Courseiva
Legal, Risk, and Compliance →mediumMultiple Select

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer is assessing a provider's compliance with the Cloud Security Alliance (CSA) STAR program. Which TWO artifacts are part of the STAR program? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any security certification or report is part of the STAR program, when STAR specifically offers the CCM and CAIQ as its own tools.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Controls Matrix (CCM)

The CSA STAR program includes the Cloud Controls Matrix (CCM) as the control framework and the Consensus Assessments Initiative Questionnaire (CAIQ) as the assessment tool. These artifacts enable cloud providers to document their security controls and customers to evaluate them. Other reports like SOC 2 or ISO certifications are separate and not unique to STAR, though they may be used in conjunction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ISO/IEC 27017 certificate

    Why it's wrong here

    ISO/IEC 27017 is a security standard for cloud services, but it is not an artifact of the CSA STAR program. While STAR may recognize ISO certifications as part of its continuous monitoring, the certificate itself is not a STAR artifact. Therefore, it is not one of the two correct choices.

  • ✓

    Cloud Controls Matrix (CCM)

    Why this is correct

    The CCM is a cybersecurity control framework specifically for cloud computing, developed by the CSA. It is a foundational component of the STAR program, providing the controls against which providers are assessed. The CCM helps customers understand necessary controls and is integral to STAR.

  • ✗

    GDPR compliance statement

    Why it's wrong here

    A GDPR compliance statement is a legal declaration, not a CSA STAR artifact. The STAR program focuses on security assessments and controls, not privacy regulation compliance. Therefore, it is not part of the STAR program's core components.

  • ✗

    SOC 2 Type II report

    Why it's wrong here

    A SOC 2 Type II report is an independent audit report, but it is not a specific artifact of the CSA STAR program. While it can be used as evidence, STAR has its own assessment mechanisms. Thus, it is not a distinct part of the STAR program's offerings.

  • ✓

    Consensus Assessments Initiative Questionnaire (CAIQ)

    Why this is correct

    The CAIQ is a standardized questionnaire developed by the CSA that cloud providers complete to document their security controls. It is a key component of the STAR program, allowing customers to assess a provider's security posture. The CAIQ covers domains from the Cloud Controls Matrix, making it a fundamental artifact for transparency.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.