ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your organization maintains an ISO/IEC 27001-certified ISMS. After migrating a critical payment application to an IaaS provider, the internal audit team needs evidence that controls at the provider's facility are operating effectively. Which approach best satisfies the ISMS's requirement for objective evidence without breaching the provider's shared-responsibility boundaries?

  • Rely on the provider's publicly posted ISO/IEC 27001 certificate as complete proof of control operation.

  • Require the provider to forward raw hypervisor audit logs to the company's SIEM every day.

  • Request and review the provider's most recent SOC 2 Type II report covering the physical and virtualization controls.

  • Conduct quarterly on-site penetration tests inside the provider's data center.

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot