Get Latest Aug-2021 Conduct effective penetration tests using PracticeMaterial CCAK exam [Q26-Q51]

Share

Get Latest [Aug-2021] Conduct effective penetration tests using  PracticeMaterial CCAK

Penetration testers simulate CCAK exam PDF

NEW QUESTION 26
Select the best definition of"compliance" from the options below.

  • A. The development of a routine that covers all necessary security measures.
  • B. The diligent habits of good security practices and recording of the same.
  • C. The awareness and adherence to obligations, including the assessment and prioritization of corrective actions deemed necessary and appropriate.
  • D. The timely and efficient filing of security reports.
  • E. The process of completing all forms and paperwork necessary to develop a defensible paper trail.

Answer: C

 

NEW QUESTION 27
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?

  • A. Infrastructure-as-a-service (IaaS)
  • B. Software-as-a-service (SaaS)
  • C. Desktop-as-a-service (DaaS)
  • D. Identity-as-a-service (IDaaS)
  • E. Platform-as-a-service (PaaS)

Answer: E

 

NEW QUESTION 28
Use elastic servers when possible and move workloads to new instances.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 29
When deploying Security as a Service in a highly regulated industry or environment, what should bothparties agree on in advance and include in the SLA?

  • A. The metrics defining the service level required to achieve regulatory objectives.
  • B. The duration of time that a security violation can occur before the client begins assessing regulatory fines.
  • C. The cost per incident for security breaches of regulated information.
  • D. The type of security software which meets regulations and the number of licenses that will be needed.
  • E. The regulations that are pertinent to the contract and how to circumvent them.

Answer: A

 

NEW QUESTION 30
What is true of security as it relates to cloud network infrastructure?

  • A. You should implement a default allow with cloud firewalls and then restrict as necessary.
  • B. You should applycloud firewalls on a per-network basis.
  • C. You should deploy your cloud firewalls identical to the existing firewalls.
  • D. You should always open traffic between workloads in the same virtual subnet for better visibility.
  • E. You should implement a default deny with cloud firewalls.

Answer: E

 

NEW QUESTION 31
Network logs from cloud providers are typically flow records, not full packet captures.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 32
What is true of companies considering a cloud computing business relationship?

  • A. The confidentiality agreements between companies using cloud computing services is limited legally to the company, not the provider.
  • B. The cloud computing companies are absolved of all data security and associated risks through contracts and data laws.
  • C. The cloud computing companies own all customer data.
  • D. The laws protecting customer data arebased on the cloud provider and customer location only.
  • E. The companies using the cloud providers are the custodians ofthe data entrusted to them.

Answer: E

 

NEW QUESTION 33
ENISA: A reason for risk concerns of a cloud provider being acquired is:

  • A. Mass layoffs may occur
  • B. Resource isolation may fail
  • C. Provider may change physical location
  • D. Non-binding agreements put at risk
  • E. Arbitrary contract termination by acquiring company

Answer: D

 

NEW QUESTION 34
CCM: In the CCM tool, ais a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.

  • A. Control Specification
  • B. Domain
  • C. Risk Impact

Answer: A

 

NEW QUESTION 35
What is true of searching data across cloud environments?

  • A. You might not have the ability oradministrative rights to search or access all hosted data.
  • B. The cloud provider must conduct the search with the full administrative controls.
  • C. Search and discovery time is alwaysfactored into a contract between the consumer and provider.
  • D. You can easily search across your environment using any E-Discovery tool.
  • E. All cloud-hosted email accounts are easily searchable.

Answer: A

 

NEW QUESTION 36
Who is responsible for the security of the physical infrastructure and virtualization platform?

  • A. The cloud provider
  • B. The responsibility is split equally
  • C. The majority is covered by the consumer
  • D. Itdepends on the agreement
  • E. The cloud consumer

Answer: A

 

NEW QUESTION 37
In volume storage, what method is often used to support resiliency and security?

  • A. hypervisor agents
  • B. random placement
  • C. data dispersion
  • D. data rights management
  • E. proxy encryption

Answer: C

 

NEW QUESTION 38
A client/server configuration will:

  • A. limit the clients and servers relationship by limiting the IS facilities to a single hardware system.
  • B. keep track of all the clients using the IS facilities of a service organization.
  • C. enhance system performance through the separation of front-end and back-end processes.
  • D. optimize system performance by having a server on a front-end and clients on a host.

Answer: C

 

NEW QUESTION 39
How does running applications on distinct virtual networks and only connecting networksas needed help?

  • A. It reduces hardware costs
  • B. It enables you to configure applications around business groups
  • C. It reduces the blast radius of a compromised system
  • D. It locks down access and provides stronger data security
  • E. It provides dynamic and granular policies with less management overhead

Answer: C

 

NEW QUESTION 40
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework

  • A. Governance and Risk Management
  • B. Governing and Risk Metrics
  • C. Governance and Retention Management

Answer: A

 

NEW QUESTION 41
During a review, an IS auditor notes that an organization's marketing department has purchased a cloud-based software application without following the procurement process. What should the auditor do FIRST?

  • A. Escalate to senior management.
  • B. Review the business impact analysis (BIA).
  • C. Review the procurement process.
  • D. Perform a risk analysis.

Answer: D

 

NEW QUESTION 42
Which concept provides the abstraction needed for resource pools?

  • A. Applistructure
  • B. Hypervisor
  • C. Virtualization
  • D. Orchestration
  • E. Metastructure

Answer: C

 

NEW QUESTION 43
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 44
What is resource pooling?

  • A. The dedicated computing resources of each client are pooled together in a colocation facility.
  • B. None of the above.
  • C. Placing Internet ("cloud") data centers near multiple sources of energy, such as hydroelectric dams.
  • D. Internet-based CPUs are pooled to enable multi-threading.
  • E. The provider's computing resources are pooled to serve multiple consumers.

Answer: E

 

NEW QUESTION 45
Sending data to a provider's storage over an API is likely as much morereliable and secure than setting up your own SFTP server on a VM in the same provider

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 46
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what?

  • A. An entrylog
  • B. An access log
  • C. An entitlement matrix
  • D. A validation process
  • E. A support table

Answer: D

 

NEW QUESTION 47
An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?

  • A. Reviewing the request for proposal (RFP)
  • B. verifying the weighting of each selection criteria
  • C. Approving the vendor selection methodology
  • D. Witnessing the vendor selection process

Answer: C

 

NEW QUESTION 48
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?

  • A. URL filters
  • B. Database Activity Monitoring
  • C. Data Loss Prevention
  • D. Cloud Access and Security Brokers (CASB)
  • E. Intrusion Prevention System

Answer: E

 

NEW QUESTION 49
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?

  • A. More physical control over assets and processes.
  • B. None of the above.
  • C. Decreased requirement for proactive management of relationship and adherence to contracts.
  • D. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
  • E. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.

Answer: E

 

NEW QUESTION 50
All cloud services utilize virtualization technologies.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 51
......

Tested Material Used To CCAK Test Engine: https://www.practicematerial.com/CCAK-exam-materials.html

Steps Necessary To Pass The CCAK Exam: https://drive.google.com/open?id=1aH2IyrhPQ0Cmq34Wm0QEjEPHheSPhMWg