
Free 2021 Cloud Security Alliance CCAK dumps are available on Google Drive shared by PracticeVCE
Welcome to download the newest PracticeVCE CCAK PDF dumps: https://www.practicevce.com/ISACA/CCAK-practice-exam-dumps.html ( 78 Q&As)
NEW QUESTION 46
Network logs from cloud providers are typically flow records, not full packet captures.
- A. True
- B. False
Answer: A
NEW QUESTION 47
An IS department is evaluated monthly on its cost-revenue ratio user satisfaction rate, and computer downtime This is BEST zed as an application of.
- A. control self-assessment (CSA)
- B. value chain analysis
- C. risk framework
- D. balanced scorecard
Answer: D
NEW QUESTION 48
How can virtual machine communications bypass network security controls?
- A. VM images can contain rootkits programmed to bypass firewalls
- B. Hypervisors depend upon multiple network interfaces
- C. VM communications may use a virtual network on the same hardware host
- D. Most network security systems do not recognize encrypted VM traffic
- E. The guest OS can invoke stealth mode
Answer: C
NEW QUESTION 49
Which statement best describes why it is important to know how data is being accessed?
- A. The devices used to access data have different storage formats.
- B. The devices used to access data may have differentownership characteristics.
- C. The devices used to access data use a variety of operating systems and may have different programs installed on them.
- D. The device may affect data dispersion.
- E. The devices used to access data use a variety of applications or clients and may have different security characteristics.
Answer: E
NEW QUESTION 50
What is resource pooling?
- A. The dedicated computing resources of each client are pooled together in a colocation facility.
- B. None of the above.
- C. Placing Internet ("cloud") data centers near multiple sources of energy, such as hydroelectric dams.
- D. Internet-based CPUs are pooled to enable multi-threading.
- E. The provider's computing resources are pooled to serve multiple consumers.
Answer: E
NEW QUESTION 51
Your SLA with your cloudprovider ensures continuity for all services.
- A. False
- B. True
Answer: A
NEW QUESTION 52
Which cloud storage technology is basically a virtual hard drive for instanced or VMs?
- A. Application
- B. Object storage
- C. Platform
- D. Database
- E. Volume storage
Answer: E
NEW QUESTION 53
What is the best way to ensure that all data has been removed from a public cloud environment including all media such as back-up tapes?
- A. Practice Integration of Duties (IOD) so that everyone is able to delete the encrypted data.
- B. Maintaining customer managed key management and revoking ordeleting keys from the key management system to prevent the data from being accessed again.
- C. Keep the keys stored on the client side so that they are secure and so that the users have the ability to delete their own data.
- D. Both B and D.
- E. Allowing the cloud provider to manage your keys so that they have the ability to access and delete the data from the main and back-up storage.
Answer: B
NEW QUESTION 54
What is defined as the process by which an opposing party may obtain private documents for use in litigation?
- A. Custody
- B. Subpoena
- C. Scope
- D. Discovery
- E. Risk Assessment
Answer: D
NEW QUESTION 55
Why is a service type of network typically isolated on different hardware?
- A. It manages resource pools for cloud consumers
- B. It manages the traffic between other networks
- C. It requires distinct access controls
- D. It has distinct functions from other networks
- E. It requires unique security
Answer: B
NEW QUESTION 56
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?
- A. More physical control over assets and processes.
- B. None of the above.
- C. Decreased requirement for proactive management of relationship and adherence to contracts.
- D. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
- E. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.
Answer: E
NEW QUESTION 57
Your cloud and on-premisesinfrastructures should always use the same network address ranges.
- A. False
- B. True
Answer: A
NEW QUESTION 58
CCM: A hypothetical company called: "Health4Sure" is located in the United States and provides cloud based services fortracking patient health. The company is compliant with HIPAA/HITECH Act among other industry standards. Health4Sure decides to assess the overall security of their cloud service against the CCM toolkit so that they will be able to present this document topotential clients.
Which of the following approach would be most suitable to assess the overall security posture of Health4Sure's cloud service?
- A. The CCM domains are not mapped to HIPAA/HITECH Act. Therefore Health4Sure should assess the security posture of their cloud service against each and every control in the CCM. This approach will allow a thorough assessment of the security posture.
- B. The CCM domain controls are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered as a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls thoroughly. This approach saves time while being able to assess the company's overall security posture in an efficient manner.
- C. The CCM columns are mapped to HIPAA/HITECH Act and therefore Health4Sure could verify the CCM controls already covered ad a result of their compliance with HIPPA/HITECH Act. They could then assess the remaining controls. This approach will save time.
Answer: A
NEW QUESTION 59
Which data security control is the LEAST likely to be assigned to an IaaSprovider?
- A. Application logic
- B. Encryption solutions
- C. Physical destruction
- D. Asset management and tracking
- E. Access controls
Answer: A
NEW QUESTION 60
In volume storage, what method is often used to support resiliency and security?
- A. hypervisor agents
- B. random placement
- C. data dispersion
- D. data rights management
- E. proxy encryption
Answer: C
NEW QUESTION 61
Which of the following should be of GREATEST concern to an IS auditor reviewing actions taken during a forensic investigation?
- A. The investigation report does not indicate a conclusion.
- B. The handling procedures of the attacked system are not documented.
- C. An image copy of the attacked system was not taken.
- D. The proper authorities were not notified.
Answer: D
NEW QUESTION 62
When deploying an application that was created using the programming language and tools supported by the cloud provider, the MOST appropriate cloud computing model for an organization to adopt is:
- A. Platform as a Service (PaaS).
- B. Infrastructure as a Service (laaS).
- C. Identity as a Service (IDaaS).
- D. Software as a Service (SaaS).
Answer: A
NEW QUESTION 63
......
Tested Material Used To CCAK: https://www.practicevce.com/ISACA/CCAK-practice-exam-dumps.html
Following are some new CCAK Real Exam Questions!: https://drive.google.com/open?id=1vUQXzLxmAx7Vi0hSXFGhoBpnsp14ll51