Which section of a contract includes the customer's right to audit the vendor to verify whether the vendor is fulfilling its contractual obligations?
A customer requests that a cloud provider physically destroys any drives storing their personal data. What must the provider do with the drives?
Which phase of software design covers the combination of individual components of developed code and the determination of proper interoperability?
When should a cloud service provider delete customer data?
Which platform component includes containers and storage?
An organization designing a data center wants the ability to quickly create and shut down virtual systems based on demand. Which concept describes this capability?
What is the process of identifying and procuring stored data as evidence for legal purposes?
Which device is used to create and manage encryption keys used for data transmission in a cloud-based environment?
After selecting a new vendor, what should an organization do next as part of the vendor onboarding process?
Which steps should an organization take to avoid risk when dealing with software licensing?
Which term refers to taking an accurate account of a system's desired standard state so changes can be quickly detected for approval or remediation?
Which business area in the enterprise risk management (ERM) strategy is concerned with formal risk assessments when forming new or renewing existing vendor relationships?
Which characteristic of cloud computing refers to sharing physical assets among multiple customers?
Which activity is within the scope of the cloud provider’s role in the chain of custody?
During a financial data investigation, the investigator is unsure how to handle a specific data set. Which set of documentation should they refer to for detailed steps on how to proceed?
Which phase of the cloud data life cycle involves activities such as data categorization and classification, including data labeling, marking, tagging, and assigning metadata?
An organization is considering a cloud provider that has multivendor pathway connectivity. What does this feature provide?
An organization is implementing a new hybrid cloud deployment. Before granting access to any of the resources, the security team wants to ensure that all employees are checked against a database to see if they are allowed to access the requested resource. Which type of security control is the organization leveraging for its employees?
An organization is planning for an upcoming Payment Card Industry Data Security Standard (PCI DSS) audit and wants to ensure that only relevant files are included in the audit materials. Which process should the organization use to ensure that the relevant files are identified?
An organization is implementing a new hybrid cloud deployment and wants all employees to provide a username, password, and security token before accessing any of the cloud resources. Which type of security control is the organization leveraging for its employees?
An internal developer deploys a new customer information system at a company. The system has an updated graphical interface with new fields. Which type of functional testing ensures that the graphical interface used by employees to input customer data behaves as the employees need it to?
Which U.S. law requires all publicly traded corporations in the United States to provide information about their financial status and implements controls to ensure the accuracy of the disclosed information?
Which methodology encompasses conducting tests around the interaction of end users with new code that is intended for a patch?
Which group should be notified for approval when a planned modification to an environment is scheduled?