nerdexam
CompTIA

CAS-001 · Question #416

A company is in the process of outsourcing its customer relationship management system to a cloud provider. It will host the entire organization's customer database. The database will be accessed by…

The correct answer is C. Security clauses are implemented into the contract such as the right to audit. D. Review of the organizations security policies, procedures and relevant hosting certifications. Due diligence in a cloud outsourcing context is about verifying the provider's security posture through documentation, legal agreements, and evidence of third-party validation-not active technical testing of systems you do not yet own or control. Reviewing the provider's…

Integration of Computing, Communications and Business Disciplines

Question

A company is in the process of outsourcing its customer relationship management system to a cloud provider. It will host the entire organization's customer database. The database will be accessed by both the company's users and its customers. The procurement department has askedwhat security activities must be performed for the deal to proceed. Which of the following are the MOST appropriate security activities to be performed as part of due diligence? (Select TWO).

Options

  • APhysical penetration test of the datacenter to ensure there are appropriate controls.
  • BPenetration testing of the solution to ensure that the customer data is well protected.
  • CSecurity clauses are implemented into the contract such as the right to audit.
  • DReview of the organizations security policies, procedures and relevant hosting certifications.
  • ECode review of the solution to ensure that there are no back doors located in the software.

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    78% (21)
  • E
    7% (2)

Explanation

Due diligence in a cloud outsourcing context is about verifying the provider's security posture through documentation, legal agreements, and evidence of third-party validation-not active technical testing of systems you do not yet own or control. Reviewing the provider's security policies, procedures, and certifications such as ISO 27001, SOC 2 Type II, or PCI-DSS (D) gives the company objective, audited evidence of the provider's security maturity. Including security clauses in the contract-especially the right to audit (C)-legally protects the company by ensuring ongoing accountability and the ability to verify compliance throughout the relationship. Physical penetration testing (A) is extremely unlikely to be permitted by a cloud provider during procurement. Penetration testing (B) and source code review (E) may occur post-contract but are not standard due diligence activities at the procurement stage and would typically require explicit contractual permission.

Topics

#cloud due diligence#right to audit#vendor security#security certifications

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice