Courseiva
hardMultiple SelectObjective-mapped

CCSP Practice Question: Which TWO of the following are primary…

Which TWO of the following are primary responsibilities of a cloud service customer under the shared responsibility model regarding compliance with regulations such as GDPR?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implementing data encryption for sensitive data at rest

The customer is responsible for data encryption and access controls (C and E). Physical security and penetration testing are provider responsibilities. Verifying certifications is a customer due diligence task but not a primary responsibility compared to direct data protection measures.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Conducting annual penetration tests on the provider's infrastructure

    Why it's wrong here

    Testing provider infrastructure is the provider's responsibility.

  • Ensuring the cloud provider's physical security controls are adequate

    Why it's wrong here

    Physical security is the provider's responsibility under the shared model.

  • Implementing data encryption for sensitive data at rest

    Why this is correct

    Data encryption is typically a customer control to protect data.

  • Verifying the provider's compliance certifications are current

    Why it's wrong here

    While advisable, it is a secondary due diligence activity, not a primary responsibility.

  • Configuring access controls for their own user accounts

    Why this is correct

    Customers control access to their own accounts and data.

About these practice questions

One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.