CCAK Practice Questions
Prepare for CCAK with more than an answer.
- Level
- Certificate
- Valid for
- No expiration
Domains covered on the exam 9
- Cloud Compliance Program21%
- Cloud Governance18%
- Cloud Auditing15%
- CCM and CAIQ: Goals, Objectives, and Structure12%
- Evaluating a Cloud Compliance Program9%
- CCM: Auditing Controls8%
- Continuous Assurance and Compliance7%
- A Threat Analysis Methodology for Cloud Using CCM5%
- STAR Program5%
- 1
Case Study:
Global Retail Corp (GRC) has adopted a continuous assurance model for its primary e-commerce platform hosted in a public cloud. The system relies on a Cloud Security Posture Management (CSPM) tool that continuously scans for misconfigurations against a baseline derived from the CSA CCM. The CSPM is configured to automatically remediate certain high-risk findings, such as publicly exposed storage buckets, by applying a restrictive policy.
During a recent sales event, the marketing team needed to temporarily share a large media file with an external partner and, finding no other way, placed it in a storage bucket and made it public. The CSPM tool detected this within minutes and automatically reverted the bucket's permissions to private, breaking the marketing team's workflow and causing a significant delay in the campaign launch. The marketing team claims the security process is too rigid and is hindering business operations.
The incident has triggered a review of the continuous assurance program. As the cloud auditor, you are asked to provide a recommendation that balances security with business agility.
What is the MOST appropriate recommendation to improve GRC's continuous assurance program?
Show answer details
Correct answer: B
A mature continuous assurance program must account for legitimate business needs that may temporarily deviate from standard policy. Simply disabling auto-remediation weakens security, while excluding teams creates security silos. The best approach is to establish a formal exception management process. This allows the marketing team to request a temporary, risk-assessed exception (e.g., a time-limited, pre-signed URL for the file instead of a public bucket). The process ensures that deviations are documented, approved by risk owners, and monitored with compensating controls, thus balancing security requirements with business agility.
- 2
A cloud customer is concerned about vendor lock-in and wants to ensure they can migrate their data and applications to another provider if needed. During an audit, which CSA CCM control domain should be the primary focus to assess the CSP's support for this requirement?
Show answer details
Correct answer: D
The Interoperability & Portability (IPY) domain of the CSA CCM is specifically designed to address the risks of vendor lock-in. Its controls focus on the ability of the customer to move their data and applications between different cloud services. An auditor would examine the provider's adherence to these controls, such as providing data export capabilities in standard formats and using non-proprietary APIs, to assess the ease of migration.
- 3
An organization wants to perform a comprehensive security assessment of its new cloud-based application. The security team wants to simulate a real-world attack with limited prior knowledge of the application's internal architecture, but they will be provided with valid user credentials. What type of penetration test does this describe?
Show answer details
Correct answer: C
Gray-box testing is a blend of white-box and black-box testing. The tester has some, but not all, information about the internal workings of the system. In this scenario, having user credentials but limited architectural knowledge fits the description perfectly. It allows the tester to assess security from the perspective of an authenticated user without having the full 'keys to the kingdom' that a white-box test would provide.
- 4
A cloud auditor is reviewing a CSP's logging and monitoring capabilities. The CSP provides evidence that all administrative actions within the cloud environment are logged. However, the auditor finds that there is no mechanism in place to prevent a privileged administrator from deleting or altering these logs. This finding represents a failure to ensure which fundamental security principle regarding audit logs?
Show answer details
Correct answer: C
Immutability is the principle that logs, once written, cannot be altered or deleted. This is crucial for maintaining the integrity and trustworthiness of audit trails. Without immutability, a malicious actor (including a privileged insider) could cover their tracks by modifying logs. Common controls to achieve this include write-once-read-many (WORM) storage, shipping logs to a separate, highly restricted security account, or using blockchain-based logging services.
- 5
When a company adopts a cloud-first strategy, the role of the internal audit function must evolve. Which of the following represents the MOST significant shift in focus for an internal auditor in a cloud-centric enterprise?
Show answer details
Correct answer: B
In a traditional on-premises environment, auditors test controls that are fully managed by the organization. In the cloud, many controls (e.g., physical security, hypervisor management) are the responsibility of the CSP. The auditor's focus must shift to critically evaluating the assurance documents provided by the CSP (like SOC 2 reports) to gain confidence in their controls. Simultaneously, the auditor must intensify the audit of the controls that are the customer's responsibility, such as IAM configuration, network security groups, and data encryption settings. This dual focus on third-party assurance and customer-side configuration is the most significant change.
- 6
A global logistics company is implementing a multi-cloud strategy, using different IaaS providers for different geographic regions to optimize latency. The CISO is concerned about maintaining a consistent security and compliance posture across all environments. As the lead cloud auditor, which of the following is the MOST critical first step in establishing a unified cloud governance framework?
Show answer details
Correct answer: B
The foundational step in governing a multi-cloud environment is to establish a common set of policies and standards that are not tied to any single provider. Mapping these to a universal framework like the CSA Cloud Controls Matrix (CCM) creates a single source of truth for security and compliance. This allows for consistent assessment and enforcement, regardless of the underlying cloud platform. Deploying tools (CSPM), creating a center of excellence, or auditing individual providers are subsequent steps that should be guided by this foundational governance framework.
- 7
During an audit of a SaaS provider, an auditor discovers that the provider relies on a third-party data processor for analytics services. The contract between the SaaS provider and the data processor lacks specific clauses regarding data breach notification timelines. This presents a significant risk to the SaaS provider's customers who are subject to GDPR. Which CSA CCM control domain is MOST directly implicated by this finding?
Show answer details
Correct answer: C
The STA domain in the CSA CCM specifically addresses the risks associated with the cloud supply chain, including third-party data processors. Controls within this domain require organizations to manage and assess the security posture of their vendors, ensure contractual agreements are in place, and define responsibilities, including incident notification. The lack of specific breach notification clauses directly relates to the controls in the STA domain.
- 8
A financial institution is using a Platform-as-a-Service (PaaS) offering to develop and deploy a new mobile banking application. The cloud auditor needs to verify that the development lifecycle includes adequate security checks. Which of the following activities should the auditor prioritize to gain assurance over the security of the application code itself? (Select TWO)
Show answer details
Correct answer: B, C
SAST tools analyze the application's source code for vulnerabilities before it is compiled or run. This is a critical control for identifying security flaws early in the development lifecycle.
DAST tools test the application in its running state, simulating attacks to find vulnerabilities that may not be apparent in the static code. This is a crucial step to identify runtime and configuration issues.
- 9
True or False: When a cloud customer uses Infrastructure as a Service (IaaS), the responsibility for patching guest operating systems and installed applications lies solely with the Cloud Service Provider (CSP).
Show answer details
Correct answer: B
This statement is false. In the IaaS model, the CSP is responsible for the security 'of' the cloud (i.e., the underlying infrastructure, hypervisor). The customer is responsible for security 'in' the cloud, which includes securing and patching the guest operating systems, middleware, and applications they install and manage on the IaaS instances. This is a fundamental concept of the shared responsibility model.
- 10
A government agency is required to establish a continuous compliance monitoring program for its sensitive workloads hosted in a community cloud. The program must provide near real-time visibility into the configuration state of all virtual machines and containerized services. The current process involves manual audits performed quarterly. To transition to a continuous model, the lead auditor recommends implementing a system based on the following workflow:
sequenceDiagram participant CMDB participant PolicyEngine as Policy Engine (Policy-as-Code) participant CSP_API as Cloud Provider API participant Dashboard as Compliance Dashboard loop Every 15 minutes PolicyEngine->>CSP_API: Query resource configurations CSP_API-->>PolicyEngine: Return current state PolicyEngine->>PolicyEngine: Compare state against defined policies alt Non-Compliant PolicyEngine->>Dashboard: Send Alert PolicyEngine->>CMDB: Update resource status to 'Non-Compliant' else Compliant PolicyEngine->>CMDB: Update resource status to 'Compliant' end endWhich of the following is the MOST significant challenge the agency will face when implementing this automated, continuous assurance model?
Show answer details
Correct answer: B
The effectiveness of the entire continuous assurance model hinges on the quality and accuracy of the policies defined in the Policy Engine. Translating complex regulatory requirements (like NIST, FedRAMP, etc.) into precise, machine-readable code (e.g., using Open Policy Agent, Sentinel) is a highly specialized and ongoing effort. These policies must be continuously updated to reflect new threats, regulatory changes, and evolving architectures. An inaccurate or incomplete policy library will lead to false positives, false negatives, and ultimately, a loss of trust in the automated system.
