ISACA CCAK Exam
Certificate of Cloud Auditing Knowledge (Page 17 )

Updated On: 9-Feb-2026

What is the advantage of using dynamic application security testing (DAST) over static application security testing (SAST) methodology?

  1. Unlike SAST, DAST is a blackbox and programming language agnostic.
  2. DAST can dynamically integrate with most CI/CD tools.
  3. DAST delivers more false positives than SAST.
  4. DAST is slower but thorough.

Answer(s): A


Reference:

https://www.synopsys.com/blogs/software-security/sast-vs-dast-difference/



Which of the following is a direct benefit of mapping the Cloud Control Matrix (CCM) to other international standards and regulations?

  1. CCM mapping entitles cloud service providers to be listed as an approved supplier for tenders and government contracts.
  2. CCM mapping enables cloud service providers and customers alike to streamline their own compliance and security efforts.
  3. CCM mapping enables an uninterrupted data flow and, in particular, the export of personal data across different jurisdictions.
  4. CCM mapping entitles cloud service providers to be certified under the CSA STAR program.

Answer(s): B


Reference:

https://cloudsecurityalliance.org/press-releases/2021/03/15/cloud-security-alliance- releasesadditional-mappings-update-to-cloud-controls-matrix-ccm-v4/



The criteria for limiting services allowing non-critical services or services requiring high availability and resilience to be moved to the cloud is an important consideration to be included PRIMARILY in the:

  1. risk management policy.
  2. cloud policy.
  3. business continuity plan.
  4. information security standard for cloud technologies.

Answer(s): C



Which of the following should be the FIRST step to establish a cloud assurance program during a cloud migration?

  1. Design
  2. Stakeholder identification
  3. Development
  4. Risk assessment

Answer(s): C



Customer management interface, if compromised over public internet, can lead to:

  1. customer’s computing and data compromise.
  2. access to the RAM of neighboring cloud computer.
  3. ease of acquisition of cloud services.
  4. incomplete wiping of the data.

Answer(s): A






Post your Comments and Discuss ISACA CCAK exam prep with other Community members:

Join the CCAK Discussion