CCSP Legal, Risk, and Compliance Practice Question
Which of the following best describes the purpose of the Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) program?
⚠ Common exam trap
CCSP often tests the confusion between CSA STAR as a cloud provider assurance program and other CSA offerings like the CCSK certification, leading candidates to select options about professional certification or mandatory standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To allow cloud providers to publicly document their security controls and achieve different levels of assurance
The CSA STAR program allows cloud providers to publicly document their security controls and achieve different levels of assurance through self-assessment, third-party audits, or certifications. It provides transparency and trust by mapping controls to recognized standards like ISO 27001 and SOC 2.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To offer a certification program for cloud security professionals
Why it's wrong here
STAR assesses cloud service providers' security posture through CAIQ self-assessments and third-party audits; it does not certify individuals. It is tempting because CSA also runs the CCSK and CCSP credentials, but those are separate professional certifications, whereas STAR targets provider offerings, not people.
- ✗
To define mandatory security requirements for all cloud services
Why it's wrong here
STAR is a voluntary assurance and transparency program: providers self-assess or obtain third-party certification against CCM, and results are published; it imposes no mandatory requirements on any cloud service. It is tempting because CCM controls look prescriptive, but adoption is opt-in and STAR does not mandate compliance.
- ✗
To provide a legal framework for cloud contracts
Why it's wrong here
STAR publishes security, privacy and compliance assessments of cloud providers against CSA controls; it does not draft or enforce contract law, which falls to legal counsel and jurisdictions. It is tempting because STAR artefacts (CAIQ, CCM) often inform contract negotiations, yet the program itself issues assurance documentation, not contractual terms.
- ✓
To allow cloud providers to publicly document their security controls and achieve different levels of assurance
Why this is correct
The CSA STAR program lets cloud providers publish security control documentation through self-assessment, third-party audit or certification, satisfying the stem's requirement to describe its purpose. Its three assurance tiers — Level 1 self-assessment, Level 2 third-party audit, and continuous monitoring — directly match "different levels of assurance".
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.