Courseiva
hardMultiple Choice

CCSP Practice Question: Uses a multi-cloud strategy and wants to perform…

An organization uses a multi-cloud strategy and wants to perform a risk assessment that accounts for the shared responsibility model. Which approach is most appropriate?

⚠ Common exam trap

CCSP often tests the misconception that any widely recognized framework (ISO 27001, NIST CSF, COBIT) is equally valid for cloud risk assessment, when the exam expects candidates to recognize that only cloud-specific frameworks like CSA STAR explicitly encode the shared responsibility model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use cloud-specific risk assessment frameworks like CSA STAR

CSA STAR (Security, Trust, Assurance, and Risk) is purpose-built for cloud environments and directly incorporates the shared responsibility model, providing a cloud-specific control framework (Cloud Controls Matrix) that maps to ISO 27001, NIST, and other standards. Because the organization operates multi-cloud, CSA STAR's provider-neutral, cloud-native controls allow consistent assessment across AWS, Azure, and GCP while explicitly delineating customer vs. provider responsibilities. This makes it the most appropriate basis for a shared-responsibility-aware risk assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use ISO 27001 controls as the sole basis for assessment

    Why it's wrong here

    ISO 27001 provides generic control objectives and does not allocate responsibilities between provider and customer, so it cannot express who owns which control layer in each cloud service model. It suits certifying an organisation's management system. A cloud-specific framework mapping controls to IaaS, PaaS and SaaS responsibilities is needed here.

  • ✗

    Apply the NIST Cybersecurity Framework across all cloud providers

    Why it's wrong here

    The NIST CSF is a voluntary framework of outcomes, not a risk-assessment method, so it cannot quantify provider-specific shared-responsibility gaps across clouds. It is tempting because it structures security programmes and controls; it would suit building a governance baseline, not assessing where each provider's responsibility boundary shifts.

  • ✓

    Use cloud-specific risk assessment frameworks like CSA STAR

    Why this is correct

    CSA STAR provides cloud-specific controls mapped to the shared responsibility model, so each party's obligations across IaaS, PaaS and SaaS are assessed. Generic frameworks such as ISO 27001 or NIST do not delineate provider versus customer duties per service model.

  • ✗

    Adopt COBIT for risk management alignment

    Why it's wrong here

    COBIT addresses IT governance and management objectives across the enterprise; it does not map controls to provider versus customer duties per service model, so shared-responsibility allocation stays undefined. COBIT fits aligning IT governance with business goals. A cloud-specific framework that assigns controls by service model is required.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.