CPA · Question 01 · Area I: Information Systems
A CPA is performing a risk assessment for a client that uses a public cloud provider for its core ERP system. The client utilizes an Infrastructure as a Service (IaaS) model. When defining the scope of the IT audit, which of the following components is the client's management primarily responsible for securing, rather than the cloud service provider?
Answer options:
Physical security of the data centers hosting the servers
Maintenance of the hypervisor and virtualization layer
Operating system configuration and application patching
Network infrastructure up to the virtualization layer
82 questions · hints · full answers · grading