Certificate of Cloud Auditing Knowledge (CCAK) — Question 85
The FINAL decision to include a material finding in a cloud audit report should be made by the:
Answer options
- A. organization’s chief information security officer (CISO).
- B. cloud auditor.
- C. auditee’s senior management.
- D. organization’s chief executive officer (CEO).
Correct answer: B
Explanation
The cloud auditor is responsible for evaluating the findings during the audit process and has the expertise to decide which material findings should be reported. The other options, while important roles, do not hold the same level of authority or specialized knowledge regarding the audit report content.