Courseiva

CCSP Legal, Risk, and Compliance Practice Question

Which of the following best describes the purpose of the Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) program?

⚠ Common exam trap

CCSP often tests the confusion between CSA STAR as a cloud provider assurance program and other CSA offerings like the CCSK certification, leading candidates to select options about professional certification or mandatory standards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To allow cloud providers to publicly document their security controls and achieve different levels of assurance

The CSA STAR program allows cloud providers to publicly document their security controls and achieve different levels of assurance through self-assessment, third-party audits, or certifications. It provides transparency and trust by mapping controls to recognized standards like ISO 27001 and SOC 2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To offer a certification program for cloud security professionals

    Why it's wrong here

    STAR assesses cloud service providers' security posture through CAIQ self-assessments and third-party audits; it does not certify individuals. It is tempting because CSA also runs the CCSK and CCSP credentials, but those are separate professional certifications, whereas STAR targets provider offerings, not people.

  • ✗

    To define mandatory security requirements for all cloud services

    Why it's wrong here

    STAR is a voluntary assurance and transparency program: providers self-assess or obtain third-party certification against CCM, and results are published; it imposes no mandatory requirements on any cloud service. It is tempting because CCM controls look prescriptive, but adoption is opt-in and STAR does not mandate compliance.

  • ✗

    To provide a legal framework for cloud contracts

    Why it's wrong here

    STAR publishes security, privacy and compliance assessments of cloud providers against CSA controls; it does not draft or enforce contract law, which falls to legal counsel and jurisdictions. It is tempting because STAR artefacts (CAIQ, CCM) often inform contract negotiations, yet the program itself issues assurance documentation, not contractual terms.

  • ✓

    To allow cloud providers to publicly document their security controls and achieve different levels of assurance

    Why this is correct

    The CSA STAR program lets cloud providers publish security control documentation through self-assessment, third-party audit or certification, satisfying the stem's requirement to describe its purpose. Its three assurance tiers — Level 1 self-assessment, Level 2 third-party audit, and continuous monitoring — directly match "different levels of assurance".

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.