Courseiva
hardMultiple ChoiceObjective-mapped

CCSP Practice Question: A healthcare company, MedSecure, is migrating its…

A healthcare company, MedSecure, is migrating its critical patient record application to a public cloud IaaS environment. The application processes Protected Health Information (PHI) subject to HIPAA in the US and also includes some patient data from EU residents subject to GDPR. MedSecure has signed Business Associate Agreements (BAAs) with the cloud provider covering US HIPAA compliance. However, the compliance officer is concerned about GDPR requirements for EU patient data. The architecture uses AWS EC2 instances behind an Application Load Balancer, with data stored in Amazon RDS (MySQL) using encryption at rest and TLS for transmission. The company uses AWS CloudTrail for logging but only retains logs for 90 days. The compliance officer has identified that the current logging retention does not meet the GDPR requirement for logs to be retained for a minimum of 12 months for audit purposes. Additionally, the data stored in RDS is in a single AWS region in the US (us-east-1). The company plans to expand to EU customers. The GDPR requires that personal data of EU residents be stored in the EU or have adequate safeguards for transfer. Currently, the company has not implemented any data residency controls. What course of action should MedSecure take to address the most critical compliance gaps?

⚠ Common exam trap

ISC2 often tests the distinction between data replication mechanisms (e.g., read replicas vs. DMS with CDC) and the specific legal documents required for different regulations (BAA for HIPAA vs. DPA for GDPR), leading candidates to choose options that mix correct concepts with incorrect implementations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable S3 Object Lock for CloudTrail logs to ensure they cannot be deleted before 12 months, and use AWS DMS with CDC to replicate data to a eu-west-1 region. Also, sign a Data Processing Agreement (DPA) with AWS specifically for GDPR coverage.

It directly addresses the two most critical compliance gaps: GDPR log retention (12 months) and data residency for EU patient data. Enabling S3 Object Lock on CloudTrail logs ensures they cannot be deleted or altered before 12 months, meeting GDPR audit requirements. Using AWS DMS with Change Data Capture (CDC) to replicate the RDS database to eu-west-1 provides a continuous, low-latency copy of PHI within the EU, satisfying GDPR data residency. Signing a Data Processing Agreement (DPA) with AWS specifically for GDPR coverage is essential because the existing BAA only covers HIPAA, and GDPR requires a separate DPA to establish the cloud provider as a data processor under EU law.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Extend CloudTrail log retention to 12 months by configuring a new trail in a separate account and storing logs in an S3 bucket with a lifecycle policy to delete after 12 months. For data residency, use AWS DMS to replicate the RDS database to a second RDS instance in the eu-west-1 region and enable cross-region replication for continuous sync.

    Why it's wrong here

    This addresses log retention and data residency, but fails to include a DPA or SCCs for the US data that may still be accessed from the EU, and the lifecycle policy does not prevent premature deletion.

  • Implement AWS Config rules to monitor compliance with both HIPAA and GDPR, and enable AWS CloudTrail Insights to detect unusual activity. For data residency, sign a Standard Contractual Clauses (SCCs) with the cloud provider for the existing US-based data.

    Why it's wrong here

    This does not fix the log retention issue (90 days), and SCCs alone for existing data do not address future EU data storage requirements.

  • Enable S3 Object Lock for CloudTrail logs to ensure they cannot be deleted before 12 months, and use AWS DMS with CDC to replicate data to a eu-west-1 region. Also, sign a Data Processing Agreement (DPA) with AWS specifically for GDPR coverage.

    Why this is correct

    This comprehensively addresses both gaps: immutable log retention, EU data replication, and a DPA to cover legal transfer safeguards.

  • Use AWS Lambda to copy CloudTrail logs from the existing trail to a separate S3 bucket with a retention policy of 12 months. For data residency, configure the RDS instance to have a read replica in eu-west-1 and implement a DPA with AWS for GDPR.

    Why it's wrong here

    Lambda copy is less reliable than native retention, and a read replica is only for read operations; new EU patient data needs to be written to the EU region, which requires a primary instance there.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.