exam questions

Exam CCAK All Questions

View all questions & answers for the CCAK exam

Exam CCAK topic 1 question 23 discussion

Actual exam question from Isaca's CCAK
Question #: 23
Topic #: 1
[All CCAK Questions]

To qualify for CSA STAR attestation for a particular cloud system, the SOC 2 report must cover:

  • A. ISO/IЕС 27001: 2013 controls.
  • B. maturity model criteria.
  • C. all Cloud Control Matrix (CCM) controls and TSPC security principles.
  • D. Cloud Control Matrix (CCM) and ISO/IEC 27001:2013 controls.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Auditor2020
2 months, 2 weeks ago
Selected Answer: C
To qualify for CSA STAR attestation, a cloud provider's SOC 2 report must cover specific criteria that align with the CSA's requirements. The correct answer is: C. all Cloud Control Matrix (CCM) controls and TSPC security principles. The CSA Security, Trust & Assurance Registry (STAR) attestation involves assessing a cloud service provider's security controls against the Cloud Control Matrix (CCM) and the Trust Services Criteria (TSC), formerly known as Trust Service Principles and Criteria (TSPC). This provides a comprehensive evaluation of the provider’s security posture and practices.
upvoted 1 times
...
SafiT
6 months, 1 week ago
CCAK -, correct ans is C
upvoted 1 times
...
sai_murthy
1 year, 3 months ago
Selected Answer: C
CSA STAR Attestation—CSA STAR Attestation is an auditing procedure to report on the examination of the implementation of trust service principles (TSP) and cloud-specific control objectives (CCM). CSA STAR Attestation can be considered as a SOC 2 Type 2 attestation augmented by CCM requirements. It was created thanks to a collaboration between CSA and the American Institute of CPAs (AICPA) to provide guidelines for CPAs to conduct SOC 2 engagements using criteria from the AICPA (Trust Service Principles, AT 101) and the CSA Cloud Controls Matrix. CCAK Guide - Page: 372
upvoted 1 times
...
vsgsds
1 year, 3 months ago
Selected Answer: C
page 379
upvoted 1 times
...
ats20
1 year, 5 months ago
Selected Answer: D
To qualify for CSA STAR attestation for a particular cloud system, the SOC 2 report must cover Cloud Control Matrix (CCM) and ISO/IEC 27001:2013 controls. The Cloud Security Alliance (CSA) Security, Trust & Assurance Registry (STAR) is a publicly accessible registry that documents the security controls provided by various cloud computing offerings. The CSA STAR attestation is a rigorous third-party independent assessment of cloud providers that is based on the Cloud Controls Matrix (CCM) and the ISO/IEC 27001:2013 standard. The CCM is a cybersecurity control framework for cloud computing that is considered the de-facto standard for cloud security and privacy. ISO/IEC 27001:2013 is an international standard that provides a framework for information security management systems (ISMS).
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...