CCAK · Question #32
To support customer's verification of the CSP claims regarding their responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?
The correct answer is D. Security assessment. A security assessment is the direct mechanism customers use to verify CSP security claims. It involves evaluating the CSP's actual security posture against stated responsibilities - testing controls, reviewing configurations, and validating that the CSP is fulfilling its side…
Question
To support customer's verification of the CSP claims regarding their responsibilities according to the shared responsibility model, which of the following tools and techniques is appropriate?
Options
- AContractual agreement
- BInternal audit
- CExternal audit
- DSecurity assessment
How the community answered
(35 responses)- A11% (4)
- B6% (2)
- C3% (1)
- D80% (28)
Explanation
A security assessment is the direct mechanism customers use to verify CSP security claims. It involves evaluating the CSP's actual security posture against stated responsibilities - testing controls, reviewing configurations, and validating that the CSP is fulfilling its side of the shared responsibility model. A contractual agreement (A) defines obligations but doesn't verify them. An internal audit (B) focuses on the customer's own environment. An external audit (C) is comprehensive but is typically performed by a third party on the CSP's behalf. A security assessment is the practical, targeted tool for a customer to independently validate CSP claims.
Topics
Community Discussion
No community discussion yet for this question.