CCSP Legal, Risk, and Compliance Practice Question
A global enterprise is conducting a cloud risk assessment. Which THREE factors should be considered? (Select three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inherent risk of data leaving the on-premises environment
Option B is correct because moving data off-premises introduces inherent risk—loss of direct physical and logical control, jurisdictional exposure, and reliance on the provider's network and encryption—which is a core element of any cloud risk assessment. Option D is correct because concentration risk (vendor lock-in and dependence on a single provider) can create systemic exposure; if that provider suffers an outage, breach, or business failure, the enterprise's operations are broadly impacted, so it must be evaluated. Option E is correct because the effectiveness of the provider's controls must be verified through independent audit reports (e.g., SOC 2 Type II, ISO/IEC 27001 certifications, or CSA STAR), which provide evidence that security, availability, and confidentiality controls actually operate as claimed. Option A is not relevant because a logo's color has no bearing on security, compliance, or operational risk. Option C is not relevant because stock price reflects market performance, not the provider's control effectiveness or the enterprise's risk exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Color of the provider's logo
Why it's wrong here
Logo colour is branding, carrying no bearing on security, data governance or availability controls assessed in cloud risk. It is tempting only as a superficial vendor-identity detail, and would never be a genuine assessment factor; provider reputation or certification status would be the legitimate analogue here.
- ✓
Inherent risk of data leaving the on-premises environment
Why this is correct
Moving data to a provider transfers it outside the customer's direct control, introducing exposure from shared infrastructure, provider personnel and cross-border transfer. This inherent risk of data leaving the on-premises environment is a core factor in the cloud risk assessment the enterprise is conducting.
- ✗
Provider's stock price
Why it's wrong here
Stock price reflects market sentiment, not the provider's security, compliance or resilience controls that a cloud risk assessment examines. It is tempting because financial stability can indicate vendor viability, so it would be relevant when assessing provider longevity or business continuity risk, not the technical risk factors the stem requires.
- ✓
Concentration risk from using a single cloud provider
Why this is correct
Relying on one provider creates correlated failure: an outage, breach or contract dispute affects every hosted workload simultaneously. This concentration risk is a distinct cloud risk assessment factor, since multi-provider or hybrid architectures would reduce the single point of dependency the stem's enterprise currently accepts.
- ✓
Effectiveness of provider controls as evidenced by audit reports
Why this is correct
The customer cannot directly observe provider operations, so assurance depends on independent attestations such as SOC 2 reports. Reviewing the effectiveness of provider controls as evidenced by audit reports is therefore a required risk assessment factor, addressing the visibility gap created by outsourcing to the cloud.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.