CCSP Cloud Concepts, Architecture, and Design Practice Question
An enterprise is evaluating whether to move a legacy customer relationship management system to a cloud provider. The security architect must assess the provider's ability to meet the enterprise's control requirements before signing. Which TWO artifacts or activities BEST provide direct evidence of the provider's security control environment? (Choose two.)
⚠ Common exam trap
The trap here is accepting provider-authored assurances or peer anecdotes as control evidence instead of independently tested reports and documented assessment results.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A current independent third-party audit report covering the relevant trust services criteria
Direct evidence comes from independent testing and from a structured, documented assessment conducted by the enterprise itself. An independent third-party audit report covers defined criteria over a stated period and discloses exceptions, while a framework-mapped questionnaire reviewed with the provider turns vague assurances into specific, verifiable answers. Marketing brochures, terms of service, and reference calls may inform the decision, but they do not establish that the provider's controls are designed and operating effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A current independent third-party audit report covering the relevant trust services criteria
Why this is correct
An independent audit report, such as a SOC 2 report, is produced by a qualified auditor and describes the design and operating effectiveness of controls against defined criteria over a specific period. It gives the architect evidence that controls exist and were tested, along with any exceptions noted. This is direct, verifiable evidence rather than a self-declaration, making it one of the strongest artifacts for pre-contract assessment.
- ✗
The provider's public marketing brochure describing its security posture
Why it's wrong here
Marketing material is written by the provider to promote its services and is not independently verified. It may describe certifications and features accurately, but it offers no testing evidence, no scope definition, and no statement of exceptions. Relying on it for a control assessment gives the architect no assurance that the claims hold in the environment where the customer relationship management system would actually run.
- ✗
A customer reference call with another organization of similar size in the same industry
Why it's wrong here
A reference call provides useful operational color about onboarding, support responsiveness, and real-world incidents, but it is anecdotal and depends on the other customer's configuration and risk tolerance. It does not test the provider's controls or define the scope of any assurance. It is helpful context for a decision, yet it is not direct evidence that the provider's control environment meets this enterprise's requirements.
- ✓
A completed security questionnaire returned by the provider, with supporting documentation reviewed in a follow-up session
Why this is correct
A structured questionnaire mapped to a recognized control framework lets the architect probe specific requirements, and reviewing the answers with the provider's subject matter experts surfaces gaps and clarifies scope. When supporting documentation is examined alongside the responses, the questionnaire becomes a targeted gap analysis that complements formal audit reports. It is a direct assessment activity rather than reliance on promotional claims.
- ✗
The provider's standard terms of service and acceptable use policy
Why it's wrong here
Terms of service and acceptable use policies define the legal relationship, customer obligations, and prohibited activities. They are important for contracting and for understanding liability, but they are not evidence that security controls are designed or operating effectively. An architect who uses them as control evidence would be substituting legal language for tested operational facts, leaving the real assessment unanswered.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.