Official Bank 0/207

Isaca Certificate of Cloud Auditing Knowledge (CCAK) - Isaca Actual Exam Questions

Last updated on April 30, 2026

97% Exam Compliance
207 Total Questions
1
Question

Which of the following BEST describes the difference between a Type 1 and a Type 2 SOC report?

Options
A

A Type 2 SOC report validates the operating effectiveness of controls, whereas a Type 1 SOC report validates the suitability of the design of the controls.

B

A Type 1 SOC report provides an attestation, whereas a Type 2 SOC report offers a certification.

C

A Type 2 SOC report validates the suitability of the control design, whereas a Type 1 SOC report validates the operating effectiveness of controls.

D

There is no difference between a Type 2 and a Type 1 SOC report.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

To promote the adoption of secure cloud services across the federal government by

Options
A

To providing a standardized approach to security and risk assessment

B

To provide agencies of the federal government a dedicated tool to certify Authority to Operate (ATO)

C

To enable 3PAOs to perform independent security assessments of cloud service providers

D

To publish a comprehensive and official framework for the secure implementation of controls for cloud security

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

Which of the following provides the BEST evidence that a cloud service provider's continuous integration and continuous delivery (CI/CD) development pipeline includes checks for compliance as new features are added to its Software as a Service (SaaS) applications?

Options
A

Compliance tests are automated and integrated within the Cl tool.

B

Developers keep credentials outside the code base and in a secure repository.

C

Frequent compliance checks are performed for development environments.

D

Third-party security libraries are continuously kept up to date.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

Which of the following enables auditors to conduct gap analyses of what a cloud service provider offers versus what the customer requires?

Options
A

Using a standardized control framework

B

The experience gained over the years

C

Understanding the customer risk profile

D

The as-is and to-be enterprise architecture (EA

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

In cloud computing, which KEY subject area relies on measurement results and metrics?

Options
A

Software as a Service (SaaS) application services

B

Infrastructure as a Service (IaaS) storage and network

C

Platform as a Service (PaaS) development environment

D

Service level agreements (SLAs)

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.