New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CCAK Exam - Topic 2 Question 45 Discussion

Actual exam question for Isaca's CCAK exam
Question #: 45
Topic #: 2
[All CCAK Questions]

An auditor identifies that a cloud service provider received multiple customer inquiries and requests for proposal (RFPs) during the last month.

Which of the following should be the BEST recommendation to reduce the provider's burden?

Show Suggested Answer Hide Answer
Suggested Answer: D

The CSA STAR registry is a publicly accessible registry that documents the security and privacy controls provided by popular cloud computing offerings1The registry is designed for users of cloud services to assess their cloud providers' security and compliance posture, including the regulations, standards, and frameworks they adhere to1The registry also promotes industry transparency and reduces complexity and costs for both providers and customers2

The provider can direct all customer inquiries to the information in the CSA STAR registry, as this would be the best recommendation to reduce the provider's burden.By publishing to the registry, the provider can show current and potential customers their security and compliance posture, without having to fill out multiple customer questionnaires or requests for proposal (RFPs)2The provider can also leverage the different levels of assurance available in the registry, such as self-assessment, third-party audit, or certification, to demonstrate their security maturity and trustworthiness1The provider can also benefit from the CSA Trusted Cloud Providers program, which recognizes providers that have fulfilled additional training and volunteer requirements with CSA, demonstrating their commitment to cloud security competency and industry best practices3

The other options are not correct because:

Option A is not correct because the provider can schedule a call with each customer is not a good recommendation to reduce the provider's burden. Scheduling a call with each customer would be time-consuming, inefficient, and impractical, especially if the provider receives multiple inquiries and RFPs every month. Scheduling a call would also not guarantee that the customer would be satisfied with the provider's security and compliance posture, as they may still request additional information or evidence. Scheduling a call would also not help the provider differentiate themselves from other providers in the market, as they may not be able to showcase their security maturity and trustworthiness effectively.

Option B is not correct because the provider can share all security reports with customers to streamline the process is not a good recommendation to reduce the provider's burden. Sharing all security reports with customers may not be feasible, as some reports may contain sensitive or confidential information that should not be disclosed to external parties. Sharing all security reports may also not be desirable, as some reports may be outdated, incomplete, or inconsistent, which could undermine the provider's credibility and reputation. Sharing all security reports may also not be effective, as some customers may not have the expertise or resources to review and understand them properly.

Option C is not correct because the provider can answer each customer individually is not a good recommendation to reduce the provider's burden. Answering each customer individually would be tedious, repetitive, and costly, as the provider would have to provide similar or identical information to different customers over and over again. Answering each customer individually would also not ensure that the provider's security and compliance posture is consistent and accurate, as they may make mistakes or omissions in their responses. Answering each customer individually would also not help the provider stand out from other providers in the market, as they may not be able to highlight their security achievements and certifications.


Contribute your Thoughts:

0/2000 characters
Jess
3 months ago
Not sure if the CSA STAR registry has all the info they need.
upvoted 0 times
...
Noelia
3 months ago
I’m surprised they haven’t done this sooner!
upvoted 0 times
...
Vinnie
3 months ago
Scheduling calls with each customer? That seems time-consuming.
upvoted 0 times
...
Jamal
4 months ago
I think directing inquiries to the CSA STAR registry is the best move.
upvoted 0 times
...
Glenna
4 months ago
Sharing security reports sounds efficient!
upvoted 0 times
...
Artie
4 months ago
I’m torn between options B and D. Sharing reports seems helpful, but I feel like directing them to the CSA registry could save a lot of time for the provider.
upvoted 0 times
...
Leigha
4 months ago
I practiced a similar question where we had to choose between individual responses and a centralized approach. I feel like option D might be the most efficient.
upvoted 0 times
...
Lou
4 months ago
I think directing inquiries to the CSA STAR registry makes sense since it centralizes information, but I wonder if customers would still prefer direct communication.
upvoted 0 times
...
Twila
5 months ago
I remember discussing how sharing security reports could help, but I'm not sure if it's the best way to reduce the burden.
upvoted 0 times
...
Gayla
5 months ago
I'm a little confused on this one. Answering each customer individually doesn't seem like the best use of the provider's time, but I'm not sure if the other options fully address the problem either. I'll have to think this through carefully.
upvoted 0 times
...
Shannan
5 months ago
Hmm, I'm a bit unsure about this one. Scheduling individual calls with each customer seems like it could be really time-consuming. Sharing security reports might be a good option, but I'm not sure if that fully addresses the burden.
upvoted 0 times
...
Tamekia
5 months ago
This seems like a straightforward question about reducing the provider's burden. I'm thinking the best option is to direct customers to the CSA STAR registry, as that would centralize the information they need.
upvoted 0 times
...
Maryann
5 months ago
Okay, I've got a strategy here. I think the key is to find a way to provide the information customers need without having to individually respond to each one. Directing them to the CSA STAR registry seems like the most efficient approach.
upvoted 0 times
...
Veronique
5 months ago
I think the key here is to look for automations that involve file transfer capabilities. Options B and C both mention "File Transfer", so those seem like the most relevant choices.
upvoted 0 times
...
Jolanda
5 months ago
I remember similar questions where the recitals talked about the parties involved. I feel like B should definitely be included in Dr. Cartier's contract.
upvoted 0 times
...
Ciara
2 years ago
Yeah, and it would reduce redundant work for the provider.
upvoted 0 times
...
Lina
2 years ago
Directing inquiries to the CSA STAR registry is a good idea. It centralizes everything.
upvoted 0 times
...
Glennis
2 years ago
I disagree. What if the reports are too complex for customers? I think Option D is better.
upvoted 0 times
...
Fredric
2 years ago
Option B might be the best. Sharing all security reports with customers could save time.
upvoted 0 times
...
Ariel
2 years ago
True, managing multiple RFPs can be overwhelming for providers.
upvoted 0 times
...
Celestina
2 years ago
I think the question is quite relevant in today's cloud-reliant business environment.
upvoted 0 times
...

Save Cancel