ISACA CCAK Exam Questions
Certificate of Cloud Auditing Knowledge (Page 8 )

Updated On: 17-Feb-2026

Within an organization, which of the following functions should be responsible for defining the cloud adoption approach?

  1. Audit committee
  2. Compliance manager
  3. IT manager
  4. Senior management

Answer(s): D


Reference:

https://www.coso.org/documents/cloud-computing-thought-paper.pdf



An independent contractor is assessing security maturity of a SaaS company against industry standards. The SaaS company has developed and hosted all their products using the cloud services provided by a third-party cloud service provider (CSP). What is the optimal and most efficient mechanism to assess the controls CSP is responsible for?

  1. Review third-party audit reports.
  2. Review CSP?s published questionnaires.
  3. Directly audit the CSP.
  4. Send supplier questionnaire to the CSP.

Answer(s): B


Reference:

https://www.sapidata.sm/img/cms/CAIQ_v3-1_2020-01-13.pdf



What areas should be reviewed when auditing a public cloud?

  1. Patching, source code reviews, hypervisor, access controls
  2. Identity and access management, data protection
  3. Patching, configuration, hypervisor, backups
  4. Vulnerability management, cyber security reviews, patching

Answer(s): B



Which of the following key stakeholders should be identified the earliest when an organization is designing a cloud compliance program?

  1. Cloud process owners
  2. Internal control function
  3. Legal functions
  4. Cloud strategy owners

Answer(s): A



Which of the following CSP activities requires a client’s approval?

  1. Delete the guest account or test accounts
  2. Delete the master account or subscription owner accounts
  3. Delete the guest account or destroy test data
  4. Delete the test accounts or destroy test data

Answer(s): D






Post your Comments and Discuss ISACA CCAK exam dumps with other Community members:

Join the CCAK Discussion