
Get Latest [Aug-2021] Conduct effective penetration tests using PracticeMaterial CCAK
Penetration testers simulate CCAK exam PDF
NEW QUESTION 26
Select the best definition of"compliance" from the options below.
- A. The development of a routine that covers all necessary security measures.
- B. The diligent habits of good security practices and recording of the same.
- C. The awareness and adherence to obligations, including the assessment and prioritization of corrective actions deemed necessary and appropriate.
- D. The timely and efficient filing of security reports.
- E. The process of completing all forms and paperwork necessary to develop a defensible paper trail.
Answer: C
NEW QUESTION 27
Which cloud-based service model enables companies to provide client-based access for partners to databases or applications?
- A. Infrastructure-as-a-service (IaaS)
- B. Software-as-a-service (SaaS)
- C. Desktop-as-a-service (DaaS)
- D. Identity-as-a-service (IDaaS)
- E. Platform-as-a-service (PaaS)
Answer: E
NEW QUESTION 28
Use elastic servers when possible and move workloads to new instances.
- A. True
- B. False
Answer: A
NEW QUESTION 29
When deploying Security as a Service in a highly regulated industry or environment, what should bothparties agree on in advance and include in the SLA?
- A. The metrics defining the service level required to achieve regulatory objectives.
- B. The duration of time that a security violation can occur before the client begins assessing regulatory fines.
- C. The cost per incident for security breaches of regulated information.
- D. The type of security software which meets regulations and the number of licenses that will be needed.
- E. The regulations that are pertinent to the contract and how to circumvent them.
Answer: A
NEW QUESTION 30
What is true of security as it relates to cloud network infrastructure?
- A. You should implement a default allow with cloud firewalls and then restrict as necessary.
- B. You should applycloud firewalls on a per-network basis.
- C. You should deploy your cloud firewalls identical to the existing firewalls.
- D. You should always open traffic between workloads in the same virtual subnet for better visibility.
- E. You should implement a default deny with cloud firewalls.
Answer: E
NEW QUESTION 31
Network logs from cloud providers are typically flow records, not full packet captures.
- A. True
- B. False
Answer: A
NEW QUESTION 32
What is true of companies considering a cloud computing business relationship?
- A. The confidentiality agreements between companies using cloud computing services is limited legally to the company, not the provider.
- B. The cloud computing companies are absolved of all data security and associated risks through contracts and data laws.
- C. The cloud computing companies own all customer data.
- D. The laws protecting customer data arebased on the cloud provider and customer location only.
- E. The companies using the cloud providers are the custodians ofthe data entrusted to them.
Answer: E
NEW QUESTION 33
ENISA: A reason for risk concerns of a cloud provider being acquired is:
- A. Mass layoffs may occur
- B. Resource isolation may fail
- C. Provider may change physical location
- D. Non-binding agreements put at risk
- E. Arbitrary contract termination by acquiring company
Answer: D
NEW QUESTION 34
CCM: In the CCM tool, ais a measure that modifies risk and includes any process, policy, device, practice or any other actions which modify risk.
- A. Control Specification
- B. Domain
- C. Risk Impact
Answer: A
NEW QUESTION 35
What is true of searching data across cloud environments?
- A. You might not have the ability oradministrative rights to search or access all hosted data.
- B. The cloud provider must conduct the search with the full administrative controls.
- C. Search and discovery time is alwaysfactored into a contract between the consumer and provider.
- D. You can easily search across your environment using any E-Discovery tool.
- E. All cloud-hosted email accounts are easily searchable.
Answer: A
NEW QUESTION 36
Who is responsible for the security of the physical infrastructure and virtualization platform?
- A. The cloud provider
- B. The responsibility is split equally
- C. The majority is covered by the consumer
- D. Itdepends on the agreement
- E. The cloud consumer
Answer: A
NEW QUESTION 37
In volume storage, what method is often used to support resiliency and security?
- A. hypervisor agents
- B. random placement
- C. data dispersion
- D. data rights management
- E. proxy encryption
Answer: C
NEW QUESTION 38
A client/server configuration will:
- A. limit the clients and servers relationship by limiting the IS facilities to a single hardware system.
- B. keep track of all the clients using the IS facilities of a service organization.
- C. enhance system performance through the separation of front-end and back-end processes.
- D. optimize system performance by having a server on a front-end and clients on a host.
Answer: C
NEW QUESTION 39
How does running applications on distinct virtual networks and only connecting networksas needed help?
- A. It reduces hardware costs
- B. It enables you to configure applications around business groups
- C. It reduces the blast radius of a compromised system
- D. It locks down access and provides stronger data security
- E. It provides dynamic and granular policies with less management overhead
Answer: C
NEW QUESTION 40
CCM: The following list of controls belong to which domain of the CCM?
GRM 06 - Policy GRM 07- Policy Enforcement GRM 08 - Policy Impact on Risk Assessments GRM 09 - Policy Reviews GRM 10 - Risk Assessments GRM 11 - Risk Management Framework
- A. Governance and Risk Management
- B. Governing and Risk Metrics
- C. Governance and Retention Management
Answer: A
NEW QUESTION 41
During a review, an IS auditor notes that an organization's marketing department has purchased a cloud-based software application without following the procurement process. What should the auditor do FIRST?
- A. Escalate to senior management.
- B. Review the business impact analysis (BIA).
- C. Review the procurement process.
- D. Perform a risk analysis.
Answer: D
NEW QUESTION 42
Which concept provides the abstraction needed for resource pools?
- A. Applistructure
- B. Hypervisor
- C. Virtualization
- D. Orchestration
- E. Metastructure
Answer: C
NEW QUESTION 43
Cloud applications can use virtual networks and other structures, for hyper-segregated environments.
- A. True
- B. False
Answer: A
NEW QUESTION 44
What is resource pooling?
- A. The dedicated computing resources of each client are pooled together in a colocation facility.
- B. None of the above.
- C. Placing Internet ("cloud") data centers near multiple sources of energy, such as hydroelectric dams.
- D. Internet-based CPUs are pooled to enable multi-threading.
- E. The provider's computing resources are pooled to serve multiple consumers.
Answer: E
NEW QUESTION 45
Sending data to a provider's storage over an API is likely as much morereliable and secure than setting up your own SFTP server on a VM in the same provider
- A. True
- B. False
Answer: A
NEW QUESTION 46
A defining set of rules composed of claims and attributes of the entities in a transaction, which is used to determine their level of access to cloud-based resources is called what?
- A. An entrylog
- B. An access log
- C. An entitlement matrix
- D. A validation process
- E. A support table
Answer: D
NEW QUESTION 47
An IS auditor is a member of an application development team that is selecting software. Which of the following would impair the auditor's independence?
- A. Reviewing the request for proposal (RFP)
- B. verifying the weighting of each selection criteria
- C. Approving the vendor selection methodology
- D. Witnessing the vendor selection process
Answer: C
NEW QUESTION 48
Which of the following is NOT normally a method for detecting and preventing data migration into the cloud?
- A. URL filters
- B. Database Activity Monitoring
- C. Data Loss Prevention
- D. Cloud Access and Security Brokers (CASB)
- E. Intrusion Prevention System
Answer: E
NEW QUESTION 49
Which of the following is a perceived advantage or disadvantage of managing enterprise risk for cloud deployments?
- A. More physical control over assets and processes.
- B. None of the above.
- C. Decreased requirement for proactive management of relationship and adherence to contracts.
- D. Increased need, but reduction in costs, for managing risks accepted by the cloud provider.
- E. Greater reliance on contracts, audits, and assessments due to lack of visibility or management.
Answer: E
NEW QUESTION 50
All cloud services utilize virtualization technologies.
- A. True
- B. False
Answer: A
NEW QUESTION 51
......
Tested Material Used To CCAK Test Engine: https://www.practicematerial.com/CCAK-exam-materials.html
Steps Necessary To Pass The CCAK Exam: https://drive.google.com/open?id=1aH2IyrhPQ0Cmq34Wm0QEjEPHheSPhMWg

