CCSP Legal, Risk, and Compliance Practice Question
A cloud customer is subject to a regulatory audit and must provide evidence of the cloud provider's security controls. The provider refuses to allow direct audits of its data centers. Which artifact should the customer rely on to satisfy the auditors?
⚠ Common exam trap
Many exam-takers confuse an ISO/IEC 27001 certificate, which certifies the management system, with a SOC 2 Type II report, which attests to the effectiveness of specific controls over time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SOC 2 Type II report
A SOC 2 Type II report is specifically designed to provide independent assurance over a period, covering the Trust Services Criteria. It is widely accepted by auditors as evidence of a cloud provider's security controls when direct audits are not feasible. Other artifacts like ISO 27001 certificates or self-assessments do not offer the same level of detailed, independent validation of control operation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Provider's self-assessment questionnaire
Why it's wrong here
A self-assessment questionnaire is completed by the provider and lacks independent verification. Auditors require objective evidence from a third party. Self-assessments are not considered reliable for regulatory compliance because they can be biased and do not demonstrate control effectiveness over time.
- ✗
Penetration test summary
Why it's wrong here
A penetration test summary shows the results of a point-in-time test but does not provide ongoing assurance of control effectiveness. Auditors require evidence of sustained control operation, not just a snapshot. Additionally, penetration tests are often not comprehensive and may not cover all relevant controls, so they are insufficient for regulatory audit purposes.
- ✗
ISO/IEC 27001 certificate
Why it's wrong here
An ISO/IEC 27001 certificate demonstrates that the provider has implemented an information security management system, but it does not provide detailed evidence of specific control effectiveness. Auditors may accept it as a baseline, but it lacks the granularity of a SOC 2 Type II report. Thus, it is less suitable for satisfying a detailed regulatory audit.
- ✓
SOC 2 Type II report
Why this is correct
A SOC 2 Type II report provides independent attestation of a service organization's controls over security, availability, processing integrity, confidentiality, and privacy over a period. It is designed for cloud providers to share with customers to demonstrate effective controls without granting direct audit rights. Auditors typically accept SOC 2 Type II as sufficient evidence, making it the appropriate artifact in this scenario.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.