hardMultiple Choice
CCSP Practice Question: Uses a multi-cloud strategy and wants to perform…
An organization uses a multi-cloud strategy and wants to perform a risk assessment that accounts for the shared responsibility model. Which approach is most appropriate?
⚠ Common exam trap
CCSP often tests the misconception that any widely recognized framework (ISO 27001, NIST CSF, COBIT) is equally valid for cloud risk assessment, when the exam expects candidates to recognize that only cloud-specific frameworks like CSA STAR explicitly encode the shared responsibility model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use cloud-specific risk assessment frameworks like CSA STAR
CSA STAR (Security, Trust, Assurance, and Risk) is purpose-built for cloud environments and directly incorporates the shared responsibility model, providing a cloud-specific control framework (Cloud Controls Matrix) that maps to ISO 27001, NIST, and other standards. Because the organization operates multi-cloud, CSA STAR's provider-neutral, cloud-native controls allow consistent assessment across AWS, Azure, and GCP while explicitly delineating customer vs. provider responsibilities. This makes it the most appropriate basis for a shared-responsibility-aware risk assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use ISO 27001 controls as the sole basis for assessment
Why it's wrong here
ISO 27001 provides generic control objectives and does not allocate responsibilities between provider and customer, so it cannot express who owns which control layer in each cloud service model. It suits certifying an organisation's management system. A cloud-specific framework mapping controls to IaaS, PaaS and SaaS responsibilities is needed here.
- ✗
Apply the NIST Cybersecurity Framework across all cloud providers
Why it's wrong here
The NIST CSF is a voluntary framework of outcomes, not a risk-assessment method, so it cannot quantify provider-specific shared-responsibility gaps across clouds. It is tempting because it structures security programmes and controls; it would suit building a governance baseline, not assessing where each provider's responsibility boundary shifts.
- ✓
Use cloud-specific risk assessment frameworks like CSA STAR
Why this is correct
CSA STAR provides cloud-specific controls mapped to the shared responsibility model, so each party's obligations across IaaS, PaaS and SaaS are assessed. Generic frameworks such as ISO 27001 or NIST do not delineate provider versus customer duties per service model.
- ✗
Adopt COBIT for risk management alignment
Why it's wrong here
COBIT addresses IT governance and management objectives across the enterprise; it does not map controls to provider versus customer duties per service model, so shared-responsibility allocation stays undefined. COBIT fits aligning IT governance with business goals. A cloud-specific framework that assigns controls by service model is required.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.