2021 CCAK Question Bank Free PDF Download Recently Updated Questions [Q27-Q47]

Share

2021 CCAK Question Bank: Free PDF Download Recently Updated Questions

CCAK Certification Exam Dumps with 78 Practice Test Questions

NEW QUESTION 27
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:

  • A. Infrastructure as a Service (laaS).
  • B. Platform as a Service (PaaS).
  • C. Identity as a Service (IDaaS).
  • D. Software as a Service (SaaS).

Answer: B

 

NEW QUESTION 28
All cloud services utilize virtualization technologies.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 29
Select the best definition of"compliance" from the options below.

  • A. The awareness and adherence to obligations, including the assessment and prioritization of corrective actions deemed necessary and appropriate.
  • B. The timely and efficient filing of security reports.
  • C. The diligent habits of good security practices and recording of the same.
  • D. The development of a routine that covers all necessary security measures.
  • E. The process of completing all forms and paperwork necessary to develop a defensible paper trail.

Answer: A

 

NEW QUESTION 30
An internal audit department recently established a quality assurance (QA) program as part of its overall audit program. Which of the following activities is MOST important to include as part of the QA program requirements?

  • A. Reporting OA program results to the audit committee
  • B. Analyzing user satisfaction reports from business lines
  • C. Benchmarking the QA framework to international standards
  • D. Conducting long-term planning for internal audit staffing

Answer: B

 

NEW QUESTION 31
Your SLA with your cloudprovider ensures continuity for all services.

  • A. True
  • B. False

Answer: B

 

NEW QUESTION 32
Dynamic Application Security Testing (DAST) might be limited or require pre-testing permission from the provider.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 33
How is encryption managed on multi-tenant storage?

  • A. Single key for all data owners
  • B. The answer could be A, B, or C depending on the provider
  • C. C for data subject to the EU Data Protection Directive; B for all others
  • D. Multiple keys per data owner
  • E. One key per data owner

Answer: E

 

NEW QUESTION 34
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?

  • A. Domain
  • B. Risk Impact
  • C. Control Specification

Answer: A

 

NEW QUESTION 35
Sending data to a provider's storage over an API is likely as much morereliable and secure than setting up your own SFTP server on a VM in the same provider

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 36
What is true of searching data across cloud environments?

  • A. All cloud-hosted email accounts are easily searchable.
  • B. You can easily search across your environment using any E-Discovery tool.
  • C. Search and discovery time is alwaysfactored into a contract between the consumer and provider.
  • D. You might not have the ability oradministrative rights to search or access all hosted data.
  • E. The cloud provider must conduct the search with the full administrative controls.

Answer: D

 

NEW QUESTION 37
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?

  • A. The proper authorities were not notified.
  • B. The investigation report does not indicate a conclusion.
  • C. The handling procedures of the attacked system are not documented.
  • D. An image copy of the attacked system was not taken.

Answer: A

 

NEW QUESTION 38
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.

  • A. risk framework
  • B. value chain analysis
  • C. control self-assessment (CSA)
  • D. balanced scorecard

Answer: D

 

NEW QUESTION 39
How can virtual machine communications bypass network security controls?

  • A. Hypervisors depend upon multiple network interfaces
  • B. The guest OS can invoke stealth mode
  • C. Most network security systems do not recognize encrypted VM traffic
  • D. VM communications may use a virtual network on the same hardware host
  • E. VM images can contain rootkits programmed to bypass firewalls

Answer: D

 

NEW QUESTION 40
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services fortracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document topotential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?

  • A. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
  • B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
  • C. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.

Answer: C

 

NEW QUESTION 41
Which statement best describes the impact of Cloud Computing on business continuity management?

  • A. A general lack of interoperability standards means that extra focus must be placed on the security aspects of migration between Cloud providers.
  • B. The size of data sets hosted at a Cloud provider can present challenges if migration to another provider becomesnecessary.
  • C. Customers of SaaS providers in particular need to mitigate the risks of application lock-in.
  • D. Clients need to do business continuity planning due diligence in case they suddenly need to switch providers.
  • E. Geographic redundancyensures that Cloud Providers provide highly available services.

Answer: E

 

NEW QUESTION 42
What is resource pooling?

  • A. None of the above.
  • B. Internet-based CPUs are pooled to enable multi-threading.
  • C. The provider's computing resources are pooled to serve multiple consumers.
  • D. The dedicated computing resources of each client are pooled together in a colocation facility.
  • E. Placing Internet ("cloud") data centers near multiple sources of energy, such as hydroelectric dams.

Answer: C

 

NEW QUESTION 43
If there are gaps in network logging data,what can you do?

  • A. Ask the cloud provider to open more ports.
  • B. Nothing. There are simply limitations around the data that can be logged in the cloud.
  • C. You can instrument the technology stack with your own logging.
  • D. Nothing. The cloud provider must make the information available.
  • E. Ask the cloud provider to close more ports.

Answer: C

 

NEW QUESTION 44
Big data includes high volume, high variety, and high velocity.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 45
A third-party service provider is hosting a private cloud for an organization. Which of the following findings during an audit of the provider poses the GREATEST risk to the organization?

  • A. Two different hypervisor versions are used due to the compatibility restrictions of some virtual machines.
  • B. 2% of backups had to be rescheduled due to backup media failures.
  • C. The organization's virtual machines share the same hypervisor with virtual machines of other clients.
  • D. 5% of detected incidents exceeded the defined service level agreement (SLA) for escalation.

Answer: C

 

NEW QUESTION 46
Which governance domain deals with evaluating how cloudcomputing affects compliance with internal security policies and various legal requirements, such as regulatory and legislative?

  • A. Infrastructure Security
  • B. Legal Issues: Contracts and Electronic Discovery
  • C. Information Governance
  • D. Governance and Enterprise Risk Management
  • E. Compliance and Audit Management

Answer: E

 

NEW QUESTION 47
......

New CCAK Exam Dumps with High Passing Rate: https://www.actualvce.com/ISACA/CCAK-valid-vce-dumps.html

ISACA CCAK Actual Questions and Braindumps: https://drive.google.com/open?id=1Gch__2tv31gRlcHO49Gx3obZU3hXfPCN