CCSP Legal, Risk, and Compliance Practice Question
A company is negotiating a cloud service agreement and wants to ensure it can periodically assess the security of the cloud provider's operations. Which contractual clause is most directly relevant to this requirement?
⚠ Common exam trap
CCSP often tests confusion between Right to Audit and other contractual clauses like SLA or data portability, but the key is that only Right to Audit directly enables security assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Right to Audit clause permitting the customer to review the provider's security controls and certifications
A Right to Audit clause explicitly grants the customer the contractual right to assess the cloud provider's security controls, certifications, and compliance through audits or inspections. This directly addresses the requirement to periodically assess the provider's operations. Other clauses address different concerns such as data portability, performance, or data deletion, but not security assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Right to Audit clause permitting the customer to review the provider's security controls and certifications
Why this is correct
A Right to Audit clause directly grants the customer contractual authority to examine the provider's security controls and certifications, satisfying the requirement for periodic assessment of the provider's operations. Without this clause, the customer relies solely on the provider's self-reported attestations, losing independent verification rights.
- ✗
Data portability clause ensuring data can be exported in a usable format
Why it's wrong here
A data portability clause guarantees export of data in a usable format, addressing exit and lock-in, not the right to audit provider operations. It tempts because portability is a common cloud negotiation priority, and would be correct if the requirement were avoiding vendor lock-in or ensuring data can be migrated elsewhere.
- ✗
Service Level Agreement (SLA) with uptime guarantees
Why it's wrong here
An SLA with uptime guarantees defines availability commitments and service credits, not a right to assess the provider's security controls, so it does not satisfy the requirement. It tempts because SLAs are central to cloud contracts, and would be correct if the concern were availability or performance rather than security assurance.
- ✗
Data deletion clause specifying how data is deleted after contract termination
Why it's wrong here
A data deletion clause governs destruction of data at contract termination; it grants no right to inspect provider operations, so it cannot support periodic security assessment. It tempts because deletion terms matter for compliance and data lifecycle, and would be correct if the requirement were ensuring data is securely erased once the agreement ends.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.