Courseiva

CCSP Cloud Concepts, Architecture, and Design Practice Question

An enterprise is evaluating a cloud service provider for a workload that handles regulated data. The security architect must assess whether the provider's cloud architecture supports the organization's data residency and audit obligations. Which TWO of the following are the MOST relevant architectural artifacts to request from the provider? (Choose two.)

⚠ Common exam trap

The trap here is accepting vendor-provided assurances or business documents in place of verifiable architectural and audit evidence.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Independent third-party audit reports and certifications such as SOC 2 and ISO/IEC 27001

Assessing data residency and audit obligations requires verifiable evidence about where data lives and how controls are validated. A data flow diagram identifies storage, processing, and replication locations, while independent audit reports and certifications demonstrate that controls have been examined against recognized standards. Together they give the architect the factual basis needed for compliance due diligence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Independent third-party audit reports and certifications such as SOC 2 and ISO/IEC 27001

    Why this is correct

    Independent audit reports and certifications provide evidence that the provider's controls have been examined against recognized criteria. They support the organization's own audit and compliance obligations by offering verifiable assurance about security, availability, and processing integrity. They also help map provider controls to regulatory requirements during due diligence.

  • ✗

    The provider's current stock price and quarterly earnings report

    Why it's wrong here

    Financial performance indicators say nothing about data residency, control effectiveness, or audit readiness. While vendor stability can be a business consideration, it does not satisfy the architect's obligation to verify where regulated data is stored and how compliance is demonstrated. This artifact is irrelevant to the stated assessment.

  • ✓

    A data flow diagram showing where data is stored, processed, and replicated across regions

    Why this is correct

    A data flow diagram reveals the geographic locations of storage, processing, and replication, which is essential for verifying data residency commitments. It also exposes hidden cross-region replication or backup paths that could violate regulatory boundaries. Without this artifact, the architect cannot confirm that regulated data stays within approved jurisdictions.

  • ✗

    A copy of the provider's internal employee acceptable use policy

    Why it's wrong here

    An internal acceptable use policy governs employee behavior but does not demonstrate where regulated data resides or how it is protected architecturally. It is not sufficient evidence for data residency or audit obligations. The architect should focus on artifacts that document data location, control effectiveness, and independent verification.

  • ✗

    The provider's marketing brochure describing its global footprint and uptime record

    Why it's wrong here

    Marketing materials are not authoritative technical artifacts and typically omit replication paths, subprocessors, and jurisdictional details. They cannot substantiate data residency or audit obligations because they are not verifiable evidence. An architect needs documented, testable information rather than promotional claims about global reach and availability.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.