
CCAK Practice Test Questions Answers Updated 78 Questions
CCAK dumps & Cloud Security Alliance Sure Practice with 78 Questions
NEW QUESTION 11
ENISA: Lock-in is ranked as a high risk in ENISA research, a key underlying vulnerability causing lock in is:
- A. Lack of information onjurisdictions
- B. No source escrow agreement
- C. Unclear asset ownership
- D. Lack of completeness and transparency in terms of use
- E. Audit or certification not available to customers
Answer: D
NEW QUESTION 12
Big data includes high volume, high variety, and high velocity.
- A. False
- B. True
Answer: B
NEW QUESTION 13
All cloud services utilize virtualization technologies.
- A. False
- B. True
Answer: B
NEW QUESTION 14
Which of the following should be an IS auditor's GREATEST concern when reviewing an outsourcing arrangement with a third-party cloud service provider to host personally identifiable data?
- A. Fees are charged based on the volume of data stored by the host.
- B. The organization's servers are not compatible with the third party's infrastructure
- C. The outsourcing contract does not contain a right-to-audit clause.
- D. The data is not adequately segregated on the host platform.
Answer: D
NEW QUESTION 15
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.
- A. False
- B. True
Answer: B
NEW QUESTION 16
What is true of searching data across cloud environments?
- A. You can easily search across your environment using any E-Discovery tool.
- B. All cloud-hosted email accounts are easily searchable.
- C. You might not have the ability oradministrative rights to search or access all hosted data.
- D. The cloud provider must conduct the search with the full administrative controls.
- E. Search and discovery time is alwaysfactored into a contract between the consumer and provider.
Answer: C
NEW QUESTION 17
Who is responsible for the security of the physical infrastructure and virtualization platform?
- A. The cloud consumer
- B. The responsibility is split equally
- C. The majority is covered by the consumer
- D. Itdepends on the agreement
- E. The cloud provider
Answer: E
NEW QUESTION 18
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?
- A. Desktop-as-a-service (DaaS)
- B. Identity-as-a-service (IDaaS)
- C. Platform-as-a-service (PaaS)
- D. Software-as-a-service (SaaS)
- E. Infrastructure-as-a-service (IaaS)
Answer: C
NEW QUESTION 19
An audit has identified that business units have purchased cloud-based applications without ITs support. What is the GREATEST risk associated with this situation?
- A. The applications may not reasonably protect data.
- B. The applications could be modified without advanced notice.
- C. The application purchases did not follow procurement policy.
- D. The applications are not included in business continuity plans (BCPs).
Answer: D
NEW QUESTION 20
Segregation of duties would be compromised if:
- A. application programmers moved programs into production.
- B. application programmers accessed test data.
- C. database administrators (DBAs) modified the structure of user tables.
- D. operations staff modified batch schedules.
Answer: B
NEW QUESTION 21
CCM: In the CCM tool, "Encryption and Key Management" is an example of which of the following?
- A. Domain
- B. Risk Impact
- C. Control Specification
Answer: A
NEW QUESTION 22
Which of the following cloud deployment models would BEST meet the needs of a startup software development organization with limited initial capital?
- A. Public
- B. Community
- C. Hybrid
- D. Private
Answer: A
NEW QUESTION 23
Which concept provides the abstraction needed for resource pools?
- A. Metastructure
- B. Hypervisor
- C. Orchestration
- D. Applistructure
- E. Virtualization
Answer: E
NEW QUESTION 24
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?
- A. An image copy of the attacked system was not taken.
- B. The investigation report does not indicate a conclusion.
- C. The proper authorities were not notified.
- D. The handling procedures of the attacked system are not documented.
Answer: C
NEW QUESTION 25
An important consideration when performing a remote vulnerability test of a cloud-based application is to
- A. Obtain provider permission for test
- B. Use techniques to evade cloud provider's detection systems
- C. Use network layer testing tools exclusively
- D. Use application layer testing tools exclusively
- E. Schedule vulnerability test at night
Answer: A
NEW QUESTION 26
ENISA: "VMhopping" is:
- A. Lack of vulnerability management standards.
- B. Looping within virtualized routing systems.
- C. Instability in VM patch management causing VM routing errors.
- D. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.
- E. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
Answer: D
NEW QUESTION 27
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework
- A. Governance and Risk Management
- B. Governance and Retention Management
- C. Governing and Risk Metrics
Answer: A
NEW QUESTION 28
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
- A. URL filters
- B. Database Activity Monitoring
- C. Cloud Access and Security Brokers (CASB)
- D. Data Loss Prevention
- E. Intrusion Prevention System
Answer: E
NEW QUESTION 29
......
New CCAK Exam Questions| Real CCAK Dumps: https://www.2pass4sure.com/Cloud-Security-Alliance/CCAK-actual-exam-braindumps.html
Get New CCAK Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=13GpnQid3DWbO5YSIC3IUkfSd_nGK8QeM