When performing audits in relation to Business Continuity Management and Operational Resilience strategy, what would be the MOST critical aspect to audit in relation to the strategy of the cloud customer that should be formulated jointly with the cloud service provider?

When performing audits in relation to Business Continuity Management and Operational Resilience strategy, what would be the MOST critical aspect to audit in relation to the strategy of the cloud customer that should be formulated jointly with the cloud service provider?A . Validate if the strategy covers unavailability of all...

December 13, 2021 No Comments READ MORE +

The criteria for limiting services allowing non-critical services or services requiring high availability and resilience to be moved to the cloud is an important consideration to be included PRIMARILY in the:

The criteria for limiting services allowing non-critical services or services requiring high availability and resilience to be moved to the cloud is an important consideration to be included PRIMARILY in the:A . risk management policy.B . cloud policy.C . business continuity plan.D . information security standard for cloud technologies.View AnswerAnswer:...

December 13, 2021 No Comments READ MORE +

The Cloud Octagon Model was developed to support organizations:

The Cloud Octagon Model was developed to support organizations:A . risk assessment methodology.B . risk treatment methodology.C . incident response methodology.D . incident detection methodology.View AnswerAnswer: A

December 12, 2021 No Comments READ MORE +

Which of the following approaches is BEST suited for such an organization to evaluate its cloud security?

An organization is in the initial phases of cloud adoption. It is not very knowledgeable about cloud security and cloud shared responsibility models. Which of the following approaches is BEST suited for such an organization to evaluate its cloud security?A . Use of an established standard/regulation to map controls and...

December 12, 2021 No Comments READ MORE +

What areas should be reviewed when auditing a public cloud?

What areas should be reviewed when auditing a public cloud?A . Patching, source code reviews, hypervisor, access controlsB . Identity and access management, data protectionC . Patching, configuration, hypervisor, backupsD . Vulnerability management, cyber security reviews, patchingView AnswerAnswer: B

December 11, 2021 No Comments READ MORE +

Which of the following would be the MOST critical finding of an application security and DevOps audit?

Which of the following would be the MOST critical finding of an application security and DevOps audit?A . The organization is not using a unified framework to integrate cloud compliance with regulatory requirements.B . Application architecture and configurations did not consider security measures.C . Outsourced cloud service interruption, breach or...

December 11, 2021 No Comments READ MORE +

From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps concept?

From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps concept?A . Process of security integration using automation in software developmentB . Development standards for addressing integration, testing, and deployment...

December 11, 2021 No Comments READ MORE +

Which of the following controls BEST matches this control description?

Policies and procedures shall be established, and supporting business processes and technical measures implemented, for maintenance of several items ensuring continuity and availability of operations and support personnel. Which of the following controls BEST matches this control description?A . Operations MaintenanceB . System Development MaintenanceC . Equipment MaintenanceD . System...

December 10, 2021 No Comments READ MORE +

A CSP providing cloud services currently being used by the United States federal government should obtain which of the following to assure compliance to stringent government standards?

A CSP providing cloud services currently being used by the United States federal government should obtain which of the following to assure compliance to stringent government standards?A . Multi-Tier Cloud Security (MTCS) AttestationB . FedRAMP AuthorizationC . ISO/IEC 27001:2013 CertificationD . CSA STAR Level CertificateView AnswerAnswer: B Explanation: Reference: https://www.ftptoday.com/blog/benefits-using-fedramp-authorized-cloud-service-provider

December 9, 2021 No Comments READ MORE +

Which of the following CSP activities requires a client’s approval?

Which of the following CSP activities requires a client’s approval?A . Delete the guest account or test accountsB . Delete the master account or subscription owner accountsC . Delete the guest account or destroy test dataD . Delete the test accounts or destroy test dataView AnswerAnswer: D

December 9, 2021 No Comments READ MORE +