Question 201
Which of the following methods can be used by a cloud service provider with a cloud customer that does not want to share security and control information?
Question 202
A new company has all its operations in the cloud. Which of the following would be the BEST information security control framework to implement?
Question 203
To qualify for CSA STAR attestation for a particular cloud system, the SOC 2 report must cover:
Question 204
REST APIs are the standard for web-based services because they run over HTTPS and work well across diverse environments.
Question 205
A cloud service provider contracts for a penetration test to be conducted on its infrastructures. The auditor engages the target with no prior knowledge of its defenses, assets, or channels. The provider's security operation center is not notified in advance of the scope of the audit and the test vectors. Which mode has been selected by the provider?