CCSP Legal, Risk, and Compliance 1 — Questions and Answers
Question 1: Which framework provides a set of controls specifically designed to assess the security of cloud service providers?
- NIST SP 800-53
- Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) (Correct answer)
- ISO/IEC 27001
- CIS Benchmarks
Correct answer: Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix (CCM) is a cybersecurity control framework specifically designed for cloud computing, mapping controls to regulatory standards and cloud service models.
Question 2: What is the primary purpose of a Business Associate Agreement (BAA) in the context of HIPAA compliance in the cloud?
- To establish pricing between a company and its cloud provider
- To legally obligate a cloud vendor handling PHI to comply with HIPAA security and privacy requirements (Correct answer)
- To authorize the cloud provider to share medical data with third parties
- To certify that a cloud provider has passed a HIPAA audit
Correct answer: To legally obligate a cloud vendor handling PHI to comply with HIPAA security and privacy requirements
A BAA is a legally binding contract required by HIPAA whenever a covered entity shares protected health information (PHI) with a third-party service provider.
Question 3: What type of audit report provides a detailed description of a service organization's controls but is intended for restricted distribution?
- SOC 1 Type II
- SOC 2 Type II (Correct answer)
- SOC 3
- ISO/IEC 27001 certificate
Correct answer: SOC 2 Type II
SOC 2 Type II reports provide detailed descriptions and evidence of controls over a period of time and are restricted to customers and stakeholders under NDA.
Question 4: What is the primary focus of the EU General Data Protection Regulation (GDPR) as it applies to cloud computing?
- Cloud service pricing transparency
- Protection of EU residents' personal data and enforcement of privacy rights including consent, access, and erasure (Correct answer)
- Security certification requirements for cloud providers
- Network performance standards for cloud services
Correct answer: Protection of EU residents' personal data and enforcement of privacy rights including consent, access, and erasure
GDPR mandates how organizations collect, process, store, and delete EU residents' personal data, imposing strict consent requirements, data subject rights, and breach notification obligations.
Question 5: In cloud risk management, what does quantitative risk analysis produce that qualitative analysis does not?
- A color-coded risk heat map
- Numerical estimates of risk in monetary terms (e.g., Annual Loss Expectancy) (Correct answer)
- A descriptive ranking of risks as high, medium, or low
- A list of applicable compliance frameworks
Correct answer: Numerical estimates of risk in monetary terms (e.g., Annual Loss Expectancy)
Quantitative risk analysis calculates numerical values such as ALE (Annual Loss Expectancy) = ARO × SLE, enabling cost-benefit comparison of security controls.
Question 6: What is the role of the Data Protection Officer (DPO) under GDPR?
- To sell personal data to marketing partners
- To ensure the organization complies with GDPR, advise on data protection obligations, and act as a contact for supervisory authorities (Correct answer)
- To manage the organization's cloud infrastructure security
- To conduct penetration tests on cloud environments
Correct answer: To ensure the organization complies with GDPR, advise on data protection obligations, and act as a contact for supervisory authorities
The DPO is an independent role required by GDPR for certain organizations to oversee data protection strategy, ensure compliance, and liaise with data protection authorities.
Which framework provides a set of controls specifically designed to assess the security of cloud service providers?