Skip to main content

CCAK Real Exam Questions

Certificate of Cloud Auditing Knowledge

232 questions available · Page 1 of 24

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

An auditor identifies that a CSP received multiple customer inquiries and RFPs during the last month.

Which of the following should be the BEST recommendation to reduce the CSP burden?

  1. A

    CSP can share all security reports with customers to streamline the process.

  2. B

    CSP can schedule a call with each customer.

  3. C

    CSP can answer each customer individually.

  4. D

    CSP can direct all customers' inquiries to the information in the CSA STAR registry.

Show answer and explanation

Correct answer: D

Question 2 Single choice

Which of the following attestation allows for immediate adoption of the Cloud Control Matrix (CCM) as additional criteria to AICPA Trust Service Criteria and provides the flexibility to update the criteria as technology and market requirements change?

  1. A

    PC-IDSS

  2. B

    CSA STAR Attestation

  3. C

    MTCS

  4. D

    BSI Criteria Catalogue C5

Show answer and explanation

Correct answer: B

Question 3 Single choice

Which of the following defines the criteria designed by the American Institute of Certified Public Accountants (AICPA) to specify trusted services?

  1. A

    Security, confidentiality, availability, privacy and processing integrity

  2. B

    Security, applicability, availability, privacy and processing integrity

  3. C

    Security, confidentiality, availability, privacy and trustworthiness

  4. D

    Security, data integrity, availability, privacy and processing integrity

Show answer and explanation

Correct answer: A

Explanation

References:
https://us.aicpa.org/content/dam/aicpa/interestareas/frc/assuranceadvisoryservices/downloadabledocuments/trust-services-criteria.pdf

Question 4 Single choice

Which industry organization offers both security controls and cloud-relevant benchmarking?

  1. A

    Cloud Security Alliance (CSA)

  2. B

    SANS Institute

  3. C

    International Organization for Standardization (ISO)

  4. D

    Center for Internet Security (CIS)

Show answer and explanation

Correct answer: A

Question 5 Single choice

Customer management interface, if compromised over public internet, can lead to:

  1. A

    customer's computing and data compromise.

  2. B

    access to the RAM of neighboring cloud computer.

  3. C

    ease of acquisition of cloud services.

  4. D

    incomplete wiping of the data.

Show answer and explanation

Correct answer: A

Question 6 Single choice

In which control should a cloud service provider, upon request, inform customers of compliance impact and risk, especially if customer data is used as part of the services?

  1. A

    Service Provider control

  2. B

    Impact and Risk control

  3. C

    Data Inventory control

  4. D

    Compliance control

Show answer and explanation

Correct answer: A

Question 7 Single choice

Which of the following is an example of financial business impact?

  1. A

    A hacker using a stolen administrator identity brings down the SaaS sales and marketing systems, resulting in the inability to process customer orders or manage customer relationships.

  2. B

    While the breach was reported in a timely manner to the CEO, the CFO and CISO blamed each other in public, resulting in a loss of public confidence that led the board to replace all three.

  3. C

    A DDoS attack renders the customer's cloud inaccessible for 24 hours resulting in millions in lost sales.

  4. D

    The cloud provider fails to report a breach of customer personal data from an unsecured server, resulting in GDPR fines of 10 million euro.

Show answer and explanation

Correct answer: C

Question 8 Single choice

An organization currently following the ISO/IEC 27002 control framework has been charged by a new CIO to switch to the NIST 800-53 control framework.

Which of the following is the FIRST step to this change?

  1. A

    Discard all work done and start implementing NIST 800-53 from scratch.

  2. B

    Recommend no change, since the scope of ISO/IEC 27002 is broader.

  3. C

    Recommend no change, since NIST 800-53 is a US-scoped control framework.

  4. D

    Map ISO/IEC 27002 and NIST 800-53 and detect gaps and commonalities.

Show answer and explanation

Correct answer: D

Question 9 Single choice

Which of the following is the FIRST step of the Cloud Risk Evaluation Framework?

  1. A

    Analyzing potential impact and likelihood

  2. B

    Establishing cloud risk profile

  3. C

    Evaluating and documenting the risks

  4. D

    Identifying key risk categories

Show answer and explanation

Correct answer: D

Question 10 Single choice

Management planes deployed in cloud environments may pose a risk of potentially allowing access to the entire environment.

Which of the following controls is MOST appropriate for mitigating this risk?

  1. A

    Change management

  2. B

    Regular audits

  3. C

    Access restriction

  4. D

    Increased monitoring

Show answer and explanation

Correct answer: C