CCSP Cloud Concepts, Architecture, and Design Practice Question
A cloud security manager is designing an exit strategy for a critical SaaS application. The provider's contract permits data export only through a proprietary API that returns records in a non-standard binary format. The manager must reduce the risk of being unable to move data to another provider. Which action BEST addresses this risk?
⚠ Common exam trap
The trap here is treating a nightly backup through the same proprietary API as a portability control, when it only replicates the lock-in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Negotiate a contractual right to receive data in a documented, non-proprietary format at any time
The core risk is that data can only be extracted in a proprietary binary format, which prevents migration to another provider. The strongest mitigation is a contractual right to receive the data in a documented, non-proprietary format on demand. Authentication hardening, backups through the same API, and API documentation do not remove the format dependency, so they cannot resolve the portability problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable multi-factor authentication for all administrative accounts on the SaaS platform
Why it's wrong here
Multi-factor authentication strengthens access security but does nothing to change the proprietary export format or guarantee data portability. It addresses unauthorized access risk, not the lock-in risk created by the binary API, so it leaves the exit problem entirely unresolved even though it is a worthwhile security control.
- ✓
Negotiate a contractual right to receive data in a documented, non-proprietary format at any time
Why this is correct
Contractual guarantees of portable, documented, non-proprietary export formats directly mitigate lock-in by ensuring data can be consumed by another provider's tools. Because the technical export path is proprietary, only a negotiated right to standard formats removes the dependency, making this the most effective control for the stated risk.
- ✗
Require the provider to publish its API documentation to the customer's security team
Why it's wrong here
Documentation may aid integration and review, but it does not change the binary format or grant rights to obtain standard exports. The data would still be locked into a proprietary representation, so this action fails to reduce the exit risk and merely improves visibility into an inherently non-portable interface.
- ✗
Replicate the SaaS data nightly to an on-premises backup appliance using the same API
Why it's wrong here
Backing up through the proprietary API produces copies in the same non-standard binary format, so the data remains dependent on the provider's tools to interpret. This improves availability and recovery but does not create portability, because restoring elsewhere would still require decoding the proprietary format.
Visual reference
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.