Courseiva

CCSP Legal, Risk, and Compliance Practice Question

A global company uses a cloud provider that stores data in multiple jurisdictions. During an eDiscovery request from a US court, which three challenges are most likely to arise? (Choose three.)

⚠ Common exam trap

The trap is assuming that encryption or cost are major eDiscovery challenges, when the real issues are legal jurisdiction, data preservation, and forensic collection limitations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Jurisdictional conflicts over which court has authority

Option A is correct because when data resides in multiple jurisdictions, US court orders can conflict with local data-protection or blocking statutes (e.g., GDPR or foreign blocking laws), creating disputes over which court or legal regime has authority over the data. Option C is correct because eDiscovery requires a legal hold to preserve potentially relevant data in place, and in multi-jurisdiction cloud environments this is complicated by distributed storage, automated lifecycle deletion, and differing retention rules that can alter or destroy evidence. Option D is correct because cloud tenants typically lack physical access to the provider's hardware, so forensically sound collection must rely on provider APIs, snapshots, and chain-of-custody documentation rather than direct disk imaging, which can be challenged in court. Option B is not correct because major cloud providers offer extensive encryption options (at rest, in transit, and customer-managed keys), so lack of encryption is not an inherent eDiscovery challenge. Option E is not correct because while cloud storage costs exist, excessive cost is not a legal or forensic challenge specific to cross-jurisdiction eDiscovery and is not among the primary issues courts focus on.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Jurisdictional conflicts over which court has authority

    Why this is correct

    Data spanning multiple jurisdictions triggers conflicting legal demands, as foreign privacy or blocking statutes may prohibit disclosure that a US court orders. This jurisdictional conflict over authority is a primary eDiscovery challenge in cross-border cloud environments.

  • ✗

    Lack of encryption options

    Why it's wrong here

    Cloud providers offer customer-managed keys, HSM-backed encryption and per-object controls, so encryption availability is not the constraint; the challenge is holding keys and proving custody across jurisdictions. It is tempting because encryption is a standard data-protection control, and would be correct if the provider offered no encryption at all.

  • ✓

    Ensuring data is preserved without alteration (legal hold)

    Why this is correct

    Legal hold demands immutable preservation across every jurisdiction where the provider stores data, yet litigation-hold tooling often cannot span sovereign boundaries or non-native storage tiers. Satisfying the eDiscovery constraint therefore requires per-jurisdiction holds that prevent alteration, deletion or overwrite while the US court request remains active.

  • ✓

    Inability to perform forensically sound collection due to lack of physical access

    Why this is correct

    Cloud data resides on provider hardware the customer never touches, so collection relies on provider APIs and tooling rather than direct disk imaging. This loss of physical custody prevents the customer from performing forensically sound acquisition, satisfying the multi-jurisdiction eDiscovery constraint in the stem.

  • ✗

    Excessive cost of cloud storage

    Why it's wrong here

    Storage cost is a commercial matter, not a legal obstacle; eDiscovery turns on where data resides and which jurisdiction's process governs its disclosure. It is tempting because multi-region replication does generate egress and duplication charges, which would be the answer if the question asked about financial rather than legal exposure.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.