Certified in Cloud Auditing Knowledge Practice Exam — CCAK:Certified in Cloud Auditing Knowledge

1. The question bank is cloud‑connected and updates automatically; no manual re‑acquisition is required.

2. Start practicing right after activating the question bank. It supports simultaneous use on websites and mini‑programs, with one‑click bilingual switching for each question.

3. Functions include online practice, mock tests, note‑taking, wrong‑question recording, etc., valid for one year.

4. Recommended practice order: Turn on review mode to browse questions → Complete sequential practice → Take mock exams for pre‑test self‑assessment.

5. Activation codes can be purchased by clicking Buy Now on the right or via our official Tmall flagship store.

6. For inquiries, contact customer service through mini‑program, WeChat, WhatsApp or LINE.

Exam information

I. Basic Exam Information

- Exam Name: ISACA Certificate of Cloud Auditing Knowledge™ (CCAK™)

- Launch & Update Date: Co-developed by the Cloud Security Alliance (CSA) and ISACA; the latest exam outline was updated in 2025.

- Exam Languages: Only English is available globally at present. No Chinese version has been announced. Candidates in Mainland China may only take the exam in English for the time being.

- Registration Eligibility: The exam is open to all candidates with no mandatory work experience requirements.

 • Prior foundational experience in IT audit, cybersecurity, risk management or cloud computing is recommended.

 • Agree to and abide by the ISACA Code of Professional Ethics.

 • Note: There are no pre-requisite credentials for CCAK; candidates may register without holding other certifications.

- Exam Fees: USD 395 for ISACA members; USD 495 for non-members. A USD 50 credential application fee is required after passing the exam.

- Exam Duration: 2 hours (120 minutes), covering all 76 exam questions.

- Exam Format: ISACA offers two standard exam modes worldwide: remote-proctored online exam (video proctoring via PSI) and in-person computer-based testing (CBT).

 Available exam modes by region:

 • Hong Kong: In-person CBT only

 • Taiwan: In-person CBT and online exam

 • Macau: In-person CBT only

 • Mainland China: In-person CBT arranged by ISACA-authorized partners

 • Overseas regions: Free to choose between remote proctoring and in-person CBT

- Exam Questions: 76 scenario-based multiple-choice questions. All questions are scored with no unscored pre-test items.

- Scoring Details:

 • A preliminary pass/fail result is provided immediately after the exam.

 • Official exam results will be sent via email within 10 working days.

 • Passing standard: 70% overall score (a minimum of 53 correct answers is required).

- Exam Eligibility Validity: After successful registration, candidates must schedule and complete the exam within 12 months. Eligibility will expire if overdue, and re-registration and payment will be required.


II. Detailed Exam Content (Latest Exam Outline)

The CCAK exam covers nine core knowledge domains with a total weight of 100%. It assesses the professional competencies and practical capabilities of cloud auditing practitioners.


1. Cloud Compliance Program (21%): Cloud compliance frameworks and standards, identification of compliance requirements, design and implementation of compliance programs, compliance monitoring and reporting.

2. Cloud Governance (18%): Cloud governance frameworks, formulation of policies and procedures, alignment between cloud strategy and business objectives, stakeholder management, cloud service provider management.

3. Cloud Auditing (15%): Cloud audit planning, audit methodologies and techniques, collection and analysis of audit evidence, audit report writing, audit follow-up and closure.

4. CCM and CAIQ: Objectives, Purpose and Structure (12%): Overview of Cloud Controls Matrix (CCM) and Cloud Controls Assessment Questionnaire (CAIQ), understanding control objectives and purposes, control mapping and alignment.

5. Cloud Compliance Program Evaluation (9%): Effectiveness assessment of compliance programs, gap analysis, development of improvement recommendations, compliance risk assessment.

6. CCM: Audit Controls (8%): Understanding CCM control families, control testing methodologies, assessment of control effectiveness, identification and reporting of control deficiencies.

7. Continuous Assurance and Compliance (7%): Continuous auditing techniques, automated compliance monitoring, real-time risk assessment, compliance dashboard design.

8. CCM-based Cloud Threat Analysis Methodology (5%): Cloud threat landscape analysis, threat modeling methodologies, risk assessment frameworks, threat response strategies.

9. Understanding the STAR Initiative (5%): Overview of the Security, Trust & Assurance Registry (STAR), STAR tier requirements, STAR certification process, interpretation of STAR reports.


Core Assessment Focus

Capabilities in cloud compliance management, design of cloud governance systems, delivery of cloud audit engagements, application of CCM and CAIQ frameworks, cloud security risk assessment and management, cross-departmental collaboration and stakeholder communication.


III. Registration Process

1. Registration Process for Non-Mainland China Candidates

1. Visit the official ISACA website: https://www.isaca.org, create and log in to your MyISACA account.

2. Select the CCAK exam for registration and fill in relevant personal information.

3. Complete exam fee payment (USD 395 for members / USD 495 for non-members).

4. Upon successful payment, your 12-month exam eligibility period will take effect.

5. Schedule your exam time and location via PSI (remote proctoring or in-person CBT is optional).

6. Prepare valid identification documents and attend the exam at the scheduled time.


2. Registration Process for Mainland China Candidates

1. Register via the official ISACA China website: https://www.isaca.org.cn or ISACA-authorized partners such as ZhongShen Audit Online and Saihu Academy.

2. Submit personal information and complete registration with assistance from authorized institutions.

3. Pay the exam fee (USD 395 for members / USD 495 for non-members). All registration formalities will be handled uniformly by the institution.

4. Upon successful registration, your 12-month exam eligibility period will take effect.

5. Follow the links or guidelines provided by the institution to schedule your exam time and test center on the PSI platform. In-person CBT is the primary option in Mainland China.

6. Present valid identification documents (ID card or passport) on exam day.


IV. Supplementary Notes

1. Credential Validity: The CCAK credential is valid for 3 years. To maintain active status, holders must earn 60 Continuing Professional Education (CPE) credits within the validity period and pay annual maintenance fees (USD 45 for members / USD 85 for non-members).

2. Retake Policy: Candidates who fail the exam must wait 30 days before retaking it. A 90-day waiting period is required after two consecutive failures. Retake fees are identical to the initial exam fees.

3. Credential Application Period: You must submit the CCAK credential application within 5 years upon passing the exam. Otherwise, you will need to retake the exam.

4. Differences from Other Cloud Credentials: CCAK focuses on cloud auditing knowledge and practices, ideal for IT auditors, cloud security professionals and risk management practitioners. CCSK (Certificate of Cloud Security Knowledge) concentrates on fundamental cloud security knowledge for cloud beginners. CISA (Certified Information Systems Auditor) covers comprehensive IT audit domains for general IT audit professionals.


Wish all candidates every success in the exam!

Sample questions

Certified in Cloud Auditing Knowledge · Q1
Question #1Changes to which of the following will MOST likely influence the expansion or reduction of controls required to remediate the risk arising from changes to an organization’s SaaS vendor?
  • A.
    Risk exceptions policy
  • B.
    Contractual requirements
  • C.
    Risk appetite
  • D.
    Board oversight

Answer: B

The question focuses on identifying which change most directly impacts the number and scope of controls required to remediate risk from changes to an organization's SaaS vendor. Per CCAK domain knowledge of cloud third-party risk management and contract governance, contractual requirements represent the legally binding, agreed-upon obligations between the organization and its SaaS vendor that govern security, compliance, privacy, and operational performance. When either party modifies contractual terms, for example adding new data residency mandates, adjusting incident response timelines, or removing a previously required compliance certification obligation, the set of controls needed to meet these terms and remediate associated risk will expand or reduce accordingly. This makes contractual requirements the most direct and impactful driver of control changes for SaaS vendor risk, as all remediation controls for third-party cloud risk are designed to first satisfy enforceable contract terms to avoid legal, financial, or operational harm. Option Analysis: A. Risk exceptions policy: Incorrect. A risk exceptions policy defines the process and criteria for accepting residual risk instead of implementing remediation controls. Changing this policy only alters when an organization may choose to forego controls, not the actual scope or number of controls that are required to remediate the SaaS vendor risk if remediation is pursued. It does not influence expansion or reduction of required remediation controls. B. Contractual requirements: Correct. Contractual terms with SaaS vendors are the primary source of enforceable requirements for risk mitigation in cloud third-party relationships. Any change to these requirements, such as new security testing obligations, modified data retention rules, or adjusted service level agreements, directly changes the controls that must be implemented to meet the terms of the agreement and remediate associated risk, making this the most impactful factor. C. Risk appetite: Incorrect. Risk appetite is the high-level organizational threshold for acceptable risk. While a change to risk appetite may change whether the organization chooses to remediate or accept a given risk from a SaaS vendor change, it does not alter the specific controls that are required to actually remediate that risk if remediation is selected. It impacts risk treatment decisions, not the scope of required remediation controls. D. Board oversight: Incorrect. Board oversight is a governance function that monitors organizational risk and compliance performance. Changes to board oversight processes only alter how controls and risk are reported or reviewed, not the scope of controls required to remediate SaaS vendor-related risk. It is a monitoring function, not a driver of control requirements. Key Concepts: 1. Cloud Third-Party Contract Governance: A core CCAK domain concept that holds that cloud service agreements, or contracts, are the primary enforceable source of security, compliance, and risk mitigation obligations for relationships with SaaS, PaaS, and IaaS vendors, and all control implementations for third-party cloud risk must align to these terms. 2. Control Alignment with Third-Party Obligations: This CCAK knowledge point states that remediation controls for cloud vendor risk are explicitly designed to meet both internal policy and external contractual requirements, so changes to contractual requirements directly modify the set of controls needed for effective risk mitigation. 3. Risk Treatment vs. Control Requirements: Risk appetite and exception policies guide risk treatment decisions, including accept, mitigate, transfer, avoid, but do not change the technical, operational, or administrative controls required to effectively mitigate an identified risk if mitigation is selected as the treatment path. References: ISACA CCAK Exam Content Outline, Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) v4.0, https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4/
Certified in Cloud Auditing Knowledge · Q2
Question #2 A CSP contracts for a penetration test to be conducted on its infrastructures. The auditor engages the target with no prior knowledge of its defenses, assets, or channels. The CSP’s security operation center is not notified in advance of the scope of the audit and the test vectors. Which mode is selected by the CSP?
  • A.
    Double gray box
  • B.
    Tandem
  • C.
    Reversal
  • D.
    Double blind

Answer: D

The scenario presents two distinct blind conditions for the penetration test aligned with CCAK cloud audit and assurance requirements. First, the auditor (penetration tester) receives no prior knowledge of the CSP's defenses, assets, or infrastructure channels, operating from the same perspective as an external threat actor with no insider system information. Second, the CSP's security operations center (SOC) is not notified in advance of the test scope or test vectors, so the SOC cannot pre-adjust controls or prepare response processes for the test activity. This combination of tester-side lack of prior knowledge and internal security team lack of prior notification is explicitly defined as double blind penetration testing in CCAK supporting frameworks. This test mode delivers an unbiased assessment of both the CSP's technical preventive security controls and its operational detective and incident response capabilities, as it simulates a real-world unsolicited cyber attack as closely as possible, aligning with CCAK Domain 3 (Cloud Audit) requirements for independent control validation and Domain 4 (Cloud Assurance) requirements for demonstrating control effectiveness to stakeholders. Option Analysis: A. Double gray box: This option is incorrect. Gray box penetration testing refers to a model where the tester is provided partial, limited internal knowledge of the target environment to focus testing efforts efficiently. "Double gray box" is not a recognized standard penetration testing mode referenced in CCAK or supporting CSA/ISACA frameworks, and the scenario explicitly states the auditor has no prior knowledge of the environment, which rules out any gray box classification. B. Tandem: This option is incorrect. Tandem penetration testing, also called coordinated testing, is a model where both the penetration testing team and the internal CSP security team are notified in advance of the test, and may coordinate activities to avoid operational disruption or target specific control sets for testing. The scenario specifies the CSP's SOC is not notified in advance, which directly contradicts the definition of tandem testing. C. Reversal: This option is incorrect. Reversal is not a recognized formal penetration testing mode in cloud audit frameworks covered by the CCAK certification. It is a distractor term unrelated to the scenario described, as it does not reference any established methodology for testing CSP infrastructure or security operations. D. Double blind: This option is correct. Double blind penetration testing is formally defined as a test model where the penetration tester is provided no prior internal knowledge of the target environment (operating as a black box tester from an external threat actor perspective) and the internal CSP security operations team is not notified of the test in advance. This exactly matches the conditions outlined in the scenario, and this test mode is a recognized control validation method covered in CCAK audit and assurance domains. Key Concepts: 1. Penetration Testing Modes for Cloud Environments: This core CCAK knowledge area covers standardized penetration testing methodologies tailored to cloud infrastructure, including classification of test types by the level of prior knowledge provided to testers and advance notification provided to internal security teams, used to validate CSP control effectiveness for compliance and assurance purposes. 2. Double Blind Penetration Testing: A specific test mode designed to simulate realistic unsolicited cyber attacks, where neither the tester receives advance internal system information nor the internal security team receives advance notice of test activity, to deliver an unbiased assessment of both technical controls and incident response capabilities. 3. CSP Independent Audit Requirements: A core CCAK domain concept covering the requirement for CSPs to conduct regular independent security testing including varied penetration test modes to demonstrate compliance with cloud security frameworks, regulatory requirements, and customer contractual obligations. References: Cloud Security Alliance (CSA) Cloud Penetration Testing Guide, ISACA Certificate of Cloud Audit Knowledge (CCAK) Official Domains Overview
Certified in Cloud Auditing Knowledge · Q3
Question #3 Due to cloud audit team resource constraints, an audit plan as initially approved cannot be completed. Assuming that the situation is communicated in the cloud audit report, which course of action is MOST relevant?
  • A.
    Focusing on auditing high-risk areas
  • B.
    Testing the adequacy of cloud controls design
  • C.
    Relying on management testing of cloud controls
  • D.
    Testing the operational effectiveness of cloud controls

Answer: A

This question aligns with CCAK Domain 2: Cloud Audit Fundamentals, specifically the subdomain covering audit planning and resource allocation. When resource constraints prevent execution of the full approved audit plan, and the resulting scope limitation is properly disclosed in the audit report, the highest priority for auditors is to deliver maximum value by focusing on the areas that pose the greatest risk to the organization’s cloud environment. Risk-based auditing, a core CCAK principle, dictates that limited resources should be allocated to high-risk areas first, as control failures in these areas would have the most severe impact on the organization’s data security, compliance, operational continuity, and financial performance. This approach ensures that even with a reduced audit scope, stakeholders are informed of the most critical gaps and vulnerabilities that require immediate remediation. Option Analysis: A. Correct. Per CCAK’s risk-based auditing framework, when audit resources are constrained and scope limitations are properly disclosed in the audit report, prioritizing high-risk areas ensures that the audit addresses the most critical threats and vulnerabilities first, maximizing the value of the limited audit effort. This is a standard, widely accepted best practice for cloud audits facing resource constraints. B. Incorrect. Testing the adequacy of cloud control design is only one discrete component of a full cloud audit, and it is not prioritized specifically when resources are constrained unless those control design gaps are tied to high-risk areas. The scenario provides no indication that control design testing is a higher priority than other audit activities, so this is not the most relevant course of action. C. Incorrect. Relying solely on management testing of cloud controls violates core CCAK audit independence and objectivity principles. Auditors are required to perform sufficient independent testing to form valid audit conclusions, and unvalidated reliance on management testing is not an acceptable alternative when facing resource constraints, even if the limitation is disclosed. D. Incorrect. Testing the operational effectiveness of cloud controls is another discrete component of a full audit, but like control design testing, it is not inherently prioritized across all areas when resources are limited. Operational effectiveness testing is only prioritized for high-risk areas, so this option is overly broad and not the most relevant action for the given scenario. Key Concepts: 1. Risk-Based Cloud Auditing: A core CCAK principle that states audit activities should be prioritized based on the level of risk associated with the cloud service, process, or control area, to ensure limited audit resources are allocated to areas with the highest potential impact to the organization. 2. Audit Scope Limitation Disclosure: Per CCAK guidance, when an audit cannot be completed as originally planned due to constraints, the scope limitation must be explicitly documented in the audit report to ensure report users are aware of reduced coverage, allowing auditors to adjust the audit plan to focus on highest priority areas without misleading stakeholders. 3. Audit Independence: A foundational CCAK principle requiring auditors to maintain objectivity and perform sufficient independent evidence gathering, rather than relying unilaterally on management-provided assessments or testing results, to ensure audit conclusions are reliable and unbiased. References: 1. ISACA CCAK Official Certification Resources, 2. ISACA IT Audit and Assurance Standard 2201: Risk Assessment in Audit Planning
Certified in Cloud Auditing Knowledge · Q4
Question #4 In an organization, how are policy violations MOST likely to occur?
  • A.
    By accident
  • B.
    Deliberately by the ISP
  • C.
    Deliberately
  • D.
    Deliberately by the cloud provider

Answer: A

This question aligns with core CCAK (Certificate of Cloud Auditing Knowledge) domains 3 (Cloud Policy, Standards, Procedures and Guidelines) and 4 (Cloud Compliance and Audit), which cover identifying root causes of policy non-compliance in on-premises and cloud environments. The vast majority of organizational policy violations stem from accidental human error, including unintended cloud resource misconfigurations, overprovisioned access permissions, non-compliance caused by lack of policy awareness, and accidental data exposure. CCAK training materials reference industry-wide statistical data that confirms accidental violations occur at a far higher rate than deliberate violations by internal or third-party parties, making this the most likely cause as requested in the question. Option Analysis: A. Correct: CCAK core curriculum identifies accidental human error as the leading cause of policy violations. Accidental actions such as misconfigurations, unintended non-compliance due to insufficient policy training, and accidental access to restricted resources are statistically far more common than any other cause of policy violations for most organizations. B. Incorrect: Deliberate policy violations by an ISP are extremely rare, as ISPs are bound by contractual service level agreements and regulatory compliance obligations that prevent intentional violation of a customer organization's internal policies. This is not a material or common source of policy violations for standard organizational operations. C. Incorrect: Deliberate policy violations by insider threats or external malicious actors do occur, but they are statistically far less frequent than accidental violations. The question asks for the most likely cause, so this option does not fit the requirement for the highest-probability event. D. Incorrect: Cloud providers operate under strict shared responsibility model commitments and contractual compliance obligations to customers. Deliberate violations of a customer's internal policies by a cloud provider are exceptionally rare, and not a common source of policy violations for customer organizations. Key Concepts: 1. Policy Non-Compliance Root Cause: A core CCAK knowledge point is that human error, rather than malicious action, is the leading root cause of internal policy violations, particularly in cloud environments where unplanned misconfigurations are a top driver of compliance gaps. 2. Shared Responsibility Model Compliance: CCAK teaches that customer organizations retain responsibility for defining and enforcing their own internal policies, and most policy violations stem from internal customer-side actions rather than deliberate actions by third-party service providers like cloud providers or ISPs. 3. Policy Violation Likelihood Assessment: As part of the CCAK risk management domain, candidates learn that accidental policy violations are classified as higher-likelihood events than rare deliberate malicious events when conducting standard compliance risk assessments for most organizations. References: ISACA CCAK Exam Outline, Verizon 2024 Data Breach Investigations Report
Certified in Cloud Auditing Knowledge · Q5
Question #5 Which of the following is the BEST tool to perform cloud security control audits?
  • A.
    General Data Protection Regulation (GDPR)
  • B.
    ISO 27001
  • C.
    Federal Information Processing Standard (FIPS) 140-2
  • D.
    CSA Cloud Control Matrix (CCM)

Answer: D

The CCAK (Certificate of Cloud Auditing Knowledge) certification is jointly developed by ISACA and the Cloud Security Alliance (CSA) to validate expertise in cloud audit principles, practices, and cloud-specific frameworks. The question asks for the best tool for cloud security control audits. The correct answer is CSA Cloud Control Matrix (CCM) because it is the only option purpose-built exclusively for cloud environment security control assessment and audit use cases. The CCM provides a standardized, comprehensive set of cloud-specific security controls mapped to global regulatory requirements, industry standards, and cloud service/deployment models, enabling auditors to efficiently assess the full scope of cloud security controls while accounting for the cloud shared responsibility model, which is a core focus of CCAK domain knowledge. No other option is tailored specifically to cloud security control audits. Option Analysis: A. General Data Protection Regulation (GDPR): Incorrect. GDPR is a European Union regulatory mandate focused on personal data protection and privacy for EU data subjects, not an audit tool for general cloud security controls. It is a compliance requirement that auditors may validate adherence to, not a framework to perform full cloud security control audits. B. ISO 27001: Incorrect. ISO 27001 is a generic standard for information security management systems (ISMS) applicable to all organizations, regardless of industry or deployment environment. It does not include cloud-specific control guidance or address unique cloud considerations like the shared responsibility model or service model-specific control obligations, making it unsuitable as the primary tool for cloud security control audits. C. Federal Information Processing Standard (FIPS) 140-2: Incorrect. FIPS 140-2 is a narrow U.S. government standard that specifies security requirements for cryptographic modules used to protect sensitive data. It only covers encryption module validation, not the full scope of cloud security controls such as access management, governance, incident response, and other core cloud security domains, so it is far too limited to serve as the primary tool for cloud security control audits. D. CSA Cloud Control Matrix (CCM): Correct. The CSA CCM is a core CCAK knowledge domain resource, designed specifically for cloud security assessment and audit. It includes 17 cloud security control domains, with controls mapped to IaaS, PaaS, and SaaS service models, and explicitly identifies which controls are the responsibility of the cloud service provider vs. the cloud customer. It aligns with all major global regulations and security standards, making it the most effective tool for conducting comprehensive cloud security control audits. Key Concepts: 1. Cloud Control Matrix (CCM): A core CCAK domain concept, the CCM is CSA's cloud-specific control framework that provides standardized, auditable cloud security controls aligned with regulatory requirements and cloud service characteristics to simplify cloud security audit and assessment activities. 2. Shared Responsibility Model: A foundational CCAK concept that defines which security controls are managed by the cloud service provider and which are managed by the cloud customer, based on the cloud service model. The CSA CCM explicitly maps control ownership to relevant parties, making it ideal for cloud audits. 3. Cloud-Specific Audit Frameworks: CCAK emphasizes that generic on-premises security standards are not sufficient for cloud audits, as cloud environments have unique risks including multi-tenancy, on-demand resource provisioning, and third-party managed infrastructure that require cloud-native audit tools like the CCM. References: Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) Official Page, https://cloudsecurityalliance.org/research/cloud-controls-matrix/ ISACA Certificate of Cloud Auditing Knowledge (CCAK) Official Page, https://www.isaca.org/credentialing/ccak

FAQ

How many practice questions are available for Certified in Cloud Auditing Knowledge?

This question bank includes 335 Certified in Cloud Auditing Knowledge practice questions covering single and multiple choice, each with answers and explanations.

Are Certified in Cloud Auditing Knowledge practice questions available in Chinese and English?

Yes, Certified in Cloud Auditing Knowledge practice questions are provided in both Chinese and English.

Can I try Certified in Cloud Auditing Knowledge practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.