ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A multinational retailer is moving its customer-loyalty application to a SaaS CRM platform that is hosted in several geographic regions. The provider is ISO 27001 certified, publishes a quarterly SOC 2 Type II report, and offers EU Standard Contractual Clauses for GDPR compliance. According to the shared-responsibility model, which action would most directly reduce residual risk that remains with the retailer (the data controller) but is not mitigated by the SaaS provider?

  • Subscribe to a continuous-monitoring service that scans the provider's public IP addresses

  • Enable multi-factor authentication for all employees who log in to the SaaS CRM portal

  • Purchase cyber-risk insurance that specifically covers a breach at the SaaS provider

  • Demand that the provider extend its certification scope to include ISO 27701 privacy controls

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot