mediumMultiple Choice
CCSP Practice Question: Wants to assess the security controls of a cloud…
An organization wants to assess the security controls of a cloud provider before entering into a contract. What is the most efficient method?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review a SOC 2 Type II report
Reviewing a SOC 2 Type II report provides an independent assessment of a provider's controls over time. On-site audits are costly and time-consuming. Vulnerability scanning and penetration test reports may not be available or comprehensive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Request a penetration test report
Why it's wrong here
A penetration test report is point-in-time and provider-commissioned, covering only the tested scope rather than the full control set; it cannot evidence controls outside that scope. It is tempting because penetration testing genuinely validates exploitable weaknesses in a live environment, which suits assessing your own deployed systems.
- ✗
Conduct an on-site audit
Why it's wrong here
On-site auditing is resource-intensive, requires provider cooperation and scheduling, and duplicates assurance the provider already documents; it does not scale across many providers. It is tempting because direct inspection gives first-hand evidence, which suits high-risk single-provider engagements or regulated environments where attestation is insufficient.
- ✗
Perform vulnerability scanning
Why it's wrong here
Vulnerability scanning from outside tests only externally reachable hosts and cannot assess the provider's internal, physical or administrative controls. It is tempting because scanning is quick and low-cost, and it genuinely suits validating your own externally exposed infrastructure rather than evaluating a provider's control environment.
- ✓
Review a SOC 2 Type II report
Why this is correct
A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of a cloud provider's controls over a period, giving efficient assurance without on-site assessment. It satisfies the pre-contract due diligence requirement more efficiently than questionnaires or point-in-time attestations.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.