Pass4itsure > Isaca > Isaca Certifications > CCAK > CCAK Online Practice Questions and Answers

CCAK Online Practice Questions and Answers

Questions 4

From the perspective of a senior cloud security audit practitioner in an organization of a mature security program with cloud adoption, which of the following statements BEST describes the DevSecOps concept?

A. Process of security integration using automation in software development

B. Development standards for addressing integration, testing, and deployment issues

C. Operational framework that promotes software consistency through automation

D. Making software development simpler, faster, and easier using automation

Buy Now
Questions 5

Which of the following would be the GREATEST governance challenge to an organization where production is hosted in a public cloud and backups are held on the premises?

A. Aligning the cloud service delivery with the organization's objective

B. Aligning the cloud provider's SLA with the organization's policy

C. Aligning shared responsibilities between provider and customer

D. Aligning the organization's activity with the cloud provider's policy

Buy Now
Questions 6

To assist an organization with planning a cloud migration strategy to execution, an auditor should recommend the use of:

A. object-oriented architecture.

B. software architecture.

C. service-oriented architecture.

D. enterprise architecture.

Buy Now
Questions 7

Which of the following would be considered as a factor to trust in a cloud service provider?

A. The level of exposure for public information

B. The level of proved technical skills

C. The level of willingness to cooperate

D. The level of open source evidence available

Buy Now
Questions 8

Which of the following would be the MOST critical finding of an application security and DevOps audit?

A. The organization is not using a unified framework to integrate cloud compliance with regulatory requirements.

B. Application architecture and configurations did not consider security measures.

C. Outsourced cloud service interruption, breach or loss of data stored at the cloud service provider.

D. Certifications with global security standards specific to cloud are not reviewed and the impact of noted findings are not assessed.

Buy Now
Questions 9

To support customer's verification of the CSP claims regarding their responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?

A. Contractual agreement

B. Internal audit

C. External audit

D. Security assessment

Buy Now
Questions 10

A. Cloud compliance program

B. Legacy IT compliance program

C. Internal audit program

D. Service organization controls report

Buy Now
Questions 11

When building a cloud governance model, which of the following requirements will focus more on the cloud service provider's evaluation and control checklist?

A. Security requirements

B. Legal requirements

C. Compliance requirements

D. Operational requirements

Buy Now
Questions 12

Which of the following parties should have accountability for cloud compliance requirements?

A. Customer

B. Equally shared between customer and provider

C. Provider

D. Either customer or provider, depending on requirements

Buy Now
Questions 13

Which of the following is a cloud-specific security standard?

A. ISO27017

B. ISO27701

C. ISO22301

D. ISO14001

Buy Now
Exam Code: CCAK
Exam Name: Certificate of Cloud Auditing Knowledge
Last Update: May 27, 2026
Questions: 126
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$49.99

VCE

$55.99

PDF + VCE

$65.99