Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer is preparing for litigation and needs to place a legal hold on specific data stored in an object storage service. The cloud provider offers features such as object lock and retention policies. What is the primary challenge the customer must address to ensure the legal hold is effective across all copies of the data?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensuring that the legal hold is applied to all copies of the data, including replicas and backups, and that the hold prevents modification as well as deletion.

In cloud environments, data may be replicated across multiple regions or stored in backups. A legal hold must prevent deletion or alteration of all copies, including replicas and backups. Failure to apply hold to all copies can result in spoliation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensuring that the legal hold is time-limited and automatically expires after 90 days.

    Why it's wrong here

    A 90-day auto-expiry defeats the purpose, since a legal hold must persist until released, not lapse on a timer. It is tempting because retention policies commonly use fixed expiry periods, and a time-limited retention rule would be the correct choice for routine data lifecycle management rather than litigation.

  • ✓

    Ensuring that the legal hold is applied to all copies of the data, including replicas and backups, and that the hold prevents modification as well as deletion.

    Why this is correct

    Object lock and retention policies apply per object or bucket, so the challenge is propagating the hold to every replica and backup copy and enforcing immutability against both modification and deletion, ensuring no copy escapes the hold.

  • ✗

    Verifying that the cloud provider has a backup of the data in a different geographic region.

    Why it's wrong here

    Cross-region backup existence is irrelevant to hold effectiveness; the challenge is propagating the hold to every replica, version and derived copy. It is tempting because geographic redundancy is a genuine resilience concern, and verifying it would be the right step when assessing disaster recovery rather than litigation preservation.

  • ✗

    Obtaining a court order that specifically authorizes the cloud provider to preserve the data.

    Why it's wrong here

    A court order compelling the provider is not a technical prerequisite; object lock and retention policies are configured by the customer through the provider's API. It is tempting because litigation holds do carry legal weight, and a court order would be the correct instrument when demanding preservation from a third party that controls the data.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.