Courseiva
Legal, Risk, and Compliance →mediumMultiple Choice

CCSP Legal, Risk, and Compliance Practice Question

A cloud customer stores data in a SaaS application that replicates across multiple jurisdictions. The customer's legal team must respond to a subpoena for data stored in a specific region. Which concept determines the legal authority over the data?

⚠ Common exam trap

The trap here is equating data residency with data sovereignty; residency is about physical location, while sovereignty is about which laws apply.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data sovereignty

Data sovereignty is the legal principle that data is governed by the laws of the country where it resides. When data is replicated across regions, each copy may fall under different sovereign laws. A subpoena from one jurisdiction may not be enforceable in another, and the cloud provider may be caught between conflicting legal demands. Understanding sovereignty helps legal teams navigate cross-border data requests and design compliance strategies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data residency

    Why it's wrong here

    Data residency refers to the physical location where data is stored, often chosen for compliance or performance. While related, it does not by itself determine legal authority; sovereignty is the legal principle. The scenario emphasizes legal authority, so residency alone is insufficient to answer the question.

  • ✗

    Data localization

    Why it's wrong here

    Data localization is a requirement to keep data within a specific country's borders. It is a regulatory mandate, not the concept that determines legal authority over data in a cross-border subpoena. The scenario involves multiple jurisdictions, and localization laws may not apply uniformly, so this is not the primary determinant.

  • ✓

    Data sovereignty

    Why this is correct

    Data sovereignty refers to the principle that data is subject to the laws and regulations of the country in which it is stored. In this scenario, the replication across jurisdictions means the data may be subject to multiple legal authorities. The subpoena's enforceability depends on which jurisdiction has sovereignty over the data at the time of the request, making this the key concept.

  • ✗

    Data portability

    Why it's wrong here

    Data portability is the right to transfer data between service providers, often under GDPR. It concerns consumer rights and interoperability, not legal authority over data in a subpoena. Thus, it is irrelevant to determining which jurisdiction's laws apply to the data.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.