Certificate of Cloud Auditing Knowledge (CCAK) Free Sample Questions

20 free sample questions269 in the full practice test

Try simulator

CCAK Sample Questions

  1. Question 1

    A global logistics company is implementing a multi-cloud strategy, using different IaaS providers for different geographic regions to optimize latency. The CISO is concerned about maintaining a consistent security and compliance posture across all environments. As the lead cloud auditor, which of the following is the MOST critical first step in establishing a unified cloud governance framework?

    Answer and explanation

    Correct answer: B

    The foundational step in governing a multi-cloud environment is to establish a common set of policies and standards that are not tied to any single provider. Mapping these to a universal framework like the CSA Cloud Controls Matrix (CCM) creates a single source of truth for security and compliance. This allows for consistent assessment and enforcement, regardless of the underlying cloud platform. Deploying tools (CSPM), creating a center of excellence, or auditing individual providers are subsequent steps that should be guided by this foundational governance framework.

  2. Question 2

    During an audit of a SaaS provider, an auditor discovers that the provider relies on a third-party data processor for analytics services. The contract between the SaaS provider and the data processor lacks specific clauses regarding data breach notification timelines. This presents a significant risk to the SaaS provider's customers who are subject to GDPR. Which CSA CCM control domain is MOST directly implicated by this finding?

    Answer and explanation

    Correct answer: C

    The STA domain in the CSA CCM specifically addresses the risks associated with the cloud supply chain, including third-party data processors. Controls within this domain require organizations to manage and assess the security posture of their vendors, ensure contractual agreements are in place, and define responsibilities, including incident notification. The lack of specific breach notification clauses directly relates to the controls in the STA domain.

  3. Question 3

    Multiple answers

    A financial institution is using a Platform-as-a-Service (PaaS) offering to develop and deploy a new mobile banking application. The cloud auditor needs to verify that the development lifecycle includes adequate security checks. Which of the following activities should the auditor prioritize to gain assurance over the security of the application code itself? (Select TWO)

    Answer and explanation

    Correct answers: B, C

    SAST tools analyze the application's source code for vulnerabilities before it is compiled or run. This is a critical control for identifying security flaws early in the development lifecycle.

    DAST tools test the application in its running state, simulating attacks to find vulnerabilities that may not be apparent in the static code. This is a crucial step to identify runtime and configuration issues.

  4. Question 4

    True or False: When a cloud customer uses Infrastructure as a Service (IaaS), the responsibility for patching guest operating systems and installed applications lies solely with the Cloud Service Provider (CSP).

    Answer and explanation

    Correct answer: B

    This statement is false. In the IaaS model, the CSP is responsible for the security 'of' the cloud (i.e., the underlying infrastructure, hypervisor). The customer is responsible for security 'in' the cloud, which includes securing and patching the guest operating systems, middleware, and applications they install and manage on the IaaS instances. This is a fundamental concept of the shared responsibility model.

  5. Question 5

    A government agency is required to establish a continuous compliance monitoring program for its sensitive workloads hosted in a community cloud. The program must provide near real-time visibility into the configuration state of all virtual machines and containerized services. The current process involves manual audits performed quarterly. To transition to a continuous model, the lead auditor recommends implementing a system based on the following workflow:

    sequenceDiagram participant CMDB participant PolicyEngine as Policy Engine (Policy-as-Code) participant CSP_API as Cloud Provider API participant Dashboard as Compliance Dashboard loop Every 15 minutes PolicyEngine->>CSP_API: Query resource configurations CSP_API-->>PolicyEngine: Return current state PolicyEngine->>PolicyEngine: Compare state against defined policies alt Non-Compliant PolicyEngine->>Dashboard: Send Alert PolicyEngine->>CMDB: Update resource status to 'Non-Compliant' else Compliant PolicyEngine->>CMDB: Update resource status to 'Compliant' end end

    Which of the following is the MOST significant challenge the agency will face when implementing this automated, continuous assurance model?

    Answer and explanation

    Correct answer: B

    The effectiveness of the entire continuous assurance model hinges on the quality and accuracy of the policies defined in the Policy Engine. Translating complex regulatory requirements (like NIST, FedRAMP, etc.) into precise, machine-readable code (e.g., using Open Policy Agent, Sentinel) is a highly specialized and ongoing effort. These policies must be continuously updated to reflect new threats, regulatory changes, and evolving architectures. An inaccurate or incomplete policy library will lead to false positives, false negatives, and ultimately, a loss of trust in the automated system.

  6. Question 6

    Case Study:

    FinSecure, a mid-sized financial technology firm, provides a SaaS platform for wealth management. The platform is built on a single major public cloud provider and handles sensitive Personally Identifiable Information (PII) and financial data, making it subject to GDPR and PCI DSS. The company has grown rapidly, and its initial cloud deployment was managed by a small development team with limited formal security oversight. They now have a dedicated security team and are preparing for their first formal, external audit.

    The current architecture consists of a three-tier web application running on virtual machines within a single Virtual Private Cloud (VPC). Data is stored in a managed relational database service. All resources were provisioned manually through the cloud console. Logging is enabled, but logs are stored in a decentralized manner within each service's local storage, and there is no centralized Security Information and Event Management (SIEM) system. Identity management relies on basic IAM roles with some users having overly permissive, long-lived credentials.

    The new Head of Compliance has engaged an external auditor to assess FinSecure's compliance program. The primary goal is to achieve a favorable audit opinion and build a sustainable compliance posture. The auditor notes that while the developers are highly skilled, there is a lack of documented policies, procedures, and evidence of control operation.

    Given the state of FinSecure's environment, what should be the auditor's primary recommendation to establish a baseline for a successful compliance program?

    Answer and explanation

    Correct answer: B

    Before implementing new tools or procedures, it is essential to understand the current state and measure it against a recognized standard. A gap analysis using the CSA CCM provides a structured and comprehensive method to evaluate FinSecure's posture. This process will systematically identify all the deficiencies noted (lack of policies, decentralized logging, poor IAM), prioritize remediation efforts, and create a roadmap for building a mature compliance program. It addresses the root cause—the lack of a structured control framework—rather than just treating symptoms like deploying a SIEM.

  7. Question 7

    An e-commerce company is preparing for its annual PCI DSS assessment for its cloud environment. The assessor has requested evidence that vulnerability scans are being performed on all in-scope systems. The company provides a report from their CSP's native vulnerability management service. However, the report only covers vulnerabilities in the underlying host operating systems of their IaaS instances. What is the MOST likely reason this evidence is insufficient for the auditor?

    Answer and explanation

    Correct answer: B

    According to the shared responsibility model for IaaS, the customer is responsible for everything from the guest OS upwards, including all applications, libraries, and configurations. The CSP's report only covers their part of the responsibility (the host OS). PCI DSS requires scanning for vulnerabilities across the entire technology stack, including the application layer. Therefore, the evidence is insufficient because it omits the customer's area of responsibility, which is a critical part of the in-scope environment.

  8. Question 8

    When evaluating a Cloud Service Provider's (CSP) submission to the CSA STAR Registry, an auditor notes the provider has a STAR Level 1 Self-Assessment based on the CAIQ. What is the primary limitation an auditor must consider when using this as evidence of the CSP's control environment?

    Answer and explanation

    Correct answer: C

    The key characteristic of STAR Level 1 is that it is a self-assessment. The CSP completes the CAIQ and attests to their own controls. While this provides transparency, it lacks the independent verification and assurance that comes from a third-party audit (found in STAR Level 2 certifications and attestations). An auditor can use the Level 1 submission as a starting point for due diligence but cannot rely on it as verified proof of control effectiveness.

  9. Question 9

    A cloud auditor is using a threat analysis methodology based on the CSA CCM to evaluate the security of a serverless application. The application uses an API Gateway to trigger a function that processes customer data from a queue and stores the results in an object storage bucket. The auditor identifies a potential threat where an attacker could inject malicious code into the function, causing it to exfiltrate data to an external endpoint. Which CCM control would be MOST effective in mitigating this specific threat?

    Answer and explanation

    Correct answer: B

    The DSP-10 control in CCM v4 focuses on Network Security, including requirements to 'restrict and monitor traffic between trusted and untrusted connections.' In the context of a serverless function, this translates to implementing strict egress filtering rules. By configuring the function's networking environment to only allow outbound connections to known, trusted endpoints (like the internal object storage service), any attempt to exfiltrate data to an unauthorized external endpoint would be blocked at the network level, directly mitigating the identified threat.

  10. Question 10

    When evaluating a cloud compliance program's maturity, an auditor observes that the organization has documented policies and procedures, but their implementation is inconsistent across different teams. Some teams use automated tools for enforcement, while others rely on manual processes. This indicates that the program is largely reactive. According to a standard capability maturity model, which level BEST describes the organization's current state?

    Answer and explanation

    Correct answer: B

    At Level 2 (Managed/Repeatable), processes are documented and activities are planned and performed according to policy. However, implementation can be inconsistent and often reactive, relying on individual heroics rather than institutionalized, organization-wide practices. The scenario describes documented policies but inconsistent and reactive implementation, which is the hallmark of this level. Level 1 is chaotic with no documented processes. Level 3 (Defined) would require organization-wide standards and proactive implementation. Level 4 (Quantitatively Managed) involves metrics and data-driven management.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 269 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon