CCSP Legal, Risk, and Compliance Practice Question
A cloud customer needs to comply with PCI DSS for a cardholder data environment (CDE) hosted on an IaaS platform. According to PCI DSS Appendix A3, which document is critical to define the security responsibilities between the customer and the cloud provider?
⚠ Common exam trap
ISC2 often tests the distinction between compliance-specific documents (like the Responsibility Matrix for PCI DSS) and general operational or regulatory documents (like SOC 2, BAA, or DPA), leading candidates to confuse a broad audit report or a different regulation's agreement with the precise shared responsibility definition required by PCI DSS Appendix A3.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Provider Responsibility Matrix
PCI DSS Appendix A3 requires cloud customers and providers to clearly define and document their respective security responsibilities for the cardholder data environment (CDE). The Cloud Provider Responsibility Matrix (often called a Shared Responsibility Matrix) is the critical document that delineates which party is responsible for each security control, such as firewall management, patch management, and access controls, ensuring compliance with PCI DSS requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud Provider Responsibility Matrix
Why this is correct
This matrix is specifically mandated by PCI DSS for cloud environments.
- ✗
Service Organization Control (SOC) 2 report
Why it's wrong here
SOC 2 is a voluntary audit report, not a requirement of PCI DSS.
- ✗
Business Associate Agreement (BAA)
Why it's wrong here
BAA is for HIPAA compliance.
- ✗
Data Processing Agreement (DPA)
Why it's wrong here
DPA is for GDPR, not PCI DSS.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.