Courseiva
Legal, Risk, and Compliance →mediumMultiple Choice

CCSP Legal, Risk, and Compliance Practice Question

A company is subject to PCI DSS and plans to use a cloud provider to process credit card transactions. The cloud provider has been assessed by a Qualified Security Assessor (QSA). According to PCI DSS, what must the company obtain from the provider to demonstrate compliance?

⚠ Common exam trap

CCSP often tests the confusion between compliance frameworks — candidates see 'cloud provider' and 'compliance' and reach for SOC 2 or ISO 27001, but PCI DSS specifically requires a QSA-issued AOC and Responsibility Matrix from the service provider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The provider's PCI DSS Attestation of Compliance (AOC) and Responsibility Matrix

Under PCI DSS, when a customer uses a cloud provider to process cardholder data, the provider must be assessed by a QSA and issue an Attestation of Compliance (AOC) along with a Responsibility Matrix (also called a Shared Responsibility Matrix or PCI DSS Responsibility Matrix). The AOC documents the provider's validated compliance status, and the Responsibility Matrix defines which PCI DSS requirements are met by the provider versus the customer. Together they let the customer demonstrate its own compliance to its acquirer or QSA.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The provider's PCI DSS Attestation of Compliance (AOC) and Responsibility Matrix

    Why this is correct

    The PCI DSS Attestation of Compliance evidences the provider's assessed compliance status, while the Responsibility Matrix defines which requirements the provider covers versus the customer. Together they satisfy the obligation to demonstrate compliance for card processing.

  • ✗

    A signed Business Associate Agreement

    Why it's wrong here

    PCI DSS requires a signed Attestation of Compliance and the QSA's Report on Compliance from the provider; a Business Associate Agreement addresses HIPAA. The BAA is tempting because it is a familiar cloud compliance artefact, but it covers protected health information, not cardholder data.

  • ✗

    An ISO 27001 certificate

    Why it's wrong here

    ISO 27001 certifies an information security management system, not the PCI DSS controls a QSA assesses; the required artefact is the QSA-issued Attestation of Compliance. It tempts because ISO 27001 is a recognised security certification, and would be the right evidence for general security assurance rather than cardholder data compliance.

  • ✗

    A SOC 2 Type II report

    Why it's wrong here

    PCI DSS requires an Attestation of Compliance and Report on Compliance from a QSA; SOC 2 reports cover trust services criteria, not cardholder data controls. It is tempting because SOC 2 Type II evidences operational effectiveness over time, and would suit vendor risk assessments outside the cardholder data environment.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.