Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A global enterprise is conducting a cloud risk assessment. Which THREE factors should be considered? (Select three.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inherent risk of data leaving the on-premises environment

Option B is correct because moving data off-premises introduces inherent risk—loss of direct physical and logical control, jurisdictional exposure, and reliance on the provider's network and encryption—which is a core element of any cloud risk assessment. Option D is correct because concentration risk (vendor lock-in and dependence on a single provider) can create systemic exposure; if that provider suffers an outage, breach, or business failure, the enterprise's operations are broadly impacted, so it must be evaluated. Option E is correct because the effectiveness of the provider's controls must be verified through independent audit reports (e.g., SOC 2 Type II, ISO/IEC 27001 certifications, or CSA STAR), which provide evidence that security, availability, and confidentiality controls actually operate as claimed. Option A is not relevant because a logo's color has no bearing on security, compliance, or operational risk. Option C is not relevant because stock price reflects market performance, not the provider's control effectiveness or the enterprise's risk exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Color of the provider's logo

    Why it's wrong here

    Logo colour is branding, carrying no bearing on security, data governance or availability controls assessed in cloud risk. It is tempting only as a superficial vendor-identity detail, and would never be a genuine assessment factor; provider reputation or certification status would be the legitimate analogue here.

  • ✓

    Inherent risk of data leaving the on-premises environment

    Why this is correct

    Moving data to a provider transfers it outside the customer's direct control, introducing exposure from shared infrastructure, provider personnel and cross-border transfer. This inherent risk of data leaving the on-premises environment is a core factor in the cloud risk assessment the enterprise is conducting.

  • ✗

    Provider's stock price

    Why it's wrong here

    Stock price reflects market sentiment, not the provider's security, compliance or resilience controls that a cloud risk assessment examines. It is tempting because financial stability can indicate vendor viability, so it would be relevant when assessing provider longevity or business continuity risk, not the technical risk factors the stem requires.

  • ✓

    Concentration risk from using a single cloud provider

    Why this is correct

    Relying on one provider creates correlated failure: an outage, breach or contract dispute affects every hosted workload simultaneously. This concentration risk is a distinct cloud risk assessment factor, since multi-provider or hybrid architectures would reduce the single point of dependency the stem's enterprise currently accepts.

  • ✓

    Effectiveness of provider controls as evidenced by audit reports

    Why this is correct

    The customer cannot directly observe provider operations, so assurance depends on independent attestations such as SOC 2 reports. Reviewing the effectiveness of provider controls as evidenced by audit reports is therefore a required risk assessment factor, addressing the visibility gap created by outsourcing to the cloud.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.