CCAK Practice Questions
Prepare for CCAK with more than an answer.
- Level
- Certificate
- Valid for
- No expiration
Domains covered on the exam 9
- Cloud Compliance Program21%
- Cloud Governance18%
- Cloud Auditing15%
- CCM and CAIQ: Goals, Objectives, and Structure12%
- Evaluating a Cloud Compliance Program9%
- CCM: Auditing Controls8%
- Continuous Assurance and Compliance7%
- A Threat Analysis Methodology for Cloud Using CCM5%
- STAR Program5%
- 1
A cloud governance committee is defining its policy for data residency to address GDPR requirements. The policy must ensure that PII from EU citizens remains within the EU. Which of the following technical controls are essential for an auditor to verify for this policy to be effective? (Select TWO)
Show answer details
Correct answer: A, C
Most major cloud providers allow customers to specify the geographic regions where their data is stored and replicated. An auditor must verify these settings are correctly configured to prevent data from being moved outside the permitted jurisdictions (the EU, in this case).
A preventive control, such as an AWS Service Control Policy (SCP) or Azure Policy, can enforce data residency at the organizational level by explicitly denying actions that would create resources or store data outside of designated EU regions. This is a critical technical enforcement of the governance policy.
- 2
A manufacturing company uses a SaaS ERP system. An auditor is tasked with verifying the provider's business continuity and disaster recovery capabilities. The provider's CAIQ states that their Recovery Time Objective (RTO) is 4 hours and their Recovery Point Objective (RPO) is 1 hour. What is the BEST form of evidence the auditor can obtain to validate these claims?
Show answer details
Correct answer: C
Claims about RTO and RPO are best validated by actual performance. A documented plan only shows intent, not capability. The most reliable evidence is the result of a recent, comprehensive DR test that simulates a real-world failure. The report should detail the entire timeline from incident declaration to service restoration, allowing the auditor to verify if the 4-hour RTO was met. It should also verify the data restoration process to confirm the 1-hour RPO. Verification by an independent third party adds a significant level of assurance to the evidence.
- 3
Case Study:
Global Retail Corp (GRC) has adopted a continuous assurance model for its primary e-commerce platform hosted in a public cloud. The system relies on a Cloud Security Posture Management (CSPM) tool that continuously scans for misconfigurations against a baseline derived from the CSA CCM. The CSPM is configured to automatically remediate certain high-risk findings, such as publicly exposed storage buckets, by applying a restrictive policy.
During a recent sales event, the marketing team needed to temporarily share a large media file with an external partner and, finding no other way, placed it in a storage bucket and made it public. The CSPM tool detected this within minutes and automatically reverted the bucket's permissions to private, breaking the marketing team's workflow and causing a significant delay in the campaign launch. The marketing team claims the security process is too rigid and is hindering business operations.
The incident has triggered a review of the continuous assurance program. As the cloud auditor, you are asked to provide a recommendation that balances security with business agility.
What is the MOST appropriate recommendation to improve GRC's continuous assurance program?
Show answer details
Correct answer: B
A mature continuous assurance program must account for legitimate business needs that may temporarily deviate from standard policy. Simply disabling auto-remediation weakens security, while excluding teams creates security silos. The best approach is to establish a formal exception management process. This allows the marketing team to request a temporary, risk-assessed exception (e.g., a time-limited, pre-signed URL for the file instead of a public bucket). The process ensures that deviations are documented, approved by risk owners, and monitored with compensating controls, thus balancing security requirements with business agility.
- 4
A cloud customer is concerned about vendor lock-in and wants to ensure they can migrate their data and applications to another provider if needed. During an audit, which CSA CCM control domain should be the primary focus to assess the CSP's support for this requirement?
Show answer details
Correct answer: D
The Interoperability & Portability (IPY) domain of the CSA CCM is specifically designed to address the risks of vendor lock-in. Its controls focus on the ability of the customer to move their data and applications between different cloud services. An auditor would examine the provider's adherence to these controls, such as providing data export capabilities in standard formats and using non-proprietary APIs, to assess the ease of migration.
- 5
An organization wants to perform a comprehensive security assessment of its new cloud-based application. The security team wants to simulate a real-world attack with limited prior knowledge of the application's internal architecture, but they will be provided with valid user credentials. What type of penetration test does this describe?
Show answer details
Correct answer: C
Gray-box testing is a blend of white-box and black-box testing. The tester has some, but not all, information about the internal workings of the system. In this scenario, having user credentials but limited architectural knowledge fits the description perfectly. It allows the tester to assess security from the perspective of an authenticated user without having the full 'keys to the kingdom' that a white-box test would provide.
- 6
A cloud auditor is reviewing a CSP's logging and monitoring capabilities. The CSP provides evidence that all administrative actions within the cloud environment are logged. However, the auditor finds that there is no mechanism in place to prevent a privileged administrator from deleting or altering these logs. This finding represents a failure to ensure which fundamental security principle regarding audit logs?
Show answer details
Correct answer: C
Immutability is the principle that logs, once written, cannot be altered or deleted. This is crucial for maintaining the integrity and trustworthiness of audit trails. Without immutability, a malicious actor (including a privileged insider) could cover their tracks by modifying logs. Common controls to achieve this include write-once-read-many (WORM) storage, shipping logs to a separate, highly restricted security account, or using blockchain-based logging services.
- 7
When a company adopts a cloud-first strategy, the role of the internal audit function must evolve. Which of the following represents the MOST significant shift in focus for an internal auditor in a cloud-centric enterprise?
Show answer details
Correct answer: B
In a traditional on-premises environment, auditors test controls that are fully managed by the organization. In the cloud, many controls (e.g., physical security, hypervisor management) are the responsibility of the CSP. The auditor's focus must shift to critically evaluating the assurance documents provided by the CSP (like SOC 2 reports) to gain confidence in their controls. Simultaneously, the auditor must intensify the audit of the controls that are the customer's responsibility, such as IAM configuration, network security groups, and data encryption settings. This dual focus on third-party assurance and customer-side configuration is the most significant change.
- 8
A global logistics company is implementing a multi-cloud strategy, using different IaaS providers for different geographic regions to optimize latency. The CISO is concerned about maintaining a consistent security and compliance posture across all environments. As the lead cloud auditor, which of the following is the MOST critical first step in establishing a unified cloud governance framework?
Show answer details
Correct answer: B
The foundational step in governing a multi-cloud environment is to establish a common set of policies and standards that are not tied to any single provider. Mapping these to a universal framework like the CSA Cloud Controls Matrix (CCM) creates a single source of truth for security and compliance. This allows for consistent assessment and enforcement, regardless of the underlying cloud platform. Deploying tools (CSPM), creating a center of excellence, or auditing individual providers are subsequent steps that should be guided by this foundational governance framework.
- 9
During an audit of a SaaS provider, an auditor discovers that the provider relies on a third-party data processor for analytics services. The contract between the SaaS provider and the data processor lacks specific clauses regarding data breach notification timelines. This presents a significant risk to the SaaS provider's customers who are subject to GDPR. Which CSA CCM control domain is MOST directly implicated by this finding?
Show answer details
Correct answer: C
The STA domain in the CSA CCM specifically addresses the risks associated with the cloud supply chain, including third-party data processors. Controls within this domain require organizations to manage and assess the security posture of their vendors, ensure contractual agreements are in place, and define responsibilities, including incident notification. The lack of specific breach notification clauses directly relates to the controls in the STA domain.
- 10
A financial institution is using a Platform-as-a-Service (PaaS) offering to develop and deploy a new mobile banking application. The cloud auditor needs to verify that the development lifecycle includes adequate security checks. Which of the following activities should the auditor prioritize to gain assurance over the security of the application code itself? (Select TWO)
Show answer details
Correct answer: B, C
SAST tools analyze the application's source code for vulnerabilities before it is compiled or run. This is a critical control for identifying security flaws early in the development lifecycle.
DAST tools test the application in its running state, simulating attacks to find vulnerabilities that may not be apparent in the static code. This is a crucial step to identify runtime and configuration issues.
