ISO/IEC 27017:2015 Code of Practice for Information Security Controls Based on ISO/IEC 27002 for Cloud Services Exam Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A multinational corporation, \"Aethelred Enterprises,\" has migrated its critical customer relationship management (CRM) system to a public cloud infrastructure. Following the migration, an unauthorized third party gained access to sensitive customer data by exploiting a misconfigured virtual firewall rule on one of the virtual machines hosting the CRM application. Analysis of the incident revealed that the virtual firewall was configured by Aethelred Enterprises\' internal IT team to allow unrestricted inbound traffic on a specific port, which was not necessary for the CRM\'s operation. Which party bears the primary responsibility for the security lapse leading to this data breach, according to the principles outlined in ISO/IEC 27017:2015?

The cloud service customer (Aethelred Enterprises)
The cloud service provider
A joint responsibility shared equally by both parties
A regulatory oversight body responsible for cloud security standards

About the ISO/IEC 27017:2015 Code of Practice for Information Security Controls Based on ISO/IEC 27002 for Cloud Services Exam Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27017:2015 Code of Practice for Information Security Controls Based on ISO/IEC 27002 for Cloud Services Exam exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.