ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your company processes payment card data and plans to deploy web servers on a public IaaS platform. Before signing the contract, the security team must confirm that the cloud provider has already been independently validated against PCI DSS requirements that apply to service providers. Which single piece of documentation would give the most reliable evidence of that validation?
A CSA STAR Level 1 self-assessment questionnaire (CAIQ) published by the provider
An ISO/IEC 27017:2015 certificate from an accredited registrar
A PCI DSS Attestation of Compliance (AOC) for Service Providers issued by a Qualified Security Assessor
A SOC 1 Type II report covering the provider's cloud platform
A PCI DSS Attestation of Compliance (AOC) for Service Providers that has been signed by a Qualified Security Assessor is produced only after the provider has undergone a full PCI DSS assessment and met all applicable controls. It therefore gives direct, third-party evidence that the provider is already PCI-compliant for its portion of the shared responsibility model. A CSA STAR Level 1 report is a self-assessment, not an external validation. ISO/IEC 27017 certification focuses on general cloud security controls, not the specific PCI DSS requirements for cardholder data. A SOC 1 Type II report addresses financial reporting controls and does not attest to PCI DSS compliance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is PCI DSS Attestation of Compliance (AOC)?
Open an interactive chat with Bash
Why does PCI DSS specifically require third-party validation?
Open an interactive chat with Bash
How does PCI DSS differ from other certifications like ISO/IEC 27017 or SOC reports?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .