CCSP Legal, Risk, and Compliance Practice Question
A cloud customer is subject to the Payment Card Industry Data Security Standard (PCI DSS) and uses a cloud provider to store cardholder data. The customer wants to reduce its PCI DSS scope. Which of the following provider attestations would best support scope reduction for the customer?
⚠ Common exam trap
The trap here is assuming that any security certification, such as ISO 27001 or SOC 2, is enough for PCI DSS scope reduction, when PCI DSS specifically requires its own attestation and report.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A PCI DSS Attestation of Compliance (AOC) and Report on Compliance (ROC) for the relevant services
To reduce PCI DSS scope, the customer needs evidence that the provider's environment meets PCI DSS requirements for the services used. A PCI DSS Attestation of Compliance and Report on Compliance provide that assurance. SOC 2 Type I, ISO 27001, and self-assessments do not specifically demonstrate PCI DSS compliance and are not sufficient for scope reduction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A self-assessment questionnaire completed by the cloud provider
Why it's wrong here
A self-assessment questionnaire (SAQ) is typically used by merchants and service providers to self-evaluate, but for a cloud provider to support a customer's scope reduction, an independent assessment is preferred. A self-assessment lacks the rigor of a QSA-led ROC. For scope reduction, the customer needs assurance that the provider's controls are independently validated, so a self-assessment is insufficient.
- ✓
A PCI DSS Attestation of Compliance (AOC) and Report on Compliance (ROC) for the relevant services
Why this is correct
The PCI DSS Attestation of Compliance and Report on Compliance are the formal documents that demonstrate a provider's compliance with PCI DSS. When a provider is a PCI DSS validated service provider, the customer can leverage that validation to reduce its own scope, provided the services used are within the provider's assessment. This is the most direct and recognized evidence for PCI DSS scope reduction.
- ✗
A SOC 2 Type I report covering security
Why it's wrong here
A SOC 2 Type I report covers the suitability of controls at a point in time, not their operating effectiveness over a period. PCI DSS requires evidence of sustained compliance. While SOC 2 can be useful, a Type I report is insufficient to support scope reduction because it does not demonstrate that controls operated effectively throughout the review period.
- ✗
An ISO/IEC 27001 certificate covering the provider's data centers
Why it's wrong here
ISO/IEC 27001 is a general information security management standard, not a PCI DSS-specific validation. While it indicates a mature security program, it does not address PCI DSS requirements such as network segmentation, encryption of cardholder data, or vulnerability management in the specific manner required. It cannot by itself support PCI DSS scope reduction for the customer.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.