Courseiva
mediumMultiple Choice

CCSP Practice Question: Wants to assess the security controls of a cloud…

An organization wants to assess the security controls of a cloud provider before entering into a contract. What is the most efficient method?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review a SOC 2 Type II report

Reviewing a SOC 2 Type II report provides an independent assessment of a provider's controls over time. On-site audits are costly and time-consuming. Vulnerability scanning and penetration test reports may not be available or comprehensive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Request a penetration test report

    Why it's wrong here

    A penetration test report is point-in-time and provider-commissioned, covering only the tested scope rather than the full control set; it cannot evidence controls outside that scope. It is tempting because penetration testing genuinely validates exploitable weaknesses in a live environment, which suits assessing your own deployed systems.

  • ✗

    Conduct an on-site audit

    Why it's wrong here

    On-site auditing is resource-intensive, requires provider cooperation and scheduling, and duplicates assurance the provider already documents; it does not scale across many providers. It is tempting because direct inspection gives first-hand evidence, which suits high-risk single-provider engagements or regulated environments where attestation is insufficient.

  • ✗

    Perform vulnerability scanning

    Why it's wrong here

    Vulnerability scanning from outside tests only externally reachable hosts and cannot assess the provider's internal, physical or administrative controls. It is tempting because scanning is quick and low-cost, and it genuinely suits validating your own externally exposed infrastructure rather than evaluating a provider's control environment.

  • ✓

    Review a SOC 2 Type II report

    Why this is correct

    A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of a cloud provider's controls over a period, giving efficient assurance without on-site assessment. It satisfies the pre-contract due diligence requirement more efficiently than questionnaires or point-in-time attestations.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.