ISC2 Certified Cloud Security Professional (CCSP) Practice Question

During due diligence for a new SaaS contract, a security engineer is asked to recommend language that will reduce the risk of vendor-lock-in if the company later decides to change providers. Which of the following clauses BEST addresses the functional requirement for portability and interoperability?

  • The provider must submit to annual ISO/IEC 27001 certification audits at its own expense.

  • The provider reserves the right to change APIs and data models with 60 days' notice.

  • The provider shall deliver all customer data, schemas, and metadata within 30 days of termination in a documented, industry-standard, machine-readable format via secure transfer.

  • The provider guarantees 99.9% service availability measured monthly, with service credits for violations.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot