easyMultiple Choice
CCSP Practice Question: A company stores PII in the cloud and needs to…
A company stores PII in the cloud and needs to ensure compliance with GDPR. What is the first step they should take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform data classification and mapping
The first step is to perform data classification and mapping to identify what PII is held, where it resides, and how it flows. This foundational activity informs all subsequent GDPR compliance actions. Option A is incorrect because deleting data may be part of data minimization but not the first step. Option B is incorrect because encryption is a security control, not the initial step. Option C is incorrect because a Data Processing Agreement is signed after identifying and understanding data processing activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete all data older than the required retention period
Why it's wrong here
Deleting aged data addresses storage limitation, yet GDPR compliance begins with identifying what personal data is held, where and why. It is tempting because retention limits are a genuine GDPR principle, and deletion is the right action once a documented retention schedule has been established for each processing purpose.
- ✗
Implement encryption for all stored data
Why it's wrong here
Encryption is a security control under Article 32, not the initial compliance step; you cannot classify or protect data you have not yet mapped. It is tempting because encryption satisfies GDPR security expectations, and it is the correct measure once data flows, lawful bases and processor relationships are understood.
- ✗
Sign a Data Processing Agreement with the CSP
Why it's wrong here
A Data Processing Agreement governs the processor relationship but does not itself establish the lawful basis, data mapping or records GDPR demands first. It is tempting because Article 28 requires such an agreement with any processor, and signing one is correct once the processing activities and lawful basis have been documented.
- ✓
Perform data classification and mapping
Why this is correct
Data classification and mapping identifies what personal data exists, where it resides and how it flows, which is the prerequisite for every subsequent GDPR control. Without this inventory, lawful basis, retention and subject-rights obligations cannot be scoped or evidenced.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.