nerdexam
(ISC)2

CCSP · Question #223

Which of the following are contractual components that the CSP should review and understand fully when contracting with a cloud service provider? (Choose two.)

The correct answer is B. Use of subcontractors D. Scope of processing. When contracting with a cloud service provider, the customer (CSP) must thoroughly understand the use of subcontractors and the explicit scope of processing to manage supply chain risks and ensure data privacy compliance.

Submitted by hans_de· Apr 18, 2026Legal, Risk and Compliance

Question

Which of the following are contractual components that the CSP should review and understand fully when contracting with a cloud service provider? (Choose two.)

Options

  • AConcurrently maintainable site infrastructure
  • BUse of subcontractors
  • CRedundant site infrastructure capacity components
  • DScope of processing

How the community answered

(69 responses)
  • A
    7% (5)
  • B
    88% (61)
  • C
    4% (3)

Why each option

When contracting with a cloud service provider, the customer (CSP) must thoroughly understand the use of subcontractors and the explicit scope of processing to manage supply chain risks and ensure data privacy compliance.

AConcurrently maintainable site infrastructure

Concurrently maintainable site infrastructure is a technical design aspect that contributes to availability, but its specifics are typically a provider's internal concern, not an explicit contractual component a customer reviews in detail.

BUse of subcontractorsCorrect

Understanding the use of subcontractors is critical as it identifies third parties who may access or process the customer's data, impacting security, compliance, and data sovereignty. This allows the customer to assess extended supply chain risks.

CRedundant site infrastructure capacity components

Redundant site infrastructure capacity components are technical details that ensure resilience; customers primarily focus on the service levels (SLAs) for availability, rather than the specific internal components achieving it.

DScope of processingCorrect

Defining the scope of processing explicitly outlines what data the cloud provider is authorized to collect, store, process, and transmit, for what purposes, and under what conditions. This is fundamental for regulatory compliance, especially with data protection laws like GDPR, ensuring the provider does not exceed its contractual authority.

Concept tested: Cloud contract clauses for customers

Source: https://gdpr-info.eu/art-28-gdpr/

Topics

#Cloud contracts#Vendor management#Data processing#Subcontractor agreements

Community Discussion

No community discussion yet for this question.

Full CCSP Practice