ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your enterprise is finalizing a long-term IaaS contract with a cloud provider. Due-diligence shows the provider purchases server hardware through multiple international distributors before equipment reaches its data centers. Executives worry that counterfeit or maliciously altered components could be substituted during transit, undermining data confidentiality once workloads are migrated. To follow ISO/IEC 27036-3 guidance for ICT supply-chain security, which contractual requirement would BEST address this specific risk?
Mandate that the provider use tamper-evident packaging and maintain verifiable chain-of-custody documentation for all hardware shipments.
Require the provider to undergo an annual SOC 1 Type II audit focused on internal financial reporting controls.
Oblige the provider to encrypt all tenant data at rest with AES-256 and rotate encryption keys every 90 days.
Include a service-level agreement guaranteeing 99.99 percent availability for all compute instances.
ISO/IEC 27036-3 focuses on protecting the information and communications technology (ICT) supply chain. Among its recommended controls are measures that preserve the authenticity and integrity of hardware as it moves from the original manufacturer to the final operating environment. Requiring tamper-evident packaging and documented chain-of-custody records directly mitigates the threat of counterfeit or modified devices being introduced in transit. The other options address important but different concerns: financial control audits (SOC 1) relate to reporting accuracy, availability SLAs cover service performance, and data-at-rest encryption protects stored information-none of which specifically reduce the risk of hardware substitution within the supply chain.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ISO/IEC 27036-3 guidance for ICT supply-chain security?
Open an interactive chat with Bash
What does tamper-evident packaging mean in this context?
Open an interactive chat with Bash
What is the chain-of-custody documentation and why is it important?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .