
Latest ISACA CCAK First Attempt, Exam real Dumps Updated [Sep-2021]
Get the superior quality CCAK Dumps Questions from Easy4Engine. Nobody can stop you from getting to your dreams now. Your bright future is just a click away!
NEW QUESTION 46
What is true of companies considering a cloud computing business relationship?
- A. The confidentiality agreements between companies using cloud computing services is limited legally to the company, not the provider.
- B. The cloud computing companies are absolved of all data security and associated risks through contracts and data laws.
- C. The cloud computing companies own all customer data.
- D. The laws protecting customer data arebased on the cloud provider and customer location only.
- E. The companies using the cloud providers are the custodians ofthe data entrusted to them.
Answer: E
NEW QUESTION 47
Who is responsible for the security of the physical infrastructure and virtualization platform?
- A. The cloud provider
- B. The responsibility is split equally
- C. The majority is covered by the consumer
- D. Itdepends on the agreement
- E. The cloud consumer
Answer: A
NEW QUESTION 48
Which statement best describes the impact of Cloud Computing on business continuity management?
- A. Geographic redundancyensures that Cloud Providers provide highly available services.
- B. Clients need to do business continuity planning due diligence in case they suddenly need to switch providers.
- C. The size of data sets hosted at a Cloud provider can present challenges if migration to another provider becomesnecessary.
- D. A general lack of interoperability standards means that extra focus must be placed on the security aspects of migration between Cloud providers.
- E. Customers of SaaS providers in particular need to mitigate the risks of application lock-in.
Answer: A
NEW QUESTION 49
Which of the following would be MOST important to update once a decision has been made to outsource a critical application to a cloud service provider?
- A. IT budget
- B. Business impact analysis (BIA)
- C. Project portfolio
- D. IT resource plan
Answer: B
NEW QUESTION 50
Which concept provides the abstraction needed for resource pools?
- A. Applistructure
- B. Hypervisor
- C. Virtualization
- D. Orchestration
- E. Metastructure
Answer: C
NEW QUESTION 51
When deploying Security as a Service in a highly regulated industry or environment, what should bothparties agree on in advance and include in the SLA?
- A. The metrics defining the service level required to achieve regulatory objectives.
- B. The duration of time that a security violation can occur before the client begins assessing regulatory fines.
- C. The cost per incident for security breaches of regulated information.
- D. The type of security software which meets regulations and the number of licenses that will be needed.
- E. The regulations that are pertinent to the contract and how to circumvent them.
Answer: A
NEW QUESTION 52
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?
- A. Applistructure
- B. Datastructure
- C. Infostructure
- D. Infrastructure
- E. Metastructure
Answer: D
NEW QUESTION 53
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
- A. URL filters
- B. Database Activity Monitoring
- C. Data Loss Prevention
- D. Cloud Access and Security Brokers (CASB)
- E. Intrusion Prevention System
Answer: E
NEW QUESTION 54
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework
- A. Governance and Risk Management
- B. Governing and Risk Metrics
- C. Governance and Retention Management
Answer: A
NEW QUESTION 55
ENISA: "VMhopping" is:
- A. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
- B. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.
- C. Looping within virtualized routing systems.
- D. Lack of vulnerability management standards.
- E. Instability in VM patch management causing VM routing errors.
Answer: B
NEW QUESTION 56
Which of the following is the GREATEST concern associated with migrating computing resources to a cloud virtualized environment?
- A. An increase in inherent vulnerability
- B. An increase in residual risk
- C. An increase in the potential for data leakage
- D. An increase in the number of e-discovery requests
Answer: C
NEW QUESTION 57
Which attack surfaces, if any, does virtualization technology introduce?
- A. All of the above
- B. The hypervisor
- C. Configuration and VM sprawl issues
- D. Virtualization management components apart from the hypervisor
Answer: A
NEW QUESTION 58
In which type of environment is it impractical to allow the customer to conduct their own audit, making it important that the data center operators are required to provide auditing for the customers?
- A. Long distance relationships
- B. Single tenantenvironments
- C. Multi-tenant environments
- D. Distributed computing arrangements
- E. Multi-application, single tenant environments
Answer: C
NEW QUESTION 59
Which of the following cloud deployment models would BEST meet the needs of a startup software development organization with limited initial capital?
- A. Community
- B. Private
- C. Public
- D. Hybrid
Answer: C
NEW QUESTION 60
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services fortracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document topotential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?
- A. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.
- B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
- C. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
Answer: A
NEW QUESTION 61
An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?
- A. Reviewing the request for proposal (RFP)
- B. verifying the weighting of each selection criteria
- C. Approving the vendor selection methodology
- D. Witnessing the vendor selection process
Answer: C
NEW QUESTION 62
An internal audit department recently established a quality assurance (QA) program as part of its overall audit program. Which of the following activities is MOST important to include as part of the QA program requirements?
- A. Reporting OA program results to the audit committee
- B. Benchmarking the QA framework to international standards
- C. Conducting long-term planning for internal audit staffing
- D. Analyzing user satisfaction reports from business lines
Answer: D
NEW QUESTION 63
How is encryption managed on multi-tenant storage?
- A. C for data subject to the EU Data Protection Directive; B for all others
- B. Multiple keys per data owner
- C. One key per data owner
- D. The answer could be A, B, or C depending on the provider
- E. Single key for all data owners
Answer: C
NEW QUESTION 64
How does virtualized storage help avoid data loss if a drive fails?
- A. Drives are backed up, swapped, and archived constantly
- B. Data loss is unavoidable with drive failures
- C. Full back ups weekly
- D. Multiple copies indifferent locations
- E. Incremental backups daily
Answer: D
NEW QUESTION 65
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?
- A. Both B and C.
- B. Negotiate long-term contracts with companies who use well-vetted software application to avoid the transient nature of the cloud environment.
- C. Inspect and account for risksinherited from other members of the cloud supply chain and take active measures to mitigate and contain risks through operational resiliency.
- D. Provide transparency to stakeholders and shareholders demonstrating fiscal solvency and organizational transparency.
- E. Respect the interdependency of the risks inherent in the cloud supply chain and communicate the corporate riskposture and readiness to consumers and dependent parties.
Answer: B
NEW QUESTION 66
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?
- A. Application
- B. Object storage
- C. Platform
- D. Database
- E. Volume storage
Answer: E
NEW QUESTION 67
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?
- A. The investigation report does not indicate a conclusion.
- B. The handling procedures of the attacked system are not documented.
- C. An image copy of the attacked system was not taken.
- D. The proper authorities were not notified.
Answer: D
NEW QUESTION 68
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?
- A. Infrastructure-as-a-service (IaaS)
- B. Software-as-a-service (SaaS)
- C. Desktop-as-a-service (DaaS)
- D. Identity-as-a-service (IDaaS)
- E. Platform-as-a-service (PaaS)
Answer: E
NEW QUESTION 69
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.
- A. True
- B. False
Answer: A
NEW QUESTION 70
......
ISACA Practice Test Engine with CCAK Questions: https://drive.google.com/open?id=1W7-QLcHY8WXCmS9RUNjBm6XzwlTV3Dqj
Guaranteed Success with Valid ISACA CCAK Dumps: https://www.easy4engine.com/CCAK-test-engine.html

