CCSP Legal, Risk, and Compliance Practice Question
A financial services company is migrating its customer account management system to a public cloud provider. The company is subject to SOX compliance requirements for internal controls over financial reporting. Which TWO controls are essential for the cloud environment to meet SOX IT general control requirements? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establishing a formal change management process
SOX requires IT general controls (ITGC) for systems that support financial reporting. Change management ensures that changes to the system are authorized and tested, and audit logs provide evidence of user activities and system events. While encryption and backup are important security measures, they are not specifically ITGC requirements under SOX.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enforcing role-based access control with least privilege
Why it's wrong here
Access control is important but not the only ITGC; the question asks for two essential controls.
- ✓
Establishing a formal change management process
Why this is correct
Change management is a key ITGC required by SOX to ensure system changes are controlled and documented.
- ✓
Enabling detailed audit logging for all user and system activities
Why this is correct
Audit logging is a key ITGC required to monitor and investigate access and changes.
- ✗
Implementing encryption for data at rest and in transit
Why it's wrong here
Encryption is a security control but not a specific SOX ITGC requirement.
- ✗
Configuring automated backups with daily snapshots
Why it's wrong here
Backups are important for disaster recovery but not a specific SOX ITGC.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.