Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 14 discussion

Actual exam question from Isaca's CISM
Question #: 14
Topic #: 1
[All CISM Questions]

An organization that uses external cloud services extensively is concerned with risk monitoring and timely response. The BEST way to address this concern is to ensure:

  • A. the availability of continuous technical support.
  • B. appropriate service level agreements (SLAs) are in place.
  • C. a right-to-audit clause is included in contracts.
  • D. internal security standards are in place.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
k4d4v4r
Highly Voted 2 years, 1 month ago
Selected Answer: B
timely response = SLA
upvoted 14 times
...
Cytrail
Highly Voted 2 years, 1 month ago
I agree with you - B
upvoted 10 times
...
greeklover84
Most Recent 2 months ago
Selected Answer: B
B makes more sense.
upvoted 1 times
...
2c24cf3
3 months, 2 weeks ago
Selected Answer: B
SLA = Timely response
upvoted 1 times
...
BamBamBigalo
5 months, 1 week ago
A right-to-audit clause allows the organization to periodically review the cloud service provider's compliance with security and risk management practices. While this is important for oversight and ensuring adherence to standards, it does not directly ensure continuous risk monitoring and timely response. It is more of a periodic check rather than a continuous process.
upvoted 1 times
...
BamBamBigalo
5 months, 1 week ago
B. Appropriate service level agreements (SLAs) are in place. SLAs are crucial because they define the expected level of service, including aspects such as uptime, performance, and response times for incidents. Effective SLAs should include specific terms for risk monitoring and timely response to incidents. This ensures that the cloud service provider is contractually obligated to monitor risks and respond within agreed-upon timeframes, directly addressing the organization's concern
upvoted 1 times
...
simon205
7 months ago
C , you should always conduct an audit as long as you want to secure something .
upvoted 1 times
...
CCIEBYDEC
8 months, 3 weeks ago
Selected Answer: C
The question addressed two things: monitoring and Time, SLA will only address time but Right to Audit Clause will address both
upvoted 2 times
...
Lalyaaa
9 months, 1 week ago
Selected Answer: C
C. a right-to-audit clause is included in contracts.
upvoted 2 times
...
cidigi
10 months, 4 weeks ago
For those that go with SLA. How do you know that SLAs are in place, are met etc if you don't perform an audit on the cloud provider? Or do you trust the reports from the cloud provider?
upvoted 3 times
...
AlexJacobson
11 months, 3 weeks ago
I'm leaning towards C. Because we're concerned with timely response AND risk monitoring. SLA would address only the former, while the audit would address the latter (and SLA's to an extent). Then again, maybe I'm overthinking it. But maybe the majority is also falling for the trap the question author has made by putting SLA on position B making it "an obvious answer"...
upvoted 2 times
AlexJacobson
10 months ago
Replying to myself here just to enforce my view of things. In vendor contracts, the right to audit clause grants the purchasing party (“Purchaser”) the authority to conduct audits or assessments of the vendor's activities, records, and *performance* to ensure compliance with the terms of the contract. In other words, it includes SLA stuff, while SLA does not include risk monitoring. So I still think it's C.
upvoted 1 times
...
...
Viperhunter
12 months ago
Selected Answer: C
Including a right-to-audit clause in contracts with external cloud service providers allows the organization to conduct audits and assessments to verify compliance with security and risk management requirements. This clause provides the organization with the ability to monitor the provider's security controls, assess the effectiveness of risk management processes, and ensure that the cloud services meet the organization's security standards. While options like the availability of continuous technical support (option A), appropriate service level agreements (SLAs) (option B), and having internal security standards in place (option D) are important considerations, the right-to-audit clause specifically empowers the organization to directly assess and monitor the security practices of the external cloud service provider.
upvoted 4 times
...
Learner76
1 year ago
I will go with C - SLA will take on timely response but to do risk monitoring you will need right to audit (including visibility to SLA). C allows u to answer both
upvoted 1 times
...
derfBabel
1 year, 1 month ago
Selected Answer: B
Can't be C. "SLA" includes: right to audit (for risk monitoring) + req for outputs (the timely response). "Right to audit" doesn't include the "timely response'.
upvoted 2 times
...
ankit420325
1 year, 2 months ago
whoever is answering can please explain right to audit how it is possible ? do you think amazon or google allow any other IT company who are using their service to come to their premises and will allow an audit ??
upvoted 2 times
...
Cert_IT
1 year, 2 months ago
Selected Answer: C
Right to audit clause
upvoted 2 times
...
Cert_IT
1 year, 2 months ago
Selected Answer: C
I go with C
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...