CCSP Legal, Risk, and Compliance Practice Question
A cloud customer's legal team must decide which party bears responsibility for generating audit evidence that demonstrates regulatory compliance. The customer uses IaaS from a provider. According to the CSA Cloud Controls Matrix and shared responsibility principles, how should audit evidence obligations be divided?
⚠ Common exam trap
The trap here is assuming that the cloud provider is responsible for all audit evidence because it owns the infrastructure, when in fact the customer must evidence the controls it operates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer must obtain evidence for controls it operates, while the provider supplies evidence for controls it operates, with each party relying on the other's attestations where appropriate.
In a shared responsibility model, audit evidence must map to who operates each control. For IaaS, the provider evidences the physical, network, and hypervisor layers, while the customer evidences the guest OS, applications, and data. Contractual audit rights and provider attestations like SOC 2 reports bridge the gap, allowing each party to rely on the other's evidence for controls outside its own scope.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The cloud provider is solely responsible for producing all audit evidence because it operates the physical infrastructure and hypervisor.
Why it's wrong here
This is incorrect because, in IaaS, control of the guest operating system, applications, and data belongs to the customer. The provider can only supply evidence for controls it operates, such as physical security and hypervisor hardening. Claiming sole provider responsibility ignores the customer's own controls and would leave critical compliance evidence, like access logs and configuration baselines, uncollected.
- ✗
A third-party auditor engaged by the customer must independently verify every control across both the provider and customer environments, regardless of who operates them.
Why it's wrong here
While third-party audits occur, universal independent verification of every control is not the standard division of responsibility. It would be impractical and costly, and it contradicts the shared responsibility model where each party attests to its own scope. The customer typically relies on the provider's independent audit reports for provider-controlled layers rather than re-auditing them.
- ✓
The customer must obtain evidence for controls it operates, while the provider supplies evidence for controls it operates, with each party relying on the other's attestations where appropriate.
Why this is correct
Under the shared responsibility model, each party is accountable for the controls it implements. In IaaS, the provider evidences physical, network, and hypervisor controls, often through SOC 2 or ISO/IEC 27001 reports; the customer evidences guest OS, application, and data controls. This division is the basis for CSA CCM and contractual audit rights, ensuring complete coverage without duplicating effort.
- ✗
The provider is responsible only for evidence related to its own internal corporate compliance, not for any controls that support customer workloads.
Why it's wrong here
This misstates the provider's role. Cloud providers routinely supply compliance reports covering the infrastructure and services used by customers, such as SOC 2 Type II reports that include the cloud service system. Limiting provider evidence to internal corporate compliance would leave customers unable to demonstrate that the underlying platform meets their regulatory requirements.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.