- B. Subpoena
- C. Scope
- D. Custody
- E. Discovery
Answer: E
NEW QUESTION 75
Which of the following data destruction methods is the MOST effective and efficient?
- A. Multi-pass wipes
- B. Physical destruction
- C. Crypto-shredding
- D. Degaussing
Answer: D
NEW QUESTION 76
The Open Certification Framework is structured on three levels of trust. Those three levels of trust are:
- A. CSA STAR Self-Assessment, STAR Certification & Attestation (Third-party Assessment), STAR Compliance
- B. CSA STAR Self-Assessment, STAR Certification & Attestation (Third-party Assessment), STAR Monitoring and Control
- C. CSA STAR Self-Assessment, STAR Certification & Attestation (Third-party Assessment), STAR Continuous
- D. CSA STAR Audit, STAR Certification & Attestation (Third-party Assessment), STAR Continuous
Answer: C
NEW QUESTION 77
What type of termination occurs at the initiative of one party, and without the fault of the other party?
- A. Termination for cause
- B. Termination for convenience
- C. Termination without the fault
- D. Termination at the end of the term
Answer: D
NEW QUESTION 78
Which of the following is an example of financial business impact?
- A. While the breach was reported in a timely manner to the CEO, the CFO and CISO blamed each other in public, resulting in a loss of public confidence that led the board to replace all three.
- B. A hacker using a stolen administrator identity brings down the SaaS sales and marketing systems, resulting in the inability to process customer orders or manage customer relationships.
- C. A DDoS attack renders the customer's cloud inaccessible for 24 hours resulting in millions in lost sales.
- D. The cloud provider fails to report a breach of customer personal data from an unsecured server, resulting in GDPR fines of 10 million euro.
Answer: C
NEW QUESTION 79
Which of the following key stakeholders should be identified the earliest when an organization is designing a cloud compliance program?
- A. Cloud strategy owners
- B. Legal functions
- C. Internal control function
- D. Cloud process owners
Answer: D
NEW QUESTION 80
Which governance domain deals with evaluating how cloudcomputing affects compliance with internal security policies and various legal requirements, such as regulatory and legislative?
- A. Infrastructure Security
- B. Compliance and Audit Management
- C. Information Governance
- D. Legal Issues: Contracts and Electronic Discovery
- E. Governance and Enterprise Risk Management
Answer: B
NEW QUESTION 81
The PRIMARY objective of an audit initiation meeting with a cloud audit client is to:
- A. discuss the scope of the cloud audit.
- B. review requested evidence provided by the audit client.
- C. identify resource requirements of the cloud audit.
- D. select the methodology of an audit.
Answer: A
NEW QUESTION 82
Which of the following is an example of a corrective control?
- A. All new employees having standard access rights until their manager approves privileged rights
- B. Privileged access to critical information systems requiring a second factor of authentication using soft token
- C. A central anti-virus system installing the latest signature files before allowing a connection to the network
- D. Unsuccessful access attempts being automatically logged for investigation
Answer: B
NEW QUESTION 83
Which of the following is the BEST control framework for a European manufacturing corporation that is migrating to the cloud?
- A. CSA's GDPR CoC
- B. NIST SP 800-53
- C. EU GDPR
- D. PCI-DSS
Answer: C
NEW QUESTION 84
Which statement best describes why it is important to know how data is being accessed?
- A. The devices used to access data use a variety of applications or clients and may have different security characteristics.
- B. The devices used to access data have different storage formats.
- C. The devices used to access data may have differentownership characteristics.
- D. The devices used to access data use a variety of operating systems and may have different programs installed on them.
- E. The device may affect data dispersion.
Answer: A
NEW QUESTION 85
A third-party service provider is hosting a private cloud for an organization. Which of the following findings during an audit of the provider poses the GREATEST risk to the organization?
- A. 2% of backups had to be rescheduled due to backup media failures.
- B. 5% of detected incidents exceeded the defined service level agreement (SLA) for escalation.
- C. The organization's virtual machines share the same hypervisor with virtual machines of other clients.
- D. Two different hypervisor versions are used due to the compatibility restrictions of some virtual machines.
Answer: C
NEW QUESTION 86
......
New CCAK Exam Dumps with High Passing Rate: https://www.itpassleader.com/ISACA/CCAK-dumps-pass-exam.html
ISACA CCAK Actual Questions and Braindumps: https://drive.google.com/open?id=1SlW7A_RsaO-4xctz67MfYKX7_fmsd0y7