exam questions

Exam CCAK All Questions

View all questions & answers for the CCAK exam

Exam CCAK topic 1 question 104 discussion

Actual exam question from Isaca's CCAK
Question #: 104
Topic #: 1
[All CCAK Questions]

You have been assigned the implementation of an ISMS, whose scope must cover both on premise and cloud infrastructure. Which of the following is your BEST option?

  • A. Implement ISO/IEC 27002 and complement it with additional controls from the CCM.
  • B. Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27017.
  • C. Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27002.
  • D. Implement ISO/IEC 27001 and complement it with additional controls from the NIST SP 800-145.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Auditor2020
4 months, 1 week ago
Selected Answer: B
The best option for implementing an Information Security Management System (ISMS) that covers both on-premise and cloud infrastructure is: **B. Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27017.** ISO/IEC 27001 provides a framework for establishing, implementing, maintaining, and continually improving an ISMS, which is applicable to any organization regardless of its size or sector. It sets out the criteria for an ISMS and is the primary standard for information security management. ISO/IEC 27017 offers additional guidance on information security controls specifically tailored for cloud services. This standard is particularly useful when the ISMS scope includes cloud infrastructure, as it provides cloud-specific controls and additional guidance that complement the general controls found in ISO/IEC 27001. Together, ISO/IEC 27001 and ISO/IEC 27017 provide a comprehensive foundation for managing security in both on-premise and cloud environments.
upvoted 1 times
...
4f2a581
11 months, 4 weeks ago
D, As NIST will provide Cloud Specific Controls
upvoted 1 times
...
Ola213
1 year, 3 months ago
B is the correct answer.
upvoted 1 times
...
sai_murthy
1 year, 5 months ago
Selected Answer: B
The ISO/IEC 27001 standard is broadly applicable to any organization, because it provides a specification for an Information Security Management System (ISMS). ISO/IEC 27002 describes controls that can be put in place to adhere to the ISO/IEC 27001 standard. Further building on these foundational pieces, ISO published ISO/IEC 27017, which provides guidance on the information security aspects of cloud computing, recommending and assisting with the implementation of cloud-specific information security controls supplementing the guidance in ISO/IEC 27002. CCAK P# 134
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...