Courseiva
Legal, Risk, and Compliance →mediumMultiple Select

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer must comply with GDPR's right to erasure (right to be forgotten). Which TWO of the following are technical challenges the customer faces when the data is stored in a cloud object storage service with versioning and cross-region replication?

⚠ Common exam trap

CCSP often tests GDPR data subject rights — candidates confuse the right to erasure (Article 17) with the right to data portability (Article 20) or pick encryption controls that address confidentiality rather than deletion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Removing previous versions of objects

Option B is correct because object storage versioning retains every prior version of an object, so a GDPR erasure request cannot be satisfied by simply deleting the current object; the customer must also enumerate and permanently remove all noncurrent versions (e.g., via S3 versioning delete markers plus explicit version deletion or lifecycle expiration). Option E is correct because cross-region replication creates additional copies in other regions, and the right to erasure requires those replicas to be deleted as well, which is technically challenging due to replication lag, delete-marker propagation behavior, and the need to verify deletion in every target region. Option A is not a right-to-erasure challenge but an access-control/network-restriction concern, typically handled with bucket policies, VPC endpoints, or IP conditions. Option C concerns encryption key management and confidentiality, not the deletion of data. Option D relates to data portability under GDPR Article 20, not the right to erasure under Article 17.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ensuring data is accessible only via a specific IP range

    Why it's wrong here

    IP-range restriction governs network access control, not erasure; it neither locates nor deletes replicated object versions. It is tempting because restricting access limits exposure, and it would be correct when the requirement is to confine data reach to trusted networks rather than to remove personal data entirely.

  • ✓

    Removing previous versions of objects

    Why this is correct

    Versioning retains every prior iteration of an object, so erasure requires enumerating and deleting each version individually rather than the current object alone. This satisfies the stem's versioning constraint, since residual versions still contain the personal data subject to the erasure request.

  • ✗

    Encrypting the data at rest with customer-managed keys

    Why it's wrong here

    Customer-managed keys protect confidentiality; they do not remove replicated object versions, so erasure remains unfulfilled. Encryption is tempting because it can render data unreadable, and it would be correct when the requirement is to control cryptographic access rather than to delete the data itself.

  • ✗

    Exporting data in a machine-readable format

    Why it's wrong here

    Machine-readable export supports GDPR portability, not erasure; it neither finds nor deletes object versions across replicas. It is tempting because both rights appear in the same regulation, and export would be correct when a data subject requests their data in a portable format rather than its deletion.

  • ✓

    Deleting data from all replicated copies across regions

    Why this is correct

    Cross-region replication asynchronously copies objects to multiple geographic locations, so deletion must be propagated to every replica. This satisfies the stem's replication constraint: erasing only the primary copy leaves personal data intact in remote regions, breaching the erasure obligation.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.