nerdexam
Isaca

CCAK · Question #32

To support customer's verification of the CSP claims regarding their responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?

The correct answer is D. Security assessment. A security assessment is the direct mechanism customers use to verify CSP security claims. It involves evaluating the CSP's actual security posture against stated responsibilities - testing controls, reviewing configurations, and validating that the CSP is fulfilling its side…

Cloud Security Auditing

Question

To support customer's verification of the CSP claims regarding their responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?

Options

  • AContractual agreement
  • BInternal audit
  • CExternal audit
  • DSecurity assessment

How the community answered

(35 responses)
  • A
    11% (4)
  • B
    6% (2)
  • C
    3% (1)
  • D
    80% (28)

Explanation

A security assessment is the direct mechanism customers use to verify CSP security claims. It involves evaluating the CSP's actual security posture against stated responsibilities - testing controls, reviewing configurations, and validating that the CSP is fulfilling its side of the shared responsibility model. A contractual agreement (A) defines obligations but doesn't verify them. An internal audit (B) focuses on the customer's own environment. An external audit (C) is comprehensive but is typically performed by a third party on the CSP's behalf. A security assessment is the practical, targeted tool for a customer to independently validate CSP claims.

Topics

#Shared Responsibility Model#CSP Claims Verification#Security Assessment#Customer Due Diligence

Community Discussion

No community discussion yet for this question.

Full CCAK Practice