10 free sample questions from a bank of 258, with the correct answers and explanations. No signup required — start practising right now.
1Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization’s SaaS vendor?
Risk exceptions policy
Contractual requirements
Risk appetite
Board oversight
Answer: B
2When a client’s business process changes, the CSP SLA should:
be reviewed, but the SLA cannot be updated.
not be reviewed, but the cloud contract should be cancelled immediately.
not be reviewed as the SLA cannot be updated.
be reviewed and updated if required.
Answer: D
3When building a cloud governance model, which of the following requirements will focus more on the cloud service provider’s evaluation and control checklist?
Security requirements
Legal requirements
Compliance requirements
Operational requirements
Answer: A
4Prioritizing assurance activities for an organization’s cloud services portfolio depends PRIMARILY on an organization’s ability to:
schedule frequent reviews with high-risk cloud service providers.
develop plans using a standardized risk-based approach.
maintain a comprehensive cloud service inventory.
collate views from various business functions using cloud services.
Answer: B
5If the degree of verification for information shared with the auditor during an audit is low, the auditor should:
reject the information as audit evidence.
stop evaluating the requirement altogether and review other audit areas.
delve deeper to obtain the required information to decide conclusively.
use professional judgment to determine the degree of reliance that can be placed on the information as evidence.
Answer: D
6Which best describes the difference between a type 1 and a type 2 SOC report?
A type 2 SOC report validates the operating effectiveness of controls whereas a type 1 SOC report validates the suitability of the design of the controls.
A type 2 SOC report validates the suitability of the design of the controls whereas a type 1 SOC report validates the operating effectiveness of controls.
A type 1 SOC report provides an attestation whereas a type 2 SOC report offers a certification.
There is no difference between a type 2 and type 1 SOC report.
Answer: A
7You have been assigned the implementation of an ISMS, whose scope must cover both on premise and cloud infrastructure. Which of the following is your BEST option?
Implement ISO/IEC 27002 and complement it with additional controls from the CCM.
Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27017.
Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27002.
Implement ISO/IEC 27001 and complement it with additional controls from the NIST SP 800-145.
Answer: B
8As a developer building codes into a container in a DevSecOps environment, which of the following is the appropriate place(s) to perform security tests?
Within developer’s laptop
Within the CI/CD server
Within version repositories
Within the CI/CD pipeline
Answer: D
9An organization that is utilizing a community cloud is contracting an auditor to conduct a review on behalf of the group of organizations within the cloud community. From the following, to whom should the auditor report the findings?
Public
Management of organization being audited
Shareholders/interested parties
Cloud service provider
Answer: C
10Which of the following parties should have accountability for cloud compliance requirements?
Customer
Equally shared between customer and provider
Provider
Either customer or provider, depending on requirements