CCSP Cloud Data Security Practice Question
A multinational corporation uses a cloud-based data warehouse to analyze customer data across regions. The company must comply with GDPR, which restricts cross-border data transfers. The security architect needs to ensure that data subjects' personal data remains within the EU region and is not replicated to other regions. Which cloud data security control should be implemented?
⚠ Common exam trap
A common mix-up: candidates confuse encryption or tokenization with data residency; both protect data but do not prevent cross-border replication, which is the core GDPR concern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data residency policies enforced through cloud provider's region lock feature
GDPR requires that personal data of EU subjects not be transferred to countries without adequate protection unless specific safeguards are in place. To ensure data remains within the EU, the organization should use the cloud provider's region lock or data residency feature, which restricts data storage and processing to a chosen region. This preventive control directly addresses the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use of a cloud access security broker (CASB) to monitor data flows
Why it's wrong here
A CASB can monitor and enforce policies on data flows, but it does not inherently prevent data from being stored in other regions. It can alert or block certain transfers, but without underlying region restrictions, data may still be replicated. The requirement is to ensure data remains in the EU, which requires a preventive control like region lock.
- ✗
Tokenization of all personal data before storing in the cloud data warehouse
Why it's wrong here
Tokenization replaces sensitive data with non-sensitive tokens, but the original data must be stored somewhere, often in a token vault. If the vault is outside the EU, the data is still transferred. Tokenization alone does not guarantee data residency; it only obfuscates data. The requirement is to keep personal data within the EU, which tokenization does not ensure.
- ✗
Encryption of data at rest with customer-managed keys stored in the EU
Why it's wrong here
Encryption at rest with customer-managed keys stored in the EU protects data confidentiality but does not prevent the encrypted data from being replicated to other regions. GDPR considers encrypted personal data still personal data, so cross-border transfer restrictions apply. Thus, encryption alone does not satisfy data residency requirements.
- ✓
Data residency policies enforced through cloud provider's region lock feature
Why this is correct
Data residency policies enforced through the cloud provider's region lock feature allow the organization to restrict data storage and processing to a specific geographic region. This ensures that personal data remains within the EU, complying with GDPR's cross-border transfer restrictions. It is a direct control that prevents replication to other regions.
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.