exam questions

Exam CCAK All Questions

View all questions & answers for the CCAK exam

Exam CCAK topic 1 question 210 discussion

Actual exam question from Isaca's CCAK
Question #: 210
Topic #: 1
[All CCAK Questions]

An organization plans to migrate to an Infrastructure as a Service (IaaS) cloud service provider and performs an evaluation of the provider's security. What would be the BEST course of action for the cloud auditor to understand the provider's network security controls?

  • A. Perform an independent audit of the cloud service provider’s premises.
  • B. Ask the cloud service provider for a detailed network diagram.
  • C. Check the information provided by the cloud service provider.
  • D. Perform pen testing against the cloud service provider's infrastructure.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Auditor2020
1 month, 2 weeks ago
Selected Answer: C
The BEST course of action for a cloud auditor to understand the provider's network security controls would be: C. Check the information provided by the cloud service provider. This option involves reviewing documentation, reports, and certifications provided by the cloud service provider, such as compliance with industry standards (e.g., ISO 27001, SOC 2) and details about their security controls. This information should give a comprehensive overview of the provider's network security measures. Additionally, cloud service providers often have established security practices and controls that have been externally audited, making this option both practical and efficient for understanding their security posture.
upvoted 1 times
...
sai_murthy
8 months, 4 weeks ago
Selected Answer: C
P# 153 The best sources of information for IaaS and PaaS services are the CSP documentation repositories. Mature CSPs include shared responsibility mappings against common frameworks, such as the AWS Standardized Architecture for NIST-based Assurance Frameworks. As a product consumer, CSPs should share under NDA their SOC II (Service Organization Controls II) type 2 assessment findings. A SOC II example from the Microsoft library requires customer sign-in prior to download. These documents should direct users to customer control responsibilities. Additionally, it is customary to have CSP experts onsite to assist further with implementing and configuring these controls.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago