CCSP Legal, Risk, and Compliance Practice Question
A European retail company is migrating its customer analytics platform to a public cloud provider. The dataset contains personal data of EU residents, and the company wants to minimize the risk of regulatory enforcement action if the cloud provider suffers a breach. Which action BEST addresses the shared responsibility for compliance in this scenario?
⚠ Common exam trap
The trap here is assuming that a provider's security certification or encryption automatically transfers GDPR accountability to the cloud provider.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Execute a data processing agreement with the provider and independently verify the technical and organizational measures applied to the personal data.
The customer remains the data controller and therefore accountable under GDPR, even when using a public cloud. A data processing agreement establishes the required contractual framework, and independent verification confirms that the provider's technical and organizational measures are effective. Together these actions address the shared responsibility model and reduce the risk of regulatory enforcement after a breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Execute a data processing agreement with the provider and independently verify the technical and organizational measures applied to the personal data.
Why this is correct
Under GDPR, a controller engaging a processor must have a data processing agreement in place, and the controller remains accountable for demonstrating compliance. Independently verifying the provider's technical and organizational measures ensures the contractual commitments are actually implemented, which directly reduces enforcement risk if a breach occurs.
- ✗
Encrypt the data at rest with provider-managed keys and consider the compliance obligation fully transferred to the cloud provider.
Why it's wrong here
Encryption is a valuable safeguard, but using provider-managed keys does not transfer GDPR accountability to the processor. The controller must still choose an appropriate lawful basis, execute a data processing agreement, and demonstrate compliance; encryption alone does not satisfy those obligations.
- ✗
Rely on the cloud provider's ISO/IEC 27001 certification as full evidence of GDPR compliance for the workload.
Why it's wrong here
An ISO/IEC 27001 certificate demonstrates that the provider operates an information security management system, but it does not certify that the customer's specific processing of EU personal data meets GDPR obligations. The customer remains the controller and must still implement its own measures, so treating the certificate as complete compliance evidence misplaces responsibility.
- ✗
Transfer all personal data to the provider's infrastructure and let the provider determine the lawful basis for processing.
Why it's wrong here
The lawful basis for processing is determined by the controller, not the processor. Delegating that decision to the cloud provider would not transfer the company's accountability and would likely result in an unlawful processing arrangement, increasing rather than reducing regulatory exposure.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.