CCAK Dumps 2021 New ISACA CCAK Exam Questions [Q29-Q51]

Share

CCAK Dumps 2021 - New ISACA CCAK Exam Questions

Free CCAK braindumps download (CCAK exam dumps Free Updated)

NEW QUESTION 29
Which of the following cloud deployment models would BEST meet the needs of a startup software development organization with limited initial capital?

  • A. Public
  • B. Community
  • C. Private
  • D. Hybrid

Answer: A

 

NEW QUESTION 30
ENISA: A reason for risk concerns of a cloud provider being acquired is:

  • A. Resource isolation may fail
  • B. Provider may change physical location
  • C. Arbitrary contract termination by acquiring company
  • D. Non-binding agreements put at risk
  • E. Mass layoffs may occur

Answer: D

 

NEW QUESTION 31
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:

  • A. Identity as a Service (IDaaS).
  • B. Infrastructure as a Service (laaS).
  • C. Platform as a Service (PaaS).
  • D. Software as a Service (SaaS).

Answer: C

 

NEW QUESTION 32
REST APIs are the standard for web-based services because they run over HTTPS and work well across diverse environments.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 33
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services fortracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document topotential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?

  • A. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.
  • B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
  • C. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.

Answer: A

 

NEW QUESTION 34
ENISA: Lock-in is ranked as a high risk in ENISA research, a key underlying vulnerability causing lock in is:

  • A. Unclear asset ownership
  • B. Lack of completeness and transparency in terms of use
  • C. Lack of information onjurisdictions
  • D. Audit or certification not available to customers
  • E. No source escrow agreement

Answer: B

 

NEW QUESTION 35
Who is responsible for the security of the physical infrastructure and virtualization platform?

  • A. The majority is covered by the consumer
  • B. The cloud provider
  • C. The responsibility is split equally
  • D. Itdepends on the agreement
  • E. The cloud consumer

Answer: B

 

NEW QUESTION 36
Use elastic servers when possible and move workloads to new instances.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 37
How does running applications on distinct virtual networks and only connecting networksas needed help?

  • A. It provides dynamic and granular policies with less management overhead
  • B. It reduces the blast radius of a compromised system
  • C. It locks down access and provides stronger data security
  • D. It enables you to configure applications around business groups
  • E. It reduces hardware costs

Answer: B

 

NEW QUESTION 38
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 39
All cloud services utilize virtualization technologies.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 40
An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?

  • A. verifying the weighting of each selection criteria
  • B. Witnessing the vendor selection process
  • C. Reviewing the request for proposal (RFP)
  • D. Approving the vendor selection methodology

Answer: D

 

NEW QUESTION 41
Sending data to a provider's storage over an API is likely as much morereliable and secure than setting up your own SFTP server on a VM in the same provider

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 42
Which statement best describes why it is important to know how data is being accessed?

  • A. The devices used to access data use a variety of operating systems and may have different programs installed on them.
  • B. The devices used to access data have different storage formats.
  • C. The devices used to access data may have differentownership characteristics.
  • D. The device may affect data dispersion.
  • E. The devices used to access data use a variety of applications or clients and may have different security characteristics.

Answer: E

 

NEW QUESTION 43
To understand their compliance alignments and gaps with a cloud provider, what must cloud customers rely on?

  • A. EDiscovery tools
  • B. Provider documentation
  • C. Provider and consumer contracts
  • D. Provider run audits and reports
  • E. Third-party attestations

Answer: E

 

NEW QUESTION 44
A client/server configuration will:

  • A. enhance system performance through the separation of front-end and back-end processes.
  • B. keep track of all the clients using the IS facilities of a service organization.
  • C. optimize system performance by having a server on a front-end and clients on a host.
  • D. limit the clients and servers relationship by limiting the IS facilities to a single hardware system.

Answer: A

 

NEW QUESTION 45
An internal audit department recently established a quality assurance (QA) program as part of its overall audit program. Which of the following activities is MOST important to include as part of the QA program requirements?

  • A. Conducting long-term planning for internal audit staffing
  • B. Analyzing user satisfaction reports from business lines
  • C. Benchmarking the QA framework to international standards
  • D. Reporting OA program results to the audit committee

Answer: B

 

NEW QUESTION 46
Which concept is a mapping of an identity, including roles, personas, and attributes, to an authorization?

  • A. Federated Identity Management
  • B. Authentication
  • C. Access control
  • D. Authoritative source
  • E. Entitlement

Answer: E

 

NEW QUESTION 47
What is resource pooling?

  • A. Internet-based CPUs are pooled to enable multi-threading.
  • B. Placing Internet ("cloud") data centers near multiple sources of energy, such as hydroelectric dams.
  • C. The provider's computing resources are pooled to serve multiple consumers.
  • D. The dedicated computing resources of each client are pooled together in a colocation facility.
  • E. None of the above.

Answer: C

 

NEW QUESTION 48
An important consideration when performing a remote vulnerability test of a cloud-based application is to

  • A. Use network layer testing tools exclusively
  • B. Use techniques to evade cloud provider's detection systems
  • C. Schedule vulnerability test at night
  • D. Obtain provider permission for test
  • E. Use application layer testing tools exclusively

Answer: D

 

NEW QUESTION 49
Your SLA with your cloudprovider ensures continuity for all services.

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 50
Which of thefollowing items is NOT an example of Security as a Service (SecaaS)?

  • A. Web filtering
  • B. Spam filtering
  • C. Provisioning
  • D. Authentication
  • E. Intrusion detection

Answer: C

 

NEW QUESTION 51
......

Verified CCAK dumps Q&As - Pass Guarantee Exam Dumps Test Engine: https://www.dumpsking.com/CCAK-testking-dumps.html

CCAK Dumps for Pass Guaranteed - Pass CCAK Exam: https://drive.google.com/open?id=1QWVBFd28vxOZlv8L0DUuKOCa62oI4Ged