Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer wants to ensure they can audit their cloud provider's security controls annually. Which contractual provision should be included in the cloud service agreement?

⚠ Common exam trap

CCSP often tests whether candidates confuse the right to audit with SLAs, data deletion, or portability clauses — the key is recognizing that only the right to audit grants control verification access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Right to audit clause

A right to audit clause contractually grants the cloud customer the ability to audit the provider's security controls, either directly or through third-party assessments, on a defined schedule. This is the specific provision that ensures annual audit capability, so D is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service level agreement (SLA) with uptime guarantees

    Why it's wrong here

    An SLA guarantees availability percentages and credits, not the customer's right to examine controls. It is tempting because SLAs are the standard contractual vehicle for measurable provider commitments, and would be correct if the requirement were uptime or performance targets rather than audit rights.

  • ✗

    Data deletion clause

    Why it's wrong here

    A data deletion clause specifies certified destruction of data at contract termination, not ongoing audit access. It is tempting because it enforces provider accountability over data lifecycle, and would be correct if the requirement were ensuring data is irrecoverably erased when the service ends.

  • ✗

    Data portability clause

    Why it's wrong here

    A data portability clause governs exporting data in a usable format on exit, granting no inspection of controls. It is tempting because it addresses lock-in and provider accountability, and would be correct if the customer needed to migrate data between providers without reformatting.

  • ✓

    Right to audit clause

    Why this is correct

    A right to audit clause grants the customer contractual permission to assess the provider's security controls, typically annually, either directly or via an independent third party. Without it, the customer has no enforceable means to verify controls beyond provider-supplied reports.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.