nerdexam
(ISC)2

CCSP · Question #440

Which of the following components are part of what a CCSP should review when looking at contracting with a cloud service provider?

The correct answer is D. Use of subcontractors. The use of subcontractors can add risk to the supply chain and should be considered; trusting the provider's management of their vendors and suppliers (including subcontractors) is important to trusting the provider. Conversely, the customer is not likely to be allowed to review

Submitted by manish99· Apr 18, 2026Legal, Risk and Compliance

Question

Which of the following components are part of what a CCSP should review when looking at contracting with a cloud service provider?

Options

  • ARedundant uplink grafts
  • BBackground checks for the provider's personnel
  • CThe physical layout of the datacenter
  • DUse of subcontractors

How the community answered

(50 responses)
  • A
    8% (4)
  • B
    6% (3)
  • C
    2% (1)
  • D
    84% (42)

Explanation

The use of subcontractors can add risk to the supply chain and should be considered; trusting the provider's management of their vendors and suppliers (including subcontractors) is important to trusting the provider. Conversely, the customer is not likely to be allowed to review the physical design of the datacenter (or, indeed, even know the exact location of the datacenter) or the personnel security specifics for the provider's staff. "Redundant uplink grafts" is a nonsense term used as a distractor.

Topics

#Cloud contracting#Vendor management#Third-party risk#Due diligence

Community Discussion

No community discussion yet for this question.

Full CCSP Practice