Skip to main content
CertRampLearning

ISC2 · Free practice questions

CCSP Practice Questions

24 original CCSP practice questions, four for each domain of the ISC2 exam outline effective 1 August 2026. Each one comes with the answer, a short explanation and the reason every other option is wrong.

Written for the exam outline effective 1 August 2026 · Updated October 1, 2026

These are original practice questions written by CertRamp to the official ISC2 exam outline. They are not real exam questions and do not come from any exam. Try each question first, then open the answer to see the explanation for every option.

Domain 1

Cloud Concepts, Architecture and Design

1.1 Understand cloud computing conceptsFoundationDomain: Cloud Concepts, Architecture and Design

Question 1. A finance team wants to charge each business unit for the cloud resources it actually consumes. Which essential characteristic of cloud computing makes this possible?

  1. Option A: Rapid elasticity
  2. Option B: Measured service
  3. Option C: Resource pooling
  4. Option D: Broad network access
Show answer and explanation

Correct answer: B. Measured service

NIST SP 800-145 lists five essential characteristics. Measured service is the one that makes usage transparent to both provider and customer — and therefore billable and chargeable.

  • A (incorrect)Elasticity is about scaling capacity up and down quickly, not about metering what was used.
  • B (correct)Correct. Resource usage is monitored, controlled and reported, which is the basis for chargeback and pay-per-use billing.
  • C (incorrect)Pooling describes the provider serving many tenants from shared resources; it does not by itself report consumption per consumer.
  • D (incorrect)This describes access over the network from many client types, not usage reporting.

Reference: NIST SP 800-145, The NIST Definition of Cloud Computing (opens in a new tab)

1.1 Understand cloud computing conceptsIntermediateDomain: Cloud Concepts, Architecture and Design

Question 2. A company deploys its own web application on a PaaS offering. The provider manages and patches the operating system and the runtime. Which task remains primarily the customer's responsibility?

  1. Option A: Patching the operating system underneath the runtime
  2. Option B: Physical security of the data center
  3. Option C: Securing the application code and configuring access to its data
  4. Option D: Maintaining the hypervisor
Show answer and explanation

Correct answer: C. Securing the application code and configuring access to its data

The further up the stack a service goes (IaaS → PaaS → SaaS), the more the provider manages. In PaaS, the customer's responsibility shrinks to the application, its configuration, access management and the data.

  • A (incorrect)In PaaS the provider manages the operating system, so patching it is the provider's job.
  • B (incorrect)Physical security is always the provider's responsibility in public cloud service models.
  • C (correct)Correct. In PaaS the customer still owns the application, its configuration, its identities and the data it processes.
  • D (incorrect)The virtualization layer is part of the provider's infrastructure in every public cloud service model.

Reference: ISC2 CCSP exam outline (opens in a new tab)

1.4 Understand design principles of secure cloud computingIntermediateDomain: Cloud Concepts, Architecture and Design

Question 3. During a business impact analysis, the owner of an order system states that the business can afford to lose at most 15 minutes of transactions after an outage. Which metric has the owner just defined?

  1. Option A: Recovery time objective (RTO)
  2. Option B: Recovery point objective (RPO)
  3. Option C: Maximum tolerable downtime (MTD)
  4. Option D: Service level agreement (SLA)
Show answer and explanation

Correct answer: B. Recovery point objective (RPO)

RPO answers 'how much data can we lose?' and drives backup and replication frequency. RTO answers 'how fast must we be back?' and drives the recovery architecture.

  • A (incorrect)RTO is the target time to restore the service, not the amount of data that may be lost.
  • B (correct)Correct. RPO is the maximum tolerable data loss, expressed as a point in time before the incident.
  • C (incorrect)MTD is how long the business function can be unavailable before the damage becomes unacceptable.
  • D (incorrect)An SLA is a contractual commitment; it may contain RPO/RTO values but is not itself the metric.

Reference: ISC2 CCSP exam outline (opens in a new tab)

1.6 Comprehend Artificial Intelligence/Machine LearningIntermediateDomain: Cloud Concepts, Architecture and Design

Question 4. A SOC uses a machine-learning model for anomaly detection that is retrained every week on recent telemetry. An attacker slowly increases malicious activity over several weeks so that the model learns to treat it as normal. Which control MOST directly reduces this risk?

  1. Option A: Validating the training data before each retraining, for example against a trusted baseline with review of unexpected drift
  2. Option B: Encrypting the trained model at rest
  3. Option C: Requiring MFA for SOC analysts
  4. Option D: Increasing the size of the model
Show answer and explanation

Correct answer: A. Validating the training data before each retraining, for example against a trusted baseline with review of unexpected drift

When a model learns from data an attacker can influence, the training data becomes an attack surface. Data source validation, baselining and human review of drift are the relevant controls.

  • A (correct)Correct. This is a training-data poisoning attack; checking what goes into the training set addresses the root cause.
  • B (incorrect)Encryption at rest protects the confidentiality of the stored model file, but the poisoned data arrives through the legitimate training pipeline.
  • C (incorrect)MFA protects analyst accounts; the attacker never needs analyst access to influence the telemetry.
  • D (incorrect)A larger model learns the poisoned pattern just as well; capacity is not a security control.

Reference: ISC2 CCSP exam outline (opens in a new tab)

Domain 2

Cloud Data Security

2.1 Describe cloud data conceptsFoundationDomain: Cloud Data Security

Question 5. In the cloud secure data lifecycle (create, store, use, share, archive, destroy), in which phase should data ideally be classified?

  1. Option A: Create
  2. Option B: Store
  3. Option C: Share
  4. Option D: Archive
Show answer and explanation

Correct answer: A. Create

Classification drives everything downstream — encryption, access, retention, deletion. The earliest point, creation, is therefore the right one.

  • A (correct)Correct. Classifying data when it is created or first acquired means the right controls can follow it through every later phase.
  • B (incorrect)Storage controls depend on the classification, so classification should already exist when data is stored.
  • C (incorrect)By the time data is shared, a missing classification may already have led to the wrong controls.
  • D (incorrect)Archiving relies on the classification for retention decisions; it is far too late to classify then.

Reference: ISC2 CCSP exam outline (opens in a new tab)

2.3 Design and apply data security technologies and strategiesIntermediateDomain: Cloud Data Security

Question 6. An analytics platform must not hold real card numbers. The numbers are to be replaced with substitute values that have no mathematical relationship to the originals, while an authorised payment system can still look up the original through a separate, secured store. Which technique fits?

  1. Option A: Hashing
  2. Option B: Format-preserving encryption
  3. Option C: Tokenization
  4. Option D: Static data masking
Show answer and explanation

Correct answer: C. Tokenization

The key phrases are 'no mathematical relationship' and 'separate store to look up the original'. That is the definition of tokenization with a token vault.

  • A (incorrect)A hash is mathematically derived from the original and cannot be reversed to look up the original value.
  • B (incorrect)The ciphertext is mathematically derived from the original using a key — exactly what the requirement excludes.
  • C (correct)Correct. In vault-based tokenization, tokens are random substitutes and the mapping to the original lives only in a separate, secured token vault.
  • D (incorrect)Masking replaces or hides values permanently; there is no secured store to look up the original.

Reference: ISC2 CCSP exam outline (opens in a new tab)

2.7 Plan and implement data retention, deletion, and archiving policiesIntermediateDomain: Cloud Data Security

Question 7. A customer leaves a public IaaS provider and must make sure its data on the provider's shared storage cannot be recovered. Physical destruction of the disks is not possible. What is the BEST approach?

  1. Option A: Degaussing the storage media
  2. Option B: Cryptographic erasure — destroying the keys used to encrypt the data
  3. Option C: Deleting the volumes through the provider's console
  4. Option D: Overwriting the volumes several times
Show answer and explanation

Correct answer: B. Cryptographic erasure — destroying the keys used to encrypt the data

In the cloud, crypto-shredding is the practical sanitisation method. It only works if all copies of the data were encrypted from the start and every copy of the key can be verifiably destroyed, which is easiest when the customer controls the keys.

  • A (incorrect)The customer has no physical access to multi-tenant media, and degaussing does not work on SSDs anyway.
  • B (correct)Correct. If all copies were encrypted and every copy of the key is destroyed, the remaining ciphertext is unreadable.
  • C (incorrect)A logical delete may leave recoverable data remnants on the underlying storage.
  • D (incorrect)On virtualised, distributed storage the customer cannot verify that every physical copy and block was overwritten.

Reference: ISC2 CCSP exam outline (opens in a new tab)

Domain 3

Cloud Platform and Infrastructure Security

3.1 Comprehend cloud infrastructure and platform componentsFoundationDomain: Cloud Platform and Infrastructure Security

Question 9. Why are Type 1 hypervisors generally preferred over Type 2 hypervisors in cloud data centers from a security perspective?

  1. Option A: They run directly on the hardware, so there is no general-purpose host operating system to attack
  2. Option B: They encrypt all virtual machine memory automatically
  3. Option C: They never need to be patched
  4. Option D: They let guest VMs share memory directly with each other
Show answer and explanation

Correct answer: A. They run directly on the hardware, so there is no general-purpose host operating system to attack

A Type 2 hypervisor runs as an application on a host OS, which adds that OS and everything running on it to the attack surface. A bare-metal Type 1 hypervisor avoids that layer.

  • A (correct)Correct. Removing the host OS layer reduces the attack surface.
  • B (incorrect)Memory encryption depends on specific hardware and configuration; it is not a property of Type 1 hypervisors as such.
  • C (incorrect)Every hypervisor has vulnerabilities and must be patched.
  • D (incorrect)Direct memory sharing between tenants would weaken isolation, not strengthen it.

Reference: ISC2 CCSP exam outline (opens in a new tab)

3.2 Design a secure data centerIntermediateDomain: Cloud Platform and Infrastructure Security

Question 10. A data center design must allow any component on the power and cooling paths to be taken offline for planned maintenance without affecting IT operations. Full fault tolerance against unplanned failures is not required. Which Uptime Institute tier matches this requirement?

  1. Option A: Tier I
  2. Option B: Tier II
  3. Option C: Tier III
  4. Option D: Tier IV
Show answer and explanation

Correct answer: C. Tier III

The key words are 'planned maintenance without affecting operations' — concurrent maintainability, which is Tier III. Fault tolerance would point to Tier IV.

  • A (incorrect)Tier I is basic capacity without redundant components; maintenance usually requires a shutdown.
  • B (incorrect)Tier II adds redundant capacity components, but the distribution path is not concurrently maintainable.
  • C (correct)Correct. Tier III is defined as concurrently maintainable.
  • D (incorrect)Tier IV adds fault tolerance, which goes beyond what the requirement asks for.

Reference: Uptime Institute — Tier Classification System (opens in a new tab)

3.3 Analyze risks associated with cloud infrastructure and platformsIntermediateDomain: Cloud Platform and Infrastructure Security

Question 11. To limit the impact of a region-wide outage at its cloud provider, a company deploys a critical workload actively in two regions. Which risk treatment is this?

  1. Option A: Risk transfer
  2. Option B: Risk avoidance
  3. Option C: Risk mitigation
  4. Option D: Risk acceptance
Show answer and explanation

Correct answer: C. Risk mitigation

Adding redundancy is a classic mitigation: the risk still exists, but its likelihood of causing an outage or its impact is reduced.

  • A (incorrect)Transfer shifts the financial impact to a third party, for example through insurance or contract terms.
  • B (incorrect)Avoidance would mean not running the workload in that environment at all.
  • C (correct)Correct. The company adds a control that reduces the impact of the risk.
  • D (incorrect)Acceptance would mean taking no further action and living with the risk.

Reference: ISC2 CCSP exam outline (opens in a new tab)

3.5 Plan business continuity and disaster recoveryAdvancedDomain: Cloud Platform and Infrastructure Security

Question 12. A team wants to test its disaster recovery plan by actually bringing up systems at the recovery site and processing data there, while production keeps running normally. Which type of test is this?

  1. Option A: Tabletop exercise
  2. Option B: Parallel test
  3. Option C: Full interruption test
  4. Option D: Checklist review
Show answer and explanation

Correct answer: B. Parallel test

Parallel tests give real evidence that the recovery site works without putting production at risk. Full interruption tests give the strongest evidence but carry real business risk.

  • A (incorrect)A tabletop walks through the plan in discussion; no systems are actually brought up.
  • B (correct)Correct. Recovery systems are activated and run alongside production, which is not interrupted.
  • C (incorrect)Here production is actually shut down and operations move to the recovery site — the most disruptive option.
  • D (incorrect)A checklist review only verifies that the plan's contents and contact details are complete and current.

Reference: ISC2 CCSP exam outline (opens in a new tab)

Domain 4

Cloud Application Security

4.3 Apply the Secure Software Development Life CycleFoundationDomain: Cloud Application Security

Question 13. During threat modeling, the team notes that users could deny having approved a payment because the application does not record who approved what and when. Which STRIDE category does this threat belong to?

  1. Option A: Spoofing
  2. Option B: Tampering
  3. Option C: Repudiation
  4. Option D: Information disclosure
Show answer and explanation

Correct answer: C. Repudiation

Repudiation threats are countered with non-repudiation controls: reliable, tamper-evident audit logs and, where needed, digital signatures.

  • A (incorrect)Spoofing is pretending to be someone else, for example with stolen credentials.
  • B (incorrect)Tampering is unauthorised modification of data or code.
  • C (correct)Correct. Repudiation is the ability to deny an action because there is no reliable evidence of it.
  • D (incorrect)Information disclosure means exposing data to people who should not see it.

Reference: ISC2 CCSP exam outline (opens in a new tab)

4.5 Use verified secure softwareIntermediateDomain: Cloud Application Security

Question 14. Developers want every build to fail automatically if it includes an open-source library with a known, published vulnerability. Which tool type should be added to the pipeline?

  1. Option A: Static application security testing (SAST)
  2. Option B: Software composition analysis (SCA)
  3. Option C: Dynamic application security testing (DAST)
  4. Option D: Fuzz testing
Show answer and explanation

Correct answer: B. Software composition analysis (SCA)

Third-party and open-source components are part of the software supply chain. SCA — ideally together with a software bill of materials — makes that supply chain visible.

  • A (incorrect)SAST analyses your own source code for insecure patterns; it is not designed to inventory third-party libraries against vulnerability databases.
  • B (correct)Correct. SCA inventories dependencies and matches them against known vulnerabilities and licence data.
  • C (incorrect)DAST tests the running application from the outside and cannot reliably name the vulnerable library version.
  • D (incorrect)Fuzzing feeds unexpected input to find unknown flaws; it does not check dependencies against known vulnerabilities.

Reference: ISC2 CCSP exam outline (opens in a new tab)

4.7 Design appropriate Identity and Access Management solutionsIntermediateDomain: Cloud Application Security

Question 15. Employees sign in to a SaaS application through the company's identity provider. The SaaS application accepts the SAML assertion it receives and grants access. In this federation, what role does the SaaS application play?

  1. Option A: Identity provider
  2. Option B: Service provider (relying party)
  3. Option C: Cloud access security broker
  4. Option D: Certificate authority
Show answer and explanation

Correct answer: B. Service provider (relying party)

In federated identity, the identity provider authenticates and asserts; the service provider (relying party) trusts the assertion and authorises access.

  • A (incorrect)The identity provider is the company system that authenticates users and issues assertions.
  • B (correct)Correct. The SaaS application relies on assertions from the identity provider instead of authenticating users itself.
  • C (incorrect)A CASB sits between users and cloud services to enforce policy; it is not a party in the SAML trust relationship described.
  • D (incorrect)A certificate authority issues certificates; it does not consume authentication assertions.

Reference: ISC2 CCSP exam outline (opens in a new tab)

4.4 Apply cloud software assurance and validationAdvancedDomain: Cloud Application Security

Question 16. A tester replays the same 'apply discount' API call 50 times to check whether a single voucher can be redeemed more than once. Which kind of testing is this?

  1. Option A: Regression testing
  2. Option B: Load testing
  3. Option C: Abuse case testing
  4. Option D: Unit testing
Show answer and explanation

Correct answer: C. Abuse case testing

Abuse (or misuse) cases describe how features can be used against the business. They complement functional tests, which only prove that the feature works as intended.

  • A (incorrect)Regression testing checks that existing functionality still works after a change.
  • B (incorrect)Load testing measures performance under volume; the goal here is misuse, not performance.
  • C (correct)Correct. The tester deliberately misuses a legitimate feature to see whether business rules can be bypassed.
  • D (incorrect)Unit tests check individual functions in isolation, usually written by developers for expected behaviour.

Reference: ISC2 CCSP exam outline (opens in a new tab)

Domain 5

Cloud Security Operations

5.3 Implement operational controls and standardsFoundationDomain: Cloud Security Operations

Question 17. The same storage outage has caused three separate incidents this month. Each time the service was restored quickly, but nobody has found out why it keeps happening. Which process should take this on?

  1. Option A: Incident management
  2. Option B: Problem management
  3. Option C: Release management
  4. Option D: Capacity management
Show answer and explanation

Correct answer: B. Problem management

Incidents are about restoring service; problems are about the cause. Recurring incidents are the typical trigger for a problem record.

  • A (incorrect)Incident management restores service as quickly as possible; it did that each time.
  • B (correct)Correct. Problem management identifies and removes the underlying root cause of recurring incidents.
  • C (incorrect)Release management plans and controls the rollout of releases.
  • D (incorrect)Capacity management ensures there are enough resources; it may contribute, but finding the root cause is problem management.

Reference: ISC2 CCSP exam outline (opens in a new tab)

5.4 Support digital forensicsIntermediateDomain: Cloud Security Operations

Question 18. A virtual machine in IaaS shows clear signs of compromise. The organisation may need to take legal action later. What should be done FIRST from the options below?

  1. Option A: Terminate the instance to stop the attack
  2. Option B: Capture memory and a disk snapshot, and record hashes of what was collected
  3. Option C: Reboot the instance to clear malicious processes
  4. Option D: Restore the instance from the last clean backup
Show answer and explanation

Correct answer: B. Capture memory and a disk snapshot, and record hashes of what was collected

Collect in order of volatility and document everything. In IaaS, memory capture and snapshots are the customer's main tools, ideally alongside isolating the instance's network access. Anything at or below the hypervisor depends on the provider.

  • A (incorrect)Terminating the instance destroys volatile evidence and possibly the disk.
  • B (correct)Correct. This preserves volatile and persistent evidence and supports the chain of custody.
  • C (incorrect)A reboot wipes memory contents, which often hold the most valuable evidence.
  • D (incorrect)Restoring overwrites the evidence before it has been collected.

Reference: ISC2 CCSP exam outline (opens in a new tab)

5.6 Manage security operationsIntermediateDomain: Cloud Security Operations

Question 19. A company wants to run a penetration test against its own workloads hosted on a public cloud platform. What should it do FIRST?

  1. Option A: Start with automated scans to keep the impact low
  2. Option B: Review the provider's penetration testing policy and obtain any approvals it requires
  3. Option C: Include the provider's management plane in scope to test it thoroughly
  4. Option D: Inform other tenants on the same hosts
Show answer and explanation

Correct answer: B. Review the provider's penetration testing policy and obtain any approvals it requires

In the cloud you test your own resources within the provider's rules. Ignoring them can breach the contract and, in the worst case, affect other customers.

  • A (incorrect)Even scans may be restricted by the provider's terms; check the rules before testing anything.
  • B (correct)Correct. The provider's terms define what may be tested, how, and whether notification or approval is needed.
  • C (incorrect)Testing the provider's shared infrastructure is normally prohibited and could affect other tenants.
  • D (incorrect)Customers cannot identify co-tenants, and testing must not target them in the first place.

Reference: ISC2 CCSP exam outline (opens in a new tab)

5.5 Manage communication with relevant partiesAdvancedDomain: Cloud Security Operations

Question 20. An EU-based company uses a SaaS provider to process its customers' personal data on its behalf. A personal data breach occurs at the provider. Under the GDPR, who is responsible for notifying the supervisory authority?

  1. Option A: The SaaS provider, because the breach happened on its systems
  2. Option B: The customer, as the controller
  3. Option C: Nobody, if the data was stored outside the EU
  4. Option D: The affected data subjects themselves
Show answer and explanation

Correct answer: B. The customer, as the controller

Communication duties follow data roles. That is why contracts with cloud providers must define how and how quickly the provider reports incidents to the customer.

  • A (incorrect)As a processor, the provider must inform the controller without undue delay — the notification to the authority is the controller's duty.
  • B (correct)Correct. Under GDPR Article 33, the controller notifies the supervisory authority; the processor must inform the controller.
  • C (incorrect)GDPR obligations can apply regardless of where the data is stored.
  • D (incorrect)Data subjects must be informed by the controller when the breach is likely to result in a high risk (Article 34), but they do not notify the authority.

Reference: GDPR, Articles 33 and 34 (opens in a new tab)

Domain 6

Legal, Risk and Compliance

6.3 Understand audit process, methodologies, and required adaptations for a cloud environmentFoundationDomain: Legal, Risk and Compliance

Question 21. A customer wants independent assurance that a cloud provider's security controls not only exist but operated effectively over a period of several months. Which report should the customer ask for?

  1. Option A: SOC 1 Type I
  2. Option B: SOC 2 Type I
  3. Option C: SOC 2 Type II
  4. Option D: SOC 3
Show answer and explanation

Correct answer: C. SOC 2 Type II

Two questions decide the report: what is covered (SOC 1 financial reporting, SOC 2 trust services criteria such as security) and when (Type I a point in time, Type II a period).

  • A (incorrect)SOC 1 covers controls relevant to financial reporting, and Type I only looks at one point in time.
  • B (incorrect)Type I assesses the design of controls at a single point in time, not their operation over a period.
  • C (correct)Correct. SOC 2 covers security-related trust services criteria, and Type II tests operating effectiveness over a period.
  • D (incorrect)A SOC 3 is a short general-use summary without the detailed test results.

Reference: ISC2 CCSP exam outline (opens in a new tab)

6.4 Understand implications of cloud to enterprise risk managementIntermediateDomain: Legal, Risk and Compliance

Question 22. A retailer stores its customers' personal data in a SaaS CRM. The CRM provider only processes the data on the retailer's documented instructions. Which roles do they have under the GDPR?

  1. Option A: The retailer is the processor and the CRM provider is the controller
  2. Option B: The retailer is the controller and the CRM provider is the processor
  3. Option C: Both are joint controllers
  4. Option D: The CRM provider is the data subject
Show answer and explanation

Correct answer: B. The retailer is the controller and the CRM provider is the processor

Accountability stays with the controller even when processing is outsourced. That is why the contract (a data processing agreement) and the provider's assurance reports matter.

  • A (incorrect)The roles are reversed: the party that decides purposes and means is the controller.
  • B (correct)Correct. The retailer decides why and how the data is processed; the provider processes it on the retailer's behalf.
  • C (incorrect)Joint control requires both to determine purposes and means together, which is not the case here.
  • D (incorrect)Data subjects are the individuals the data is about — here, the retailer's customers.

Reference: GDPR, Article 4 (definitions) and Article 28 (opens in a new tab)

6.1 Articulate legal requirements and unique risks within the cloud environmentIntermediateDomain: Legal, Risk and Compliance

Question 23. Which ISO/IEC standard series provides guidance on electronic discovery (eDiscovery)?

  1. Option A: ISO/IEC 27017
  2. Option B: ISO/IEC 27018
  3. Option C: ISO/IEC 27037
  4. Option D: ISO/IEC 27050
Show answer and explanation

Correct answer: D. ISO/IEC 27050

Several 270xx standards appear in cloud security work. Knowing which one covers what — 27017 cloud controls, 27018 PII in public cloud, 27037 evidence handling, 27050 eDiscovery — helps you pick the right standard in a scenario.

  • A (incorrect)ISO/IEC 27017 gives information security controls for cloud services.
  • B (incorrect)ISO/IEC 27018 covers the protection of personally identifiable information in public clouds.
  • C (incorrect)ISO/IEC 27037 covers identifying, collecting, acquiring and preserving digital evidence — related, but not eDiscovery.
  • D (correct)Correct. The ISO/IEC 27050 series addresses electronic discovery.

Reference: ISC2 CCSP exam outline (opens in a new tab)

6.3 Understand audit process, methodologies, and required adaptations for a cloud environmentAdvancedDomain: Legal, Risk and Compliance

Question 24. A SaaS provider's SOC 2 report uses the carve-out method for the IaaS provider that hosts the service. What does this mean for the SaaS customer?

  1. Option A: The IaaS provider's controls were tested as part of the SaaS provider's report
  2. Option B: The customer should obtain other assurance for the IaaS provider, such as that provider's own report
  3. Option C: The report is invalid and must be rejected
  4. Option D: The IaaS provider has no relevant controls
Show answer and explanation

Correct answer: B. The customer should obtain other assurance for the IaaS provider, such as that provider's own report

Always read the scope section of an audit report. Carved-out subservice organisations and complementary user entity controls show where your own assurance work starts.

  • A (incorrect)That describes the inclusive method. With carve-out, the subservice organisation's controls are excluded.
  • B (correct)Correct. The carved-out controls are outside the auditor's opinion, so the customer needs separate assurance for them.
  • C (incorrect)Carve-out is a recognised and common method; it limits the scope but does not invalidate the report.
  • D (incorrect)The controls exist; they simply were not tested in this report.

Reference: ISC2 CCSP exam outline (opens in a new tab)

Want more practice?

24 questions are a sample. The exam is 100 to 150 items.

The full CertRamp CCSP practice exams have 900 questions in 6 tests that grow with you — from a diagnostic start to an exam-level Test 4 and a challenge set beyond the exam, with an explanation for every option.