Certificate of Cloud Auditing Knowledge (CCAK) — Question 254
Reviewing which of the following gives an auditor the BEST insight into how a client determines the continued suitability of a cloud vendor that has recently experienced multiple changes to its business model?
Answer options
- A. Organizational risk tolerance
- B. Compliance obligations register
- C. Cloud service inventory
- D. Competitor insight reports
Correct answer: A
Explanation
The correct answer is A, as understanding the organizational risk tolerance provides insight into how a client evaluates the risks associated with their cloud vendor, especially after changes in the vendor's business model. The other options, while relevant to compliance and inventory, do not directly address the client's criteria for vendor suitability.