CCSP Legal, Risk, and Compliance Practice Question
A company is subject to PCI DSS because it processes credit card transactions. It plans to use a cloud provider that is not specifically listed as a PCI DSS validated service provider. What is the most important step the company must take to ensure compliance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The company must obtain a copy of the cloud provider's PCI DSS Attestation of Compliance (AOC) and ensure the provider is assessed by a Qualified Security Assessor (QSA).
PCI DSS requires that if a cloud provider is not already validated, the customer must ensure the provider undergoes a PCI DSS assessment. The shared responsibility matrix (SRM) is used to delineate which controls are the provider's and which are the customer's.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The company must sign a Business Associate Agreement (BAA) with the cloud provider.
Why it's wrong here
BAA is for HIPAA, not PCI DSS. PCI DSS requires a shared responsibility matrix.
- ✗
The company must conduct its own on-site audit of the cloud provider's data centers.
Why it's wrong here
On-site audits may not be practical or permitted; assessment via SAQ or by a QSA is typical.
- ✗
The company must ensure that the cloud provider encrypts all cardholder data at rest and in transit.
Why it's wrong here
Encryption is required, but the primary step is to validate the provider's compliance status.
- ✓
The company must obtain a copy of the cloud provider's PCI DSS Attestation of Compliance (AOC) and ensure the provider is assessed by a Qualified Security Assessor (QSA).
Why this is correct
The customer must verify the provider's PCI DSS compliance through a valid AOC.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.