
Valid CCAK Exam Q&A PDF CCAK Dump is Ready (Updated 78 Questions)
Exam Questions and Answers for CCAK Study Guide
NEW QUESTION 15
Which of the following should be the PRIMARY concern of an IS auditor during a review of an external IT service level agreement (SLA) for computer operations?
- A. Lack of software escrow provisions
- B. Vendor has exclusive control of IT resources
- C. No employee succession plan
- D. Changes in services are not tracked
Answer: D
NEW QUESTION 16
An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?
- A. Reviewing the request for proposal (RFP)
- B. verifying the weighting of each selection criteria
- C. Approving the vendor selection methodology
- D. Witnessing the vendor selection process
Answer: C
NEW QUESTION 17
What is defined as the process by which an opposing party may obtain private documents for use in litigation?
- A. Custody
- B. Subpoena
- C. Scope
- D. Discovery
- E. Risk Assessment
Answer: D
NEW QUESTION 18
Which of the following would be MOST important to update once a decision has been made to outsource a critical application to a cloud service provider?
- A. IT budget
- B. Business impact analysis (BIA)
- C. Project portfolio
- D. IT resource plan
Answer: B
NEW QUESTION 19
How can virtual machine communications bypass network security controls?
- A. VM images can contain rootkits programmed to bypass firewalls
- B. Hypervisors depend upon multiple network interfaces
- C. VM communications may use a virtual network on the same hardware host
- D. Most network security systems do not recognize encrypted VM traffic
- E. The guest OS can invoke stealth mode
Answer: C
NEW QUESTION 20
Big data includes high volume, high variety, and high velocity.
- A. True
- B. False
Answer: A
NEW QUESTION 21
What is known as a code execution environment running within an operating system that shares and uses the resources of the operating system?
- A. Abstraction
- B. Container
- C. Platform-basedWorkload
- D. Pod
- E. Virtual machine
Answer: B
NEW QUESTION 22
Which attack surfaces, if any, does virtualization technology introduce?
- A. All of the above
- B. The hypervisor
- C. Configuration and VM sprawl issues
- D. Virtualization management components apart from the hypervisor
Answer: A
NEW QUESTION 23
Dynamic Application Security Testing (DAST) might be limited or require pre-testing permission from the provider.
- A. True
- B. False
Answer: A
NEW QUESTION 24
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?
- A. Application
- B. Object storage
- C. Platform
- D. Database
- E. Volume storage
Answer: E
NEW QUESTION 25
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?
- A. The investigation report does not indicate a conclusion.
- B. The handling procedures of the attacked system are not documented.
- C. An image copy of the attacked system was not taken.
- D. The proper authorities were not notified.
Answer: D
NEW QUESTION 26
Which of the following is the GREATEST security risk associated with data migration from a legacy human resources (HR) system to a cloud-based system''
- A. Data from the source and target system may have different data formats
- B. Records past their retention period may not be migrated to the new system
- C. System performance may be impacted by the migration
- D. Data from the source and target system may be intercepted
Answer: D
NEW QUESTION 27
An internal audit department recently established a quality assurance (QA) program as part of its overall audit program. Which of the following activities is MOST important to include as part of the QA program requirements?
- A. Reporting OA program results to the audit committee
- B. Benchmarking the QA framework to international standards
- C. Conducting long-term planning for internal audit staffing
- D. Analyzing user satisfaction reports from business lines
Answer: D
NEW QUESTION 28
What item below allows disparate directory services and independent security domains to be interconnected?
- A. Coalition
- B. Cloud
- C. Federation
- D. Union
- E. Intersection
Answer: C
NEW QUESTION 29
Your SLA with your cloudprovider ensures continuity for all services.
- A. False
- B. True
Answer: A
NEW QUESTION 30
What is the newer application development methodology and philosophy focused on automation of application development and deployment?
- A. SecDevOps
- B. DevOps
- C. Agile
- D. BusOps
- E. Scrum
Answer: B
NEW QUESTION 31
A client/server configuration will:
- A. limit the clients and servers relationship by limiting the IS facilities to a single hardware system.
- B. keep track of all the clients using the IS facilities of a service organization.
- C. enhance system performance through the separation of front-end and back-end processes.
- D. optimize system performance by having a server on a front-end and clients on a host.
Answer: C
NEW QUESTION 32
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework
- A. Governance and Risk Management
- B. Governing and Risk Metrics
- C. Governance and Retention Management
Answer: A
NEW QUESTION 33
ENISA: "VMhopping" is:
- A. Improper management of VM instances, causing customer VMs to be commingled with other customer systems.
- B. Using a compromised VM to exploit a hypervisor, used to take control of other VMs.
- C. Looping within virtualized routing systems.
- D. Lack of vulnerability management standards.
- E. Instability in VM patch management causing VM routing errors.
Answer: B
NEW QUESTION 34
Who is responsible for the security of the physical infrastructure and virtualization platform?
- A. The cloud provider
- B. The responsibility is split equally
- C. The majority is covered by the consumer
- D. Itdepends on the agreement
- E. The cloud consumer
Answer: A
NEW QUESTION 35
......
Certification dumps - Cloud Security Alliance CCAK guides - 100% valid: https://www.exam4free.com/CCAK-valid-dumps.html
100% Pass Your CCAK Certificate of Cloud Auditing Knowledge at First Attempt with Exam4Free: https://drive.google.com/open?id=1xXFlfce1jY9cuOcg2HftROr0VnCZDa54
