Courseiva
Cloud Data Security →mediumMultiple Choice

CCSP Cloud Data Security Practice Question

A multinational corporation must ensure that customer data from the European Union is stored and processed only within EU regions to comply with GDPR. They are using a cloud provider with data centers globally. What is the primary mechanism to enforce this requirement?

⚠ Common exam trap

CCSP often tests the misconception that encryption or access controls satisfy data residency, when the exam expects recognition that only physical region selection enforces where data is stored and processed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Selecting cloud regions located within the EU for all services

The primary mechanism to enforce EU-only data residency is to select cloud regions physically located within the EU for all services that store or process the data, since data residency is fundamentally about where the data at rest and in processing resides. Region selection is a deployment-time architectural decision that determines the physical location of storage, compute, and backups. Other controls (encryption, VPN, IAM) complement but do not substitute for choosing EU regions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Selecting cloud regions located within the EU for all services

    Why this is correct

    Region selection is the foundational control: compute, storage and processing resources deployed only in EU regions keep data physically within the jurisdiction. It is the prerequisite mechanism on which replication restrictions and contractual safeguards then depend for GDPR residency.

  • ✗

    Client-side encryption with keys stored in the EU

    Why it's wrong here

    Encrypting with EU-held keys protects confidentiality but leaves ciphertext stored and processed on whichever global region the provider selects, so GDPR's residency requirement is unmet. It is tempting because key custody genuinely supports sovereignty, and it would be the right control when the concern is unauthorised disclosure rather than location.

  • ✗

    Using a VPN to route all traffic through an EU gateway

    Why it's wrong here

    A VPN changes only the network path traffic traverses; the provider still writes and processes the data in whichever region the service selects. It is tempting because encrypted tunnels feel like geographic control, and VPN routing would be correct when the requirement is protecting data in transit from interception.

  • ✗

    Configuring IAM policies to restrict access to EU-based administrators

    Why it's wrong here

    IAM policies govern who may access resources, not where those resources or their data physically reside, so processing can still occur outside the EU. It is tempting because restricting administrator nationality appears sovereign, and IAM conditions would be correct when the requirement is limiting access to particular identities or networks.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.