During the course of an audit, which of the following would NOT be an input into the control requirements used as part of a gap analysis. A. Contractual requirements B. Regulations C. Vendor recommendations D. Corporate policy Suggested Answer: C Community Answer: C Vendor recommendations would not be pertinent to the gap analysis after an audit. Although vendor recommendations will typically play a role in the development of corporate policies or contractual requirements, they are not required. Regulations, corporate policy, and contractual requirements all determine the expected or mandated controls in place on a system. This question is in CCSP Certified Cloud Security Professional Exam For getting Certified Cloud Security Professional (CCSP) Certificate Disclaimers: The website is not related to, affiliated with, endorsed or authorized by ISC. Trademarks, certification & product names are used for reference only and belong to ISC. The website does not contain actual questions and answers from ISC's Certification Exams.
Please login or Register to submit your answer