CCSP Legal, Risk, and Compliance Practice Question
A company is negotiating a cloud contract and wants to ensure data ownership and deletion. Which TWO clauses should be included? (Select two.)
⚠ Common exam trap
The trap is selecting clauses that are generally important (like right to audit or SLA) but do not specifically address the question's focus on data ownership and deletion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data ownership clause
Option C, the data ownership clause, is correct because it contractually establishes that the company retains legal ownership of its data stored or processed by the cloud provider, preventing the provider from claiming rights over that data. Option E, the data deletion clause, is correct because it specifies the provider's obligations to securely and verifiably delete the company's data upon contract termination or on request, including timelines and certification of destruction. Option A, the right to audit clause, is not among the marked correct answers because while it supports compliance verification, it does not directly address ownership or deletion of data. Option B, the non-disclosure agreement, is not marked correct because it protects confidentiality of shared information but does not establish data ownership or mandate deletion. Option D, the service level agreement, is not marked correct because it defines performance metrics such as uptime and availability, not data ownership or deletion rights.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Right to audit clause
Why it's wrong here
A right to audit grants inspection of provider controls and records; it does not establish data ownership or mandate deletion upon termination. It is tempting because audit rights feel like strong contractual protection, and this clause would be correct when the requirement is verifying compliance controls rather than specifying ownership and destruction.
- ✗
Non-disclosure agreement
Why it's wrong here
NDA protects confidentiality, not data ownership or deletion.
- ✓
Data ownership clause
Why this is correct
A data ownership clause contractually confirms the customer retains all rights to its data stored or processed in the cloud, preventing the provider from claiming or exploiting it. This directly satisfies the stated requirement to ensure data ownership.
- ✗
Service level agreement
Why it's wrong here
An SLA defines uptime, performance and support response targets, not who owns the data or how it is destroyed at contract end. It is tempting because availability guarantees feel central to cloud contracting, and an SLA would be the right clause when negotiating measurable service commitments and remedies for outages.
- ✓
Data deletion clause
Why this is correct
A data deletion clause contractually binds the provider to erase the company's data on termination, satisfying the stem's deletion requirement. It specifies retention periods, verification evidence, and backup disposal timelines, ensuring the customer retains control over data lifecycle rather than relying on provider defaults.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.