Certificate of Cloud Auditing Knowledge (CCAK) — Question 96
What data center and physical security measures should a cloud customer consider when assessing a cloud service provider?
Answer options
- A. Assess use of monitoring systems to control ingress and egress points of entry to the data center.
- B. Implement physical security perimeters to safeguard personnel, data and information systems.
- C. Conduct a due diligence to verify the cloud provider applies adequate physical security measures.
- D. Review internal policies and procedures for relocation of hardware and software to an offsite location.
Correct answer: C
Explanation
The correct answer is C, as conducting due diligence is essential to confirm that the cloud provider maintains adequate physical security protocols. Option A focuses on monitoring systems, which is just one aspect of security, while B discusses establishing perimeters, which is a broader strategy but does not ensure that adequate measures are in place. Option D is about internal policies, which do not directly assess the cloud provider's security measures.