Courseiva
mediumMultiple ChoiceObjective-mapped

CCSP Practice Question: A multinational corporation uses a SaaS…

A multinational corporation uses a SaaS application for customer relationship management (CRM). The CRM application stores customer data including names, email addresses, and purchase history. The company has operations in the EU, California, and Japan. A new regulation in Japan requires that any transfer of personal data outside Japan must have the data subject's consent if the destination country does not have an adequacy decision. The company's cloud provider stores data in the United States. The company currently relies on the provider's data processing agreement that includes standard contractual clauses (SCCs). However, the Japanese regulator has stated that SCCs are not sufficient for transfers from Japan unless supplemented. You are tasked with ensuring compliance for Japanese data subjects. Which of the following is the most appropriate next step? A. Obtain explicit consent from each Japanese data subject for data transfer to the US. B. Move the data for Japanese subjects to a data center in Japan. C. Continue using SCCs as they are recognized internationally. D. Pseudonymize the data before transfer.

Which option best addresses the compliance requirement while considering the operational impact?

⚠ Common exam trap

ISC2 often tests the misconception that pseudonymization or data localization alone can bypass cross-border transfer restrictions, when in fact explicit consent or an approved mechanism is required under the specific regulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Obtain explicit consent from each Japanese data subject for data transfer to the US.

The Japanese regulator has explicitly stated that SCCs alone are insufficient for transfers from Japan, and obtaining explicit consent from each data subject directly satisfies the requirement for a valid transfer mechanism under Japanese law. This approach ensures compliance without requiring infrastructure changes, though it may be operationally burdensome. The other options either fail to meet regulatory requirements or introduce unnecessary operational impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Move the data for Japanese subjects to a data center in Japan.

    Why it's wrong here

    Moving data to Japan may be effective but is operationally complex and costly; consent is more immediate.

  • Continue using SCCs as they are recognized internationally.

    Why it's wrong here

    The Japanese regulator has stated SCCs are not sufficient, so this would not ensure compliance.

  • Pseudonymize the data before transfer.

    Why it's wrong here

    Pseudonymization reduces risk but does not eliminate the need for a transfer mechanism under Japanese law.

  • Obtain explicit consent from each Japanese data subject for data transfer to the US.

    Why this is correct

    Correct. Explicit consent is a valid legal basis under Japanese law when other mechanisms are insufficient.

About these practice questions

Courseiva writes every CCSP question from scratch — 964 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.