Courseiva
mediumMatchingObjective-mapped

CCSP Practice Question: Match each cloud auditing term to its definition.

Match each cloud auditing term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Service organization control report for security

Assessment of cloud provider controls

Analysis of logs for incident investigation

Real-time assessment of security controls

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SOC 2: A report that evaluates a service provider's controls related to security, availability, processing integrity, confidentiality, or privacy.

Auditing in cloud requires continuous monitoring and third-party attestations like SOC 2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • SOC 2: A report that evaluates a service provider's controls related to security, availability, processing integrity, confidentiality, or privacy.

    Why this is correct

    SOC 2 is a widely used auditing standard for service organizations, with reports focused on specified trust principles.

  • Continuous monitoring: The ongoing observation and assessment of cloud resources to identify security incidents and compliance deviations.

    Why this is correct

    Continuous monitoring is a key process for maintaining security posture and detecting issues in real time.

  • CSA STAR: A program that provides cloud-specific assessments and certifications based on the Cloud Security Alliance's guidance.

    Why this is correct

    CSA STAR is a framework that includes self-assessment and third-party certification for cloud providers.

  • SOC 2: A program that provides cloud-specific assessments and certifications based on the Cloud Security Alliance's guidance.

    Why it's wrong here

    Incorrect — this describes CSA STAR, not SOC 2. SOC 2 reports are based on AICPA standards, not CSA.

  • Continuous monitoring: A report that evaluates a service provider's controls.

    Why it's wrong here

    Incorrect — continuous monitoring is an ongoing process, not a report. This describes SOC 2.

  • CSA STAR: The ongoing observation of cloud resources.

    Why it's wrong here

    Incorrect — this describes continuous monitoring, not CSA STAR.

About these practice questions

One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.