exam questions

Exam CCAK All Questions

View all questions & answers for the CCAK exam

Exam CCAK topic 1 question 101 discussion

Actual exam question from Isaca's CCAK
Question #: 101
Topic #: 1
[All CCAK Questions]

Prioritizing assurance activities for an organization’s cloud services portfolio depends PRIMARILY on an organization’s ability to:

  • A. schedule frequent reviews with high-risk cloud service providers.
  • B. develop plans using a standardized risk-based approach.
  • C. maintain a comprehensive cloud service inventory.
  • D. collate views from various business functions using cloud services.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Auditor2020
3 months, 1 week ago
Selected Answer: B
The correct answer is: **B. develop plans using a standardized risk-based approach.** Prioritizing assurance activities for an organization’s cloud services portfolio primarily depends on using a risk-based approach to identify and evaluate potential risks associated with different cloud services. This approach allows the organization to systematically assess which services pose higher risks and require more frequent or in-depth assurance activities. By focusing on risk, the organization can allocate resources effectively and ensure that the most critical areas receive appropriate attention. While scheduling reviews, maintaining inventories, and gathering business function insights are important, the standardized risk-based approach provides the necessary framework to prioritize assurance activities based on the actual risk profile of the cloud services portfolio.
upvoted 1 times
...
sai_murthy
10 months, 1 week ago
Selected Answer: B
Design the risk assessment program for cloud migration—all deployment models (private vs. public), service models (IaaS/PaaS/SaaS) and data classification models affect the risk management process. Organizations should list the cloud risks they foresee, and then examine the designated cloud service against those risks to determine risk likelihood, impact and tolerance. CCAK P# 36
upvoted 2 times
...
ME79
1 year, 9 months ago
Selected Answer: B
Answer B. CCAK Study Guide, p. 265-266, Section 5.5.1 Understanding the Required Level of Assurance to Satisfy the Cloud Customer, "Based on the penetration of cloud services into the typical organization technology environment and the two-dimensional aspect of both the number of service providers and the number of organizational instances, it is imperative that an enterprise risk management program be implemented or extended to include all known and unknown (shadow IT) cloud services and providers. This risk-based approach will facilitate the creation of a portfolio view of all CSPs, with risk ratings for each type of service provided to the organization."
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...