Which of the following is a category of trust in cloud computing?

Which of the following is a category of trust in cloud computing?A . Loyalty-based trustB . Background-based trustC . Reputation-based trustD . Transparency-based trustView AnswerAnswer: C Explanation: Reputation-based trust is a category of trust in cloud computing that relies on the feedback, ratings, reviews, or recommendations of other users or...

February 17, 2025 No Comments READ MORE +

What is an advantage of using dynamic application security testing (DAST) over static application security testing (SAST) methodology?

What is an advantage of using dynamic application security testing (DAST) over static application security testing (SAST) methodology?A . DAST is slower but thorough.B . Unlike SAST, DAST is a black box and programming language agnostic.C . DAST can dynamically integrate with most continuous integration and continuous delivery (CI/CD) tools.D...

February 15, 2025 No Comments READ MORE +

In relation to testing business continuity management and operational resilience, an auditor should review which of the following database documentation?

In relation to testing business continuity management and operational resilience, an auditor should review which of the following database documentation?A . Database backup and replication guidelinesB . System backup documentationC . Incident management documentationD . Operational manualsView AnswerAnswer: A Explanation: Database backup and replication guidelines are essential for ensuring the...

February 13, 2025 No Comments READ MORE +

Which of the following would be the BEST information security control framework to implement?

A new company has all its operations in the cloud. Which of the following would be the BEST information security control framework to implement?A . NIST 800-73, because it is a control framework implemented by the main cloud providersB . ISO/IEC 27018C . ISO/IEC 27002D . (S) Cloud Security Alliance...

February 11, 2025 No Comments READ MORE +

Which of the following is a cloud-specific security standard?

Which of the following is a cloud-specific security standard?A . 15027017B . 15014001C . 15022301D . 15027701View AnswerAnswer: A Explanation: ISO/IEC 15027017 is a cloud-specific security standard that provides guidelines for information security controls applicable to the provision and use of cloud services. It is based on ISO/IEC 27002, which...

February 8, 2025 No Comments READ MORE +

To support a customer's verification of the cloud service provider claims regarding its responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?

To support a customer's verification of the cloud service provider claims regarding its responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?A . External auditB . Internal auditC . Contractual agreementD . Security assessmentView AnswerAnswer: A Explanation: An external audit is an appropriate...

February 7, 2025 No Comments READ MORE +

Which of the following can be used to determine whether access keys are stored in the source code or any other configuration files during development?

Which of the following can be used to determine whether access keys are stored in the source code or any other configuration files during development?A . Static code reviewB . Dynamic code reviewC . Vulnerability scanningD . Credential scanningView AnswerAnswer: D Explanation: Credential scanning is a technique that can be...

February 5, 2025 No Comments READ MORE +

Which of the following is the GREATEST risk associated with hidden interdependencies between cloud services?

Which of the following is the GREATEST risk associated with hidden interdependencies between cloud services?A . The IT department does not clearly articulate the cloud to the organization.B . There is a lack of visibility over the cloud service providers' supply chain.C . Customers do not understand cloud technologies in...

February 5, 2025 No Comments READ MORE +

The PRIMARY objective for an auditor to understand the organization's context for a cloud audit is to:

The PRIMARY objective for an auditor to understand the organization's context for a cloud audit is to:A . determine whether the organization has carried out control self-assessment (CSA) and validated audit reports of the cloud service providers.B . validate an understanding of the organization's current state and how the cloud...

February 4, 2025 No Comments READ MORE +

Which of the following is the reason for designing the Consensus Assessments Initiative Questionnaire (CAIQ)?

Which of the following is the reason for designing the Consensus Assessments Initiative Questionnaire (CAIQ)?A . Cloud service providers need the CAIQ to improve quality of customer service.B . Cloud service providers can document their security and compliance controls.C . Cloud service providers can document roles and responsibilities for cloud...

February 4, 2025 No Comments READ MORE +