When developing a cloud compliance program, what is the PRIMARY reason for a cloud customer
What do cloud service providers offer to encourage clients to extend the cloud platform?
Organizations maintain mappings between the different control frameworks they adopt to:
is it important for the individuals in charge of cloud compliance to understand the organization's past?
During the cloud service provider evaluation process, which of the following BEST helps identify baseline configuration requirements?
The PRIMARY purpose of Open Certification Framework (OCF) for the CSA STAR program is to:
Which of the following is the GREATEST risk associated with hidden interdependencies between cloud services?
Which of the following MOST enhances the internal stakeholder decision-making process for the remediation of risks identified from an organization's cloud compliance program?
Under GDPR, an organization should report a data breach within what time frame?
To ensure a cloud service provider is complying with an organization's privacy requirements, a cloud auditor should FIRST review:
What is a sign that an organization has adopted a shift-left concept of code release cycles?
Which of the following activities is performed outside information security monitoring?
An organization that is utilizing a community cloud is contracting an auditor to conduct a review on behalf of the group of organizations within the cloud community. Of the following, to whom should the auditor report the findings?
Which of the following cloud service provider activities MUST obtain a client's approval?
Which of the following standards is designed to be used by organizations for cloud services that intend to select controls within the process of implementing an information security management system based on ISO/IEC 27001?
Which of the following can be used to determine whether access keys are stored in the source code or any other configuration files during development?
Which of the following is the BEST tool to perform cloud security control audits?
Controls mapping found in the Scope Applicability column of the Cloud Controls Matrix (CCM) may help organizations to realize cost savings:
In a situation where duties related to cloud risk management and control are split between an organization and its cloud service providers, which of the following would BEST help to ensure a coordinated approach to risk and control processes?
Supply chain agreements between a cloud service provider and cloud customers should, at a minimum, include:
When an organization is moving to the cloud, responsibilities are shared based upon the cloud service provider's model and accountability is:
The CSA STAR Certification is based on criteria outlined the Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) in addition to:
Which of the following would be considered as a factor to trust in a cloud service provider?
Which of the following is MOST important to manage risk from cloud vendors who might accidentally introduce unnecessary risk to an organization by adding new features to their solutions?
With regard to the Cloud Controls Matrix (CCM), the Architectural Relevance is a feature that enables the filtering of security controls by:
Which of the following BEST ensures adequate restriction on the number of people who can access the pipeline production environment?
A cloud auditor should use statistical sampling rather than judgment (nonstatistical) sampling when:
DevSecOps aims to integrate security tools and processes directly into the software development life cycle and should be done:
Which of the following is the MOST relevant question in the cloud compliance program design phase?
Which of the following is a cloud-native solution designed to counter threats that do not exist within the enterprise?
When applying the Top Threats Analysis methodology following an incident, what is the scope of the technical impact identification step?
A business unit introducing cloud technologies to the organization without the knowledge or approval of the appropriate governance function is an example of:
A cloud auditor observed that just before a new software went live, the librarian transferred production data to the test environment to confirm the new software can work in the production environment. What additional control should the cloud auditor check?
Regarding suppliers of a cloud service provider, it is MOST important for the auditor to be aware that the:
What aspect of Software as a Service (SaaS) functionality and operations would the cloud customer be responsible for and should be audited?
An organization currently following the ISO/IEC 27002 control framework has been charged by a new CIO to switch to the NIST 800-53 control framework. Which of the following is the FIRST step to this change?
Regarding cloud service provider agreements and contracts, unless otherwise stated, the provider is:
Which of the following are the three MAIN phases of the Cloud Controls Matrix (CCM) mapping methodology?
A contract containing the phrase "You automatically consent to these terms by using or logging into the service to which they pertain" is establishing a contract of:
Which of the following should be an assurance requirement when an organization is migrating to a Software as a Service (SaaS) provider?
Which of the following activities are part of the implementation phase of a cloud assurance program during a cloud migration?
During an audit, it was identified that a critical application hosted in an off-premises cloud is not part of the organization's disaster recovery plan (DRP). Management stated that it is responsible for ensuring the cloud service provider has a plan that is tested annually. What should be the auditor's NEXT course of action?
A cloud service customer is looking to subscribe to a finance solution provided by a cloud service provider. The provider has clarified that the audit logs cannot be taken out of the cloud environment by the customer to its security information and event management (SIEM) solution for monitoring purposes. Which of the following should be the GREATEST concern to the auditor?
In a multi-level supply chain structure where cloud service provider A relies on other sub cloud services, the provider should ensure that any compliance requirements relevant to the provider are: