An audit has identified that business units have purchased cloud-based applications without ITs support. What is the GREATEST risk associated with this situation?
A CSP contracts for a penetration test to be conducted on its infrastructures. The auditor engages the target with no prior knowledge of its defenses, assets, or channels. The CSP's security operation center is not notified in advance of the scope of the audit and the test vectors. Which mode is selected by the CSP?
In all three cloud deployment models, (IaaS, PaaS, and SaaS), who is responsible for the patching of the hypervisor layer?
An auditor is performing an audit on behalf of a cloud customer. For assessing security awareness, the auditor should: