Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CCAK Exam - Topic 3 Question 61 Discussion

A business unit introducing cloud technologies to the organization without the knowledge or approval of the appropriate governance function is an example of:
C) Shadow IT
A) IT exception
B) Threat
D) Vulnerability

Isaca CCAK Exam - Topic 3 Question 61 Discussion

Actual exam question for Isaca's CCAK exam
Question #: 61
Topic #: 3
[All CCAK Questions]

A business unit introducing cloud technologies to the organization without the knowledge or approval of the appropriate governance function is an example of:

Show Suggested Answer Hide Answer
Suggested Answer: C

Shadow IT refers to the use of IT resources (hardware, software, or cloud services) within an organization without the explicit approval of the IT or governance team. This practice is often flagged in cloud audits due to potential risks of compliance violations and security threats. The CCAK documentation from ISACA highlights the need for visibility and governance over all IT assets, with specific controls listed in the CSA CCM for Cloud Governance (GOV-09). Shadow IT poses risks to data security, compliance, and can introduce vulnerabilities, as systems are not subject to organizational standards and oversight.


Contribute your Thoughts:

0/2000 characters
Tasia
7 months ago
I thought vulnerabilities were more about security flaws, not this!
upvoted 0 times
...
Ashley
8 months ago
This is a classic case of Shadow IT for sure.
upvoted 0 times
...
Colene
8 months ago
Wait, are we sure it's not just an IT exception?
upvoted 0 times
...
Bette
8 months ago
Totally agree, it's a big risk!
upvoted 0 times
...
Gwen
8 months ago
That's definitely Shadow IT.
upvoted 0 times
...
Sharee
9 months ago
I could see it being a threat too, but I feel like Shadow IT fits better based on what we practiced.
upvoted 0 times
...
Venita
9 months ago
This sounds like Shadow IT to me, especially since it involves cloud technologies being used without governance approval.
upvoted 0 times
...
Odelia
9 months ago
I'm not entirely sure, but I remember something about IT exceptions being about deviations from standard practices.
upvoted 0 times
...
Katheryn
9 months ago
I think this might be related to Shadow IT since it involves using technology without proper oversight.
upvoted 0 times
...
Lucina
9 months ago
Okay, let me re-read the question and options. I think I've got it - the business unit is bypassing the proper governance process, so the answer must be C, Shadow IT.
upvoted 0 times
...
Nell
9 months ago
Ah, I recognize this type of scenario from our class discussions. I believe the correct answer is C - Shadow IT, since the business unit is introducing cloud tech without approval.
upvoted 0 times
...
Margurite
9 months ago
Hmm, I'm not entirely sure about this one. I'll need to think through the differences between the options carefully before selecting an answer.
upvoted 0 times
...
Mozelle
9 months ago
This looks like a straightforward question about IT governance. I'll focus on the key terms like "cloud technologies" and "governance function" to determine the best answer.
upvoted 0 times
...
Maryann
2 years ago
Without a doubt, C) Shadow IT. This is the IT equivalent of a kid trying to sneak a cookie before dinner.
upvoted 0 times
...
Bernardine
2 years ago
I think it could also be considered a Threat, as it opens up the organization to potential security breaches.
upvoted 0 times
...
Lisbeth
2 years ago
I agree with Elbert. It's definitely Shadow IT because it's unauthorized and can pose risks to the organization.
upvoted 0 times
...
Vilma
2 years ago
C) Shadow IT, hands down. It's like they're playing IT hide and seek, but the IT team always loses.
upvoted 0 times
Dorcas
2 years ago
B) Threats from Shadow IT can undermine the organization's IT strategy.
upvoted 0 times
...
Stevie
2 years ago
C) Shadow IT can lead to data breaches and compliance issues.
upvoted 0 times
...
Darci
2 years ago
A) IT exception is important to prevent unauthorized technology implementations.
upvoted 0 times
...
Blair
2 years ago
C) Shadow IT is a big problem. It can create security risks for the organization.
upvoted 0 times
...
...
Elbert
2 years ago
C) Shadow IT
upvoted 0 times
...
Mona
2 years ago
Ah, good ol' Shadow IT. Gotta love how creative these employees can get when they want to bypass the system.
upvoted 0 times
...
Bok
2 years ago
Hmm, I was torn between C and D, but I think C is the better option. Shadow IT is the perfect term for this scenario.
upvoted 0 times
Herminia
2 years ago
User 3: It's important for businesses to have proper governance in place to avoid these situations.
upvoted 0 times
...
Allene
2 years ago
User 2: Yeah, introducing cloud technologies without approval is a classic example of Shadow IT.
upvoted 0 times
...
Hayley
2 years ago
User 1: I agree, Shadow IT is definitely the right choice.
upvoted 0 times
...
...
Jamal
2 years ago
C) Shadow IT - that's definitely the correct answer here. Sneaking in cloud tech without approval? That's a classic case of Shadow IT.
upvoted 0 times
Fallon
2 years ago
Organizations need to have clear policies in place to prevent unauthorized technology use.
upvoted 0 times
...
Jeff
2 years ago
Shadow IT can also lead to compliance issues if not properly managed.
upvoted 0 times
...
Sheridan
2 years ago
The IT department needs to be aware of all technology being used in the organization.
upvoted 0 times
...
In
2 years ago
It's important for all technology implementations to go through the proper channels for approval.
upvoted 0 times
...
Stephanie
2 years ago
Shadow IT can lead to security breaches and compliance issues.
upvoted 0 times
...
Dannie
2 years ago
It's important for all technology implementations to go through the proper channels.
upvoted 0 times
...
Levi
2 years ago
Yes, you're right. Shadow IT can create security risks for the organization.
upvoted 0 times
...
Lilli
2 years ago
Yes, you're right. Shadow IT can pose a lot of risks to the organization.
upvoted 0 times
...
...

Save Cancel