hardMultiple Choice
CCSP Practice Question: A company uses a cloud-based intrusion detection…
A company uses a cloud-based intrusion detection system (IDS) that generates logs containing IP addresses. The company is headquartered in a country with data localization laws. What is the primary compliance risk?
⚠ Common exam trap
Watch out — candidates often confuse security risks (like tampering) with compliance risks. Candidates might focus on the technical aspects of IDS logs rather than the legal implications of cross-border data processing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log data containing personal data may be processed in a different jurisdiction
The primary compliance risk is that log data containing personal data (such as IP addresses, which can be considered personal data under GDPR and other laws) may be processed in a different jurisdiction. Data localization laws require that certain data be stored and processed within the country's borders. If the cloud-based IDS processes logs outside the country, it could violate these laws.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The logs may be tampered with in transit
Why it's wrong here
Tampering is an integrity risk mitigated by encryption and signing, not the residency obligation the law imposes. It is tempting because log integrity is a genuine cloud concern, and would be correct if the scenario asked about protecting logs from modification rather than keeping them within national borders.
- ✗
The IDS logs consume too much storage
Why it's wrong here
Storage consumption is a cost and capacity issue, unrelated to where data is stored or processed. It is tempting because log volume genuinely grows quickly, and would be correct if the question concerned operational overhead or retention costs rather than data localisation compliance.
- ✓
Log data containing personal data may be processed in a different jurisdiction
Why this is correct
IDS logs containing IP addresses constitute personal data, so processing them in a cloud region outside the headquarters' jurisdiction breaches data localisation requirements. This cross-border transfer is the primary compliance risk the stem's localisation laws create.
- ✗
The IDS may miss certain attack patterns
Why it's wrong here
Detection coverage is a security efficacy concern, not a data residency one; the logs still leave the jurisdiction regardless of whether attacks are caught. It is tempting because IDS accuracy matters operationally, and would be the answer if the question asked about detection gaps rather than localisation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.