You must map legal duties to cloud controls: know the GDPR 72-hour notification trigger, apply S3 Object Lock legal hold for eDiscovery, and keep PCI DSS customer obligations despite provider assessments. The key is correctly assigning responsibility between provider and customer under shared controls.
Start practicing
Legal, Risk, and Compliance — choose a session length
Free · No account required
Domain overview
This domain covers how cloud adoption reshapes legal obligations, risk management, and compliance accountability. It tests GDPR breach timelines, PCI DSS shared responsibility, eDiscovery holds on cloud storage, jurisdictional conflicts, and contract/audit artifacts. Expect scenario questions where you must pick the correct AWS control, legal deadline, or compliance responsibility rather than recite definitions.
Exam objectives
GDPR 72-hour controller notification to supervisory authority after awareness of a personal data breach
AWS S3 Object Lock in legal hold mode to preserve objects for eDiscovery
PCI DSS responsibility split between cloud provider and customer, evidenced by QSA assessment
Cross-border eDiscovery challenges: data sovereignty, conflicting laws, and provider control limits
Treating the 72-hour GDPR clock as starting at breach discovery by a third party rather than controller awareness.
Assuming a QSA-assessed cloud provider transfers all PCI DSS obligations to the provider instead of retaining customer responsibilities.
Confusing S3 Object Lock retention modes with legal hold, or believing deletion protection alone satisfies eDiscovery preservation.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A covered entity under HIPAA is planning to migrate electronic protected health information (ePHI) to a public cloud environment. Which of the following is a mandatory requirement before using the cloud service?
2A cloud customer receives a litigation hold notice requiring preservation of data stored in an object storage service. Which service feature should the customer use to ensure data cannot be modified or deleted until the hold is released?
3A company is negotiating a cloud service agreement and wants to ensure it can verify the provider's security controls independently. Which contractual clause is essential for this purpose?
4A cloud provider's data center is located in Country A, but the customer's data is subject to litigation in Country B. The court in Country B orders the cloud provider to produce data. The cloud provider refuses, citing Country A's laws that prohibit disclosure. This situation best illustrates which challenge in eDiscovery?
5When assessing cloud risk, an organization identifies that if a single cloud provider fails, the organization cannot operate. This risk is known as:
6A company using a SaaS application for HR management receives a data subject access request (DSAR) under GDPR from an employee. The cloud provider is the data processor. The company as data controller must respond within what timeframe?
7A cloud customer is considering adopting a multi-cloud strategy to avoid vendor lock-in. Which risk is this strategy primarily intended to mitigate?
8A cloud customer is terminating its contract with a cloud provider and needs to ensure all data, including backups, is permanently deleted. Which contractual clause is most relevant?
9A cloud customer must comply with GDPR's right to erasure (right to be forgotten). Which TWO of the following are technical challenges the customer faces when the data is stored in a cloud object storage service with versioning and cross-region replication?
10A company subject to SOX is using a cloud ERP system. Which THREE of the following IT general controls are essential for SOX compliance?
11A covered entity under HIPAA is moving electronic protected health information (ePHI) to a public cloud. What is the primary requirement before the cloud provider hosts ePHI?
12A company subject to PCI DSS is considering a cloud provider to process credit card transactions. What must the cloud provider present to demonstrate compliance with PCI DSS?
13During an eDiscovery process, a company needs to preserve data stored in AWS S3 that may be relevant to a lawsuit. Which AWS feature should be used to implement a legal hold?
14A cloud customer is negotiating a contract and wants to ensure they have the right to verify the cloud provider's security controls. Which contractual provision is most important?
15A company is using a single cloud provider for all critical services. What is the primary risk this company faces?
16Under GDPR, a cloud data controller must notify the supervisory authority of a personal data breach within what timeframe?
17A cloud customer wants to ensure that when the contract ends, the cloud provider deletes all customer data, including from backups. Which contractual clause is essential?
18A cloud customer is concerned about the risk of unauthorized access to data due to the shared infrastructure of a public cloud. What type of risk does this represent?
19A company needs to export data from a cloud service in a machine-readable format to comply with a data subject's right to data portability under GDPR. Which format is most appropriate?
20A global company uses a cloud provider that stores data in multiple jurisdictions. During an eDiscovery request from a US court, which three challenges are most likely to arise? (Choose three.)
21A company is adopting a multi-cloud strategy to reduce concentration risk. Which two benefits are directly associated with this approach? (Choose two.)
22A healthcare organization stores protected health information (PHI) in a cloud environment. Under HIPAA, what must the organization obtain from the cloud provider before processing PHI?
23Under GDPR, what is the maximum time allowed for a data controller to notify the supervisory authority of a personal data breach?
24A company is subject to PCI DSS and plans to use a cloud provider to process credit card transactions. The cloud provider has been assessed by a Qualified Security Assessor (QSA). According to PCI DSS, what must the company obtain from the provider to demonstrate compliance?
25A company is subject to a legal hold order and uses a cloud storage service with object replication across multiple regions. Which cloud feature should the company use to prevent deletion or modification of relevant data?
26A cloud customer wants to ensure they can audit their cloud provider's security controls annually. Which contractual provision should be included in the cloud service agreement?
27Which CSA STAR tier involves a third-party assessment against ISO 27001?
28A company is evaluating the risk of using a single cloud provider for all critical workloads. Which risk is most directly associated with this scenario?
29In a cloud environment, a data subject exercises their right to erasure under GDPR. The cloud provider has multiple replicas and backups. What is the primary technical challenge in fulfilling this request?
30Under GDPR, what is the role of a cloud provider that processes personal data solely on behalf of a customer?
31A company wants to export its data from a cloud provider to another provider upon contract termination. Which contract clause is essential to ensure the data can be exported in a usable format?
32A company is negotiating a cloud contract and wants to ensure data ownership and deletion. Which TWO clauses should be included? (Select two.)
33A global enterprise is conducting a cloud risk assessment. Which THREE factors should be considered? (Select three.)
34A healthcare provider is planning to migrate its electronic health records (EHR) system to a public cloud infrastructure. The system will store protected health information (PHI). Under HIPAA, what must the healthcare provider obtain from the cloud service provider before beginning the migration?
35A financial institution is required to comply with the Sarbanes-Oxley Act (SOX) for its cloud-hosted financial applications. The cloud provider is responsible for the underlying infrastructure. Which of the following controls is most likely the responsibility of the financial institution as part of IT general controls (ITGC)?
36Under the General Data Protection Regulation (GDPR), if a cloud service provider (acting as a data processor) suffers a personal data breach, what is the provider's obligation regarding notification?
37A cloud customer is preparing for litigation and needs to place a legal hold on specific data stored in an object storage service. The cloud provider offers features such as object lock and retention policies. What is the primary challenge the customer must address to ensure the legal hold is effective across all copies of the data?
38A company is negotiating a cloud service agreement and wants to ensure it can periodically assess the security of the cloud provider's operations. Which contractual clause is most directly relevant to this requirement?
39Which of the following is a key requirement for data portability under the General Data Protection Regulation (GDPR)?
40A multinational corporation uses multiple cloud service providers for its critical applications. The board is concerned about concentration risk. Which strategy would best address this risk?
41A cloud customer is subject to eDiscovery requirements in a lawsuit. The data resides in a cloud storage service that uses encryption. What is the primary challenge in collecting this data in a forensically sound manner?
42Which of the following best describes the purpose of the Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) program?
43A cloud customer is concerned about the right to erasure under GDPR because the cloud provider replicates data across multiple regions and keeps backups. What technical challenge does this create for complying with a erasure request?
44A cloud customer is assessing the risk of using a cloud provider. Which THREE factors are most important in evaluating the inherent risk of migrating data and applications to the cloud?
45In the context of eDiscovery, a legal hold must be placed on data stored in a cloud environment. Which THREE actions should the cloud customer take to ensure the legal hold is effective?
46A multinational corporation is implementing a multi-cloud strategy to avoid concentration risk. The risk management team is evaluating the inherent risks of using multiple cloud providers. Which THREE risks are specifically associated with a multi-cloud strategy? (Choose three.)
47A cloud customer is negotiating a contract with a new cloud provider. The customer wants to ensure they can maintain control over their data and verify the provider's security posture. Which TWO contractual provisions are most critical for these purposes? (Choose two.)
48A healthcare analytics company processes electronic protected health information (ePHI) for multiple covered entities using a public cloud provider. The company signs a Business Associate Agreement (BAA) with each covered entity and also signs a BAA with the cloud provider. A security analyst discovers that the cloud provider stores backups of the ePHI in a region outside the United States and refuses to sign a separate BAA for that region. Which of the following is the MOST appropriate action for the company to take to maintain compliance with HIPAA?
49A cloud customer is subject to a regulatory audit and must provide evidence of the cloud provider's security controls. The provider refuses to allow direct audits of its data centers. Which artifact should the customer rely on to satisfy the auditors?
50A European retail company is migrating its customer analytics platform to a public cloud provider. The dataset contains personal data of EU residents, and the company wants to minimize the risk of regulatory enforcement action if the cloud provider suffers a breach. Which action BEST addresses the shared responsibility for compliance in this scenario?
51A cloud customer stores data in a SaaS application that replicates across multiple jurisdictions. The customer's legal team must respond to a subpoena for data stored in a specific region. Which concept determines the legal authority over the data?
52A cloud customer is subject to an eDiscovery request and stores business records in a cloud object storage service. The legal team needs to preserve potentially relevant data and prevent it from being altered or deleted while the matter is active. Which cloud capability should the customer configure to meet this obligation?
53A cloud customer's legal team must decide which party bears responsibility for generating audit evidence that demonstrates regulatory compliance. The customer uses IaaS from a provider. According to the CSA Cloud Controls Matrix and shared responsibility principles, how should audit evidence obligations be divided?
54A European retailer stores customer personal data in a cloud-hosted e-commerce platform. The cloud provider processes data only on documented instructions from the retailer, which determines the purposes and means of processing. Under the General Data Protection Regulation (GDPR), which role does the cloud provider hold?
55A cloud customer is subject to a regulatory audit and must provide evidence that the cloud provider's security controls are effective. The customer has no right to audit the provider directly but can rely on third-party attestations. Which report should the customer request to obtain an independent assessment of the provider's controls relevant to security, availability, and confidentiality?
56A company is migrating to a public cloud and must ensure compliance with PCI DSS. Which responsibility does the cloud customer retain under the shared responsibility model?
57A cloud customer requires that its data stored by a provider be irretrievably destroyed after contract termination, even if the provider uses backup tapes and replicated storage. Which contractual and technical provision best supports this requirement?
58A cloud service provider is expanding into a new jurisdiction and must demonstrate compliance with local data protection laws. The provider's legal team is reviewing the shared responsibilities between the provider and its customers. Which TWO activities are the provider's responsibility under a typical cloud shared responsibility model? (Choose two.)
59A US-based retail company stores customer personal data in a cloud provider's data center located in Germany. The company is subject to GDPR because it offers goods to EU residents. Which legal mechanism most directly establishes that the controller and the cloud provider may lawfully transfer personal data from the EU to the provider's US-based support team?
60A cloud customer is assessing a provider's compliance with the Cloud Security Alliance (CSA) STAR program. Which TWO artifacts are part of the STAR program? (Choose two.)
61A cloud provider discovers a security incident affecting a customer's personal data stored in its platform. The customer acts as the data controller under the General Data Protection Regulation (GDPR). Which obligation does the provider have regarding notification of this breach?
62A cloud customer is reviewing its contract with a cloud provider. The customer wants to ensure that if the provider subcontracts any part of the service to a third party, the customer's data remains protected. Which contract provision is most critical to address this risk?
63A cloud customer is evaluating a provider's compliance with the Payment Card Industry Data Security Standard (PCI DSS). The customer plans to store cardholder data in the provider's IaaS environment. Which responsibility does the customer retain under PCI DSS?
64A cloud customer is reviewing its incident response plan and wants to ensure it can meet regulatory breach notification timelines. The customer's data is hosted by a cloud provider that does not automatically notify customers of security incidents. Which action should the customer take FIRST to address this gap?
65A multinational retailer uses a SaaS e-commerce platform hosted in the EU and serves customers in the EU, the UK, and the US. The legal team must determine which cross-border data transfer mechanism can be used to lawfully move customer personal data from the EU entity to the US parent company for analytics. Which mechanism should the legal team select?
66A cloud customer's security team learns that a provider's subprocessor experienced a breach affecting the customer's data. The customer's contract requires the provider to notify the customer of subprocessor breaches. Under the GDPR, within what timeframe must the cloud provider, acting as a processor, notify the controller of a personal data breach?
67A U.S. financial services firm uses a cloud provider with data centers in the EU. The firm must comply with both SEC regulations requiring books and records preservation and the GDPR. A data subject requests erasure of personal data that is also subject to a legal hold. What should the firm do?
68A cloud service provider wants to demonstrate compliance with ISO/IEC 27017 for cloud services. Which TWO controls are specific additions that this standard introduces beyond ISO/IEC 27002? (Choose two.)
69A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The customer must ensure compliance with legal and regulatory requirements. Which TWO factors are most important to address in the contract with the provider? (Choose two.)
70A cloud provider operates a public IaaS environment. A customer's legal team is reviewing the provider's audit rights clause and wants to ensure the provider will cooperate with a regulatory examination by a financial services regulator. The provider's standard contract currently states that customers may review SOC 2 reports annually but does not grant any right to audit. Which action should the customer's legal team take to best satisfy the regulator's expectations while maintaining a workable relationship with the provider?
71A multinational company is evaluating a cloud provider for a workload that processes personal data of employees in several countries. The company wants to ensure that cross-border data transfers comply with legal requirements. Which consideration is MOST important when assessing the provider's data transfer mechanisms?
72A cloud customer operates a SaaS-based HR platform in the EU and receives a data subject access request (DSAR) from an employee. The provider's standard contract states it will only assist with DSARs on a 'reasonable efforts' basis and bills hourly for that assistance. Under GDPR Article 28, which contractual element must the customer ensure is in place before relying on this SaaS platform?
73A cloud customer is subject to the EU GDPR and stores personal data with a provider that replicates it across data centers in several countries. The customer's legal team must confirm that appropriate safeguards exist for each international transfer. Which TWO elements are required for a valid transfer under GDPR Chapter V? (Choose two.)
74A cloud customer stores personal data of EU residents in a SaaS application. The customer's contract with the SaaS provider includes a data processing addendum. The customer's legal team wants to understand the allocation of GDPR responsibilities. Which of the following best describes the roles of the customer and the SaaS provider under GDPR?
75A cloud customer stores regulated data with a provider that uses sub-processors in multiple countries. The customer's legal team wants to ensure that international transfers of personal data remain lawful under the General Data Protection Regulation (GDPR). Which mechanism is the most appropriate to implement with the provider?
76A US-based cloud customer stores EU personal data in a provider's Singapore region and uses the provider's support team located in India. The customer relies on the EU-US Data Privacy Framework (DPF) for its own US transfers. Which action is required to legitimize the support team's access to that EU data?
77A cloud customer is subject to the Payment Card Industry Data Security Standard (PCI DSS) and uses a cloud provider to store cardholder data. The customer wants to reduce its PCI DSS scope. Which of the following provider attestations would best support scope reduction for the customer?
78A cloud customer is preparing for an audit of its provider and wants to rely on the provider's existing independent attestation rather than conduct its own on-site review. Which document should the customer request to evaluate the provider's controls over security, availability, and confidentiality?
79A cloud customer's legal team is reviewing a provider's contract and finds a clause requiring the customer to resolve all disputes through binding arbitration in the provider's home country. The customer operates in several jurisdictions and wants to preserve its options. Which contract provision should the customer negotiate to best address this concern?
80A cloud customer is preparing for an audit of its cloud environment. The provider offers a SOC 2 Type II report covering security and availability. What does this report provide to the customer's auditors?
81A cloud customer's provider announces that a sub-processor in a new jurisdiction will begin handling EU personal data next month. The customer's DPA gives it a right to object but states that continued use of the service constitutes acceptance. Which action best preserves the customer's legal position under GDPR Article 28(2)?
82A multinational bank uses a cloud provider for a system that processes customer transactions. A regulator asks the bank to demonstrate that it maintains effective control over the data and can meet its legal obligations even if the provider fails. Which activity best demonstrates that the bank has retained accountability for the outsourced processing?
83A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The legal team must ensure the policy addresses key contractual and regulatory considerations. Which TWO elements should the policy include? (Choose two.)
84A cloud customer is building its compliance monitoring program for a provider-hosted workload that processes regulated data. The customer must ensure it can demonstrate ongoing compliance to regulators between audits. Which TWO provider commitments should the customer secure in the contract to sustain continuous compliance evidence? (Choose two.)
You must map legal duties to cloud controls: know the GDPR 72-hour notification trigger, apply S3 Object Lock legal hold for eDiscovery, and keep PCI DSS customer obligations despite provider assessments. The key is correctly assigning responsibility between provider and customer under shared controls.
The Courseiva CCSP question bank contains 84 questions in the Legal, Risk, and Compliance domain, covering the 13% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Legal, Risk, and Compliance domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included