ISC2 CISSP Practice Question

Following a merger, a financial services company is consolidating its technology vendors and must assess three different cloud service providers (CSPs) that currently handle sensitive payment card information. The CISO has been tasked with obtaining assurance that each provider's security controls are designed and operating effectively to meet PCI DSS requirements. Given that the company has no direct administrative access to the CSPs' underlying infrastructure, which assessment strategy would be MOST effective for this purpose?

  • Third-party certification review

  • Penetration testing campaign

  • Security architecture review

  • Internal compliance audit

ISC2 CISSP
Security Assessment and Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot