ISACA CCAKテストエンジン問題集トレーニングには207問あります [Q111-Q126]

Share

ISACA CCAKテストエンジン問題集トレーニングには207問あります

CCAK問題一発合格させる問題集はCloud Security Alliance認定


CCAK認定試験は、クラウドコンピューティングの概念、クラウドサービスプロバイダー、クラウドセキュリティとプライバシー、リスク管理、コンプライアンスなど、クラウドコンピューティング監査に関連する幅広いトピックをカバーしています。この試験は、クラウドコンピューティング環境の監査とクラウドサービスプロバイダーの評価を担当する専門家の知識とスキルをテストするように設計されています。

 

質問 # 111
Which of the following can be used to determine whether access keys are stored in the source code or any other configuration files during development?

  • A. Vulnerability scanning
  • B. Credential scanning
  • C. Static code review
  • D. Dynamic code review

正解:B

解説:
Explanation
Credential scanning is a technique that can be used to detect and prevent the exposure of access keys and other sensitive information in the source code or any other configuration files during development. Credential scanning tools can scan the code repositories, files, and commits for any hardcoded credentials, such as access keys, passwords, tokens, certificates, and connection strings. They can also alert the developers or security teams of any potential leaks and suggest remediation actions, such as rotating or revoking the compromised keys, removing the credentials from the code, or using secure storage mechanisms like vaults or environment variables. Credential scanning can be integrated into the development pipeline as part of the continuous integration and continuous delivery (CI/CD) process, or performed periodically as a security audit. Credential scanning can help reduce the risk of credential leakage, which can lead to unauthorized access, data breaches, or account compromise. References:
Protecting Source Code in the Cloud with DSPM
Best practices for managing service account keys
Protect your code repository


質問 # 112
Which of the following is MOST important to consider when an organization is building a compliance program for the cloud?

  • A. The rapidly changing service portfolio and architecture of the cloud.
  • B. The fairly static nature of the service portfolio and architecture of the cloud.
  • C. The cloud is similar to the on-premise environment in terms of compliance.
  • D. Cloud providers should not be part of the compliance program.

正解:A


質問 # 113
Which of the following aspects of risk management involves identifying the potential reputational harm and/or financial harm when an incident occurs?

  • A. Likelihood
  • B. Residual risk
  • C. Impact Analysis
  • D. Mitigations

正解:C


質問 # 114
How should controls be designed by an organization?

  • A. Using the organization's risk management framework
  • B. Using the ISO27001 framework
  • C. By the internal audit team
  • D. By the cloud provider

正解:C


質問 # 115
In which control should a cloud service provider, upon request, inform customers of compliance impact and risk, especially if customer data is used as part of the services?

  • A. Compliance control
  • B. Service Provider control
  • C. Data Inventory control
  • D. Impact and Risk control

正解:B


質問 # 116
An organization that is utilizing a community cloud is contracting an auditor to conduct a review on behalf of the group of organizations within the cloud community. Of the following, to whom should the auditor report the findings?

  • A. Public
  • B. Shareholders and interested parties
  • C. Management of the organization being audited
  • D. Cloud service provider

正解:C

解説:
According to the ISACA Cloud Auditing Knowledge Certificate Study Guide, the auditor should report the findings to the management of the organization being audited, as they are the primary stakeholders and decision makers for the audit. The management is responsible for ensuring that the cloud service provider meets the contractual obligations and service level agreements, as well as the security and compliance requirements of the community cloud. The auditor should also communicate with the cloud service provider and other relevant parties, such as regulators or customers, as appropriate, but the final report should be addressed to the management of the organization being audited. References: ISACA Cloud Auditing Knowledge Certificate Study Guide, page 17


質問 # 117
During an audit, it was identified that a critical application hosted in an off-premises cloud is not part of the organization's disaster recovery plan (DRP). Management stated that it is responsible for ensuring the cloud service provider has a plan that is tested annually. What should be the auditor's NEXT course of action?

  • A. Review the security white paper of the provider.
  • B. Plan an audit of the provider.
  • C. Review the contract and DR capability.
  • D. Review the provider's audit reports.

正解:C

解説:
The auditor's next course of action should be to review the contract and DR capability of the cloud service provider. The contract should specify the roles and responsibilities of both parties regarding disaster recovery, as well as the service level agreements (SLAs) and recovery time objectives (RTOs) for the critical application. The DR capability should demonstrate that the cloud service provider has a plan that is aligned with the organization's requirements and expectations, and that it is tested annually and validated by independent auditors. The auditor should also verify that the organization has a process to monitor and review the cloud service provider's performance and compliance with the contract and SLAs.
Planning an audit of the provider (B) may not be feasible or necessary, as the auditor may not have access to the provider's environment or data, and may not have the authority or expertise to conduct such an audit. The auditor should rely on the provider's audit reports and certifications to assess their compliance with relevant standards and regulations.
Reviewing the security white paper of the provider may not be sufficient or relevant, as the security white paper may not cover the specific aspects of disaster recovery for the critical application, or may not reflect the current state of the provider's security controls and practices. The security white paper may also be biased or outdated, as it is produced by the provider themselves.
Reviewing the provider's audit reports (D) may be helpful, but not enough, as the audit reports may not address the specific requirements and expectations of the organization for disaster recovery, or may not cover the latest changes or incidents that may affect the provider's DR capability. The audit reports may also have limitations or qualifications that may affect their reliability or validity. References :=
* Audit a Disaster Recovery Plan | AlertFind
* ISACA Introduces New Audit Programs for Business Continuity/Disaster ...
* How to Maintain and Test a Business Continuity and Disaster Recovery Plan


質問 # 118
In a multi-level supply chain structure where cloud service provider A relies on other sub cloud services, the provider should ensure that any compliance requirements relevant to the provider are:

  • A. treated as sensitive information and withheld from certain sub cloud service providers.
  • B. treated as confidential information and withheld from all sub cloud service providers.
  • C. passed to the sub cloud service providers.
  • D. passed to the sub cloud service providers based on the sub cloud service providers' geographic location.

正解:C

解説:
In a multi-level supply chain structure where cloud service provider A relies on other sub cloud service providers, the provider should ensure that any compliance requirements relevant to the provider are passed to the sub cloud service providers. This is because the sub cloud service providers may have access to or process the provider's data or resources, and therefore need to comply with the same standards and regulations as the provider. Passing the compliance requirements to the sub cloud service providers can also help the provider to monitor and audit the sub cloud service providers' performance and security, and to mitigate any risks or issues that may arise.
References:
* ISACA, Certificate of Cloud Auditing Knowledge (CCAK) Study Guide, 2021, p. 85-86.
* CSA, Cloud Controls Matrix (CCM) v4.0, 2021, p. 7-8


質問 # 119
Which of the following is the MOST important strategy and governance documents to provide to the auditor prior to a cloud service provider review?

  • A. Enterprise cloud strategy and policy, as well as inventory of third-party attestation reports
  • B. Policies and procedures established around third-party risk assessments, including questionnaires that are required to be completed to assess risk associated with use of third-party services
  • C. Enterprise cloud strategy and policy, as well as the enterprise cloud security strategy
  • D. Inventory of third-party attestation reports and enterprise cloud security strategy

正解:C

解説:
The best approach for an auditor to review the operating effectiveness of the password requirement is to review the configuration settings on the Configuration Management (CM) tool and verify that the CM tool agents are functioning correctly on the VMs. This method ensures that the password policies are being enforced as intended and that the CM tool is effectively managing the configurations across the organization's virtual machines. It provides a balance between relying solely on automated tools and manual verification processes.
Reference = This approach is supported by best practices in cloud security and auditing, which recommend a combination of automated tools and manual checks to ensure the effectiveness of security controls123. The use of CM tools for enforcing password policies is a common practice, and their effectiveness must be regularly verified to maintain the security posture of cloud services.


質問 # 120
Which concept is a mapping of an identity, including roles, personas, and attributes, to an authorization?

  • A. Authoritative source
  • B. Access control
  • C. Federated Identity Management
  • D. Entitlement
  • E. Authentication

正解:D


質問 # 121
After finding a vulnerability in an Internet-facing server of an organization, a cybersecurity criminal is able to access an encrypted file system and successfully manages to overwrite parts of some files with random data. In reference to the Top Threats Analysis methodology, how would the technical impact of this incident be categorized?

  • A. As an availability breach
  • B. As an integrity breach
  • C. As a confidentiality breach
  • D. As a control breach

正解:B

解説:
Explanation
The technical impact of this incident would be categorized as an integrity breach in reference to the Top Threats Analysis methodology. The Top Threats Analysis methodology is a process developed by the Cloud Security Alliance (CSA) to help organizations identify, analyze, and mitigate the top threats to cloud computing, as defined in the CSA Top Threats reports. The methodology consists of six steps: scope definition, threat identification, technical impact identification, business impact identification, risk assessment, and risk treatment. Each of these provides different insights and visibility into the organization's security posture.1 The technical impact identification step involves determining the impact on confidentiality, integrity, and availability of the information system caused by each threat. Confidentiality refers to the protection of data from unauthorized access or disclosure. Integrity refers to the protection of data from unauthorized modification or deletion. Availability refers to the protection of data and services from disruption or denial.2 An integrity breach occurs when a threat compromises the accuracy and consistency of the data or system. An integrity breach can result in data corruption, falsification, or manipulation, which can affect the reliability and trustworthiness of the data or system. An integrity breach can also have serious consequences for the business operations and decisions that depend on the data or system.3 In this case, the cybersecurity criminal was able to access an encrypted file system and overwrite parts of some files with random data. This means that the data in those files was altered without authorization and became unusable or invalid. This is a clear example of an integrity breach, as it violated the principle of ensuring that data is accurate and consistent throughout its lifecycle.4 References := CCAK Study Guide, Chapter 4: A Threat Analysis Methodology for Cloud Using CCM, page
811; What is CIA Triad? Definition and Examples2; Data Integrity vs Data Security: What's The Difference?3; Data Integrity: Definition & Examples


質問 # 122
The MOST important factor to consider when implementing cloud-related controls is the:

  • A. risk reporting.
  • B. shared responsibility model.
  • C. effectiveness of the controls.
  • D. risk ownership

正解:B

解説:
The most important factor to consider when implementing cloud-related controls is the shared responsibility model. The shared responsibility model is a framework that defines the roles and responsibilities of cloud service providers (CSPs) and cloud customers (CCs) in ensuring the security and compliance of cloud computing environments. The shared responsibility model helps to clarify which security tasks are handled by the CSP and which tasks are handled by the CC, depending on the type of cloud service model (IaaS, PaaS, SaaS) and the specific contractual agreements. The shared responsibility model also helps to avoid gaps or overlaps in security controls, and to allocate resources and accountability accordingly12.
References:
* Shared responsibility in the cloud - Microsoft Azure
* Understanding the Shared Responsibilities Model in Cloud Services - ISACA


質問 # 123
If a customer management interface is compromised over the public Internet, it can lead to:

  • A. computing and data compromise for customers.
  • B. access to the RAM of neighboring cloud computers.
  • C. incomplete wiping of the data.
  • D. ease of acquisition of cloud services.

正解:A

解説:
Customer management interfaces are the web portals or applications that allow customers to access and manage their cloud services, such as provisioning, monitoring, billing, etc. These interfaces are exposed to the public Internet and may be vulnerable to attacks such as phishing, malware, denial-of-service, or credential theft. If an attacker compromises a customer management interface, they can potentially access and manipulate the customer's cloud resources, data, and configurations, leading to computing and data compromise for customers. This can result in data breaches, service disruptions, unauthorized transactions, or other malicious activities.
References:
* Cloud Computing - Security Benefits and Risks | PPT - SlideShare1, slide 10
* Cloud Security Risks: The Top 8 According To ENISA - CloudTweaks2, section on Management Interface Compromise
* Certificate of Cloud Auditing Knowledge (CCAK) Study Guide, section 2.3.2.1 :
https://www.isaca.org/-/media/info/ccak/ccak-study-guide.pdf


質問 # 124
An organization employing the Cloud Controls Matrix (CCM) to perform a compliance assessment leverages the Scope Applicability direct mapping to:

  • A. understand which controls encompassed by the CCM may already be partially or fully implemented because of the compliance with other standards.
  • B. obtain the ISO/IEC 27001 certification from an accredited certification body (CB) following the ISO/IEC 17021-1 standard.
  • C. determine whether the organization can be considered fully compliant with the mapped standards because of the implementation of every CCM Control Specification.

正解:A

解説:
An organization employing the Cloud Controls Matrix (CCM) to perform a compliance assessment leverages the Scope Applicability direct mapping to understand which controls encompassed by the CCM may already be partially or fully implemented because of the compliance with other standards. The Scope Applicability direct mapping is a worksheet within the CCM that maps the CCM control specifications to several standards within the ISO/IEC 27000 series, such as ISO/IEC 27001, ISO/IEC 27002, ISO/IEC 27017, and ISO/IEC
27018. The mapping helps the organization to identify the commonalities and differences between the CCM and the ISO/IEC standards, and to determine the level of compliance with each standard based on the implementation of the CCM controls. The mapping also helps the organization to avoid duplication of work and to streamline the compliance assessment process.12 References := What you need to know: Transitioning CSA STAR for Cloud Controls Matrix ...1; Cloud Controls Matrix (CCM) - CSA3


質問 # 125
What aspect of Software as a Service (SaaS) functionality and operations would the cloud customer be responsible for and should be audited?

  • A. Source code reviews
  • B. Patching
  • C. Vulnerability management
  • D. Access controls

正解:D

解説:
According to the cloud shared responsibility model, the cloud customer is responsible for managing the access controls for the SaaS functionality and operations, and this should be audited by the cloud auditor12. Access controls are the mechanisms that restrict and regulate who can access and use the SaaS applications and data, and how they can do so. Access controls include identity and access management, authentication, authorization, encryption, logging, and monitoring. The cloud customer is responsible for defining and enforcing the access policies, roles, and permissions for the SaaS users, as well as ensuring that the access controls are aligned with the security and compliance requirements of the customer's business context12.
The other options are not the aspects of SaaS functionality and operations that the cloud customer is responsible for and should be audited. Option B is incorrect, as vulnerability management is the process of identifying, assessing, and mitigating the security weaknesses in the SaaS applications and infrastructure, and this is usually handled by the cloud service provider12. Option C is incorrect, as patching is the process of updating and fixing the SaaS applications and infrastructure to address security issues or improve performance, and this is also usually handled by the cloud service provider12. Option D is incorrect, as source code reviews are the process of examining and testing the SaaS applications' source code to detect errors or vulnerabilities, and this is also usually handled by the cloud service provider12. Reference:
Shared responsibility in the cloud - Microsoft Azure
The Customer's Responsibility in the Cloud Shared Responsibility Model - ISACA


質問 # 126
......


CCAK認定は、情報セキュリティとガバナンスの分野にある2つの主要な組織であるCloud Security Alliance(CSA)とISACAによって開発されました。 CSAは、クラウドコンピューティングのセキュリティのためのベストプラクティスと基準を促進することに専念する非営利組織です。 ISACAは、情報ガバナンス、リスク管理、セキュリティの分野で専門家にガイダンスとサポートを提供するITプロフェッショナルのグローバルな協会です。 CSAと協力することにより、Isacaはクラウド監査の専門家のニーズを満たす認定を開発することができました。

 

CCAK練習テストPDF試験材料:https://www.goshiken.com/ISACA/CCAK-mondaishu.html

CCAK解答の無料サンプルには全てリアル試験に基づいています:https://drive.google.com/open?id=1WlRd1PnqjXFwzsYIEiHttmQtdJsjn_b_