Courseiva

CISA Protection of Information Assets Practice Question

An organization is implementing a privacy program to comply with GDPR. Which THREE of the following are essential elements for managing cross-border data transfers?

⚠ Common exam trap

The trap is selecting security measures like encryption or risk assessments as legal transfer mechanisms. Candidates might think encryption alone suffices, but GDPR requires a legal basis for transfer. The exam tests knowledge of the specific legal instruments (SCCs, adequacy, BCRs) that are explicitly recognized.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Standard Contractual Clauses (SCCs)

Standard Contractual Clauses (SCCs) (A) are a core GDPR transfer mechanism under Article 46, providing pre-approved contractual terms that legally safeguard personal data when it moves to a third country lacking an adequacy finding. An adequacy decision by the European Commission (C) is essential because under Article 45 it declares a third country's data protection regime essentially equivalent to the EU's, allowing transfers without additional safeguards. Binding Corporate Rules (BCRs) (D) are another Article 47 mechanism, essential for multinational groups to legitimize intra-group cross-border transfers through internally binding data protection policies approved by supervisory authorities. The unmarked options do not belong: a DPIA (B) is a risk assessment tool for high-risk processing, not a transfer mechanism, and encryption at rest (E) is a security control that may supplement but does not by itself legalize a cross-border transfer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Standard Contractual Clauses (SCCs)

    Why this is correct

    SCCs are the European Commission's approved contractual template that imposes GDPR-equivalent safeguards on a data importer in a third country lacking an adequacy decision. They provide the lawful transfer mechanism the privacy program requires for such restricted jurisdictions.

  • ✗

    Data Protection Impact Assessment (DPIA)

    Why it's wrong here

    A DPIA assesses risks of high-risk processing under Article 35; it is not a Chapter V transfer mechanism, so it neither authorises nor safeguards a cross-border transfer. It tempts because DPIAs are core GDPR compliance artefacts, and would be correct where the question asked how to evaluate a new high-risk processing activity.

  • ✓

    Adequacy decision by the European Commission

    Why this is correct

    An adequacy decision is a formal European Commission determination that a third country's legal framework offers essentially equivalent data protection, permitting transfers without further safeguards. It satisfies the GDPR transfer condition directly for any jurisdiction the Commission has so recognised.

  • ✓

    Binding Corporate Rules (BCRs)

    Why this is correct

    BCRs are binding, approved intra-group policies enabling multinational organisations to transfer personal data between their own entities under enforceable GDPR-equivalent protections. They supply the lawful transfer mechanism for internal cross-border flows where an adequacy decision is absent.

  • ✗

    Data encryption at rest

    Why it's wrong here

    Encryption at rest protects stored data on a device or volume; it does not govern the legal mechanism authorising a transfer to another jurisdiction, so it satisfies no GDPR Chapter V requirement. It tempts because encryption is a genuine GDPR security measure under Article 32, correct when the question concerns safeguarding data rather than transfer legality.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.