Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer is negotiating a contract and wants to ensure they have the right to verify the cloud provider's security controls. Which contractual provision is most important?

⚠ Common exam trap

The trap is confusing the right to audit with other contractual clauses like SLAs or data portability; candidates may pick SLA because it sounds like it ensures performance, but it does not cover security verification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Right to audit clause

The right to audit clause is a contractual provision that grants the cloud customer the ability to verify the provider's security controls, either through direct audits or by accepting third-party audit reports. It is essential for ensuring compliance and trust in the cloud provider's security posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data portability clause

    Why it's wrong here

    Data portability governs exporting and migrating data between providers on termination; it grants no audit or verification rights over controls. It is tempting because it appears in most cloud contracts and supports exit planning, but the right to assess security controls comes from an audit or assessment clause.

  • ✗

    Data deletion clause

    Why it's wrong here

    A data deletion clause governs secure disposal and return of data at contract termination, not the customer's right to inspect or verify security controls during the subscription. It is tempting because deletion is a common cloud governance concern, but it addresses data lifecycle, not assurance or audit access.

  • ✓

    Right to audit clause

    Why this is correct

    A right to audit clause contractually grants the customer the ability to verify the provider's security controls, whether directly or via an independent assessor. This directly satisfies the stated requirement to secure verification rights during contract negotiation.

  • ✗

    Service Level Agreement (SLA) for uptime

    Why it's wrong here

    An uptime SLA guarantees availability percentages and service credits, not audit or verification rights over security controls. It is tempting because SLAs are the headline contractual artefact in cloud negotiations, and availability is measurable, but the scenario demands a right-to-audit or assessment provision.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.