Question 541 of 964
easyMultiple ChoiceObjective-mapped
CCSP Practice Question: A company receives an erasure request under GDPR
A company receives an erasure request under GDPR. The cloud provider can delete from active storage within 24 hours but requires 90 days to delete from archives. The company has a contractual obligation to ensure deletion within 30 days. What should the company do?
⚠ Common exam trap
ISC2 often tests the misconception that a cloud provider's default retention policy absolves the controller of contractual or regulatory deadlines, when in fact the controller must actively manage the processor's actions or employ alternative technical controls like key destruction to meet the timeline.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request the provider to delete from archives within 30 days and verify.
The company has a contractual obligation to ensure deletion within 30 days, which overrides the provider's default 90-day archive retention policy. The company must formally request the provider to expedite the deletion from archives and verify compliance, as GDPR Article 17 requires the controller to ensure erasure without undue delay, and the provider as processor must assist. Relying on the provider's standard timeline without action would breach the contract and GDPR accountability requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the data from the application layer only and rely on provider for archives.
Why it's wrong here
Partial deletion does not satisfy the erasure request; the data subject expects complete deletion.
- ✗
Accept the 90-day timeline and inform the data subject accordingly.
Why it's wrong here
This violates the contractual 30-day requirement and may breach GDPR.
- ✓
Request the provider to delete from archives within 30 days and verify.
Why this is correct
This actively pursues compliance with both the contract and GDPR by expediting deletion.
- ✗
Reject the request as impractical.
Why it's wrong here
Rejection violates GDPR's right to erasure unless an exception applies.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 30, 2026
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.