MultipleChoice
Policies and procedures shall be established, and supporting business processes and technical measures implemented, for maintenance of several items ensuring continuity and availability of operations and support personnel. Which of the following controls BEST matches this control description?
OptionsMultipleChoice
An auditor identifies that a CSP received multiple customer inquiries and RFPs during the last month. Which of the following should be the BEST recommendation to reduce the CSP burden?
OptionsMultipleChoice
The PRIMARY objective of an audit initiation meeting with a cloud audit client is to:
OptionsMultipleChoice
When a client's business process changes, the CSP SLA should:
OptionsMultipleChoice
SAST testing is performed by:
OptionsMultipleChoice
After finding a vulnerability in an internet-facing server of an organization, a cybersecurity criminal is able to access an encrypted file system and successfully manages to overwrite part of some files with random dat
a. In reference to the Top Threats Analysis methodology, how would you categorize the technical impact of this incident?
OptionsMultipleChoice
Network environments and virtual instances shall be designed and configured to restrict and monitor traffic between trusted and untrusted connections. These configurations shall be reviewed at least annually, and supported by a documented justification for use for all allowed services, protocols, ports, and by compensating controls. Which of the following controls BEST matches this control description?
OptionsMultipleChoice
In an organization, how are policy violations MOST likely to occur?
OptionsMultipleChoice
Due to cloud audit team resource constraints, an audit plan as initially approved cannot be completed. Assuming that the situation is communicated in the cloud audit report which course of action is MOST relevant?
OptionsMultipleChoice
Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization's SaaS vendor?
Options