Courseiva
Legal, Risk, and Compliance →mediumMultiple Choice

CCSP Legal, Risk, and Compliance Practice Question

A company is negotiating a cloud service agreement and wants to ensure it can periodically assess the security of the cloud provider's operations. Which contractual clause is most directly relevant to this requirement?

⚠ Common exam trap

CCSP often tests confusion between Right to Audit and other contractual clauses like SLA or data portability, but the key is that only Right to Audit directly enables security assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Right to Audit clause permitting the customer to review the provider's security controls and certifications

A Right to Audit clause explicitly grants the customer the contractual right to assess the cloud provider's security controls, certifications, and compliance through audits or inspections. This directly addresses the requirement to periodically assess the provider's operations. Other clauses address different concerns such as data portability, performance, or data deletion, but not security assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Right to Audit clause permitting the customer to review the provider's security controls and certifications

    Why this is correct

    A Right to Audit clause directly grants the customer contractual authority to examine the provider's security controls and certifications, satisfying the requirement for periodic assessment of the provider's operations. Without this clause, the customer relies solely on the provider's self-reported attestations, losing independent verification rights.

  • ✗

    Data portability clause ensuring data can be exported in a usable format

    Why it's wrong here

    A data portability clause guarantees export of data in a usable format, addressing exit and lock-in, not the right to audit provider operations. It tempts because portability is a common cloud negotiation priority, and would be correct if the requirement were avoiding vendor lock-in or ensuring data can be migrated elsewhere.

  • ✗

    Service Level Agreement (SLA) with uptime guarantees

    Why it's wrong here

    An SLA with uptime guarantees defines availability commitments and service credits, not a right to assess the provider's security controls, so it does not satisfy the requirement. It tempts because SLAs are central to cloud contracts, and would be correct if the concern were availability or performance rather than security assurance.

  • ✗

    Data deletion clause specifying how data is deleted after contract termination

    Why it's wrong here

    A data deletion clause governs destruction of data at contract termination; it grants no right to inspect provider operations, so it cannot support periodic security assessment. It tempts because deletion terms matter for compliance and data lifecycle, and would be correct if the requirement were ensuring data is securely erased once the agreement ends.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.