
Certified Cloud Security Professional
Domain 6Objective 3
Understand Audit Process, Methodologies, and Required Adaptations for a Cloud Environment CCSP Practice Questions (Page 5)
Part of the Legal, Risk and Compliance domain, which accounts for 13% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
13concepts
13%of the exam
Questions 21–25
- 21
Why is it important for a cloud customer to review the scope statement of an SSAE or ISAE report?
Select an answer first - 22
An auditor is reviewing a cloud provider's ISAE 3402 report (Type II) for a client that uses the provider's infrastructure as a service. The report's scope statement includes the provider's data centers and network operations, but explicitly excludes the virtualization layer and the customer-facing management portal. The client's internal audit team wants to rely on this report for their annual audit. What is the most appropriate conclusion for the auditor to communicate?
Select an answer first - 23
Which type of policy would most likely include requirements for cloud service provider risk assessments?
Select an answer first - 24
A company's external auditor is planning the annual financial statement audit. The company uses a cloud provider for its accounting system. The external auditor needs to obtain assurance over the provider's controls that are relevant to financial reporting. Which of the following is the most appropriate source of assurance for the external auditor?
Select an answer first - 25
Which of the following is a unique assurance challenge introduced by virtualization in cloud computing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.