CCSP Legal, Risk, and Compliance Practice Question
A company is negotiating a cloud service agreement and wants to ensure it can verify the provider's security controls independently. Which contractual clause is essential for this purpose?
⚠ Common exam trap
CCSP often tests the distinction between contractual clauses, and candidates may confuse the right to audit with SLAs or data deletion, overlooking that only the right to audit enables independent verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right to audit clause
A right to audit clause is essential because it contractually grants the customer the ability to independently verify the provider's security controls, either through direct audits or by accepting third-party audit reports. This clause ensures transparency and accountability, which is critical for compliance and risk management in cloud services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data deletion clause
Why it's wrong here
A data deletion clause governs secure erasure of data at contract termination, not independent verification of provider controls. It is tempting because deletion is a common assurance concern, yet the clause that grants audit or assessment rights is what enables verification.
- ✓
Right to audit clause
Why this is correct
A right to audit clause contractually grants the customer the ability to independently verify the provider's security controls, through assessments or evidence review. Without it, assurance rests solely on provider assertions, so it directly satisfies the requirement for independent verification.
- ✗
Service Level Agreement (SLA) on uptime
Why it's wrong here
An uptime SLA defines availability commitments and remedies, not the right to inspect or assess security controls. It is tempting because SLAs are central to cloud contracts, but availability metrics do not provide independent verification of security practice.
- ✗
Data portability clause
Why it's wrong here
Data portability addresses moving data between providers and avoiding lock-in, not verifying security controls. It is tempting because portability is a frequent contractual demand, yet it concerns exit and migration, not audit or assessment rights.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.