Try 12 Certificate of Cloud Auditing Knowledge (CCAK) sample questions on cloud audit scope, evidence, controls, risk, compliance, logging, and assurance.
The Certificate of Cloud Auditing Knowledge (CCAK) focuses on cloud audit and assurance. It is useful for candidates who need cloud control objectives, evidence, risk assessment, compliance mapping, shared responsibility, and audit reporting.
Use these 12 original sample questions for initial self-assessment. They are not official Cloud Security Alliance questions and do not reproduce a live exam.
Verify current certificate names, exam policies, and requirements with the Cloud Security Alliance education page .
Topic: audit scope
What should a cloud audit scope define first?
Best answer: A
Explanation: Scope must define what is being audited, which controls matter, who owns them, and what evidence can support conclusions.
Topic: shared responsibility evidence
Which evidence best tests a customer-owned cloud control?
Best answer: C
Explanation: Customer-owned controls require customer-side evidence. Provider attestations do not prove customer configuration quality.
Topic: provider assurance
Why are provider assurance reports useful?
Best answer: B
Explanation: Assurance reports are useful only when the auditor understands scope, period, exceptions, and complementary controls.
Topic: evidence reliability
Which evidence is generally strongest for testing whether logging is enabled?
Best answer: D
Explanation: System-generated configuration evidence is stronger than informal statements when it is relevant, complete, and tied to the audit period.
Topic: cloud inventory
Why is cloud inventory important for audit?
Best answer: C
Explanation: Dynamic cloud resources can escape control coverage if inventory and ownership are weak.
Topic: control mapping
What does control mapping help an auditor do?
Best answer: A
Explanation: Mapping clarifies which controls satisfy which requirements and who operates them.
Topic: configuration drift
Why is configuration drift a cloud audit concern?
Best answer: D
Explanation: Drift can weaken controls after initial approval, so audits need evidence over time.
Topic: continuous auditing
Which cloud feature supports continuous auditing?
Best answer: B
Explanation: Cloud APIs and telemetry can support more continuous, evidence-driven audit approaches.
Topic: incident evidence
During a cloud incident audit, which evidence matters most?
Best answer: A
Explanation: Incident assurance needs factual records of what happened, response actions, and control improvements.
Topic: audit finding
What makes a cloud audit finding useful?
Best answer: C
Explanation: Findings should be evidence-based and tied to criteria, risk, and remediation.
Topic: data residency
What evidence helps test data-residency controls?
Best answer: D
Explanation: Data residency requires evidence about where data is stored, replicated, processed, and monitored.
Topic: audit independence
Why should auditors avoid operating the controls they audit?
Best answer: B
Explanation: Auditors should evaluate controls without taking over management’s control responsibilities.