
Ultimate Guide to Prepare CCAK Certification Exam for Cloud Security Alliance in 2021
Use Real CCAK Dumps - ISACA Correct Answers updated on 2021
NEW QUESTION 18
Network logs from cloud providers are typically flow records, not full packet captures.
- A. True
- B. False
Answer: A
NEW QUESTION 19
Your cloud and on-premisesinfrastructures should always use the same network address ranges.
- A. False
- B. True
Answer: A
NEW QUESTION 20
How is encryption managed on multi-tenant storage?
- A. C for data subject to the EU Data Protection Directive; B for all others
- B. Multiple keys per data owner
- C. One key per data owner
- D. The answer could be A, B, or C depending on the provider
- E. Single key for all data owners
Answer: C
NEW QUESTION 21
Which of the following is NOT a cloud computing characteristic that impacts incidence response?
- A. The possibility of data crossing geographic or jurisdictional boundaries.
- B. Privacy concerns for co-tenants regarding the collection and analysis of telemetry and artifacts associated with an incident.
- C. Object-based storage in a private cloud.
- D. The resource pooling practiced by cloud services, in addition to the rapid elasticity offered by cloud infrastructures.
- E. The on demand self-service nature of cloud computing environments.
Answer: B
NEW QUESTION 22
An internal audit department recently established a quality assurance (QA) program as part of its overall audit program. Which of the following activities is MOST important to include as part of the QA program requirements?
- A. Reporting OA program results to the audit committee
- B. Benchmarking the QA framework to international standards
- C. Conducting long-term planning for internal audit staffing
- D. Analyzing user satisfaction reports from business lines
Answer: D
NEW QUESTION 23
Which term is used to describe the use of tools to selectively degrade portions of the cloud to continuously test business continuity?
- A. Organized Downtime
- B. PlannedOutages
- C. Resiliency Planning
- D. Chaos Engineering
- E. Expected Engineering
Answer: D
NEW QUESTION 24
What is defined as the process by which an opposing party may obtain private documents for use in litigation?
- A. Custody
- B. Subpoena
- C. Scope
- D. Discovery
- E. Risk Assessment
Answer: D
NEW QUESTION 25
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?
- A. Risk Impact
- B. Domain
- C. Control Specification
Answer: B
NEW QUESTION 26
Which attack surfaces, if any, does virtualization technology introduce?
- A. All of the above
- B. The hypervisor
- C. Configuration and VM sprawl issues
- D. Virtualization management components apart from the hypervisor
Answer: A
NEW QUESTION 27
Which layer is the most important for securing because it is considered to be the foundation for secure cloud operations?
- A. Applistructure
- B. Datastructure
- C. Infostructure
- D. Infrastructure
- E. Metastructure
Answer: D
NEW QUESTION 28
Big data includes high volume, high variety, and high velocity.
- A. True
- B. False
Answer: A
NEW QUESTION 29
How can virtual machine communications bypass network security controls?
- A. VM images can contain rootkits programmed to bypass firewalls
- B. Hypervisors depend upon multiple network interfaces
- C. VM communications may use a virtual network on the same hardware host
- D. Most network security systems do not recognize encrypted VM traffic
- E. The guest OS can invoke stealth mode
Answer: C
NEW QUESTION 30
When deploying Security as a Service in a highly regulated industry or environment, what should bothparties agree on in advance and include in the SLA?
- A. The metrics defining the service level required to achieve regulatory objectives.
- B. The duration of time that a security violation can occur before the client begins assessing regulatory fines.
- C. The cost per incident for security breaches of regulated information.
- D. The type of security software which meets regulations and the number of licenses that will be needed.
- E. The regulations that are pertinent to the contract and how to circumvent them.
Answer: A
NEW QUESTION 31
What factors should you understand about the data specifically due to legal, regulatory, and jurisdictional factors?
- A. The fragmentation and encryption algorithms employed
- B. Thephysical location of the data and how it is accessed
- C. The actualsize of the data and the storage format
- D. The language of the data and how it affects the user
- E. The implications of storing complex information on simple storage systems
Answer: E
NEW QUESTION 32
ENISA: A reason for risk concerns of a cloud provider being acquired is:
- A. Mass layoffs may occur
- B. Resource isolation may fail
- C. Provider may change physical location
- D. Non-binding agreements put at risk
- E. Arbitrary contract termination by acquiring company
Answer: D
NEW QUESTION 33
What is the newer application development methodology and philosophy focused on automation of application development and deployment?
- A. SecDevOps
- B. DevOps
- C. Agile
- D. BusOps
- E. Scrum
Answer: B
NEW QUESTION 34
Why is a service type of network typically isolated on different hardware?
- A. It manages resource pools for cloud consumers
- B. It manages the traffic between other networks
- C. It requires distinct access controls
- D. It has distinct functions from other networks
- E. It requires unique security
Answer: B
NEW QUESTION 35
REST APIs are the standard for web-based services because they run over HTTPS and work well across diverse environments.
- A. True
- B. False
Answer: A
NEW QUESTION 36
Use elastic servers when possible and move workloads to new instances.
- A. True
- B. False
Answer: A
NEW QUESTION 37
Sending data to a provider's storage over an API is likely as much morereliable and secure than setting up your own SFTP server on a VM in the same provider
- A. True
- B. False
Answer: A
NEW QUESTION 38
Which of the following is the GREATEST security risk associated with data migration from a legacy human resources (HR) system to a cloud-based system''
- A. Data from the source and target system may have different data formats
- B. Records past their retention period may not be migrated to the new system
- C. System performance may be impacted by the migration
- D. Data from the source and target system may be intercepted
Answer: D
NEW QUESTION 39
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?
- A. The investigation report does not indicate a conclusion.
- B. The handling procedures of the attacked system are not documented.
- C. An image copy of the attacked system was not taken.
- D. The proper authorities were not notified.
Answer: D
NEW QUESTION 40
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
- A. URL filters
- B. Database Activity Monitoring
- C. Data Loss Prevention
- D. Cloud Access and Security Brokers (CASB)
- E. Intrusion Prevention System
Answer: E
NEW QUESTION 41
What is resource pooling?
- A. The dedicated computing resources of each client are pooled together in a colocation facility.
- B. None of the above.
- C. Placing Internet ("cloud") data centers near multiple sources of energy, such as hydroelectric dams.
- D. Internet-based CPUs are pooled to enable multi-threading.
- E. The provider's computing resources are pooled to serve multiple consumers.
Answer: E
NEW QUESTION 42
......
Cloud Security Alliance -CCAK Exam-Practice-Dumps: https://www.easy4engine.com/CCAK-test-engine.html
CCAK Premium Files Test pdf - Free Dumps Collection: https://drive.google.com/open?id=1W7-QLcHY8WXCmS9RUNjBm6XzwlTV3Dqj

