Which of the following configuration change controls is acceptable to a cloud auditor?
Options:
A.
Programmers have permanent access to production software.
B.
Programmers cannot make uncontrolled changes to the source code production version.
C.
Development, test, and production are hosted in the same network environment.
D.
The head of development approves changes requested to production.
Answer:
B
Question 61
Which of the following cloud environments should be a concern to an organization s cloud auditor?
Options:
A.
The cloud service provider s data center is more than 100 miles away.
B.
The technical team is trained on only one vendor Infrastructure as a Service (laaS) platform, but the organization has subscribed to another vendor's laaS platform as an alternative.
C.
The organization entirely depends on several proprietary Software as a Service (SaaS) applications.
D.
The failover region of the cloud service provider is on another continent
Answer:
C
Explanation:
This situation poses a significant concern for a cloud auditor because it indicates a potential gap in the technical team’s ability to effectively manage and secure the IaaS platform provided by the alternative vendor. Without proper training on the specific features, security practices, and operational procedures of the new platform, the organization may face increased risks of misconfiguration, security vulnerabilities, and inefficiencies in cloud operations. It is crucial for the technical team to have a comprehensive understanding of all platforms in use to ensure they can maintain the security and performance standards required for a robust cloud environment.
References = The concern is based on common cloud auditing challenges, such as controlling and monitoring user access, and ensuring the IT team is equipped to manage the cloud environment effectively12. Additionally, best practices suggest that network segmentation, user authentication, and access control are critical areas to address in a cloud audit3. These principles are widely recognized in the field of cloud security and compliance.
Question 62
In audit parlance, what is meant by "management representation"?
Options:
A.
A person or group of persons representing executive management during audits
B.
A mechanism to represent organizational structure
C.
A project management technique to demonstrate management's involvement in key
project stages
D.
Statements made by management in response to specific inquiries
Answer:
D
Explanation:
Management representation is a term used in audit parlance to refer to the statements made by management in response to specific inquiries or through the financial statements, as part of the audit evidence that the auditor obtains. Management representation can be oral or written, but the auditor usually obtains written representation from management in the form of a letter that attests to the accuracy and completeness of the financial statements and other information provided to the auditor. The management representation letter is signed by senior management, such as the CEO and CFO, and is dated the same date of audit work completion. The management representation letter confirms or documents the representations explicitly or implicitly given to the auditor during the audit, indicates the continuing appropriateness of such representations, and reduces the possibility of misunderstanding concerning the matters that are the subject of the representations12.