CCAK Sample Questions & Answers
Cloud compliance program frameworks top the weighting, just ahead of cloud governance, planning and executing audits, the structure of Cloud Controls Matrix and CAIQ, auditing controls, continuous monitoring, evaluating a program, and the STAR registry.
Launch the full CCAK simulator →Free CCAK Sample Questions with Answers
Real questions from the Certificate of Cloud Auditing Knowledge (CCAK) practice test — answers and explanations included. Showing 10 of 20 free samples.
- Question 1Advanced
Cloud Compliance Program · Compliance Program Structure
Case Study:
FinSecure, a mid-sized financial technology firm, provides a SaaS platform for wealth management. The platform is built on a single major public cloud provider and handles sensitive Personally Identifiable Information (PII) and financial data, making it subject to GDPR and PCI DSS. The company has grown rapidly, and its initial cloud deployment was managed by a small development team with limited formal security oversight. They now have a dedicated security team and are preparing for their first formal, external audit.
The current architecture consists of a three-tier web application running on virtual machines within a single Virtual Private Cloud (VPC). Data is stored in a managed relational database service. All resources were provisioned manually through the cloud console. Logging is enabled, but logs are stored in a decentralized manner within each service's local storage, and there is no centralized Security Information and Event Management (SIEM) system. Identity management relies on basic IAM roles with some users having overly permissive, long-lived credentials.
The new Head of Compliance has engaged an external auditor to assess FinSecure's compliance program. The primary goal is to achieve a favorable audit opinion and build a sustainable compliance posture. The auditor notes that while the developers are highly skilled, there is a lack of documented policies, procedures, and evidence of control operation.
Given the state of FinSecure's environment, what should be the auditor's primary recommendation to establish a baseline for a successful compliance program?
Show answer & explanation
Correct answer: B
Before implementing new tools or procedures, it is essential to understand the current state and measure it against a recognized standard. A gap analysis using the CSA CCM provides a structured and comprehensive method to evaluate FinSecure's posture. This process will systematically identify all the deficiencies noted (lack of policies, decentralized logging, poor IAM), prioritize remediation efforts, and create a roadmap for building a mature compliance program. It addresses the root cause—the lack of a structured control framework—rather than just treating symptoms like deploying a SIEM.
- Question 2Intermediate
Cloud Auditing · Evidence Collection
An e-commerce company is preparing for its annual PCI DSS assessment for its cloud environment. The assessor has requested evidence that vulnerability scans are being performed on all in-scope systems. The company provides a report from their CSP's native vulnerability management service. However, the report only covers vulnerabilities in the underlying host operating systems of their IaaS instances. What is the MOST likely reason this evidence is insufficient for the auditor?
Show answer & explanation
Correct answer: B
According to the shared responsibility model for IaaS, the customer is responsible for everything from the guest OS upwards, including all applications, libraries, and configurations. The CSP's report only covers their part of the responsibility (the host OS). PCI DSS requires scanning for vulnerabilities across the entire technology stack, including the application layer. Therefore, the evidence is insufficient because it omits the customer's area of responsibility, which is a critical part of the in-scope environment.
- Question 3Intermediate
STAR Program · STAR Registry and Certification
When evaluating a Cloud Service Provider's (CSP) submission to the CSA STAR Registry, an auditor notes the provider has a STAR Level 1 Self-Assessment based on the CAIQ. What is the primary limitation an auditor must consider when using this as evidence of the CSP's control environment?
Show answer & explanation
Correct answer: C
The key characteristic of STAR Level 1 is that it is a self-assessment. The CSP completes the CAIQ and attests to their own controls. While this provides transparency, it lacks the independent verification and assurance that comes from a third-party audit (found in STAR Level 2 certifications and attestations). An auditor can use the Level 1 submission as a starting point for due diligence but cannot rely on it as verified proof of control effectiveness.
- Question 4Advanced
A Threat Analysis Methodology for Cloud Using CCM · Cloud Threat Analysis
A cloud auditor is using a threat analysis methodology based on the CSA CCM to evaluate the security of a serverless application. The application uses an API Gateway to trigger a function that processes customer data from a queue and stores the results in an object storage bucket. The auditor identifies a potential threat where an attacker could inject malicious code into the function, causing it to exfiltrate data to an external endpoint. Which CCM control would be MOST effective in mitigating this specific threat?
Show answer & explanation
Correct answer: B
The DSP-10 control in CCM v4 focuses on Network Security, including requirements to 'restrict and monitor traffic between trusted and untrusted connections.' In the context of a serverless function, this translates to implementing strict egress filtering rules. By configuring the function's networking environment to only allow outbound connections to known, trusted endpoints (like the internal object storage service), any attempt to exfiltrate data to an unauthorized external endpoint would be blocked at the network level, directly mitigating the identified threat.
- Question 5Intermediate
Evaluating a Cloud Compliance Program · Program Evaluation Criteria
When evaluating a cloud compliance program's maturity, an auditor observes that the organization has documented policies and procedures, but their implementation is inconsistent across different teams. Some teams use automated tools for enforcement, while others rely on manual processes. This indicates that the program is largely reactive. According to a standard capability maturity model, which level BEST describes the organization's current state?
Show answer & explanation
Correct answer: B
At Level 2 (Managed/Repeatable), processes are documented and activities are planned and performed according to policy. However, implementation can be inconsistent and often reactive, relying on individual heroics rather than institutionalized, organization-wide practices. The scenario describes documented policies but inconsistent and reactive implementation, which is the hallmark of this level. Level 1 is chaotic with no documented processes. Level 3 (Defined) would require organization-wide standards and proactive implementation. Level 4 (Quantitatively Managed) involves metrics and data-driven management.
- Question 6Intermediate
CCM: Auditing Controls · Control Testing Methodologies
An auditor is testing the effectiveness of a cloud provider's logical access controls as specified in the CSA CCM. The auditor selects a sample of recently terminated employees and checks if their access to cloud management consoles and APIs was revoked. To ensure the test is robust, the auditor must verify that revocation occurred within the timeframe specified in the customer's _________.
Show answer & explanation
Correct answer: B
The Service Level Agreement (SLA) is the contractual document that defines the specific, measurable service levels the provider commits to, including timelines for critical security operations like access revocation. While an organization's internal policies define their requirements, the SLA codifies the provider's obligation. Therefore, the auditor must test against the contractually agreed-upon timeframe in the SLA to determine if the control is operating effectively from a customer assurance perspective.
- Question 7Intermediate
Cloud Compliance Program · Legal and Regulatory Requirements
A healthcare organization is migrating its Electronic Health Record (EHR) system to a public cloud provider. To comply with HIPAA, the organization must sign a Business Associate Agreement (BAA) with the provider. As part of the organization's compliance program, what is the PRIMARY purpose of the BAA from an audit perspective?
Show answer & explanation
Correct answer: C
A Business Associate Agreement is a legally binding contract required by HIPAA. Its primary function is to ensure that the cloud provider (the Business Associate) understands and accepts its responsibility to safeguard PHI according to HIPAA rules. It contractually obligates the CSP to implement appropriate administrative, physical, and technical safeguards and defines what the CSP can and cannot do with the PHI. For an auditor, the BAA is critical evidence that the relationship and responsibilities regarding PHI protection have been formally established.
- Question 8Beginner
CCM and CAIQ: Goals, Objectives, and Structure · Consensus Assessments Initiative Questionnaire (CAIQ)
True or False: The CSA CAIQ is a comprehensive audit report that provides an independent auditor's opinion on the design and operating effectiveness of a Cloud Service Provider's controls.
Show answer & explanation
Correct answer: B
This statement is false. The CAIQ (Consensus Assessments Initiative Questionnaire) is a questionnaire, typically completed by the CSP themselves as part of a self-assessment (STAR Level 1). It provides transparency into a CSP's security practices but does not constitute an audit report or an independent auditor's opinion. An independent auditor's opinion on control effectiveness would be found in reports like a SOC 2 Type II or an ISO 27001 certification, which correspond to STAR Level 2.
- Question 9IntermediateSelect 2
Cloud Governance · Cloud Governance Policies
A cloud governance committee is defining its policy for data residency to address GDPR requirements. The policy must ensure that PII from EU citizens remains within the EU. Which of the following technical controls are essential for an auditor to verify for this policy to be effective? (Select TWO)
Show answer & explanation
Correct answers: A, C
Most major cloud providers allow customers to specify the geographic regions where their data is stored and replicated. An auditor must verify these settings are correctly configured to prevent data from being moved outside the permitted jurisdictions (the EU, in this case).
A preventive control, such as an AWS Service Control Policy (SCP) or Azure Policy, can enforce data residency at the organizational level by explicitly denying actions that would create resources or store data outside of designated EU regions. This is a critical technical enforcement of the governance policy.
- Question 10Advanced
Cloud Auditing · Evidence Collection
A manufacturing company uses a SaaS ERP system. An auditor is tasked with verifying the provider's business continuity and disaster recovery capabilities. The provider's CAIQ states that their Recovery Time Objective (RTO) is 4 hours and their Recovery Point Objective (RPO) is 1 hour. What is the BEST form of evidence the auditor can obtain to validate these claims?
Show answer & explanation
Correct answer: C
Claims about RTO and RPO are best validated by actual performance. A documented plan only shows intent, not capability. The most reliable evidence is the result of a recent, comprehensive DR test that simulates a real-world failure. The report should detail the entire timeline from incident declaration to service restoration, allowing the auditor to verify if the 4-hour RTO was met. It should also verify the data restoration process to confirm the 1-hour RPO. Verification by an independent third party adds a significant level of assurance to the evidence.
Ready for the real thing?
The full CCAK simulator has every exam-style question, timed mode, and instant scoring.