nerdexam
(ISC)2

CCSP · Question #304

The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common threats to organizations participating in cloud computing. A cloud customer that does not perform sufficient due…

The correct answer is B. Vendor lock-out. The problem where a cloud customer loses access to their data because their cloud provider has ceased operations is known as vendor lock-out.

Submitted by devops_kid· Apr 18, 2026Legal, Risk and Compliance

Question

The Cloud Security Alliance (CSA) publishes the Notorious Nine, a list of common threats to organizations participating in cloud computing. A cloud customer that does not perform sufficient due diligence can suffer harm if the cloud provider they've selected goes out of business. What do we call this problem? Response:

Options

  • AVendor lock-in
  • BVendor lock-out
  • CVendor incapacity
  • DUnscaled

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    94% (34)
  • C
    3% (1)

Why each option

The problem where a cloud customer loses access to their data because their cloud provider has ceased operations is known as vendor lock-out.

AVendor lock-in

Vendor lock-in refers to the difficulty or high cost associated with switching from one cloud provider to another, not the complete loss of access due to the provider's demise.

BVendor lock-outCorrect

Vendor lock-out is the specific term used to describe the situation where a customer loses access to their data and applications because a cloud provider has ceased operations or terminated services. This prevents the customer from retrieving or migrating their critical assets.

CVendor incapacity

"Vendor incapacity" is not a standard, recognized term in cloud security for the provider going out of business and causing data loss.

DUnscaled

"Unscaled" refers to a lack of scalability or inability to handle increased demand, which is unrelated to a provider ceasing operations.

Concept tested: Cloud vendor risks (Vendor Lock-out)

Topics

#Vendor lock-out#Cloud risks#Provider failure#CSA Notorious Nine

Community Discussion

No community discussion yet for this question.

Full CCSP Practice