Pass the Isaca Cloud Security Alliance CCAK Questions and answers with CertsForce

Viewing page 5 out of 7 pages
Viewing questions 41-50 out of questions
Questions # 41:

"Network environments and virtual instances shall be designed and configured to restrict and monitor traffic between trusted and untrusted connections. These configurations shall be reviewed at least annually, and supported by a documented justification for use for all allowed services, protocols, ports, and by compensating controls." Which of the following types of controls BEST matches this control description?

Options:

A.

Virtual instance and OS hardening


B.

Network security


C.

Network vulnerability management


D.

Change detection


Questions # 42:

Which of the following can be used to determine whether access keys are stored in the source code or any other configuration files during development?

Options:

A.

Static code review


B.

Dynamic code review


C.

Vulnerability scanning


D.

Credential scanning


Questions # 43:

A cloud auditor should use statistical sampling rather than judgment (nonstatistical) sampling when:

Options:

A.

generalized audit software is unavailable.


B.

the auditor wants to avoid sampling risk.


C.

the probability of error must be objectively quantified.


D.

the tolerable error rate cannot be determined.


Questions # 44:

Which industry organization offers both security controls and cloud-relevant benchmarking?

Options:

A.

Cloud Security Alliance (CSA)


B.

SANS Institute


C.

International Organization for Standardization (ISO)


D.

Center for Internet Security (CIS)


Questions # 45:

"Policies and procedures shall be established, and supporting business processes and technical measures implemented, for maintenance of several items ensuring continuity and availability of operations and support personnel." Which of the following types of controls BEST matches this control description?

Options:

A.

System development maintenance


B.

Operations maintenance


C.

System maintenance


D.

Equipment maintenance


Questions # 46:

In a multi-level supply chain structure where cloud service provider A relies on other sub cloud services, the provider should ensure that any compliance requirements relevant to the provider are:

Options:

A.

treated as confidential information and withheld from all sub cloud service providers.


B.

treated as sensitive information and withheld from certain sub cloud service providers.


C.

passed to the sub cloud service providers.


D.

passed to the sub cloud service providers based on the sub cloud service providers' geographic location.


Questions # 47:

Which of the following is the BEST recommendation to offer an organization's HR department planning to adopt a new public Software as a Service (SaaS) application to ease the recruiting process?

Options:

A.

Implement a cloud access security broker (CASB).


B.

Do not allow data to be in clear text.


C.

Ensure HIPAA compliance.


D.

Consult the legal department.


Questions # 48:

Which of the following MOST enhances the internal stakeholder decision-making process for the remediation of risks identified from an organization's cloud compliance program?

Options:

A.

Establishing ownership and accountability


B.

Reporting emerging threats to senior stakeholders


C.

Monitoring key risk indicators (KRIs) for multi-cloud environments


D.

Automating risk monitoring and reporting processes


Questions # 49:

Organizations maintain mappings between the different control frameworks they adopt to:

Options:

A.

help identify controls with common assessment status.


B.

avoid duplication of work when assessing compliance,


C.

help identify controls with different assessment status.


D.

start a compliance assessment using the latest assessment.


Questions # 50:

A cloud service provider contracts for a penetration test to be conducted on its infrastructures. The auditor engages the target with no prior knowledge of its defenses, assets, or channels. The provider's security operation center is not notified in advance of the scope of the audit and the test vectors. Which mode has been selected by the provider?

Options:

A.

Reversal


B.

Double blind


C.

Double gray box


D.

Tandem


Viewing page 5 out of 7 pages
Viewing questions 41-50 out of questions