New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Isaca CCAK Exam - Topic 4 Question 51 Discussion

Actual exam question for Isaca's CCAK exam
Question #: 51
Topic #: 4
[All CCAK Questions]

During the cloud service provider evaluation process, which of the following BEST helps identify baseline configuration requirements?

Show Suggested Answer Hide Answer
Suggested Answer: C

: During the cloud service provider evaluation process, benchmark controls lists BEST help identify baseline configuration requirements.Benchmark controls lists are standardized sets of security and compliance controls that are applicable to different cloud service models, deployment models, and industry sectors1.They provide a common framework and language for assessing and comparing the security posture and capabilities of cloud service providers2.They also help cloud customers to define their own security and compliance requirements and expectations based on best practices and industry standards3.

Some examples of benchmark controls lists are:

The Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM), which is a comprehensive list of 133 control objectives that cover 16 domains of cloud security4.

The National Institute of Standards and Technology (NIST) Special Publication 800-53, which is a catalog of 325 security and privacy controls for federal information systems and organizations, including cloud-based systems5.

The International Organization for Standardization (ISO) / International Electrotechnical Commission (IEC) 27017, which is a code of practice that provides guidance on 121 information security controls for cloud services based on ISO/IEC 270026.


CSA Security Guidance for Cloud Computing | CSA1, section on Identify necessary security and compliance requirements

Evaluation Criteria for Cloud Infrastructure as a Service - Gartner2, section on Security Controls

Checklist: Cloud Services Provider Evaluation Criteria | Synoptek3, section on Security

Cloud Controls Matrix | CSA4, section on Overview

NIST Special Publication 800-53 - NIST Pages5, section on Abstract

ISO/IEC 27017:2015(en), Information technology --- Security techniques ...6, section on Scope

What is vendor management?Definition from WhatIs.com7, section on Vendor management

What is Benchmarking?Definition from WhatIs.com8, section on Benchmarking

What is Terms and Conditions?Definition from WhatIs.com9, section on Terms and Conditions

Contribute your Thoughts:

0/2000 characters
Annmarie
3 months ago
I didn't realize product benchmarks could be so crucial!
upvoted 0 times
...
Maurine
3 months ago
Totally agree with the vendor requirements option!
upvoted 0 times
...
Reita
3 months ago
Wait, are contract terms really that important?
upvoted 0 times
...
Emmett
4 months ago
I think benchmark controls lists are more reliable.
upvoted 0 times
...
Milly
4 months ago
Product benchmarks are key for baseline configs.
upvoted 0 times
...
Adelina
4 months ago
Vendor requirements might be useful, but I thought we emphasized the importance of benchmarks in our practice questions.
upvoted 0 times
...
Idella
4 months ago
Contract terms and conditions could help, but I feel like they focus more on legal aspects rather than technical configurations.
upvoted 0 times
...
Thurman
4 months ago
I remember discussing benchmark controls lists in class; they seem relevant for identifying configurations, but I wonder if they're the best option here.
upvoted 0 times
...
Mira
5 months ago
I think product benchmarks might be the right choice since they provide specific performance metrics, but I'm not entirely sure.
upvoted 0 times
...
Denae
5 months ago
I'm not totally confident on this, but I'm leaning towards product benchmarks as the best way to identify baseline configuration requirements. The other options don't seem as directly relevant.
upvoted 0 times
...
Leanna
5 months ago
Okay, I think I've got this. Vendor requirements would likely include the baseline configurations they recommend, so that seems like the best option here.
upvoted 0 times
...
Elinore
5 months ago
Hmm, I'm a bit unsure about this one. I'll need to review my notes on the cloud service provider evaluation process to see what the key factors are for determining baseline configurations.
upvoted 0 times
...
Hershel
5 months ago
This seems like a tricky one. I'll need to think carefully about the different options and how they relate to identifying baseline configuration requirements.
upvoted 0 times
...
An
5 months ago
Benchmark controls lists could also be helpful in determining baseline configurations, but I think vendor requirements is the most straightforward answer here.
upvoted 0 times
...
Nicolette
5 months ago
I'm a bit confused by the wording of the options. I'll need to review my notes on Chalmers' work to make sure I grasp the nuances of his views on consciousness.
upvoted 0 times
...
Valentine
5 months ago
Option D seems the most specific about when background checks are absolutely necessary - that might be a clue to the FALSE statement.
upvoted 0 times
...
Apolonia
5 months ago
This seems like a tricky one. I'll need to carefully review the details about the data storage and management practices at the medical center.
upvoted 0 times
...
Charisse
2 years ago
Benchmark controls lists? Sounds like a job for a spreadsheet wizard. Or maybe a data analyst with a love for Excel. Either way, I'm feeling that option.
upvoted 0 times
Karma
1 year ago
Definitely, it helps streamline the evaluation process and ensure nothing is overlooked.
upvoted 0 times
...
Yolando
1 year ago
I agree, it's like having a checklist to ensure all necessary requirements are met.
upvoted 0 times
...
Marta
1 year ago
Yeah, they provide a good reference point for evaluating cloud service providers.
upvoted 0 times
...
Jules
1 year ago
I agree, having a detailed list of benchmarks can really streamline the evaluation process.
upvoted 0 times
...
Ressie
1 year ago
I think benchmark controls lists are important for identifying baseline configuration requirements.
upvoted 0 times
...
Kimbery
1 year ago
Option C) Benchmark controls lists is definitely the way to go. It helps identify baseline configuration requirements.
upvoted 0 times
...
...
Tamala
2 years ago
Vendor requirements? Isn't that like asking a wolf to guard the henhouse? I'll stick with product benchmarks, thank you very much.
upvoted 0 times
...
Ashleigh
2 years ago
Contract terms and conditions? Psh, who reads those anyway? Definitely going with product benchmarks - you can't beat those hard numbers.
upvoted 0 times
Louvenia
1 year ago
Alberto: True, but I still think product benchmarks provide the most accurate information.
upvoted 0 times
...
Alberto
2 years ago
Vendor requirements might also be important to consider.
upvoted 0 times
...
Gretchen
2 years ago
I agree, product benchmarks are definitely the way to go.
upvoted 0 times
...
...
Chau
2 years ago
I agree with Kenneth, vendor requirements are crucial for baseline configuration.
upvoted 0 times
...
Alaine
2 years ago
I think D) Contract terms and conditions are the most important.
upvoted 0 times
...
Lorita
2 years ago
Benchmark controls lists, all the way. You can't just rely on the vendor's word, you know? Gotta have that checklist to make sure you're getting what you need.
upvoted 0 times
...
Basilia
2 years ago
Vendor requirements? Seriously? That's like asking a car salesman what kind of car I should buy. Gotta go with product benchmarks - that's where the real meat is.
upvoted 0 times
Tish
1 year ago
Benchmark controls lists can also be helpful in evaluating the baseline configuration requirements.
upvoted 0 times
...
King
2 years ago
I agree, vendor requirements can be biased. Product benchmarks provide a more objective comparison.
upvoted 0 times
...
Mendy
2 years ago
I agree, but product benchmarks give a more objective view of what the service can offer.
upvoted 0 times
...
Rashad
2 years ago
Product benchmarks are definitely important to consider. They give a good idea of what the service can actually deliver.
upvoted 0 times
...
Eric
2 years ago
Vendor requirements are important to consider, they provide valuable insights.
upvoted 0 times
...
...
Hyun
2 years ago
I disagree, I believe it's C) Benchmark controls lists.
upvoted 0 times
...
Kenneth
2 years ago
I think it's A) Vendor requirements.
upvoted 0 times
...

Save Cancel