nerdexam
CSA

CCSK · Question #66

CCM: A company wants to use the IaaS offering of some CSP. Which of the following options for using CCM is NOT suitable for the company as a cloud customer?

The correct answer is A. Submit the CCM on behalf of the CSP to CSA Security, Trust & Assurance Registry (STAR), a. The CSA Cloud Controls Matrix (CCM) is a cybersecurity framework for cloud environments. This question tests whether students understand the boundary between cloud customer and CSP responsibilities when using CCM.

Governance

Question

CCM: A company wants to use the IaaS offering of some CSP. Which of the following options for using CCM is NOT suitable for the company as a cloud customer?

Options

  • ASubmit the CCM on behalf of the CSP to CSA Security, Trust & Assurance Registry (STAR), a
  • BUse CCM to build a detailed list of requirements and controls that they want their CSP to
  • CUse CCM to help assess the risk associated with the CSP
  • DNone of the above

How the community answered

(33 responses)
  • A
    82% (27)
  • B
    3% (1)
  • C
    9% (3)
  • D
    6% (2)

Why each option

The CSA Cloud Controls Matrix (CCM) is a cybersecurity framework for cloud environments. This question tests whether students understand the boundary between cloud customer and CSP responsibilities when using CCM.

ASubmit the CCM on behalf of the CSP to CSA Security, Trust & Assurance Registry (STAR), aCorrect

Submitting the CCM assessment to the CSA STAR registry is the sole responsibility of the CSP, not the cloud customer. The STAR registry is a publicly accessible registry where CSPs self-publish their security and compliance posture. A cloud customer has no authority or standing to submit documentation to STAR on a CSP's behalf.

BUse CCM to build a detailed list of requirements and controls that they want their CSP to

Building a detailed list of requirements and controls to present to a CSP is a valid and intended use of CCM for cloud customers during vendor evaluation and procurement.

CUse CCM to help assess the risk associated with the CSP

Using CCM to assess the risk of a CSP is a core intended use case for cloud customers, as the matrix provides a structured control framework for evaluating provider security.

DNone of the above

This is incorrect because option A is genuinely not suitable for a cloud customer, meaning at least one answer qualifies and 'None of the above' does not apply.

Concept tested: CSA CCM customer vs. CSP STAR submission responsibility

Source: https://cloudsecurityalliance.org/research/cloud-controls-matrix/

Topics

#CCM#CSA STAR#IaaS#cloud customer controls

Community Discussion

No community discussion yet for this question.

Full CCSK Practice