CCSP · domain
Legal, Risk, and Compliance
This domain covers how cloud adoption reshapes legal obligations, risk management, and compliance accountability. It tests GDPR breach timelines, PCI DSS shared responsibility, eDiscovery holds on cloud storage, jurisdictional conflicts, and contract/audit artifacts. Expect scenario questions where you must pick the correct AWS control, legal deadline, or compliance responsibility rather than recite definitions.
Focused practice
Practice Legal, Risk, and Compliance questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Legal, Risk, and Compliance
You must map legal duties to cloud controls: know the GDPR 72-hour notification trigger, apply S3 Object Lock legal hold for eDiscovery, and keep PCI DSS customer obligations despite provider assessments. The key is correctly assigning responsibility between provider and customer under shared controls.
GDPR 72-hour controller notification to supervisory authority after awareness of a personal data breach
AWS S3 Object Lock in legal hold mode to preserve objects for eDiscovery
PCI DSS responsibility split between cloud provider and customer, evidenced by QSA assessment
Cross-border eDiscovery challenges: data sovereignty, conflicting laws, and provider control limits
Watch out for
Common Legal, Risk, and Compliance exam traps
- ▸Treating the 72-hour GDPR clock as starting at breach discovery by a third party rather than controller awareness.
- ▸Assuming a QSA-assessed cloud provider transfers all PCI DSS obligations to the provider instead of retaining customer responsibilities.
- ▸Confusing S3 Object Lock retention modes with legal hold, or believing deletion protection alone satisfies eDiscovery preservation.
Question index
All Legal, Risk, and Compliance questions (84)
Click any question to see the full explanation, or start a practice session above.
A company is subject to PCI DSS and plans to use a cloud provider to process credit card transactions. The cloud provider has been assessed by a Qualified Security Assessor (QSA). According to PCI DSS, what must the company obtain from the provider to demonstrate compliance?
Medium2A cloud customer is preparing for litigation and needs to place a legal hold on specific data stored in an object storage service. The cloud provider offers features such as object lock and retention policies. What is the primary challenge the customer must address to ensure the legal hold is effective across all copies of the data?
Hard3A cloud customer's provider announces that a sub-processor in a new jurisdiction will begin handling EU personal data next month. The customer's DPA gives it a right to object but states that continued use of the service constitutes acceptance. Which action best preserves the customer's legal position under GDPR Article 28(2)?
Hard4A cloud customer is preparing for an audit of its provider and wants to rely on the provider's existing independent attestation rather than conduct its own on-site review. Which document should the customer request to evaluate the provider's controls over security, availability, and confidentiality?
Easy5A company subject to SOX is using a cloud ERP system. Which THREE of the following IT general controls are essential for SOX compliance?
Medium6A cloud customer's legal team must decide which party bears responsibility for generating audit evidence that demonstrates regulatory compliance. The customer uses IaaS from a provider. According to the CSA Cloud Controls Matrix and shared responsibility principles, how should audit evidence obligations be divided?
Medium7A cloud customer must comply with GDPR's right to erasure (right to be forgotten). Which TWO of the following are technical challenges the customer faces when the data is stored in a cloud object storage service with versioning and cross-region replication?
Medium8Which CSA STAR tier involves a third-party assessment against ISO 27001?
Easy9A cloud customer stores data in a SaaS application that replicates across multiple jurisdictions. The customer's legal team must respond to a subpoena for data stored in a specific region. Which concept determines the legal authority over the data?
Medium10A cloud customer is evaluating a provider's compliance with the Payment Card Industry Data Security Standard (PCI DSS). The customer plans to store cardholder data in the provider's IaaS environment. Which responsibility does the customer retain under PCI DSS?
Easy11A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The customer must ensure compliance with legal and regulatory requirements. Which TWO factors are most important to address in the contract with the provider? (Choose two.)
Hard12A cloud customer is subject to an eDiscovery request and stores business records in a cloud object storage service. The legal team needs to preserve potentially relevant data and prevent it from being altered or deleted while the matter is active. Which cloud capability should the customer configure to meet this obligation?
Hard13A U.S. financial services firm uses a cloud provider with data centers in the EU. The firm must comply with both SEC regulations requiring books and records preservation and the GDPR. A data subject requests erasure of personal data that is also subject to a legal hold. What should the firm do?
Hard14A cloud customer wants to ensure they can audit their cloud provider's security controls annually. Which contractual provision should be included in the cloud service agreement?
Hard15A cloud customer is terminating its contract with a cloud provider and needs to ensure all data, including backups, is permanently deleted. Which contractual clause is most relevant?
Medium16A company is negotiating a cloud service agreement and wants to ensure it can periodically assess the security of the cloud provider's operations. Which contractual clause is most directly relevant to this requirement?
Medium17A US-based retail company stores customer personal data in a cloud provider's data center located in Germany. The company is subject to GDPR because it offers goods to EU residents. Which legal mechanism most directly establishes that the controller and the cloud provider may lawfully transfer personal data from the EU to the provider's US-based support team?
Easy18A cloud customer is assessing a provider's compliance with the Cloud Security Alliance (CSA) STAR program. Which TWO artifacts are part of the STAR program? (Choose two.)
Medium19Under GDPR, what is the maximum time allowed for a data controller to notify the supervisory authority of a personal data breach?
Easy20A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The legal team must ensure the policy addresses key contractual and regulatory considerations. Which TWO elements should the policy include? (Choose two.)
Medium21Under GDPR, what is the role of a cloud provider that processes personal data solely on behalf of a customer?
Easy22A European retail company is migrating its customer analytics platform to a public cloud provider. The dataset contains personal data of EU residents, and the company wants to minimize the risk of regulatory enforcement action if the cloud provider suffers a breach. Which action BEST addresses the shared responsibility for compliance in this scenario?
Medium23A cloud customer is negotiating a contract with a new cloud provider. The customer wants to ensure they can maintain control over their data and verify the provider's security posture. Which TWO contractual provisions are most critical for these purposes? (Choose two.)
Medium24A cloud customer is subject to a regulatory audit and must provide evidence that the cloud provider's security controls are effective. The customer has no right to audit the provider directly but can rely on third-party attestations. Which report should the customer request to obtain an independent assessment of the provider's controls relevant to security, availability, and confidentiality?
Hard25A cloud customer's legal team is reviewing a provider's contract and finds a clause requiring the customer to resolve all disputes through binding arbitration in the provider's home country. The customer operates in several jurisdictions and wants to preserve its options. Which contract provision should the customer negotiate to best address this concern?
Medium26Which of the following is a key requirement for data portability under the General Data Protection Regulation (GDPR)?
Easy27A cloud customer is negotiating a contract and wants to ensure they have the right to verify the cloud provider's security controls. Which contractual provision is most important?
Hard28A healthcare organization stores protected health information (PHI) in a cloud environment. Under HIPAA, what must the organization obtain from the cloud provider before processing PHI?
Medium29A cloud service provider wants to demonstrate compliance with ISO/IEC 27017 for cloud services. Which TWO controls are specific additions that this standard introduces beyond ISO/IEC 27002? (Choose two.)
Medium30A cloud customer is assessing the risk of using a cloud provider. Which THREE factors are most important in evaluating the inherent risk of migrating data and applications to the cloud?
Hard31A company using a SaaS application for HR management receives a data subject access request (DSAR) under GDPR from an employee. The cloud provider is the data processor. The company as data controller must respond within what timeframe?
Medium32A cloud customer is subject to eDiscovery requirements in a lawsuit. The data resides in a cloud storage service that uses encryption. What is the primary challenge in collecting this data in a forensically sound manner?
Medium33A company wants to export its data from a cloud provider to another provider upon contract termination. Which contract clause is essential to ensure the data can be exported in a usable format?
Medium34A global company uses a cloud provider that stores data in multiple jurisdictions. During an eDiscovery request from a US court, which three challenges are most likely to arise? (Choose three.)
Hard35A European retailer stores customer personal data in a cloud-hosted e-commerce platform. The cloud provider processes data only on documented instructions from the retailer, which determines the purposes and means of processing. Under the General Data Protection Regulation (GDPR), which role does the cloud provider hold?
Medium36A cloud customer is building its compliance monitoring program for a provider-hosted workload that processes regulated data. The customer must ensure it can demonstrate ongoing compliance to regulators between audits. Which TWO provider commitments should the customer secure in the contract to sustain continuous compliance evidence? (Choose two.)
Medium37A cloud provider discovers a security incident affecting a customer's personal data stored in its platform. The customer acts as the data controller under the General Data Protection Regulation (GDPR). Which obligation does the provider have regarding notification of this breach?
Hard38A cloud customer is subject to a regulatory audit and must provide evidence of the cloud provider's security controls. The provider refuses to allow direct audits of its data centers. Which artifact should the customer rely on to satisfy the auditors?
Hard39A cloud customer stores personal data of EU residents in a SaaS application. The customer's contract with the SaaS provider includes a data processing addendum. The customer's legal team wants to understand the allocation of GDPR responsibilities. Which of the following best describes the roles of the customer and the SaaS provider under GDPR?
Medium40A healthcare analytics company processes electronic protected health information (ePHI) for multiple covered entities using a public cloud provider. The company signs a Business Associate Agreement (BAA) with each covered entity and also signs a BAA with the cloud provider. A security analyst discovers that the cloud provider stores backups of the ePHI in a region outside the United States and refuses to sign a separate BAA for that region. Which of the following is the MOST appropriate action for the company to take to maintain compliance with HIPAA?
Hard41When assessing cloud risk, an organization identifies that if a single cloud provider fails, the organization cannot operate. This risk is known as:
Easy42A covered entity under HIPAA is planning to migrate electronic protected health information (ePHI) to a public cloud environment. Which of the following is a mandatory requirement before using the cloud service?
Medium43A cloud service provider is expanding into a new jurisdiction and must demonstrate compliance with local data protection laws. The provider's legal team is reviewing the shared responsibilities between the provider and its customers. Which TWO activities are the provider's responsibility under a typical cloud shared responsibility model? (Choose two.)
Medium44A multinational bank uses a cloud provider for a system that processes customer transactions. A regulator asks the bank to demonstrate that it maintains effective control over the data and can meet its legal obligations even if the provider fails. Which activity best demonstrates that the bank has retained accountability for the outsourced processing?
Hard45Under the General Data Protection Regulation (GDPR), if a cloud service provider (acting as a data processor) suffers a personal data breach, what is the provider's obligation regarding notification?
Easy46A company needs to export data from a cloud service in a machine-readable format to comply with a data subject's right to data portability under GDPR. Which format is most appropriate?
Hard47A company is evaluating the risk of using a single cloud provider for all critical workloads. Which risk is most directly associated with this scenario?
Medium48A company is adopting a multi-cloud strategy to reduce concentration risk. Which two benefits are directly associated with this approach? (Choose two.)
Easy49A cloud customer is reviewing its contract with a cloud provider. The customer wants to ensure that if the provider subcontracts any part of the service to a third party, the customer's data remains protected. Which contract provision is most critical to address this risk?
Medium50Which of the following best describes the purpose of the Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) program?
Easy51A cloud customer requires that its data stored by a provider be irretrievably destroyed after contract termination, even if the provider uses backup tapes and replicated storage. Which contractual and technical provision best supports this requirement?
Medium52A company is subject to a legal hold order and uses a cloud storage service with object replication across multiple regions. Which cloud feature should the company use to prevent deletion or modification of relevant data?
Medium53A company subject to PCI DSS is considering a cloud provider to process credit card transactions. What must the cloud provider present to demonstrate compliance with PCI DSS?
Medium54A cloud provider's data center is located in Country A, but the customer's data is subject to litigation in Country B. The court in Country B orders the cloud provider to produce data. The cloud provider refuses, citing Country A's laws that prohibit disclosure. This situation best illustrates which challenge in eDiscovery?
Medium55A cloud customer is reviewing its incident response plan and wants to ensure it can meet regulatory breach notification timelines. The customer's data is hosted by a cloud provider that does not automatically notify customers of security incidents. Which action should the customer take FIRST to address this gap?
Easy56A cloud customer wants to ensure that when the contract ends, the cloud provider deletes all customer data, including from backups. Which contractual clause is essential?
Medium57A cloud customer is considering adopting a multi-cloud strategy to avoid vendor lock-in. Which risk is this strategy primarily intended to mitigate?
Hard58Under GDPR, a cloud data controller must notify the supervisory authority of a personal data breach within what timeframe?
Hard59A cloud customer stores regulated data with a provider that uses sub-processors in multiple countries. The customer's legal team wants to ensure that international transfers of personal data remain lawful under the General Data Protection Regulation (GDPR). Which mechanism is the most appropriate to implement with the provider?
Hard60A cloud customer is preparing for an audit of its cloud environment. The provider offers a SOC 2 Type II report covering security and availability. What does this report provide to the customer's auditors?
Medium61A cloud customer is concerned about the right to erasure under GDPR because the cloud provider replicates data across multiple regions and keeps backups. What technical challenge does this create for complying with a erasure request?
Medium62A company is migrating to a public cloud and must ensure compliance with PCI DSS. Which responsibility does the cloud customer retain under the shared responsibility model?
Easy63A global enterprise is conducting a cloud risk assessment. Which THREE factors should be considered? (Select three.)
Hard64A multinational corporation uses multiple cloud service providers for its critical applications. The board is concerned about concentration risk. Which strategy would best address this risk?
Hard65A covered entity under HIPAA is moving electronic protected health information (ePHI) to a public cloud. What is the primary requirement before the cloud provider hosts ePHI?
Hard66A cloud customer's security team learns that a provider's subprocessor experienced a breach affecting the customer's data. The customer's contract requires the provider to notify the customer of subprocessor breaches. Under the GDPR, within what timeframe must the cloud provider, acting as a processor, notify the controller of a personal data breach?
Medium67A financial institution is required to comply with the Sarbanes-Oxley Act (SOX) for its cloud-hosted financial applications. The cloud provider is responsible for the underlying infrastructure. Which of the following controls is most likely the responsibility of the financial institution as part of IT general controls (ITGC)?
Hard68A US-based cloud customer stores EU personal data in a provider's Singapore region and uses the provider's support team located in India. The customer relies on the EU-US Data Privacy Framework (DPF) for its own US transfers. Which action is required to legitimize the support team's access to that EU data?
Hard69A cloud customer is concerned about the risk of unauthorized access to data due to the shared infrastructure of a public cloud. What type of risk does this represent?
Easy70A company is negotiating a cloud service agreement and wants to ensure it can verify the provider's security controls independently. Which contractual clause is essential for this purpose?
Medium71A cloud customer is subject to the EU GDPR and stores personal data with a provider that replicates it across data centers in several countries. The customer's legal team must confirm that appropriate safeguards exist for each international transfer. Which TWO elements are required for a valid transfer under GDPR Chapter V? (Choose two.)
Hard72In a cloud environment, a data subject exercises their right to erasure under GDPR. The cloud provider has multiple replicas and backups. What is the primary technical challenge in fulfilling this request?
Hard73In the context of eDiscovery, a legal hold must be placed on data stored in a cloud environment. Which THREE actions should the cloud customer take to ensure the legal hold is effective?
Medium74A multinational company is evaluating a cloud provider for a workload that processes personal data of employees in several countries. The company wants to ensure that cross-border data transfers comply with legal requirements. Which consideration is MOST important when assessing the provider's data transfer mechanisms?
Hard75A company is negotiating a cloud contract and wants to ensure data ownership and deletion. Which TWO clauses should be included? (Select two.)
Medium76A cloud customer receives a litigation hold notice requiring preservation of data stored in an object storage service. Which service feature should the customer use to ensure data cannot be modified or deleted until the hold is released?
Easy77A multinational corporation is implementing a multi-cloud strategy to avoid concentration risk. The risk management team is evaluating the inherent risks of using multiple cloud providers. Which THREE risks are specifically associated with a multi-cloud strategy? (Choose three.)
Hard78A company is using a single cloud provider for all critical services. What is the primary risk this company faces?
Medium79A healthcare provider is planning to migrate its electronic health records (EHR) system to a public cloud infrastructure. The system will store protected health information (PHI). Under HIPAA, what must the healthcare provider obtain from the cloud service provider before beginning the migration?
Medium80A cloud customer is subject to the Payment Card Industry Data Security Standard (PCI DSS) and uses a cloud provider to store cardholder data. The customer wants to reduce its PCI DSS scope. Which of the following provider attestations would best support scope reduction for the customer?
Hard81A cloud provider operates a public IaaS environment. A customer's legal team is reviewing the provider's audit rights clause and wants to ensure the provider will cooperate with a regulatory examination by a financial services regulator. The provider's standard contract currently states that customers may review SOC 2 reports annually but does not grant any right to audit. Which action should the customer's legal team take to best satisfy the regulator's expectations while maintaining a workable relationship with the provider?
Hard82A cloud customer operates a SaaS-based HR platform in the EU and receives a data subject access request (DSAR) from an employee. The provider's standard contract states it will only assist with DSARs on a 'reasonable efforts' basis and bills hourly for that assistance. Under GDPR Article 28, which contractual element must the customer ensure is in place before relying on this SaaS platform?
Medium83During an eDiscovery process, a company needs to preserve data stored in AWS S3 that may be relevant to a lawsuit. Which AWS feature should be used to implement a legal hold?
Medium84A multinational retailer uses a SaaS e-commerce platform hosted in the EU and serves customers in the EU, the UK, and the US. The legal team must determine which cross-border data transfer mechanism can be used to lawfully move customer personal data from the EU entity to the US parent company for analytics. Which mechanism should the legal team select?
MediumOther domains
All CCSP exam domains
Frequently asked questions
- What does the Legal, Risk, and Compliance domain cover on the CCSP exam?
- You must map legal duties to cloud controls: know the GDPR 72-hour notification trigger, apply S3 Object Lock legal hold for eDiscovery, and keep PCI DSS customer obligations despite provider assessments. The key is correctly assigning responsibility between provider and customer under shared controls.
- How many questions are in this domain?
- This page lists all 84 Legal, Risk, and Compliance questions in the CCSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Legal, Risk, and Compliance questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.