ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization is considering a cloud service provider that claims its hardware security modules (HSMs) have been certified at "Level 3" to satisfy U.S. government requirements for protecting encryption keys at rest. To confirm that the provider's HSMs meet the appropriate system/sub-system product certification, which document or designation should you request from the provider?

  • A recent SOC 2 Type II report for the provider's overall cloud platform.

  • A Common Criteria certificate showing Evaluation Assurance Level 4+ for the HSM firmware.

  • The module's FIPS 140-2 Level 3 validation certificate and CMVP validation report.

  • An ISO/IEC 27018 conformity statement covering protection of personally identifiable information.

ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot