Certificate of Cloud Auditing Knowledge (CCAK) — Question 225
Which of the following is the PRIMARY area for an auditor to examine in order to understand the criticality of the cloud services in an organization, along with their dependencies and risks?
Answer options
- A. Turtle diagram
- B. Data security process flow
- C. Contractual documents of the cloud service provider
- D. Heat maps
Correct answer: C
Explanation
The correct answer is C because contractual documents of the cloud service provider outline the terms, conditions, and responsibilities which are crucial for understanding service criticality and risks. The other options, while useful, do not provide the same level of insight into contractual obligations and dependencies related to cloud services.