Question 206

The effect of which of the following should have priority in planning the scope and objectives of a cloud audit?
  • Question 207

    During an audit, it was identified that a critical application hosted in an off-premises cloud is not part of the organization's disaster recovery plan (DRP). Management stated that it is responsible for ensuring the cloud service provider has a plan that is tested annually. What should be the auditor's NEXT course of action?
  • Question 208

    An auditor identifies that a cloud service provider received multiple customer inquiries and requests for proposal (RFPs) during the last month. Which of the following What should be the BEST recommendation to reduce the provider's burden?
  • Question 209

    If a customer management interface is compromised over the public Internet, it can lead to:
  • Question 210

    ENISA: Lock-in is ranked as a high risk in ENISA research, a key underlying vulnerability causing lock in is: