CCSP Legal, Risk, and Compliance Practice Question
A financial institution is required to comply with the Sarbanes-Oxley Act (SOX) for its cloud-hosted financial applications. The cloud provider is responsible for the underlying infrastructure. Which of the following controls is most likely the responsibility of the financial institution as part of IT general controls (ITGC)?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Logical access controls to the financial application, including user provisioning and segregation of duties
SOX requires organizations to maintain ITGCs over systems that support financial reporting. Logical access controls (e.g., user provisioning, authentication) are typically the responsibility of the customer (the financial institution) because they manage who can access the application and data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical security of the data center housing the cloud servers
Why it's wrong here
Physical security is typically the provider's responsibility.
- ✓
Logical access controls to the financial application, including user provisioning and segregation of duties
Why this is correct
The customer controls user access to the application and data, which is a key ITGC area.
- ✗
Network intrusion detection at the cloud perimeter
Why it's wrong here
Network security is often shared, but perimeter intrusion detection is usually the provider's responsibility.
- ✗
Patching of the hypervisor that hosts the virtual machines
Why it's wrong here
Hypervisor patching is the provider's responsibility.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.