ISACA Certificate of Cloud Auditing Knowledge - CCAK Exam Practice Test
The three layers of Open Certification Framework (OCF) PRIMARILY help cloud service providers and cloud clients improve the level of:
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which of the following enables auditors to conduct gap analyses of what a cloud service provider offers versus what the customer requires?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
"Policies and procedures shall be established, and supporting business processes and technical measures implemented, for maintenance of several items ensuring continuity and availability of operations and support personnel." Which of the following types of controls BEST matches this control description?
Correct Answer: C
Which of the following is a KEY benefit of using the Cloud Controls Matrix (CCM)?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Regarding suppliers of a cloud service provider, it is MOST important for the auditor to be aware that the:
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A cloud service provider utilizes services of other service providers for its cloud service. Which of the following is the BEST approach for the auditor while performing the audit for the cloud service?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which of the following types of SOC reports BEST helps to ensure operating effectiveness of controls in a cloud service provider offering?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
To BEST prevent a data breach from happening, cryptographic keys should be:
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
The BEST way to deliver continuous compliance in a cloud environment is to:
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
Which of the following is a KEY benefit of using the Cloud Controls Matrix (CCM)?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
The CSA STAR Certification is based on criteria outlined the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) in addition to:
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).