ISC2 Certified Cloud Security Professional (CCSP) Practice Question

During a compliance audit of your organization's public IaaS environment, the auditor asks for evidence that the underlying hypervisor is patched and configured according to a recognized benchmark. The cloud provider refuses to share the hypervisor configuration files or screenshots of the management console, citing multi-tenant security and proprietary information. Which specific assurance challenge of virtualization does this situation illustrate, and therefore should be addressed in future contractual language or right-to-audit clauses?

  • Inability to run vulnerability scans inside guest operating systems

  • Absence of perimeter firewalls between tenant virtual networks

  • Lack of encryption for data at rest on virtual machine disks

  • Limited transparency into provider-controlled hypervisor and virtualization management layers

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot