Isaca

CCAK practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 233-question bank.

Provider
Isaca
Question bank
233
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CCAK, a certification listed under Isaca. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isaca. The certification credential is issued by Isaca, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization’s SaaS vendor?

    Choose one answer.

    • Risk exceptions policy
    • Contractual requirements
    • Risk appetite
    • Board oversight
  2. Question 2 · 1

    When a client’s business process changes, the CSP SLA should:

    Choose one answer.

    • be reviewed, but the SLA cannot be updated.
    • not be reviewed, but the cloud contract should be cancelled immediately.
    • not be reviewed as the SLA cannot be updated.
    • be reviewed and updated if required.
  3. Question 3 · 1

    When building a cloud governance model, which of the following requirements will focus more on the cloud service provider’s evaluation and control checklist?

    Choose one answer.

    • Security requirements
    • Legal requirements
    • Compliance requirements
    • Operational requirements
  4. Question 4 · 1

    Prioritizing assurance activities for an organization’s cloud services portfolio depends PRIMARILY on an organization’s ability to:

    Choose one answer.

    • schedule frequent reviews with high-risk cloud service providers.
    • develop plans using a standardized risk-based approach.
    • maintain a comprehensive cloud service inventory.
    • collate views from various business functions using cloud services.
  5. Question 5 · 1

    If the degree of verification for information shared with the auditor during an audit is low, the auditor should:

    Choose one answer.

    • reject the information as audit evidence.
    • stop evaluating the requirement altogether and review other audit areas.
    • delve deeper to obtain the required information to decide conclusively.
    • use professional judgment to determine the degree of reliance that can be placed on the information as evidence.
  6. Question 6 · 1

    Which best describes the difference between a type 1 and a type 2 SOC report?

    Choose one answer.

    • A type 2 SOC report validates the operating effectiveness of controls whereas a type 1 SOC report validates the suitability of the design of the controls.
    • A type 2 SOC report validates the suitability of the design of the controls whereas a type 1 SOC report validates the operating effectiveness of controls.
    • A type 1 SOC report provides an attestation whereas a type 2 SOC report offers a certification.
    • There is no difference between a type 2 and type 1 SOC report.
  7. Question 7 · 1

    You have been assigned the implementation of an ISMS, whose scope must cover both on premise and cloud infrastructure. Which of the following is your BEST option?

    Choose one answer.

    • Implement ISO/IEC 27002 and complement it with additional controls from the CCM.
    • Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27017.
    • Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27002.
    • Implement ISO/IEC 27001 and complement it with additional controls from the NIST SP 800-145.
  8. Question 8 · 1

    As a developer building codes into a container in a DevSecOps environment, which of the following is the appropriate place(s) to perform security tests?

    Choose one answer.

    • Within developer’s laptop
    • Within the CI/CD server
    • Within version repositories
    • Within the CI/CD pipeline
  9. Question 9 · 1

    An organization that is utilizing a community cloud is contracting an auditor to conduct a review on behalf of the group of organizations within the cloud community. From the following, to whom should the auditor report the findings?

    Choose one answer.

    • Public
    • Management of organization being audited
    • Shareholders/interested parties
    • Cloud service provider
  10. Question 10 · 1

    Which of the following parties should have accountability for cloud compliance requirements?

    Choose one answer.

    • Customer
    • Equally shared between customer and provider
    • Provider
    • Either customer or provider, depending on requirements
  11. Question 11 · 1

    Which of the following data destruction methods is the MOST effective and efficient?

    Choose one answer.

    • Crypto-shredding
    • Degaussing
    • Multi-pass wipes
    • Physical destruction
  12. Question 12 · 1

    Under GDPR, an organization should report a data breach within what time frame?

    Choose one answer.

    • 72 hours
    • 2 weeks
    • 1 week
    • 48 hours
  13. Question 13 · 1

    The PRIMARY objective of an audit initiation meeting with a cloud audit client is to:

    Choose one answer.

    • select the methodology of the audit.
    • review requested evidence provided by the audit client.
    • discuss the scope of the cloud audit.
    • identify resource requirements of the cloud audit.
  14. Question 14 · 1

    What type of termination occurs at the initiative of one party, and without the fault of the other party?

    Choose one answer.

    • Termination for cause
    • Termination for convenience
    • Termination at the end of the term
    • Termination without the fault
  15. Question 15 · 1

    An auditor is performing an audit on behalf of a cloud customer. For assessing security awareness, the auditor should:

    Choose one answer.

    • assess the existence and adequacy of a security awareness training program at the cloud service provider’s organization as the cloud customer hired the auditor to review and cloud service.
    • assess the existence and adequacy of a security awareness training program at both the cloud customer’s organization and the cloud service provider’s organization.
    • assess the existence and adequacy of a security awareness training program at the cloud customer’s organization as they hired the auditor.
    • not assess the security awareness training program as it is each organization’s responsibility

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free