ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization is migrating a regulated workload from its own data center, where auditors regularly log on to servers and perform physical inspections, to a multitenant public IaaS platform. While preparing the first cloud-based internal audit plan, which additional action is most critical to ensure you can still gather adequate evidence of the provider's operating security controls without violating common cloud-provider restrictions on direct testing and physical access?

  • Schedule authenticated vulnerability and penetration tests against the provider's management plane without prior notification to validate its security posture.

  • Request the provider's most recent SOC 2 Type II report and map its control statements to your audit objectives.

  • Negotiate temporary root access to the underlying physical hosts during the audit window to confirm baseline configurations.

  • Arrange a site visit to the provider's data center so auditors can visually inspect the hypervisor hardware hosting your virtual machines.

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot