PrepAway - Latest Free Exam Questions & Answers

Category: CCAK

Which of the following is the BEST tool to perform cloud security control audits?

Which of the following is the BEST tool to perform cloud security control audits? A. General Data Protection Regulation (GDPR) B. ISO 27001 C. Federal Information Processing Standard (FIPS) 140-2 D. CSA Cloud Control Matrix (CCM) Reference: https://www.isaca.org/resources/news-and-trends/newsletters/atisaca/2021/volume-22/preventing-the-next-cybersecurity-attack-with-effective-cloud-security-audits

Due to cloud audit team resource constraints, an audit plan as initially approved cannot be completed.

Due to cloud audit team resource constraints, an audit plan as initially approved cannot be completed. Assuming that the situation is communicated in the cloud audit report which course of action is MOST relevant? A. Focusing on auditing high-risk areas B. Testing the adequacy of cloud controls design C. Relying on management testing of cloud […]

Changes to which of the following will MOST likely influence the expansion or reduction of controls required t

Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization’s SaaS vendor? A. Risk exceptions policy B. Contractual requirements C. Risk appetite D. Board oversight Reference: https://assets.kpmg/content/dam/kpmg/ch/pdf/key-risks-internal-audit-2018.pdf


Page 2 of 212