ISC2 Certified Cloud Security Professional (CCSP) Practice Question

During due-diligence for moving a public key infrastructure (PKI) workload to a public cloud, your compliance team states that all modules containing root CA private keys must be validated to at least FIPS 140-2 Level 3. The cloud provider claims its multitenant hardware security modules (HSMs) satisfy this requirement. To confirm the claim with minimal additional testing effort, which single piece of evidence should you request from the provider?

  • A recent SOC 2 Type II report that includes the Trust Services Criteria for Security and Confidentiality

  • A Common Criteria Evaluation Assurance Level 4+ certificate for the HSM hardware

  • The cloud provider's ISO/IEC 27001:2013 certification scope statement covering its key management service

  • A CMVP validation certificate listing the HSM hardware and firmware as FIPS 140-2 Level 3 compliant

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot