ISC2 Certified Cloud Security Professional (CCSP) Practice Question

While planning an internal audit of a PaaS provider, you must verify that the supplier's written policies clearly define who is responsible for generating, rotating, and revoking customers' database-encryption keys. Which layer of the provider's security documentation is most likely to contain the level of operational detail and role assignment you need to review first?

  • Corporate governance charter

  • Organizational (program-level) security policy

  • Issue-specific (functional) security policy on cryptographic controls

  • System hardening guideline for the database platform

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot