Courseiva
Legal, Risk, and CompliancehardMultiple ChoiceObjective-mapped

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer needs to comply with PCI DSS for a cardholder data environment (CDE) hosted on an IaaS platform. According to PCI DSS Appendix A3, which document is critical to define the security responsibilities between the customer and the cloud provider?

⚠ Common exam trap

ISC2 often tests the distinction between compliance-specific documents (like the Responsibility Matrix for PCI DSS) and general operational or regulatory documents (like SOC 2, BAA, or DPA), leading candidates to confuse a broad audit report or a different regulation's agreement with the precise shared responsibility definition required by PCI DSS Appendix A3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cloud Provider Responsibility Matrix

PCI DSS Appendix A3 requires cloud customers and providers to clearly define and document their respective security responsibilities for the cardholder data environment (CDE). The Cloud Provider Responsibility Matrix (often called a Shared Responsibility Matrix) is the critical document that delineates which party is responsible for each security control, such as firewall management, patch management, and access controls, ensuring compliance with PCI DSS requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Provider Responsibility Matrix

    Why this is correct

    This matrix is specifically mandated by PCI DSS for cloud environments.

  • Service Organization Control (SOC) 2 report

    Why it's wrong here

    SOC 2 is a voluntary audit report, not a requirement of PCI DSS.

  • Business Associate Agreement (BAA)

    Why it's wrong here

    BAA is for HIPAA compliance.

  • Data Processing Agreement (DPA)

    Why it's wrong here

    DPA is for GDPR, not PCI DSS.

About these practice questions

This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.