
Certified Cloud Security Professional
Domain 6Objective 3
Understand Audit Process, Methodologies, and Required Adaptations for a Cloud Environment CCSP Practice Questions (Page 8)
Part of the Legal, Risk and Compliance domain, which accounts for 13% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 40 practice questions to prepare you well beyond it. (estimate)
40questions here
8free pages
13concepts
13%of the exam
Questions 36–40
- 36
In a cloud environment, what is the primary role of external audit controls?
Select an answer first - 37
A multinational company uses a distributed IT model where data is processed in cloud data centers located in the United States, the European Union, and Asia. The company is planning an audit that must cover all locations. The audit team is concerned about the different legal jurisdictions and the ability to access data for audit purposes. Which of the following is the most important consideration for the audit plan?
Select an answer first - 38
Which of the following should be included in an audit plan for a cloud environment?
Select an answer first - 39
A financial services company is migrating its customer relationship management (CRM) system to a public cloud provider. The compliance officer needs assurance that the provider's controls over the underlying infrastructure are effective. The company's internal audit team will not be able to test the provider's physical security or hypervisor configuration directly. Which approach best addresses the assurance need while respecting the shared responsibility model?
Select an answer first - 40
What is a key assurance challenge of dynamic resource allocation in cloud computing?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CCSP
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.