Certificate of Cloud Auditing Knowledge (CCAK) — Question 255
A cloud customer has recently failed an audit certification. An auditor has reviewed the logging and monitoring policy defined by the cloud customer and identified that the policy is aligned to the compliance requirements. Which of the following could be the reason for the audit failure?
Answer options
- A. The policy is not accessible to all employees.
- B. The policy does not mention that it is cloud-relevant.
- C. The policy does not have the revision history.
- D. The policy is available only in a Word document.
Correct answer: C
Explanation
The correct answer is C because having a revision history is crucial for demonstrating that the policy is regularly updated and maintained, which is often a requirement for compliance. Options A and D do not directly relate to compliance standards, and option B may be a concern but does not typically lead to an audit failure if the policy is compliant overall.