Which industry organization offers both security controls and cloud-relevant benchmarking?
Which of the following cloud service provider activities MUST obtain a client's approval?
Which of the following is the reason for designing the Consensus Assessments Initiative Questionnaire (CAIQ)?
During the planning phase of a cloud audit, the PRIMARY goal of a cloud auditor is to:
Which of the following is an example of availability technical impact?
When establishing cloud governance, an organization should FIRST test by migrating:
An organization that is utilizing a community cloud is contracting an auditor to conduct a review on behalf of the group of organizations within the cloud community. Of the following, to whom should the auditor report the findings?
Which of the following is an example of reputational business impact?
To support a customer's verification of the cloud service provider claims regarding its responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?
A cloud service provider contracts for a penetration test to be conducted on its infrastructures. The auditor engages the target with no prior knowledge of its defenses, assets, or channels. The provider's security operation center is not notified in advance of the scope of the audit and the test vectors. Which mode has been selected by the provider?
PDF + Testing Engine
|
---|
$66 |
Testing Engine
|
---|
$50 |
PDF (Q&A)
|
---|
$42 |
Isaca Free Exams |
---|
![]() |