Courseiva
Legal, Risk, and CompliancemediumMultiple SelectObjective-mapped

CCSP Legal, Risk, and Compliance Practice Question

A financial services company is migrating its customer account management system to a public cloud provider. The company is subject to SOX compliance requirements for internal controls over financial reporting. Which TWO controls are essential for the cloud environment to meet SOX IT general control requirements? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Establishing a formal change management process

SOX requires IT general controls (ITGC) for systems that support financial reporting. Change management ensures that changes to the system are authorized and tested, and audit logs provide evidence of user activities and system events. While encryption and backup are important security measures, they are not specifically ITGC requirements under SOX.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enforcing role-based access control with least privilege

    Why it's wrong here

    Access control is important but not the only ITGC; the question asks for two essential controls.

  • Establishing a formal change management process

    Why this is correct

    Change management is a key ITGC required by SOX to ensure system changes are controlled and documented.

  • Enabling detailed audit logging for all user and system activities

    Why this is correct

    Audit logging is a key ITGC required to monitor and investigate access and changes.

  • Implementing encryption for data at rest and in transit

    Why it's wrong here

    Encryption is a security control but not a specific SOX ITGC requirement.

  • Configuring automated backups with daily snapshots

    Why it's wrong here

    Backups are important for disaster recovery but not a specific SOX ITGC.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.