
Certification Training for CCAK Exam Dumps Test Engine [2021]
Aug 24, 2021 Step by Step Guide to Prepare for CCAK Exam
NEW QUESTION 34
Which data security control is the LEAST likely to be assigned to an IaaSprovider?
- A. Application logic
- B. Encryption solutions
- C. Physical destruction
- D. Asset management and tracking
- E. Access controls
Answer: A
NEW QUESTION 35
Which concept provides the abstraction needed for resource pools?
- A. Applistructure
- B. Hypervisor
- C. Virtualization
- D. Orchestration
- E. Metastructure
Answer: C
NEW QUESTION 36
Which of thefollowing items is NOT an example of Security as a Service (SecaaS)?
- A. Authentication
- B. Provisioning
- C. Intrusion detection
- D. Spam filtering
- E. Web filtering
Answer: B
NEW QUESTION 37
In volume storage, what method is often used to support resiliency and security?
- A. hypervisor agents
- B. random placement
- C. data dispersion
- D. data rights management
- E. proxy encryption
Answer: C
NEW QUESTION 38
If there are gaps in network logging data,what can you do?
- A. Nothing. The cloud provider must make the information available.
- B. Ask the cloud provider to open more ports.
- C. You can instrument the technology stack with your own logging.
- D. Nothing. There are simply limitations around the data that can be logged in the cloud.
- E. Ask the cloud provider to close more ports.
Answer: C
NEW QUESTION 39
How is encryption managed on multi-tenant storage?
- A. C for data subject to the EU Data Protection Directive; B for all others
- B. Multiple keys per data owner
- C. One key per data owner
- D. The answer could be A, B, or C depending on the provider
- E. Single key for all data owners
Answer: C
NEW QUESTION 40
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?
- A. Applistructure
- B. Datastructure
- C. Infostructure
- D. Infrastructure
- E. Metastructure
Answer: D
NEW QUESTION 41
Dynamic Application Security Testing (DAST) might be limited or require pre-testing permission from the provider.
- A. True
- B. False
Answer: A
NEW QUESTION 42
In which type of environment is it impractical to allow the customer to conduct their own audit, making it important that the data center operators are required to provide auditing for the customers?
- A. Long distance relationships
- B. Single tenantenvironments
- C. Multi-tenant environments
- D. Distributed computing arrangements
- E. Multi-application, single tenant environments
Answer: C
NEW QUESTION 43
ENISA: Lock-in is ranked as a high risk in ENISA research, a key underlying vulnerability causing lock in is:
- A. Unclear asset ownership
- B. Audit or certification not available to customers
- C. No source escrow agreement
- D. Lack of completeness and transparency in terms of use
- E. Lack of information onjurisdictions
Answer: D
NEW QUESTION 44
Segregation of duties would be compromised if:
- A. operations staff modified batch schedules.
- B. database administrators (DBAs) modified the structure of user tables.
- C. application programmers accessed test data.
- D. application programmers moved programs into production.
Answer: C
NEW QUESTION 45
To understand their compliance alignments and gaps with a cloud provider, what must cloud customers rely on?
- A. Provider and consumer contracts
- B. EDiscovery tools
- C. Third-party attestations
- D. Provider run audits and reports
- E. Provider documentation
Answer: C
NEW QUESTION 46
ENISA: A reason for risk concerns of a cloud provider being acquired is:
- A. Mass layoffs may occur
- B. Resource isolation may fail
- C. Provider may change physical location
- D. Non-binding agreements put at risk
- E. Arbitrary contract termination by acquiring company
Answer: D
NEW QUESTION 47
Select the best definition of"compliance" from the options below.
- A. The development of a routine that covers all necessary security measures.
- B. The diligent habits of good security practices and recording of the same.
- C. The awareness and adherence to obligations, including the assessment and prioritization of corrective actions deemed necessary and appropriate.
- D. The timely and efficient filing of security reports.
- E. The process of completing all forms and paperwork necessary to develop a defensible paper trail.
Answer: C
NEW QUESTION 48
During a review, an IS auditor notes that an organization's marketing department has purchased a cloud-based software application without following the procurement process. What should the auditor do FIRST?
- A. Escalate to senior management.
- B. Review the business impact analysis (BIA).
- C. Review the procurement process.
- D. Perform a risk analysis.
Answer: D
NEW QUESTION 49
Your SLA with your cloudprovider ensures continuity for all services.
- A. False
- B. True
Answer: A
NEW QUESTION 50
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:
- A. Platform as a Service (PaaS).
- B. Infrastructure as a Service (laaS).
- C. Identity as a Service (IDaaS).
- D. Software as a Service (SaaS).
Answer: A
NEW QUESTION 51
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?
- A. Risk Impact
- B. Domain
- C. Control Specification
Answer: B
NEW QUESTION 52
An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?
- A. Reviewing the request for proposal (RFP)
- B. verifying the weighting of each selection criteria
- C. Approving the vendor selection methodology
- D. Witnessing the vendor selection process
Answer: C
NEW QUESTION 53
An organization recently implemented a cloud document storage solution and removed the ability for end users to save data to their local workstation hard drives Which of the following findings should be the IS auditor's GREATEST concern?
- A. Mobile devices are not encrypted.
- B. Users have not been trained on the new system.
- C. Users are not required to sign updated acceptable
- D. The business continuity plan (BCP) was not updated.
Answer: D
NEW QUESTION 54
Cloud services exhibit fiveessential characteristics that demonstrate their relation to, and differences from, traditional computing approaches. Which one of the five characteristics is described as: a consumer can unilaterally provision computing capabilities such as server time and network storage as needed.
- A. On-demand self-service
- B. Measured service
- C. Broad network access
- D. Resource pooling
- E. Rapid elasticity
Answer: A
NEW QUESTION 55
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.
- A. control self-assessment (CSA)
- B. value chain analysis
- C. risk framework
- D. balanced scorecard
Answer: D
NEW QUESTION 56
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework
- A. Governance and Risk Management
- B. Governing and Risk Metrics
- C. Governance and Retention Management
Answer: A
NEW QUESTION 57
......
Ultimate Guide to Prepare CCAK Certification Exam for Cloud Security Alliance: https://www.itexamsimulator.com/CCAK-brain-dumps.html
Cloud Security Alliance CCAK Real Exam Questions and Answers FREE Updated: https://drive.google.com/open?id=1JmjuNVDq640SphaSz9xi8m4EBVejSwuP

