exam questions

Exam CCAK All Questions

View all questions & answers for the CCAK exam

Exam CCAK topic 1 question 176 discussion

Actual exam question from Isaca's CCAK
Question #: 176
Topic #: 1
[All CCAK Questions]

Which of the following enables auditors to conduct gap analyses of what a cloud service provider offers versus what the customer requires?

  • A. The as-is and to-be enterprise architecture (EA)
  • B. Using a standardized control framework
  • C. The experience gained over the years
  • D. Understanding the customer risk profile
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
84501e1
18 hours, 50 minutes ago
Selected Answer: B
B. Using a standardized control framework has many benefits, including the following: - Gap analyses of what a CSP offers versus what the customer requires - Comparisons of cloud security features - Benchmarking of competing cloud services - anchors the implementation of security controls into a well-known reference system and language - supports auditors’ efforts to assess an information system based on a well-defined set of controls
upvoted 1 times
...
Auditor2020
8 months, 1 week ago
Selected Answer: B
The most appropriate choice for enabling auditors to conduct gap analyses of what a cloud service provider offers versus what the customer requires is: **B. Using a standardized control framework** Using a standardized control framework allows auditors to systematically evaluate the cloud service provider's offerings against a set of predefined controls and requirements. Frameworks such as ISO 27001, NIST, or COBIT provide a comprehensive set of criteria that can be used to assess the adequacy of the provider's controls relative to the customer's needs. This approach enables the identification of gaps in areas such as security, compliance, and data protection, facilitating a clear comparison and helping to determine if the provider meets the customer's requirements.
upvoted 1 times
...
sai_murthy
1 year, 3 months ago
Selected Answer: B
CCAK P# 141 Using a standardized control framework has many benefits, including the following: • It anchors the implementation of security controls into a well-known reference system and language recognized by many practitioners across an industry. • It supports auditors’ efforts to assess an information system based on a well-defined set of controls, enabling the following actions: o Comparisons of cloud security features across different time periods or different cloud services o Gap analyses of what a CSP offers versus what the customer requires o Benchmarking of competing cloud services (e.g., in the context of procurement) • It enables the building of trusted certifications schemes by ensuring that information systems are assessed with a comparable set of criteria.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...