Courseiva
easyMultiple Choice

CCSP Practice Question: A company stores PII in the cloud and needs to…

A company stores PII in the cloud and needs to ensure compliance with GDPR. What is the first step they should take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Perform data classification and mapping

The first step is to perform data classification and mapping to identify what PII is held, where it resides, and how it flows. This foundational activity informs all subsequent GDPR compliance actions. Option A is incorrect because deleting data may be part of data minimization but not the first step. Option B is incorrect because encryption is a security control, not the initial step. Option C is incorrect because a Data Processing Agreement is signed after identifying and understanding data processing activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete all data older than the required retention period

    Why it's wrong here

    Deleting aged data addresses storage limitation, yet GDPR compliance begins with identifying what personal data is held, where and why. It is tempting because retention limits are a genuine GDPR principle, and deletion is the right action once a documented retention schedule has been established for each processing purpose.

  • ✗

    Implement encryption for all stored data

    Why it's wrong here

    Encryption is a security control under Article 32, not the initial compliance step; you cannot classify or protect data you have not yet mapped. It is tempting because encryption satisfies GDPR security expectations, and it is the correct measure once data flows, lawful bases and processor relationships are understood.

  • ✗

    Sign a Data Processing Agreement with the CSP

    Why it's wrong here

    A Data Processing Agreement governs the processor relationship but does not itself establish the lawful basis, data mapping or records GDPR demands first. It is tempting because Article 28 requires such an agreement with any processor, and signing one is correct once the processing activities and lawful basis have been documented.

  • ✓

    Perform data classification and mapping

    Why this is correct

    Data classification and mapping identifies what personal data exists, where it resides and how it flows, which is the prerequisite for every subsequent GDPR control. Without this inventory, lawful basis, retention and subject-rights obligations cannot be scoped or evidenced.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.