
The Best ISACA CCAK Study Guides and Dumps of 2021
Top ISACA CCAK Exam Audio Study Guide! Practice Questions Edition
NEW QUESTION 29
Use elastic servers when possible and move workloads to new instances.
- A. False
- B. True
Answer: B
NEW QUESTION 30
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services fortracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document topotential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?
- A. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
- B. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
- C. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.
Answer: C
NEW QUESTION 31
If there are gaps in network logging data,what can you do?
- A. Nothing. The cloud provider must make the information available.
- B. Ask the cloud provider to open more ports.
- C. Ask the cloud provider to close more ports.
- D. You can instrument the technology stack with your own logging.
- E. Nothing. There are simply limitations around the data that can be logged in the cloud.
Answer: D
NEW QUESTION 32
Who is responsible for the security of the physical infrastructure and virtualization platform?
- A. The cloud consumer
- B. The responsibility is split equally
- C. The majority is covered by the consumer
- D. Itdepends on the agreement
- E. The cloud provider
Answer: E
NEW QUESTION 33
Big data includes high volume, high variety, and high velocity.
- A. False
- B. True
Answer: B
NEW QUESTION 34
How does virtualized storage help avoid data loss if a drive fails?
- A. Full back ups weekly
- B. Incremental backups daily
- C. Drives are backed up, swapped, and archived constantly
- D. Multiple copies indifferent locations
- E. Data loss is unavoidable with drive failures
Answer: D
NEW QUESTION 35
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
- A. URL filters
- B. Database Activity Monitoring
- C. Cloud Access and Security Brokers (CASB)
- D. Data Loss Prevention
- E. Intrusion Prevention System
Answer: E
NEW QUESTION 36
How does running applications on distinct virtual networks and only connecting networksas needed help?
- A. It enables you to configure applications around business groups
- B. It provides dynamic and granular policies with less management overhead
- C. It reduces hardware costs
- D. It reduces the blast radius of a compromised system
- E. It locks down access and provides stronger data security
Answer: D
NEW QUESTION 37
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?
- A. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
- B. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.
- C. None of the above.
- D. Decreased requirement for proactive management of relationship and adherence to contracts.
- E. More physical control over assets and processes.
Answer: B
NEW QUESTION 38
Which of the following should be an IS auditor's GREATEST concern when reviewing an outsourcing arrangement with a third-party cloud service provider to host personally identifiable data?
- A. Fees are charged based on the volume of data stored by the host.
- B. The organization's servers are not compatible with the third party's infrastructure
- C. The outsourcing contract does not contain a right-to-audit clause.
- D. The data is not adequately segregated on the host platform.
Answer: D
NEW QUESTION 39
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:
- A. Identity as a Service (IDaaS).
- B. Infrastructure as a Service (laaS).
- C. Platform as a Service (PaaS).
- D. Software as a Service (SaaS).
Answer: C
NEW QUESTION 40
Your cloud and on-premisesinfrastructures should always use the same network address ranges.
- A. False
- B. True
Answer: A
NEW QUESTION 41
ENISA: A reason for risk concerns of a cloud provider being acquired is:
- A. Mass layoffs may occur
- B. Provider may change physical location
- C. Resource isolation may fail
- D. Non-binding agreements put at risk
- E. Arbitrary contract termination by acquiring company
Answer: D
NEW QUESTION 42
A third-party service provider is hosting a private cloud for an organization. Which of the following findings during an audit of the provider poses the GREATEST risk to the organization?
- A. The organization's virtual machines share the same hypervisor with virtual machines of other clients.
- B. 2% of backups had to be rescheduled due to backup media failures.
- C. Two different hypervisor versions are used due to the compatibility restrictions of some virtual machines.
- D. 5% of detected incidents exceeded the defined service level agreement (SLA) for escalation.
Answer: A
NEW QUESTION 43
ENISA: "VMhopping" is:
- A. Lack of vulnerability management standards.
- B. Looping within virtualized routing systems.
- C. Instability in VM patch management causing VM routing errors.
- D. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.
- E. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
Answer: D
NEW QUESTION 44
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what?
- A. An entitlement matrix
- B. An entrylog
- C. A support table
- D. A validation process
- E. An access log
Answer: D
NEW QUESTION 45
All cloud services utilize virtualization technologies.
- A. False
- B. True
Answer: B
NEW QUESTION 46
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?
- A. Volume storage
- B. Object storage
- C. Platform
- D. Application
- E. Database
Answer: A
NEW QUESTION 47
REST APIs are the standard for web-based services because they run over HTTPS and work well across diverse environments.
- A. False
- B. True
Answer: B
NEW QUESTION 48
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
- A. Maintaining customer managed key management and revoking ordeleting keys from the key management system to prevent the data from being accessed again.
- B. Allowing the cloud provider to manage your keys so that they have the ability to access and delete the data from the main and back-up storage.
- C. Keep the keys stored on the client side so that they are secure and so that the users have the ability to delete their own data.
- D. Practice Integration of Duties (IOD) so that everyone is able to delete the encrypted data.
- E. Both B and D.
Answer: A
NEW QUESTION 49
......
Valid CCAK Exam Updates - 2021 Study Guide: https://www.prep4sures.top/CCAK-exam-dumps-torrent.html
CCAK Certification - The Ultimate Guide: https://drive.google.com/open?id=1MlWTdWBZCgNqu3Z3P0we7rxTIsfHNim5