ISACA CCAK Exam
Certificate of Cloud Auditing Knowledge (Page 8 )

Updated On: 1-Feb-2026

In all three cloud deployment models, (IaaS, PaaS, and SaaS), who is responsible for the patching of the hypervisor layer?

  1. Cloud service customer
  2. Shared responsibility
  3. Cloud service provider
  4. Patching on hypervisor layer is not required

Answer(s): A



A certification target helps in the formation of a continuous certification framework by incorporating:

  1. CSA STAR level 2 attestation.
  2. service level objective and service qualitative objective.
  3. frequency of evaluating security attributes.
  4. scope description and security attributes to be tested.

Answer(s): B



When migrating to a cloud environment, which of the following should be the PRIMARY driver for the use of encryption?

  1. Cloud Service Provider encryption capabilities
  2. The presence of PII
  3. Organizational security policies
  4. Cost-benefit analysis

Answer(s): A



Which of the following would be considered as a factor to trust in a cloud service provider?

  1. The level of exposure for public information
  2. The level of proved technical skills
  3. The level of willingness to cooperate
  4. The level of open source evidence available

Answer(s): C



Which of the following activities are part of the implementation phase of a cloud assurance program during a cloud migration?

  1. Development of the monitoring goals and requirements
  2. Identification of processes, functions, and systems
  3. Identification of the relevant laws, regulations, and standards
  4. Identification of roles and responsibilities

Answer(s): B


Reference:

https://www.isaca.org/resources/isaca-journal/past-issues/2012/cloud-risk-10-principles-and-aframework-for-assessment



Viewing page 8 of 63
Viewing questions 36 - 40 out of 334 questions



Post your Comments and Discuss ISACA CCAK exam prep with other Community members:

Join the CCAK Discussion