CCSP Legal, Risk, and Compliance Practice Question
A cloud customer is reviewing its incident response plan and wants to ensure it can meet regulatory breach notification timelines. The customer's data is hosted by a cloud provider that does not automatically notify customers of security incidents. Which action should the customer take FIRST to address this gap?
⚠ Common exam trap
The trap here is assuming that public status pages, monitoring tools, or insurance can substitute for a contractual notification requirement from the provider.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include a contractual clause requiring the provider to notify the customer of security incidents within a specified timeframe.
The customer cannot meet regulatory breach notification deadlines if it learns about a provider-side incident too late. A contractual notification clause with a defined timeframe creates an enforceable obligation and ensures the customer receives timely information to begin its own incident assessment and notification process. This is the foundational step before technical monitoring or insurance can be effective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Include a contractual clause requiring the provider to notify the customer of security incidents within a specified timeframe.
Why this is correct
Regulatory breach notification timelines often start when the customer becomes aware of an incident. A contract clause that obligates the provider to notify the customer within a defined period ensures the customer receives timely information and can start its own assessment and notification process. This directly closes the gap.
- ✗
Purchase cyber insurance to cover the costs of a breach notification and any regulatory fines.
Why it's wrong here
Cyber insurance can transfer some financial risk, but it does not create the notification channel or contractual obligation needed to learn about a provider-side incident. Without timely notice from the provider, the customer cannot meet regulatory timelines, and insurance does not solve that operational gap.
- ✗
Deploy a third-party vulnerability scanner to continuously monitor the provider's infrastructure for signs of compromise.
Why it's wrong here
Customers typically do not have the authorization or technical access to scan the provider's underlying infrastructure, and doing so could violate the terms of service. A scanner also would not provide the contractual assurance of notification that the customer needs to meet regulatory timelines.
- ✗
Rely on the provider's public status dashboard and security blog to learn about incidents affecting the customer's data.
Why it's wrong here
Public dashboards and blogs are designed for general service availability and may not disclose customer-specific incidents or the details needed for a regulatory notification. They are not a reliable or timely notification mechanism and do not create an enforceable obligation on the provider.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.