
Download the Latest CCAK Dumps - 2022 CCAK Exam Questions
Latest ISACA CCAK Certification Practice Test Questions
NEW QUESTION 41
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?
- A. Platform
- B. Object storage
- C. Application
- D. Volume storage
- E. Database
Answer: D
NEW QUESTION 42
What factors should you understand about the data specifically due to legal, regulatory, and jurisdictional factors?
- A. The actualsize of the data and the storage format
- B. The language of the data and how it affects the user
- C. The fragmentation and encryption algorithms employed
- D. The implications of storing complex information on simple storage systems
- E. Thephysical location of the data and how it is accessed
Answer: D
NEW QUESTION 43
If there are gaps in network logging data,what can you do?
- A. Ask the cloud provider to open more ports.
- B. Nothing. There are simply limitations around the data that can be logged in the cloud.
- C. You can instrument the technology stack with your own logging.
- D. Nothing. The cloud provider must make the information available.
- E. Ask the cloud provider to close more ports.
Answer: C
NEW QUESTION 44
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?
- A. Infrastructure-as-a-service (IaaS)
- B. Identity-as-a-service (IDaaS)
- C. Software-as-a-service (SaaS)
- D. Platform-as-a-service (PaaS)
- E. Desktop-as-a-service (DaaS)
Answer: D
NEW QUESTION 45
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework
- A. Governance and Retention Management
- B. Governance and Risk Management
- C. Governing and Risk Metrics
Answer: B
NEW QUESTION 46
What item below allows disparate directory services and independent security domains to be interconnected?
- A. Intersection
- B. Cloud
- C. Federation
- D. Union
- E. Coalition
Answer: C
NEW QUESTION 47
Which of the following is the GREATEST concern associated with migrating computing resources to a cloud virtualized environment?
- A. An increase in the number of e-discovery requests
- B. An increase in the potential for data leakage
- C. An increase in residual risk
- D. An increase in inherent vulnerability
Answer: B
NEW QUESTION 48
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?
- A. Applistructure
- B. Infostructure
- C. Metastructure
- D. Infrastructure
- E. Datastructure
Answer: D
NEW QUESTION 49
What is known as a code execution environment running within an operating system that shares and uses the resources of the operating system?
- A. Platform-basedWorkload
- B. Abstraction
- C. Container
- D. Virtual machine
- E. Pod
Answer: C
NEW QUESTION 50
What is true of searching data across cloud environments?
- A. All cloud-hosted email accounts are easily searchable.
- B. You can easily search across your environment using any E-Discovery tool.
- C. Search and discovery time is alwaysfactored into a contract between the consumer and provider.
- D. You might not have the ability oradministrative rights to search or access all hosted data.
- E. The cloud provider must conduct the search with the full administrative controls.
Answer: D
NEW QUESTION 51
Who is responsible for the security of the physical infrastructure and virtualization platform?
- A. Itdepends on the agreement
- B. The responsibility is split equally
- C. The majority is covered by the consumer
- D. The cloud consumer
- E. The cloud provider
Answer: E
NEW QUESTION 52
When deploying Security as a Service in a highly regulated industry or environment, what should bothparties agree on in advance and include in the SLA?
- A. The duration of time that a security violation can occur before the client begins assessing regulatory fines.
- B. The type of security software which meets regulations and the number of licenses that will be needed.
- C. The cost per incident for security breaches of regulated information.
- D. The regulations that are pertinent to the contract and how to circumvent them.
- E. The metrics defining the service level required to achieve regulatory objectives.
Answer: E
NEW QUESTION 53
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?
- A. Domain
- B. Risk Impact
- C. Control Specification
Answer: A
NEW QUESTION 54
Sending data to a provider's storage over an API is likely as much morereliable and secure than setting up your own SFTP server on a VM in the same provider
- A. True
- B. False
Answer: A
NEW QUESTION 55
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.
- A. risk framework
- B. value chain analysis
- C. control self-assessment (CSA)
- D. balanced scorecard
Answer: D
NEW QUESTION 56
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:
- A. Infrastructure as a Service (laaS).
- B. Platform as a Service (PaaS).
- C. Identity as a Service (IDaaS).
- D. Software as a Service (SaaS).
Answer: B
NEW QUESTION 57
Big data includes high volume, high variety, and high velocity.
- A. True
- B. False
Answer: A
NEW QUESTION 58
Which concept is a mapping of an identity, including roles, personas, and attributes, to an authorization?
- A. Entitlement
- B. Authoritative source
- C. Authentication
- D. Federated Identity Management
- E. Access control
Answer: A
NEW QUESTION 59
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
- A. URL filters
- B. Cloud Access and Security Brokers (CASB)
- C. Database Activity Monitoring
- D. Intrusion Prevention System
- E. Data Loss Prevention
Answer: D
NEW QUESTION 60
Select the best definition of"compliance" from the options below.
- A. The awareness and adherence to obligations, including the assessment and prioritization of corrective actions deemed necessary and appropriate.
- B. The timely and efficient filing of security reports.
- C. The diligent habits of good security practices and recording of the same.
- D. The development of a routine that covers all necessary security measures.
- E. The process of completing all forms and paperwork necessary to develop a defensible paper trail.
Answer: A
NEW QUESTION 61
......
Verified CCAK Dumps Q&As - 1 Year Free & Quickly Updates: https://www.exam-killer.com/CCAK-valid-questions.html
Get 2022 Updated Free ISACA CCAK Exam Questions & Answer: https://drive.google.com/open?id=1eG9L6TPmO4nkak96wkOR9dwt7EeCcvub

