Practice with CCAK Dumps for Cloud Security Alliance Certified Exam Questions & Answer [Q63-Q80]

Share

Practice with CCAK Dumps for Cloud Security Alliance Certified Exam Questions & Answer

REAL CCAK Exam Questions With 100% Refund Guarantee

NEW QUESTION # 63
When an organization is using cloud services, the security responsibilities largely vary depending on the service delivery model used, while the accountability for compliance should remain with the:

  • A. certification authority (CA)
  • B. cloud user.
  • C. cloud service provider. 0
  • D. cloud customer.

Answer: D

Explanation:
Explanation
According to the ISACA Cloud Auditing Knowledge Certificate Study Guide, the cloud customer is the entity that retains accountability for the business outcome of the system or the processes that are supported by the cloud service1. The cloud customer is also responsible for ensuring that the cloud service meets the legal, regulatory, and contractual obligations that apply to the customer's business context1. The cloud customer should also perform due diligence and risk assessment before selecting a cloud service provider, and establish a clear and enforceable contract that defines the roles and responsibilities of both parties1.
The cloud user is the entity that uses the cloud service on behalf of the cloud customer, but it is not necessarily accountable for the compliance of the service1. The cloud service provider is the entity that makes the cloud service available to the cloud customer, but it is not accountable for the compliance of the customer's business context1. The certification authority (CA) is an entity that issues digital certificates to verify the identity or authenticity of other entities, but it is not accountable for the compliance of the cloud service2. References:
ISACA Cloud Auditing Knowledge Certificate Study Guide, page 10-11.
Certification authority - Wikipedia


NEW QUESTION # 64
Your company is purchasing an application from a vendor. They do not allow you to perform an on-site audit on their information system. However, they say, they will provide the third-party audit attestation on the adequate control design within their environment. Which report is the vendor providing you?

  • A. SOC 2, TYPE 1
  • B. SOC 2, TYPE 2
  • C. SOC 1
  • D. SOC 3

Answer: B


NEW QUESTION # 65
Which of the following enables auditors to conduct gap analyses of what a cloud service provider offers versus what the customer requires?

  • A. Understanding the customer risk profile
  • B. The experience gained over the years
  • C. The as-is and to-be enterprise architecture (EA
  • D. Using a standardized control framework

Answer: D

Explanation:
Explanation
Using a standardized control framework enables auditors to conduct gap analyses of what a cloud service provider (CSP) offers versus what the customer requires. A standardized control framework is a set of guidelines, best practices, and criteria that help to evaluate and improve the security, privacy, and compliance of cloud computing environments. Examples of standardized control frameworks include ISO/IEC
27001/27002/27017/27018, NIST SP 800-53, CSA Cloud Controls Matrix (CCM), COBIT, etc. By using a standardized control framework, auditors can compare the CSP's policies, procedures, and practices with the customer's expectations and requirements, and identify any gaps or discrepancies that may pose risks or issues. A gap analysis can help the auditors to provide recommendations and suggestions to the CSP and the customer on how to close the gaps and enhance the quality and performance of the cloud services12.
References:
Cloud Controls Matrix (CCM) - CSA
Cloud Computing Audit Program - ISACA


NEW QUESTION # 66
How can virtual machine communications bypass network security controls?

  • A. VM images can contain rootkits programmed to bypass firewalls
  • B. Most network security systems do not recognize encrypted VM traffic
  • C. Hypervisors depend upon multiple network interfaces
  • D. VM communications may use a virtual network on the same hardware host
  • E. The guest OS can invoke stealth mode

Answer: D


NEW QUESTION # 67
Who is accountable for the use of a cloud service?

  • A. The cloud access security broker (CASB)
  • B. The organization (client)
  • C. The cloud service provider
  • D. The supplier

Answer: B

Explanation:
The organization (client) is accountable for the use of a cloud service. Accountability in cloud computing is the responsibility of cloud service providers and other parties in the cloud ecosystem to protect and properly process the data of their clients and users. However, accountability ultimately rests with the organization (client) that uses the cloud service, as it is the data owner and controller. The organization (client) has to ensure that the cloud service provider and its suppliers meet the agreed-upon service levels, security standards, and regulatory requirements. The organization (client) also has to perform due diligence and oversight on the cloud service provider and its suppliers, as well as to comply with the shared responsibility model, which defines how the security and compliance tasks and obligations are divided between the cloud service provider and the organization (client)123.
The other options are not correct. Option A, the cloud access security broker (CASB), is incorrect because a CASB is a software tool or service that acts as an intermediary between cloud users and cloud service providers, providing visibility, data security, threat protection, and compliance. A CASB does not use the cloud service, but facilitates its secure and compliant use4. Option B, the supplier, is incorrect because a supplier is a third-party entity that provides services or products to the cloud service provider, such as infrastructure, software, hardware, or support. A supplier does not use the cloud service, but supports its delivery5. Option C, the cloud service provider, is incorrect because a cloud service provider is a company that provides cloud computing services to the organization (client). A cloud service provider does not use the cloud service, but offers it to the organization (client)6. References :=
* Accountability Issues in Cloud Computing (5 Step ... - Medium1
* Shared responsibility in the \uE000cloud\uE001 - Microsoft Azure2
* Who Is Responsible for Cloud Security? - Security Intelligence3
* What is CASB? - Cloud Security Alliance4
* Cloud Computing: Auditing Challenges - ISACA5
* What is Cloud Provider? - Definition from Techopedia


NEW QUESTION # 68
Which of the following CSP activities requires a client's approval?

  • A. Delete the master account or subscription owner accounts
  • B. Delete the test accounts or destroy test data
  • C. Delete the guest account or test accounts
  • D. Delete the guest account or destroy test data

Answer: B


NEW QUESTION # 69
Which of the following standards is designed to be used by organizations for cloud services that intend to select controls within the process of implementing an information security management system based on ISO/IEC 27001?

  • A. NIST SP 800-146
  • B. ISO/IEC 27002
  • C. Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)
  • D. ISO/IEC 27017:2015

Answer: D

Explanation:
ISO/IEC 27017:2015 is a standard that provides guidelines for information security controls applicable to the provision and use of cloud services by providing additional implementation guidance for relevant controls specified in ISO/IEC 27002, as well as additional controls with implementation guidance that specifically relate to cloud services1. ISO/IEC 27017:2015 is designed to be used by organizations for cloud services that intend to select controls within the process of implementing an information security management system based on ISO/IEC 270011. ISO/IEC 27001 is a standard that specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization.
ISO/IEC 27002 is a standard that provides a code of practice for information security controls, but it does not provide specific guidance for cloud services. NIST SP 800-146 is a publication that provides an overview of cloud computing, its characteristics, service models, deployment models, and security considerations, but it does not provide a standard for selecting controls for cloud services. CSA CCM is a framework that provides detailed understanding of security concepts and principles that are aligned to the Cloud Security Alliance guidance in 13 domains, but it is not a standard that is based on ISO/IEC 27001. References:
* ISO/IEC 27017:2015
* [ISO/IEC 27001:2013]
* [ISO/IEC 27002:2013]
* [NIST SP 800-146]
* [CSA CCM]


NEW QUESTION # 70
Which of the following is a category of trust in cloud computing?

  • A. Reputation-based trust
  • B. Loyalty-based trust
  • C. Transparency-based trust
  • D. Background-based trust

Answer: A

Explanation:
Reputation-based trust is a category of trust in cloud computing that relies on the feedback, ratings, reviews, or recommendations of other users or third parties who have used or evaluated the cloud service provider or the cloud service. Reputation-based trust reflects the collective opinion and experience of the cloud community regarding the quality, reliability, security, and performance of the cloud service provider or the cloud service.
Reputation-based trust can help potential customers to make informed decisions about choosing a cloud service provider or a cloud service based on the reputation score or ranking of the provider or the service.
Reputation-based trust can also motivate cloud service providers to improve their services and maintain their reputation by meeting or exceeding customer expectations.
Reputation-based trust is one of the most common and widely used forms of trust in cloud computing, as it is easy to access and understand. However, reputation-based trust also has some limitations and challenges, such as:
* The accuracy and validity of the reputation data may depend on the source, method, and frequency of data collection and aggregation. For example, some reputation data may be outdated, incomplete, biased, manipulated, or falsified by malicious actors or competitors.
* The interpretation and comparison of the reputation data may vary depending on the context, criteria, and preferences of the customers. For example, some customers may value different aspects of the cloud service more than others, such as security, availability, cost, or functionality.
* The trustworthiness and accountability of the reputation system itself may be questionable. For example, some reputation systems may lack transparency, consistency, or standardization in their design, implementation, or operation.
Therefore, reputation-based trust should not be the only factor for trusting a cloud service provider or a cloud service. Customers should also consider other forms of trust in cloud computing, such as evidence-based trust, policy-based trust, or certification-based trust


NEW QUESTION # 71
Which of the following should be the FIRST step to establish a cloud assurance program during a cloud migration?

  • A. Risk assessment
  • B. Development
  • C. Design
  • D. Stakeholder identification

Answer: B


NEW QUESTION # 72
Which of the following is NOT a cloud computing characteristic that impacts incidence response?

  • A. Privacy concerns for co-tenants regarding the collection and analysis of telemetry and artifacts associated with an incident.
  • B. The possibility of data crossing geographic or jurisdictional boundaries.
  • C. The resource pooling practiced by cloud services, in addition to the rapid elasticity offered by cloud infrastructures.
  • D. The on demand self-service nature of cloud computing environments.
  • E. Object-based storage in a private cloud.

Answer: A


NEW QUESTION # 73
What is true of companies considering a cloud computing business relationship?

  • A. The confidentiality agreements between companies using cloud computing services is limited legally to the company, not the provider.
  • B. The cloud computing companies are absolved of all data security and associated risks through contracts and data laws.
  • C. The cloud computing companies own all customer data.
  • D. The laws protecting customer data arebased on the cloud provider and customer location only.
  • E. The companies using the cloud providers are the custodians ofthe data entrusted to them.

Answer: E


NEW QUESTION # 74
The PRIMARY purpose of Open Certification Framework (OCF) for the CSA STAR program is to:

  • A. facilitate an effective relationship between the cloud service provider and cloud client.
  • B. ensure understanding of true risk and perceived risk by the cloud service users
  • C. enable the cloud service provider to prioritize resources to meet its own requirements.
  • D. provide global, accredited, and trusted certification of the cloud service provider.

Answer: D

Explanation:
Explanation
The primary purpose of the Open Certification Framework (OCF) for the CSA STAR program is to provide global, accredited, and trusted certification of the cloud service provider. According to the CSA website1, the OCF is an industry initiative to allow global, trusted independent evaluation of cloud providers. It is a program for flexible, incremental and multi-layered cloud provider certification and/or attestation according to the Cloud Security Alliance's industry leading security guidance and control framework. The OCF aims to address the gaps within the IT ecosystem that are inhibiting market adoption of secure and reliable cloud services. The OCF also integrates with popular third-party assessment and attestation statements developed within the public accounting community to avoid duplication of effort and cost. The OCF manages the foundation that runs and monitors the CSA STAR Certification program, which is an assurance framework that enables cloud service providers to embed cloud-specific security controls. The STAR Certification program has three levels of assurance, each based on a different type of audit or assessment: Level 1: Self-Assessment, Level 2:
Third-Party Audit, and Level 3: Continuous Auditing. The OCF also oversees the CSA STAR Registry, which is a publicly accessible repository that documents the security controls provided by various cloud computing offerings2. The OCF helps consumers to evaluate and compare their providers' resilience, data protection, privacy capabilities, and service portability. It also helps providers to demonstrate their compliance with industry standards and best practices.
References:
Open Certification Framework Working Group | CSA
STAR | CSA


NEW QUESTION # 75
The BEST method to report continuous assessment of a cloud provider's services to the CSA is through:

  • A. SOC 2 Type 2 attestation.
  • B. tools selected by the third-party auditor.
  • C. CCM assessment by a third-party auditor on a periodic basis.
  • D. a set of dedicated application programming interfaces (APIs).

Answer: C


NEW QUESTION # 76
Which of the following is the FIRST step of the Cloud Risk Evaluation Framework?

  • A. Establishing cloud risk profile
  • B. Identifying key risk categories
  • C. Evaluating and documenting the risks
  • D. Analyzing potential impact and likelihood

Answer: B

Explanation:
The first step of the Cloud Risk Evaluation Framework is to identify key risk categories. Key risk categories are the broad areas or domains of cloud security and compliance that may affect the cloud service provider and the cloud service customer. Key risk categories may include data security, identity and access management, encryption and key management, incident response, disaster recovery, audit assurance and compliance, etc.
Identifying key risk categories helps to scope and focus the cloud risk assessment process, as well as to prioritize and rank the risks based on their relevance and significance. Identifying key risk categories also helps to align and map the risks with the applicable standards, regulations, or frameworks that govern cloud security and compliance12.
Analyzing potential impact and likelihood (A) is not the first step of the Cloud Risk Evaluation Framework, but rather the third step. Analyzing potential impact and likelihood is the process of estimating the consequences or effects of a risk event on the business objectives, operations, processes, or functions (impact), as well as the probability or frequency of a risk event occurring (likelihood). Analyzing potential impact and likelihood helps to measure and quantify the severity or magnitude of the risk event, as well as to prioritize and rank the risks based on their impact and likelihood12.
Establishing cloud risk profile (B) is not the first step of the Cloud Risk Evaluation Framework, but rather the second step. Establishing cloud risk profile is the process of defining and documenting the expected level of risk that an organization is willing to accept or tolerate in relation to its cloud services (risk appetite), as well as the actual level of risk that an organization faces or encounters in relation to its cloud services (risk exposure). Establishing cloud risk profile helps to determine and communicate the objectives, expectations, and responsibilities of cloud security and compliance, as well as to align and integrate them with the business strategy and goals12.
Evaluating and documenting the risks is not the first step of the Cloud Risk Evaluation Framework, but rather the fourth step. Evaluating and documenting the risks is the process of assessing and reporting on the effectiveness and efficiency of the controls or actions that are implemented or applied to prevent, avoid, transfer, or accept a risk event (risk treatment), as well as identifying and addressing any gaps or issues that may arise (risk monitoring). Evaluating and documenting the risks helps to ensure that the actual level of risk is aligned with the desired level of risk, as well as to update and improve the risk management strategy and plan12. References :=
* Cloud Auditing Knowledge: Preparing for the CCAK Certificate Exam
* Cloud Risk-10 Principles and a Framework for Assessment - ISACA


NEW QUESTION # 77
When developing a cloud compliance program, what is the PRIMARY reason for a cloud customer to review which cloud services will be deployed?

  • A. To confirm if the compensating controls implemented are sufficient for the cloud
  • B. To determine how those services will fit within its policies and procedures
  • C. To confirm which vendor will be selected based on the compliance with security requirements
  • D. To determine the total cost of the cloud services to be deployed

Answer: B


NEW QUESTION # 78
A cloud service provider utilizes services of other service providers for its cloud service. Which of the following is the BEST approach for the auditor while performing the audit for the cloud service?

  • A. The auditor should review the service providers' security controls even more strictly, as they are further separated from the cloud customer.
  • B. As the contract for the cloud service is between the cloud customer and the cloud service provider, there is no need for the auditor to review the services provided by the service providers.
  • C. As the relationship between the cloud service provider and its service providers is governed by separate contracts between them, there is no need for the auditor to review the services
  • D. The auditor should review the relationship between the cloud service provider and its service provider to help direct and estimate the level of effort and analysis the auditor should apply.

Answer: D

Explanation:
Explanation
According to the ISACA Cloud Auditing Knowledge Certificate Study Guide, the auditor should review the relationship between the cloud service provider and its service provider to help direct and estimate the level of effort and analysis the auditor should apply1. The auditor should understand the nature and scope of the services provided by the service provider, the contractual obligations and service level agreements, the security and compliance requirements, and the monitoring and reporting mechanisms. The auditor should also assess the risks and controls associated with the service provider, and determine if additional audit procedures are needed to obtain sufficient assurance.
The other options are not the best approach for the auditor. Option A is too strict and might not be feasible or necessary, depending on the type and level of services provided by the service provider. Option C is too lax and might overlook significant risks and gaps in the cloud service. Option D is too narrow and might ignore the impact of the service provider on the cloud customer's business context. References:
ISACA Cloud Auditing Knowledge Certificate Study Guide, page 13-14.


NEW QUESTION # 79
Big data includes high volume, high variety, and high velocity.

  • A. False
  • B. True

Answer: B


NEW QUESTION # 80
......

PDF Download ISACA Test To Gain Brilliante Result!: https://www.exam-killer.com/CCAK-valid-questions.html

Get Special Discount Offer on CCAK Dumps PDF: https://drive.google.com/open?id=19FDK698OrqARt3eW3CizMpolRJqUY9Aa