Courseiva
Legal, Risk, and Compliance →mediumMultiple Select

CCSP Legal, Risk, and Compliance Practice Question

A cloud service provider wants to demonstrate compliance with ISO/IEC 27017 for cloud services. Which TWO controls are specific additions that this standard introduces beyond ISO/IEC 27002? (Choose two.)

⚠ Common exam trap

The trap here is assuming ISO/IEC 27017 mandates specific technologies or certifications, when it actually adds cloud-specific guidance and controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Guidance on shared roles and responsibilities between cloud service customers and cloud service providers.

ISO/IEC 27017 extends ISO/IEC 27002 with cloud-specific implementation guidance, notably clarifying shared roles and responsibilities between customers and providers, and addressing the return or removal of customer assets at service termination. These additions target the unique risks of cloud arrangements rather than imposing technology mandates or certification requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A mandate that all cloud personnel hold a Certified Cloud Security Professional (CCSP) certification.

    Why it's wrong here

    No ISO/IEC standard requires personnel to hold the CCSP or any specific certification. ISO/IEC 27017 focuses on cloud-specific controls and implementation guidance. Competence requirements are general and risk-based, so mandating a particular credential is not part of this standard.

  • ✗

    A requirement to publish real-time security incident dashboards to all customers.

    Why it's wrong here

    ISO/IEC 27017 does not require public real-time dashboards. It addresses cloud-specific controls such as shared responsibilities and asset handling, and incident management remains aligned with ISO/IEC 27002's risk-based approach. Real-time public dashboards are a commercial transparency feature, not a standard requirement.

  • ✓

    Guidance on shared roles and responsibilities between cloud service customers and cloud service providers.

    Why this is correct

    ISO/IEC 27017 explicitly addresses the division of security responsibilities between cloud service customers and providers. This guidance clarifies who handles which controls in the shared responsibility model, reducing ambiguity. It is one of the cloud-specific additions not found in the base ISO/IEC 27002 control set.

  • ✓

    Requirements for the removal or return of cloud service customer assets upon contract termination.

    Why this is correct

    ISO/IEC 27017 adds cloud-specific guidance on the return, transfer, or disposal of customer assets when a service ends. This extends asset management and supplier relationship controls to address exit scenarios, which the generic ISO/IEC 27002 control set does not cover in cloud terms.

  • ✗

    Mandatory encryption of all data at rest using AES-256 or an equivalent algorithm.

    Why it's wrong here

    ISO/IEC 27017 does not mandate a specific encryption algorithm or key length. It provides cloud-specific implementation guidance and additional controls, while cryptographic choices remain risk-based decisions. Prescribing AES-256 as a mandatory requirement mischaracterizes the standard's prescriptive scope.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.