CCSP Legal, Risk, and Compliance Practice Question
A cloud customer is building its compliance monitoring program for a provider-hosted workload that processes regulated data. The customer must ensure it can demonstrate ongoing compliance to regulators between audits. Which TWO provider commitments should the customer secure in the contract to sustain continuous compliance evidence? (Choose two.)
⚠ Common exam trap
The trap here is assuming that continuous compliance requires intrusive continuous access, such as on-site auditors or raw vulnerability data, when the workable contractual levers are change notification and periodic refreshed attestation evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A right to obtain current independent audit reports, bridge letters, and certification evidence at least annually and after significant changes.
Sustaining compliance between audits requires current evidence and early awareness of change. Contractual rights to timely notification of material changes and to updated audit reports, bridge letters, and certification evidence let the customer refresh its compliance file, reassess risk, and respond to regulator requests without waiting for the next scheduled audit cycle or renegotiating access each year.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A right to obtain current independent audit reports, bridge letters, and certification evidence at least annually and after significant changes.
Why this is correct
Regulators expect current evidence, and audit reports are point-in-time. Contractual access to updated SOC 2 reports, bridge letters covering gaps, and renewed certifications ensures the customer can refresh its compliance file without renegotiating each time. This right also supports due diligence when the provider changes its architecture or service scope.
- ✗
A right to receive the provider's internal penetration test raw findings and unfiltered vulnerability backlog for continuous review.
Why it's wrong here
Raw penetration test findings and vulnerability backlogs are highly sensitive and could expose other tenants or the provider's infrastructure if shared. Providers typically release summary letters or attestations instead. Requesting raw data is unlikely to be granted and does not scale as a continuous compliance mechanism; summarized assurance plus notification rights is the workable approach.
- ✗
A right to require the provider to adopt the customer's internal control framework verbatim across all its tenants.
Why it's wrong here
A public cloud provider cannot tailor its control framework to one tenant's internal standard without affecting all tenants and its own economies of scale. The customer's obligation is to map the provider's attested controls to its own framework and address gaps with complementary controls. Demanding verbatim adoption is both impractical and outside the provider's service model.
- ✗
A right to embed the customer's own auditors full-time inside the provider's data centers to observe live operations.
Why it's wrong here
Few providers grant continuous on-site auditor presence because it conflicts with tenant isolation and other customers' confidentiality. This demand is commercially unrealistic and, if pursued, may push the provider to decline the workload entirely. Independent reports, certifications, and notification rights achieve the same assurance objective without continuous physical access.
- ✓
A right to receive timely notification of material changes to the provider's control environment, sub-processors, and security certifications.
Why this is correct
Continuous compliance depends on knowing when the provider's controls, sub-processors, or certifications change. A contractual notification right lets the customer reassess risk and update its own records between audits. Without it, the customer may rely on stale evidence and discover a material change only during a regulator inquiry or the next annual review.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.