[Nov-2021] CCAK Free PDF from Actualtests4sure [Q32-Q53]

Share

Nov-2021 Latest Actualtests4sure CCAK Exam Dumps with PDF and Exam Engine Free Updated Today!

Following are some new CCAK Real Exam Questions!

NEW QUESTION 32
CCM: In the CCM tool, ais a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.

  • A. Risk Impact
  • B. Control Specification
  • C. Domain

Answer: B

 

NEW QUESTION 33
Which of the following is the GREATEST security risk associated with data migration from a legacy human resources (HR) system to a cloud-based system''

  • A. Data from the source and target system may be intercepted
  • B. Data from the source and target system may have different data formats
  • C. Records past their retention period may not be migrated to the new system
  • D. System performance may be impacted by the migration

Answer: A

 

NEW QUESTION 34
An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?

  • A. verifying the weighting of each selection criteria
  • B. Approving the vendor selection methodology
  • C. Witnessing the vendor selection process
  • D. Reviewing the request for proposal (RFP)

Answer: B

 

NEW QUESTION 35
What factors should you understand about the data specifically due to legal, regulatory, and jurisdictional factors?

  • A. The actualsize of the data and the storage format
  • B. The implications of storing complex information on simple storage systems
  • C. Thephysical location of the data and how it is accessed
  • D. The language of the data and how it affects the user
  • E. The fragmentation and encryption algorithms employed

Answer: B

 

NEW QUESTION 36
Which of the following should be an IS auditor's GREATEST concern when reviewing an outsourcing arrangement with a third-party cloud service provider to host personally identifiable data?

  • A. Fees are charged based on the volume of data stored by the host.
  • B. The organization's servers are not compatible with the third party's infrastructure
  • C. The outsourcing contract does not contain a right-to-audit clause.
  • D. The data is not adequately segregated on the host platform.

Answer: D

 

NEW QUESTION 37
What is defined as the process by which an opposing party may obtain private documents for use in litigation?

  • A. Scope
  • B. Risk Assessment
  • C. Custody
  • D. Subpoena
  • E. Discovery

Answer: E

 

NEW QUESTION 38
Select the best definition of"compliance" from the options below.

  • A. The timely and efficient filing of security reports.
  • B. The diligent habits of good security practices and recording of the same.
  • C. The development of a routine that covers all necessary security measures.
  • D. The process of completing all forms and paperwork necessary to develop a defensible paper trail.
  • E. The awareness and adherence to obligations, including the assessment and prioritization of corrective actions deemed necessary and appropriate.

Answer: E

 

NEW QUESTION 39
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework

  • A. Governance and Risk Management
  • B. Governance and Retention Management
  • C. Governing and Risk Metrics

Answer: A

 

NEW QUESTION 40
What is known as a code execution environment running within an operating system that shares and uses the resources of the operating system?

  • A. Abstraction
  • B. Virtual machine
  • C. Container
  • D. Platform-basedWorkload
  • E. Pod

Answer: C

 

NEW QUESTION 41
Which of the following statements are NOT requirements of governance and enterprise risk management in a cloud environment?

  • A. Respect the interdependency of the risks inherent in the cloud supply chain and communicate the corporate riskposture and readiness to consumers and dependent parties.
  • B. Inspect and account for risksinherited from other members of the cloud supply chain and take active measures to mitigate and contain risks through operational resiliency.
  • C. Provide transparency to stakeholders and shareholders demonstrating fiscal solvency and organizational transparency.
  • D. Negotiate long-term contracts with companies who use well-vetted software application to avoid the transient nature of the cloud environment.
  • E. Both B and C.

Answer: D

 

NEW QUESTION 42
Which data security control is the LEAST likely to be assigned to an IaaSprovider?

  • A. Access controls
  • B. Encryption solutions
  • C. Application logic
  • D. Asset management and tracking
  • E. Physical destruction

Answer: C

 

NEW QUESTION 43
What is the newer application development methodology and philosophy focused on automation of application development and deployment?

  • A. SecDevOps
  • B. DevOps
  • C. Agile
  • D. Scrum
  • E. BusOps

Answer: B

 

NEW QUESTION 44
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?

  • A. An image copy of the attacked system was not taken.
  • B. The investigation report does not indicate a conclusion.
  • C. The proper authorities were not notified.
  • D. The handling procedures of the attacked system are not documented.

Answer: C

 

NEW QUESTION 45
An organization recently implemented a cloud document storage solution and removed the ability for end users to save data to their local workstation hard drives Which of the following findings should be the IS auditor's GREATEST concern?

  • A. The business continuity plan (BCP) was not updated.
  • B. Mobile devices are not encrypted.
  • C. Users are not required to sign updated acceptable
  • D. Users have not been trained on the new system.

Answer: A

 

NEW QUESTION 46
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?

  • A. Maintaining customer managed key management and revoking ordeleting keys from the key management system to prevent the data from being accessed again.
  • B. Allowing the cloud provider to manage your keys so that they have the ability to access and delete the data from the main and back-up storage.
  • C. Keep the keys stored on the client side so that they are secure and so that the users have the ability to delete their own data.
  • D. Practice Integration of Duties (IOD) so that everyone is able to delete the encrypted data.
  • E. Both B and D.

Answer: A

 

NEW QUESTION 47
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?

  • A. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
  • B. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.
  • C. None of the above.
  • D. Decreased requirement for proactive management of relationship and adherence to contracts.
  • E. More physical control over assets and processes.

Answer: B

 

NEW QUESTION 48
How can virtual machine communications bypass network security controls?

  • A. VM images can contain rootkits programmed to bypass firewalls
  • B. Most network security systems do not recognize encrypted VM traffic
  • C. The guest OS can invoke stealth mode
  • D. Hypervisors depend upon multiple network interfaces
  • E. VM communications may use a virtual network on the same hardware host

Answer: E

 

NEW QUESTION 49
APIs and web services require extensive hardening and must assume attacks from authenticated and unauthenticated adversaries.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 50
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?

  • A. URL filters
  • B. Database Activity Monitoring
  • C. Cloud Access and Security Brokers (CASB)
  • D. Data Loss Prevention
  • E. Intrusion Prevention System

Answer: E

 

NEW QUESTION 51
Which statement best describes why it is important to know how data is being accessed?

  • A. The devices used to access data use a variety of applications or clients and may have different security characteristics.
  • B. The device may affect data dispersion.
  • C. The devices used to access data may have differentownership characteristics.
  • D. The devices used to access data use a variety of operating systems and may have different programs installed on them.
  • E. The devices used to access data have different storage formats.

Answer: A

 

NEW QUESTION 52
Which of the following cloud deployment models would BEST meet the needs of a startup software development organization with limited initial capital?

  • A. Public
  • B. Community
  • C. Hybrid
  • D. Private

Answer: A

 

NEW QUESTION 53
......


Resources From:

  1. 2021 Latest Actualtests4sure CCAK Exam Dumps (PDF & Exam Engine) Free Share: https://www.actualtests4sure.com/CCAK-test-questions.html
  2. 2021 Latest Actualtests4sure CCAK PDF and CCAK Exam Dumps Free Share: https://drive.google.com/open?id=1HNBkayJzwkLDEMy0H5LvKx2W37dUWTiV

Free Resources from Actualtests4sure, We Devoted to Helping You 100% Pass All Exams!