exam questions

Exam CCAK All Questions

View all questions & answers for the CCAK exam

Exam CCAK topic 1 question 186 discussion

Actual exam question from Isaca's CCAK
Question #: 186
Topic #: 1
[All CCAK Questions]

How should an auditor deal with auditing a cloud service provider’s suppliers?

  • A. Share the responsibility with the cloud provider to audit the cloud provider’s suppliers.
  • B. No action is necessary, as any aspect of the cloud supplier program is the cloud provider’s responsibility.
  • C. Audit the effectiveness of the cloud provider’s supplier management program.
  • D. No action necessary, as the cloud provider’s suppliers are not part of the compliance program.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Auditor2020
1 month, 2 weeks ago
Selected Answer: C
C. Audit the effectiveness of the cloud provider’s supplier management program. When auditing a cloud service provider, it's important to ensure that the provider's suppliers (often referred to as "subservice organizations") are also effectively managed and compliant with relevant standards and requirements. By auditing the effectiveness of the cloud provider's supplier management program, the auditor can assess how well the cloud provider manages its relationships with suppliers, including how it ensures that those suppliers meet necessary compliance and security standards. This approach allows the auditor to evaluate the risks associated with the supply chain without needing to directly audit each individual supplier.
upvoted 1 times
...
sai_murthy
9 months ago
Selected Answer: C
P# 63 If the CSP outsources parts of its infrastructure, operations or maintenance, these third parties may not satisfy or support the requirements that the CSP is contracted to provide to cloud customers. An organization needs to evaluate how the CSP enforces compliance and check if the CSP flows its own requirements down to third parties. Having regular discussions with the CSPs on supply chain contractual requirements and activities through risk/KPI reports helps to identify risks that need mitigation. If the requirements are not being levied on the supply chain, then the threat to the customer increases. This threat increases as an organization uses more CSP services, and it is dependent on individual CSPs and their supply chain policies.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago