CCSP Cloud Data Security Practice Question
A company is required by a data sovereignty law to ensure that all data generated by its EU customers is stored and processed within the EU. The company uses a cloud provider with data centers in multiple regions. Which cloud storage configuration should they implement?
⚠ Common exam trap
CCSP often tests the misconception that encryption or data classification alone can satisfy data sovereignty requirements, when in fact they do not control data location; the key is to ensure data remains within the required legal jurisdiction by selecting appropriate regions and disabling cross-region replication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Select a cloud region located in the EU and disable cross-region replication.
Data sovereignty requires that data remains within a specific legal jurisdiction. By selecting a cloud region physically located in the EU and disabling cross-region replication, the company ensures that data is stored and processed only within EU borders, satisfying the legal requirement. Cross-region replication, even within the same country, could still violate the law if the replication target is outside the EU or if the law requires strict in-region processing. Encryption and classification do not change the physical location of data, so they do not address sovereignty.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable cross-region replication to a region in the same country.
Why it's wrong here
Cross-region replication copies data to another region, which may lie outside the EU, breaching the sovereignty requirement. It is tempting because replication improves durability and availability, and would be correct for disaster recovery or latency reduction, not for confining storage and processing to a single jurisdiction.
- ✓
Select a cloud region located in the EU and disable cross-region replication.
Why this is correct
Pinning storage to an EU region satisfies the residency requirement, since object data physically resides on EU soil. Disabling cross-region replication prevents automatic copying of objects to non-EU regions, closing the secondary path by which data could leave the jurisdiction.
- ✗
Use client-side encryption for all EU data.
Why it's wrong here
Client-side encryption protects confidentiality but leaves ciphertext in whatever region the provider stores it, so EU data can still reside outside the EU. It is tempting because it addresses data-at-rest exposure; it would be the right control when the requirement is protecting data from the provider itself, not enforcing geographic residency.
- ✗
Apply data classification labels to all EU data.
Why it's wrong here
Classification labels tag and govern data but do not constrain where it is stored or processed, so EU records can still replicate to non-EU regions. Labels are tempting because they drive policy enforcement; they would be correct when the requirement is identifying sensitive data for handling rules, not enforcing geographic residency.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.