CCAK — ISACA Certificate of Cloud Auditing Knowledge
ISACA

ISACA Certificate of Cloud Auditing Knowledge (CCAK) Practice Questions

★★★★★★ 4.8 145 verified reviews
257 questions
2026-06-21 updated
✓ Online quiz simulator

Domain coverage

  • Cloud Concepts, Architecture, and Design (15%)
  • Cloud Data Security (14%)
  • Cloud Platform and Infrastructure Security (14%)
  • Cloud Application Security (9%)
  • Cloud Security Operations (12%)
  • Legal, Risk, and Compliance (12%)
  • Cloud Auditing Knowledge and Skills (24%)

Sample Questions (26 of 257 shown)

Q1
Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization’s SaaS vendor?
  1. Risk exceptions policy
  2. Contractual requirements
  3. Risk appetite
  4. Board oversight
✓ Correct Answer: B
Changes to contractual requirements (B) will MOST likely influence the expansion or reduction of controls required to remediate risk from SaaS vendor changes. Contractual requirements define the obligations, responsibilities, and controls that both parties must adhere to. When contractual terms change, the control environment must be adjusted accordingly. Risk exceptions policy (A), risk appetite (C), and board oversight (D) influence risk management but don't directly drive control changes like contractual requirements do.
Q2
Prioritizing assurance activities for an organization’s cloud services portfolio depends PRIMARILY on an organization’s ability to:
  1. schedule frequent reviews with high-risk cloud service providers.
  2. develop plans using a standardized risk-based approach.
  3. maintain a comprehensive cloud service inventory.
  4. collate views from various business functions using cloud services.
✓ Correct Answer: B
Prioritizing assurance activities for an organization's cloud services portfolio depends PRIMARILY on the ability to develop plans using a standardized risk-based approach (B). A risk-based approach ensures that audit resources are allocated to the highest-risk areas, providing the most value. This is fundamental to effective audit planning. Frequent reviews (A), comprehensive inventory (C), and collating views (D) are important but secondary to having a risk-based approach.
Q3
An organization that is utilizing a community cloud is contracting an auditor to conduct a review on behalf of the group of organizations within the cloud community. From the following, to whom should the auditor report the findings?
  1. Public
  2. Management of organization being audited
  3. Shareholders/interested parties
  4. Cloud service provider
✓ Correct Answer: C
In a community cloud where an auditor is contracted to conduct a review on behalf of the group of organizations, the auditor should report findings to shareholders/interested parties (C). In a community cloud, multiple organizations share the infrastructure and costs. The auditor represents the collective interests of all participating organizations, so findings should be reported to the collective stakeholders (shareholders/interested parties). Reporting only to one organization's management (B) or the cloud provider (D) doesn't fulfill the obligation to the community.
Q4
Which of the following data destruction methods is the MOST effective and efficient?
  1. Crypto-shredding
  2. Degaussing
  3. Multi-pass wipes
  4. Physical destruction
✓ Correct Answer: A
Crypto-shredding (A) is the MOST effective and efficient data destruction method. Crypto-shredding involves destroying the encryption keys, making the encrypted data permanently unreadable. This is more efficient than multi-pass wipes (C) or physical destruction (D), and more effective than degaussing (B) which only works on magnetic media. Crypto-shredding can instantly render large amounts of data unrecoverable.
Q5
Which of the following cloud models prohibits penetration testing?
  1. Hybrid Cloud
  2. Private Cloud
  3. Public Cloud
  4. Community Cloud
✓ Correct Answer: C
Public Cloud (C) models typically prohibit penetration testing. Public cloud providers often have strict terms of service that prohibit unauthorized security testing to protect their infrastructure and other tenants. Private Cloud (B) and Hybrid Cloud (A) typically allow penetration testing with proper authorization. Community Cloud (D) policies vary but are generally more permissive than public cloud.
Q6
What type of termination occurs at the initiative of one party, and without the fault of the other party?
  1. Termination for cause
  2. Termination for convenience
  3. Termination at the end of the term
  4. Termination without the fault
✓ Correct Answer: B
Termination for convenience (B) occurs at the initiative of one party without the fault of the other party. This allows either party to terminate the contract for any reason (or no reason) with proper notice. Termination for cause (A) occurs due to fault/breach by the other party. Termination at the end of term (C) is natural expiration. 'Termination without the fault' (D) is not a standard legal term.
Q7
The MOST critical concept of managing the build and test of code in DevOps is:
  1. continuous build.
  2. continuous delivery.
  3. continuous deployment.
  4. continuous integration.
✓ Correct Answer: D
The MOST critical concept of managing build and test of code in DevOps is continuous integration (D). Continuous integration involves frequently merging code changes into a central repository, followed by automated builds and tests. This enables early detection of integration issues. Continuous build (A) is part of CI. Continuous delivery (B) and continuous deployment (C) are subsequent stages in the DevOps pipeline.
Q8
The Cloud Computing Compliance Controls Catalogue (C5) framework is maintained by which of the following agencies?
  1. Agence nationale de la sécurité des systèmes d’information (ANSSI)
  2. National Institute of Standards and Technology (NIST)
  3. National Security Agency (NSA)
  4. Bundesamt für Sicherheit in der Informationstechnik (BSI)
✓ Correct Answer: D
The Cloud Computing Compliance Controls Catalogue (C5) framework is maintained by the Bundesamt für Sicherheit in der Informationstechnik (BSI) (D) - the German Federal Office for Information Security. C5 is a German cloud security certification framework. ANSSI (A) is French, NIST (B) is U.S., and NSA (C) is U.S. National Security Agency.
Q9
Which objective is MOST appropriate to measure the effectiveness of password policy?
  1. The number of related incidents increases.
  2. Attempts to log with weak credentials increases.
  3. Newly created account credentials satisfy requirements.
  4. The number of related incidents decreases.
✓ Correct Answer: D
The MOST appropriate objective to measure password policy effectiveness is that the number of related incidents decreases (D). A decrease in password-related incidents (e.g., brute force attacks, credential stuffing) indicates the policy is effective. Increased incidents (A) or weak credential attempts (B) would indicate policy failure. New account credentials satisfying requirements (C) measures compliance, not effectiveness.
Q10
Which of the following is a cloud-specific security standard?
  1. ISO27017
  2. ISO27701
  3. ISO22301
  4. ISO14001
✓ Correct Answer: A
ISO27017 (A) is a cloud-specific security standard. It provides guidance on information security controls and implementation guidance for cloud services. ISO27701 (B) is for privacy (PIMS). ISO22301 (C) is for business continuity. ISO14001 (D) is for environmental management.
Q11
Account design in the cloud should be driven by:
  1. security requirements.
  2. organizational structure.
  3. business continuity policies.
  4. management structure.
✓ Correct Answer: A
Account design in the cloud should be driven by security requirements (A). Security requirements define access needs, least privilege, segregation of duties, and other security principles that should shape account design. Organizational structure (B), business continuity policies (C), and management structure (D) are considerations but secondary to security requirements.
Q12
The cloud risk management process should:
  1. evaluate only the cloud providers’ general maturity.
  2. verify the provider’s policy aligns with the customer’s policy.
  3. evaluate the specific cloud service features.
  4. evaluate the services of the same security features.
✓ Correct Answer: C
The cloud risk management process should evaluate the specific cloud service features (C). Each cloud service has unique features, configurations, and risk profiles that must be assessed. Evaluating only general maturity (A) is too superficial. Verifying policy alignment (B) is important but doesn't replace evaluating specific features. Evaluating services of the same security features (D) is too narrow.
Q13
Which of the following is a category of trust in cloud computing?
  1. Reputation-based trust
  2. Background-based trust
  3. Loyalty-based trust
  4. Transparency-based trust
✓ Correct Answer: A
Reputation-based trust (A) is a category of trust in cloud computing. Reputation-based trust relies on the history and track record of the cloud provider. Other categories include policy-based trust, identity-based trust, and transaction-based trust. Background-based trust (B), loyalty-based trust (C), and transparency-based trust (D) are not standard categories of cloud trust.
Q14
While using public cloud services, cloud users may cede direct control over:
  1. anti-malware solutions.
  2. encryption keys.
  3. security patching.
  4. penetration testing.
✓ Correct Answer: C
While using public cloud services, cloud users may cede direct control over security patching (C). In public cloud (especially SaaS and PaaS), the CSP is responsible for patching the underlying infrastructure and platform. The customer loses direct control over when and how patching is done. Anti-malware solutions (A), encryption keys (B), and penetration testing (D) are typically under customer control (depending on service model).
Q15
In which of the following risk scenarios should a cloud customer have the full responsibility in all cloud service models?
  1. Infrastructure risk
  2. Identity and access risk
  3. Endpoint risk
  4. Data classification risk
✓ Correct Answer: D
In all cloud service models, the cloud customer should have full responsibility for data classification risk (D). Data classification is fundamentally the customer's responsibility because only the customer knows the sensitivity and classification of their own data. The CSP cannot classify customer data appropriately without this knowledge. Infrastructure risk (A), identity and access risk (B), and endpoint risk (C) may be shared or CSP-managed depending on the service model.
Q16
In a multi-level supply chain structure where cloud service provider A relies on other sub cloud services, the provider should ensure that any compliance requirements relevant to the provider are:
  1. passed to the sub cloud service providers based on the sub cloud service providers’ geographic location.
  2. passed to the sub cloud service providers.
  3. treated as confidential information and withheld from all sub cloud service providers.
  4. treated as sensitive information and withheld from certain sub cloud service providers.
✓ Correct Answer: B
In a multi-level supply chain, the cloud service provider should ensure compliance requirements are passed to sub cloud service providers (B). This ensures the entire supply chain meets necessary compliance standards. Passing based on geographic location (A) is not sufficient. Treating as confidential (C) or withholding from certain providers (D) would break the compliance chain and create gaps.
Q17
Which of the following is an important challenge in the design and building of a cloud compliance program?
  1. Determining the total cost of all cloud components
  2. Identifying all cloud components used in the organization
  3. Assigning risk ownership for the cloud components
  4. Understanding the cloud computing context
✓ Correct Answer: D
The MOST important challenge in designing and building a cloud compliance program is understanding the cloud computing context (D). Cloud computing introduces shared responsibility, multi-tenancy, dynamic provisioning, and other unique characteristics that differ from traditional IT. Understanding this context is foundational to designing an effective compliance program. Cost determination (A), identifying components (B), and assigning risk ownership (C) are important but come after understanding the context.
Q18
Which of the following BEST describes the Center for Internet Security (CIS) benchmarks applied to a cloud service provider?
  1. Best practices for the tuning of performance in cloud service providers’ services
  2. Best practices for the secure configuration of the cloud service provider services
  3. Comparisons of the performance obtained from the cloud service providers
  4. Comparisons of the security capabilities provided by the cloud service providers
✓ Correct Answer: B
CIS benchmarks applied to a CSP BEST describe best practices for secure configuration of cloud services (B). CIS benchmarks are consensus-based, secure configuration guidelines for various technologies. They help CSPs and customers ensure secure configuration. Performance tuning (A), performance comparison (C), and security capability comparison (D) are not the purpose of CIS benchmarks.
Q19
Which of the following has been provided by the Federal Office for Information Security in Germany to support customers in selecting, controlling, and monitoring their cloud service providers?
  1. German IDW PS 951
  2. Multi-Tier Cloud Security (MTCS)
  3. BSI Criteria Catalogue C5
  4. BSI IT-basic protection catalogue
✓ Correct Answer: C
The BSI Criteria Catalogue C5 (C) has been provided by the German Federal Office for Information Security (BSI) to support customers in selecting, controlling, and monitoring their cloud service providers. C5 is a certification framework for cloud services. German IDW PS 951 (A) is an audit standard. MTCS (B) is Singapore's multi-tier cloud security standard. BSI IT-basic protection catalogue (D) is for general IT security.
Q20
Organizations, including cloud service providers or cloud customers, must have methods for determining the disruption to processes, people, and technology. Which of the following processes can BEST help identify the issues?
  1. Impact analysis
  2. Research analysis
  3. Predictive analysis
  4. Disruption analysis
✓ Correct Answer: A
Impact analysis (A) is the process that can BEST help identify disruption issues to processes, people, and technology. Business Impact Analysis (BIA) identifies critical business functions and the impact of disruptions. This is fundamental to business continuity and disaster recovery planning. Research analysis (B), predictive analysis (C), and 'disruption analysis' (D) are not standard terms for this process.
Q21
Which of the following cloud environments should be a concern to an organization’s cloud auditor?
  1. The cloud service provider’s data center is more than 100 miles away.
  2. The organization entirely depends on several proprietary Software as a Service (SaaS) applications.
  3. The failover region of the cloud service provider is on another continent.
  4. The technical team is trained on only one vendor Infrastructure as a Service (Iaas) platform, but the organization has subscribed to another vendor’s IaaS platform as an alternative.
✓ Correct Answer: D
The cloud environment that should be a concern to an organization's cloud auditor is when the technical team is trained on only one vendor IaaS platform, but the organization has subscribed to another vendor's IaaS platform as an alternative (D). This creates operational risk - the team lacks the skills to properly manage and secure the alternative platform. Other options (A, B, C) describe normal business decisions that don't necessarily represent audit concerns.
Q22
When performing audits in relation to Business Continuity Management and Operational Resilience strategy, what would be the MOST critical aspect to audit in relation to the strategy of the cloud customer that should be formulated jointly with the cloud service provider?
  1. Validate if the strategy covers unavailability of all components required to operate the business-as-usual or in disrupted mode, in parts or total- when impacted by a disruption.
  2. Validate if the strategy covers all aspects of Business Continuity and Resilience planning, taking inputs from the assessed impact and risks, to consider activities for before, during, and after a disruption.
  3. Validate if the strategy covers all activities required to continue and recover prioritized activities within identified time frames and agreed capacity, aligned to the risk appetite of the organization including the invocation of continuity plans and crisis management capabilities.
  4. Validate if the strategy is developed by both cloud service providers and cloud service consumers within the acceptable limits of their risk appetite.
✓ Correct Answer: C
When auditing Business Continuity Management and Operational Resilience strategy, the MOST critical aspect is validating if the strategy covers all activities required to continue and recover prioritized activities within identified time frames and agreed capacity, aligned to the organization's risk appetite including invocation of continuity plans and crisis management capabilities (C). This directly addresses the operational resilience objectives. Options A, B, and D are components but C is the most comprehensive and critical.
Q23
Which of the following cloud service models creates a cloud version of a contract template?
  1. Software as a Service (SaaS)
  2. Security as a Service (SecaaS)
  3. Infrastructure as a Service (IaaS)
  4. Platform as a Service (PaaS)
✓ Correct Answer: A
Software as a Service (SaaS) (A) cloud service model creates a cloud version of a contract template. SaaS applications often use standardized contract templates (terms of service) that are presented to all users. These are 'click-wrap' or 'browse-wrap' agreements that become contracts. SecaaS (B), IaaS (C), and PaaS (D) may also have contracts but SaaS is most known for standardized contract templates.
Q24
Which of the following is the MOST likely reason for a deletion command not resulting in full destruction of data in the cloud?
  1. The cloud service provider may have extra copies for availability purposes.
  2. The cloud customer may not have the required rights to delete the data.
  3. Cloud encryption may not allow the data to be deleted completely.
  4. The cloud customer may not know the proper way to delete the data.
✓ Correct Answer: A
The MOST likely reason for a deletion command not resulting in full destruction of data in the cloud is that the CSP may have extra copies for availability purposes (A). Cloud providers maintain redundant copies, backups, and snapshots to ensure high availability and durability. These may persist beyond the deletion command. Lack of rights (B), encryption preventing deletion (C), and not knowing proper deletion method (D) are possible but less likely than provider redundancy.
Q25
Which of the following cloud service provider activities MUST obtain a client’s approval?
  1. Deleting test accounts
  2. Deleting subscription owner accounts
  3. Deleting guest accounts
  4. Destroying test data
✓ Correct Answer: B
Deleting subscription owner accounts (B) is a CSP activity that MUST obtain a client's approval. Subscription owner accounts have full control over cloud resources and billing. Deleting them can cause service disruption and financial impact. Deleting test accounts (A), guest accounts (C), and test data (D) are typically lower-risk activities that may not require explicit approval.
Q26
If a cloud agreement allows the cloud service provider to decommission any service within a set period, who is responsible for managing the risk introduced by this change?
  1. Cloud service provider and risk manager
  2. Regulator
  3. Cloud service provider
  4. Cloud customer
✓ Correct Answer: D
If a cloud agreement allows the CSP to decommission any service within a set period, the cloud customer (D) is responsible for managing the risk introduced by this change. The customer must understand the business impact of service decommissioning and develop contingency plans. The CSP is exercising their contractual right; the customer bears the risk of dependence on that service. Risk manager (A) and regulator (B) don't directly manage this operational risk.

You've viewed 3 of 257 questions. Start the free practice exam to answer all questions with instant feedback.

Exam overview

The Certificate of Cloud Auditing Knowledge (CCAK) is the first and only vendor-neutral cloud auditing certification, jointly developed by ISACA and the Cloud Security Alliance (CSA). It fills a critical gap in the market by equipping IT audit, risk, and security professionals with the technical knowledge to audit cloud environments. Unlike general IT audit certifications, CCAK dives deep into cloud-specific concepts—shared responsibility models, cloud architecture patterns, and the unique security controls required across IaaS, PaaS, and SaaS deployments.

Our CCAK practice test suite is built around the official ISACA-CCAK exam blueprint. With 400+ unique questions spanning all seven domains, you will practice auditing cloud concepts and architecture against frameworks like CSA's Cloud Controls Matrix (CCM), evaluating cloud data security controls including encryption key management, and assessing cloud platform and application security. Each question includes detailed audit reasoning that explains not just what the correct finding is, but why the auditor's approach matters—whether you are tracing the shared responsibility boundary or evaluating a CSP's SOC 2 report.

What makes CCAK uniquely valuable is its dual endorsement. ISACA brings decades of IT audit methodology; CSA contributes the definitive cloud security frameworks (CCM, CAIQ, STAR). The exam tests your ability to bridge these worlds—applying audit standards to cloud-native environments where traditional perimeter-based controls do not apply. At $580, CCAK is an investment in becoming the cloud audit professional every organization needs as they accelerate cloud adoption.

Official Exam Domains & Weighting

  • Domain 1: Cloud Concepts, Architecture, and Design (15%) — IaaS/PaaS/SaaS models, shared responsibility, cloud deployment models (public, private, hybrid, community), virtualization and containerization, cloud-native design principles.
  • Domain 2: Cloud Data Security (14%) — Data classification, encryption (at-rest, in-transit, in-use), key management (BYOK, HYOK, CSEK), data loss prevention, data residency, and sovereignty.
  • Domain 3: Cloud Platform and Infrastructure Security (14%) — Identity and access management (IAM), network security (VPC, security groups, WAF), compute and storage security, hypervisor security.
  • Domain 4: Cloud Application Security (9%) — SDLC in cloud environments, DevSecOps, CI/CD pipeline security, container and serverless security, API security testing.
  • Domain 5: Cloud Security Operations (12%) — Incident response in cloud, logging and monitoring (SIEM integration), vulnerability management, configuration management, CSP forensics.
  • Domain 6: Legal, Risk, and Compliance (12%) — Cloud-specific regulations (GDPR, CCPA), CSA STAR certification, SOC 2 Type II audits, third-party risk management, contract review.
  • Domain 7: Cloud Auditing Knowledge and Skills (24%) — Audit planning for cloud, CSA Cloud Controls Matrix (CCM) application, STAR audit evidence collection, audit reporting, continuous cloud auditing approaches.

What Our Customers Say 145 verified reviews

4.8 ★★★★★★ Based on 145 reviews
★★★★★★
The CCAK explanations are detailed and educational. I learned more from reviewing wrong answers than from any book.
— Rachel S.
★★★★★★
Three of my coworkers used this for CCAK and all passed. Figured I’d give it a shot — worked like a charm.
— Derek S.
★★★★★★
I liked that the CCAK questions update regularly. Felt current and aligned with what I actually saw on the test.
— Dylan P.
★★★★★★
I let my coworker borrow my CCAK account to study — he passed too. These questions are legit.
— Grayson P.
★★★★★★
I bought access for the CCAK exam as a gift for my brother. He passed on his first try and said the questions were spot-on.
— Cameron J.
★★★★★
I passed CCAK on my first try thanks to these practice questions. The unlimited retakes were essential for building confidence.
— Nicole K.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

CCAK is cloud-specific. CISA is broad IT audit; CISM is broad security management. CCAK focuses exclusively on auditing cloud environments—applying ISACA audit methodology within CSA's cloud security frameworks. If your career involves cloud adoption, migration, or governance, CCAK provides specialized knowledge that general certifications cannot.

ISACA recommends foundational knowledge of cloud computing concepts and IT audit principles. While no formal prerequisites exist, candidates with some cloud platform familiarity (AWS, Azure, GCP) benefit significantly. Our practice tests include introductory-level cloud concept questions that help bridge knowledge gaps.

The CSA Cloud Controls Matrix (CCM) is the central framework. Expect questions on mapping CCM controls to audit objectives, using the Consensus Assessments Initiative Questionnaire (CAIQ), and evaluating STAR certifications. Our Domain 7 section dedicates extensive coverage to CCM audit applications.

Most candidates invest 6-8 weeks (1-2 hours/day). If you have both cloud and audit experience, 4-6 weeks may suffice. Domain 7 (Cloud Auditing, 24%) deserves proportional study time—it is the highest-weighted domain and requires integrating audit methodology with cloud-specific controls.

Yes, CCAK is available in 8 languages including English, Japanese, Chinese, Korean, Spanish, German, French, and Portuguese. Our product page provides preparation materials in multiple languages.