CCSP - Legal, Risk and Compliance - Section 6.3

Understand audit process, methodologies, and required adaptations for a cloud environment.

Internal and external audit controls, impact of audit requirements, assurance challenges of virtualisation and cloud, audit reports, gap analysis, audit planning, and the internal information security management system.

internal and external auditSOC 2 Type IIgap analysisaudit scope statementsinformation security management system (ISMS)

Practice question for this objective

Free sampleLegal, Risk and Compliancemedium

Aster Logistics processes confidential shipping data on an IaaS deployment in a public cloud. Its internal audit team is scoping an audit of the environment and must decide what falls within the audit boundary given the shared responsibility model. Which element is properly INSIDE the scope of Aster's own audit?

  • AThe physical security of the cloud provider's data centre facilities
  • BThe patching of the underlying hypervisor running the tenant's virtual machines
  • CThe configuration of guest operating systems and security groups the tenant manages Correct
  • DThe provider's internal staff vetting and background-check procedures
Scope a cloud audit to the layers the customer actually controls under the shared responsibility model for the service model in use. In IaaS the responsibility boundary places the guest OS, network configuration and application on the customer, while physical, hypervisor and provider-staff controls remain with the provider, so only the customer-managed layers belong in the customer's audit scope.

Why A is wrong: Physical facility security is the provider's responsibility under IaaS and is covered by the provider's own attestations, so it sits outside the customer's audit boundary.

Why B is wrong: The hypervisor is maintained by the provider in any cloud service model, so the tenant cannot audit or control its patching and it lies outside the customer scope.

Why C is correct: Under IaaS the customer manages the guest OS, network security groups and application layer, so these tenant-controlled configurations are squarely within Aster's own audit scope.

Why D is wrong: Provider personnel screening is part of the provider's control set assessed through its own audits, not something the customer includes in its audit scope.

See more CCSP practice questions, answers explained.

More in this domain

Back to all Legal, Risk and Compliance objectives, or the CCSP cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.