exam questions

Exam CCAK All Questions

View all questions & answers for the CCAK exam

Exam CCAK topic 1 question 201 discussion

Actual exam question from Isaca's CCAK
Question #: 201
Topic #: 1
[All CCAK Questions]

Which of the following cloud service models recommends building guardrails for developers and DevOps?

  • A. Infrastructure as a Service (IaaS)
  • B. Security as a Service (SecaaS)
  • C. Platform as a Service (PaaS)
  • D. Software as a Service (SaaS)]
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Auditor2020
1 month, 2 weeks ago
Selected Answer: A
A. Infrastructure as a Service (IaaS) Infrastructure as a Service (IaaS) is the cloud service model that recommends building guardrails for developers and DevOps teams. In an IaaS environment, users have significant control over the infrastructure, including virtual machines, storage, and networks. This level of control requires careful management to prevent misconfigurations and ensure security best practices are followed. Building guardrails involves setting up automated policies and controls that guide developers and DevOps teams in deploying resources securely and efficiently within the IaaS environment. These guardrails help prevent errors, enforce compliance with security standards, and optimize resource usage without constraining the flexibility needed for innovation and development. In contrast, PaaS and SaaS models abstract much of the infrastructure management, reducing the need for such guardrails, while SecaaS focuses on delivering security solutions through the cloud.
upvoted 1 times
...
sai_murthy
9 months ago
Selected Answer: C
P# 28 PaaS governance policies should function like guardrails—allow enough freedom to innovate, but make sure that certain security requirements are always met. P# 351 Automation is used to improve overall security operations unrelated to development. Guardrails, for example, are one form of automation that can remediate misconfigurations in cloud deployments. Many organizations are rapidly integrating automation into their incident response playbooks. Although not all of these are directly DevSecOps, they typically involve leveraging the same automation tools and technologies used by traditional DevOps, but in the security context.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago