
Certified Cloud Security Professional
Domain 6Objective 3
Understand Audit Process, Methodologies, and Required Adaptations for a Cloud Environment CCSP Practice Questions (Page 4)
Part of the Legal, Risk and Compliance domain, which accounts for 13% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
13concepts
13%of the exam
Questions 16–20
- 16
A company is establishing an internal ISMS to support its cloud operations. The ISMS will be used as the basis for internal and external audits. Which of the following components is essential for the ISMS to effectively support audits?
Select an answer first - 17
In a cloud environment, how do audit requirements typically affect the cloud service provider (CSP) and the customer under the shared responsibility model?
Select an answer first - 18
A company is performing a gap analysis of its cloud-based email system against its internal security baseline. The baseline is defined in the company's ISMS. The gap analysis reveals that the email system does not enforce multi-factor authentication (MFA) for all users, while the baseline requires MFA for all remote access. Which of the following is the most appropriate next step?
Select an answer first - 19
A company's internal audit department is evaluating the effectiveness of its information security controls system. The company uses a public cloud for data storage and has implemented an ISMS. The internal audit team wants to assess whether the controls are operating effectively. Which activity is most appropriate for the internal audit team to perform?
Select an answer first - 20
A company's internal audit team is preparing for an annual audit of its cloud-based HR system. The team wants to identify gaps between the current security controls and the company's baseline security policy. The HR system is hosted in a public cloud, and the company has an ISMS that documents its security policies and controls. Which approach is most effective for the audit team to perform the gap analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.