Official Bank 0/207

Isaca Certificate of Cloud Auditing Knowledge (CCAK) - Isaca Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
207 Total Questions
1
Question
What areas should be reviewed when auditing a public cloud?
Options
A Identity and access management (IAM) and data protection
B Patching and configuration
C Source code reviews and hypervisor
D Vulnerability management and cyber security reviews
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
Which of the following is a category of trust in cloud computing?
Options
A Reputation-based trust
B Loyalty-based trust
C Background-based trust
D Transparency-based trust
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
A cloud auditor should use statistical sampling rather than judgment (nonstatistical) sampling when:
Options
A the probability of error must be objectively quantified.
B generalized audit software is unavailable.
C the auditor wants to avoid sampling risk.
D the tolerable error rate cannot be determined.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
In cloud computing, which KEY subject area relies on measurement results and metrics?
Options
A Platform as a Service (PaaS) development environment
B Software as a Service (SaaS) application services
C Infrastructure as a Service (IaaS) storage and network
D Service level agreements (SLAs)
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
Which of the following would be the MOST critical finding of an application security and DevOps audit?
Options
A Certifications with global security standards specific to cloud are not reviewed, and the impact of noted findings are not assessed.
B The organization is not using a unified framework to integrate cloud compliance with regulatory requirements.
C Outsourced cloud service interruption, breach, or loss of stored data occurred at the cloud service provider.
D Application architecture and configurations did not consider security measures.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.