Pass the Isaca Cloud Security Alliance CCAK Questions and answers with CertsForce

Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions
Questions # 51:

Which of the following is an example of reputational business impact?

Options:

A.

While the breach was reported in a timely manner to the CEO, the CFO and CISO blamed each other in public, resulting in a loss of public confidence that led the board to replace all three.


B.

The cloud provider fails to report a breach of customer personal data from an unsecured server, resulting in GDPR fines of 10 million euros.


C.

A distributed denial of service (DDoS) attack renders the customer’s cloud inaccessible for 24 hours, resulting in millions in lost sales.


D.

A hacker using a stolen administrator identity brings down the Software as a Service (SaaS) sales and marketing systems, resulting in the inability to process customer orders or manage customer relationships.


Questions # 52:

Which of the following types of SOC reports BEST helps to ensure operating effectiveness of controls in a cloud service provider offering?

Options:

A.

SOC 3 Type 2


B.

SOC 2 Type 2


C.

SOC 1 Type 1


D.

SOC 2 Type 1


Questions # 53:

Account design in the cloud should be driven by:

Options:

A.

business continuity policies.


B.

security requirements.


C.

management structure.


D.

organizational structure.


Questions # 54:

Which of the following is the GREATEST risk associated with hidden interdependencies between cloud services?

Options:

A.

The IT department does not clearly articulate the cloud to the organization.


B.

There is a lack of visibility over the cloud service providers' supply chain.


C.

Customers do not understand cloud technologies in enough detail.


D.

Cloud services are very complicated.


Questions # 55:

Under GDPR, an organization should report a data breach within what time frame?

Options:

A.

48 hours


B.

72 hours


C.

1 week


D.

2 weeks


Questions # 56:

An auditor identifies that a cloud service provider received multiple customer inquiries and requests for proposal (RFPs) during the last month. Which of the following

What should be the BEST recommendation to reduce the provider’s burden?

Options:

A.

The provider can answer each customer individually.


B.

The provider can direct all customer inquiries to the information in the CSA STAR registry.


C.

The provider can schedule a call with each customer.


D.

The provider can share all security reports with customers to streamline the process


Questions # 57:

One of the control specifications in the Cloud Controls Matrix (CCM) states that "independent reviews and assessments shall be performed at least annually to ensure that the organization addresses nonconformities of established policies, standards, procedures, and compliance obligation." Which of the following controls under the Audit Assurance and Compliance domain does this match to?

Options:

A.

Information system and regulatory mapping


B.

GDPR auditing


C.

Audit planning


D.

Independent audits


Questions # 58:

An organization that is utilizing a community cloud is contracting an auditor to conduct a review on behalf of the group of organizations within the cloud community. Of the following, to whom should the auditor report the findings?

Options:

A.

Management of the organization being audited


B.

Shareholders and interested parties


C.

Cloud service provider


D.

Public


Questions # 59:

An organization that is utilizing a community cloud is contracting an auditor to conduct a review on behalf of the group of organizations within the cloud community. Of the following, to whom should the auditor report the findings?

Options:

A.

Management of the organization being audited


B.

Public


C.

Shareholders and interested parties


D.

Cloud service provider


Questions # 60:

What type of termination occurs at the initiative of one party and without the fault of the other party?

Options:

A.

Termination without the fault


B.

Termination at the end of the term


C.

Termination for cause


D.

Termination for convenience


Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions