CCAK 無料問題集「ISACA Certificate of Cloud Auditing Knowledge」

Why should the results of third-party audits and certification be relied on when analyzing and assessing the cybersecurity risks in the cloud?

解説: (JPNTest メンバーにのみ表示されます)
Which of the following MOST enhances the internal stakeholder decision-making process for the remediation of risks identified from an organization's cloud compliance program?

解説: (JPNTest メンバーにのみ表示されます)
A cloud auditor should use statistical sampling rather than judgment (nonstatistical) sampling when:

解説: (JPNTest メンバーにのみ表示されます)
During an audit, it was identified that a critical application hosted in an off-premises cloud is not part of the organization's disaster recovery plan (DRP). Management stated that it is responsible for ensuring the cloud service provider has a plan that is tested annually. What should be the auditor's NEXT course of action?

解説: (JPNTest メンバーにのみ表示されます)
Regarding cloud service provider agreements and contracts, unless otherwise stated, the provider is:

解説: (JPNTest メンバーにのみ表示されます)
What is a sign that an organization has adopted a shift-left concept of code release cycles?

解説: (JPNTest メンバーにのみ表示されます)
The Cloud Computing Compliance Controls Catalogue (C5) framework is maintained by which of the following agencies?

An independent contractor is assessing the security maturity of a Software as a Service (SaaS) company against industry standards. The SaaS company has developed and hosted all its products using the cloud services provided by a third-party cloud service provider. What is the optimal and most efficient mechanism to assess the controls provider is responsible for?

解説: (JPNTest メンバーにのみ表示されます)
To promote the adoption of secure cloud services across the federal government by

解説: (JPNTest メンバーにのみ表示されます)
Which of the following is the reason for designing the Consensus Assessments Initiative Questionnaire (CAIQ)?

解説: (JPNTest メンバーにのみ表示されます)
Which of the following would be the GREATEST governance challenge to an organization where production is hosted in a public cloud and backups are held on the premises?

解説: (JPNTest メンバーにのみ表示されます)
A dot release of the Cloud Controls Matrix (CCM) indicates:

解説: (JPNTest メンバーにのみ表示されます)
During an audit, it was identified that a critical application hosted in an off-premises cloud is not part of the organization's disaster recovery plan (DRP). Management stated that it is responsible for ensuring the cloud service provider has a plan that is tested annually. What should be the auditor's NEXT course of action?

解説: (JPNTest メンバーにのみ表示されます)
What aspect of Software as a Service (SaaS) functionality and operations would the cloud customer be responsible for and should be audited?

解説: (JPNTest メンバーにのみ表示されます)
In the context of Infrastructure as a Service (laaS), a vulnerability assessment will scan virtual machines to identify vulnerabilities in:

解説: (JPNTest メンバーにのみ表示されます)
An organization currently following the ISO/IEC 27002 control framework has been charged by a new CIO to switch to the NIST 800-53 control framework. Which of the following is the FIRST step to this change?

解説: (JPNTest メンバーにのみ表示されます)
Which of the following types of SOC reports BEST helps to ensure operating effectiveness of controls in a cloud service provider offering?

解説: (JPNTest メンバーにのみ表示されます)

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡