Exam Details

  • Exam Code
    :CCAK
  • Exam Name
    :Certificate of Cloud Auditing Knowledge
  • Certification
    :Cloud Security Alliance
  • Vendor
    :Isaca
  • Total Questions
    :126 Q&As
  • Last Updated
    :May 09, 2024

Isaca Cloud Security Alliance CCAK Questions & Answers

  • Question 121:

    Network environments and virtual instances shall be designed and configured to restrict and monitor traffic between trusted and untrusted connections. These configurations shall be reviewed at least annually, and supported by a documented justification for use for all allowed services, protocols, ports, and by compensating controls. Which of the following controls BEST matches this control description?

    A. Network Security

    B. Change Detection

    C. Virtual Instance and OS Hardening

    D. Network Vulnerability Management

  • Question 122:

    Which of the following is the BEST tool to perform cloud security control audits?

    A. General Data Protection Regulation (GDPR)

    B. ISO 27001

    C. Federal Information Processing Standard (FIPS) 140-2

    D. CSA Cloud Control Matrix (CCM)

  • Question 123:

    In an organization, how are policy violations MOST likely to occur?

    A. By accident

    B. Deliberately by the ISP

    C. Deliberately

    D. Deliberately by the cloud provider

  • Question 124:

    Due to cloud audit team resource constraints, an audit plan as initially approved cannot be completed. Assuming that the situation is communicated in the cloud audit report which course of action is MOST relevant?

    A. Focusing on auditing high-risk areas

    B. Testing the adequacy of cloud controls design

    C. Relying on management testing of cloud controls

    D. Testing the operational effectiveness of cloud controls

  • Question 125:

    A CSP contracts for a penetration test to be conducted on its infrastructures. The auditor engages the target with no prior knowledge of its defenses, assets, or channels. The CSP's security operation center is not notified in advance of the scope of the audit and the test vectors. Which mode is selected by the CSP?

    A. Double gray box

    B. Tandem

    C. Reversal

    D. Double blind

  • Question 126:

    Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization's SaaS vendor?

    A. Risk exceptions policy

    B. Contractual requirements

    C. Risk appetite

    D. Board oversight

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Isaca exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CCAK exam preparations and Isaca certification application, do not hesitate to visit our Vcedump.com to find your solutions here.