CCSP Legal, Risk, and Compliance Practice Question
A company is subject to PCI DSS and plans to use a cloud provider to process credit card transactions. The cloud provider has been assessed by a Qualified Security Assessor (QSA). According to PCI DSS, what must the company obtain from the provider to demonstrate compliance?
⚠ Common exam trap
CCSP often tests the confusion between compliance frameworks — candidates see 'cloud provider' and 'compliance' and reach for SOC 2 or ISO 27001, but PCI DSS specifically requires a QSA-issued AOC and Responsibility Matrix from the service provider.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The provider's PCI DSS Attestation of Compliance (AOC) and Responsibility Matrix
Under PCI DSS, when a customer uses a cloud provider to process cardholder data, the provider must be assessed by a QSA and issue an Attestation of Compliance (AOC) along with a Responsibility Matrix (also called a Shared Responsibility Matrix or PCI DSS Responsibility Matrix). The AOC documents the provider's validated compliance status, and the Responsibility Matrix defines which PCI DSS requirements are met by the provider versus the customer. Together they let the customer demonstrate its own compliance to its acquirer or QSA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The provider's PCI DSS Attestation of Compliance (AOC) and Responsibility Matrix
Why this is correct
The PCI DSS Attestation of Compliance evidences the provider's assessed compliance status, while the Responsibility Matrix defines which requirements the provider covers versus the customer. Together they satisfy the obligation to demonstrate compliance for card processing.
- ✗
A signed Business Associate Agreement
Why it's wrong here
PCI DSS requires a signed Attestation of Compliance and the QSA's Report on Compliance from the provider; a Business Associate Agreement addresses HIPAA. The BAA is tempting because it is a familiar cloud compliance artefact, but it covers protected health information, not cardholder data.
- ✗
An ISO 27001 certificate
Why it's wrong here
ISO 27001 certifies an information security management system, not the PCI DSS controls a QSA assesses; the required artefact is the QSA-issued Attestation of Compliance. It tempts because ISO 27001 is a recognised security certification, and would be the right evidence for general security assurance rather than cardholder data compliance.
- ✗
A SOC 2 Type II report
Why it's wrong here
PCI DSS requires an Attestation of Compliance and Report on Compliance from a QSA; SOC 2 reports cover trust services criteria, not cardholder data controls. It is tempting because SOC 2 Type II evidences operational effectiveness over time, and would suit vendor risk assessments outside the cardholder data environment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.