Courseiva

CCSP · domain

Legal, Risk, and Compliance

This domain covers how cloud adoption reshapes legal obligations, risk management, and compliance accountability. It tests GDPR breach timelines, PCI DSS shared responsibility, eDiscovery holds on cloud storage, jurisdictional conflicts, and contract/audit artifacts. Expect scenario questions where you must pick the correct AWS control, legal deadline, or compliance responsibility rather than recite definitions.

84 questions15 easy40 medium29 hard

Focused practice

Practice Legal, Risk, and Compliance questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Legal, Risk, and Compliance

You must map legal duties to cloud controls: know the GDPR 72-hour notification trigger, apply S3 Object Lock legal hold for eDiscovery, and keep PCI DSS customer obligations despite provider assessments. The key is correctly assigning responsibility between provider and customer under shared controls.

GDPR 72-hour controller notification to supervisory authority after awareness of a personal data breach

AWS S3 Object Lock in legal hold mode to preserve objects for eDiscovery

PCI DSS responsibility split between cloud provider and customer, evidenced by QSA assessment

Cross-border eDiscovery challenges: data sovereignty, conflicting laws, and provider control limits

Watch out for

Common Legal, Risk, and Compliance exam traps

  • ▸Treating the 72-hour GDPR clock as starting at breach discovery by a third party rather than controller awareness.
  • ▸Assuming a QSA-assessed cloud provider transfers all PCI DSS obligations to the provider instead of retaining customer responsibilities.
  • ▸Confusing S3 Object Lock retention modes with legal hold, or believing deletion protection alone satisfies eDiscovery preservation.

Question index

All Legal, Risk, and Compliance questions (84)

Click any question to see the full explanation, or start a practice session above.

1

A company is subject to PCI DSS and plans to use a cloud provider to process credit card transactions. The cloud provider has been assessed by a Qualified Security Assessor (QSA). According to PCI DSS, what must the company obtain from the provider to demonstrate compliance?

Medium
2

A cloud customer is preparing for litigation and needs to place a legal hold on specific data stored in an object storage service. The cloud provider offers features such as object lock and retention policies. What is the primary challenge the customer must address to ensure the legal hold is effective across all copies of the data?

Hard
3

A cloud customer's provider announces that a sub-processor in a new jurisdiction will begin handling EU personal data next month. The customer's DPA gives it a right to object but states that continued use of the service constitutes acceptance. Which action best preserves the customer's legal position under GDPR Article 28(2)?

Hard
4

A cloud customer is preparing for an audit of its provider and wants to rely on the provider's existing independent attestation rather than conduct its own on-site review. Which document should the customer request to evaluate the provider's controls over security, availability, and confidentiality?

Easy
5

A company subject to SOX is using a cloud ERP system. Which THREE of the following IT general controls are essential for SOX compliance?

Medium
6

A cloud customer's legal team must decide which party bears responsibility for generating audit evidence that demonstrates regulatory compliance. The customer uses IaaS from a provider. According to the CSA Cloud Controls Matrix and shared responsibility principles, how should audit evidence obligations be divided?

Medium
7

A cloud customer must comply with GDPR's right to erasure (right to be forgotten). Which TWO of the following are technical challenges the customer faces when the data is stored in a cloud object storage service with versioning and cross-region replication?

Medium
8

Which CSA STAR tier involves a third-party assessment against ISO 27001?

Easy
9

A cloud customer stores data in a SaaS application that replicates across multiple jurisdictions. The customer's legal team must respond to a subpoena for data stored in a specific region. Which concept determines the legal authority over the data?

Medium
10

A cloud customer is evaluating a provider's compliance with the Payment Card Industry Data Security Standard (PCI DSS). The customer plans to store cardholder data in the provider's IaaS environment. Which responsibility does the customer retain under PCI DSS?

Easy
11

A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The customer must ensure compliance with legal and regulatory requirements. Which TWO factors are most important to address in the contract with the provider? (Choose two.)

Hard
12

A cloud customer is subject to an eDiscovery request and stores business records in a cloud object storage service. The legal team needs to preserve potentially relevant data and prevent it from being altered or deleted while the matter is active. Which cloud capability should the customer configure to meet this obligation?

Hard
13

A U.S. financial services firm uses a cloud provider with data centers in the EU. The firm must comply with both SEC regulations requiring books and records preservation and the GDPR. A data subject requests erasure of personal data that is also subject to a legal hold. What should the firm do?

Hard
14

A cloud customer wants to ensure they can audit their cloud provider's security controls annually. Which contractual provision should be included in the cloud service agreement?

Hard
15

A cloud customer is terminating its contract with a cloud provider and needs to ensure all data, including backups, is permanently deleted. Which contractual clause is most relevant?

Medium
16

A company is negotiating a cloud service agreement and wants to ensure it can periodically assess the security of the cloud provider's operations. Which contractual clause is most directly relevant to this requirement?

Medium
17

A US-based retail company stores customer personal data in a cloud provider's data center located in Germany. The company is subject to GDPR because it offers goods to EU residents. Which legal mechanism most directly establishes that the controller and the cloud provider may lawfully transfer personal data from the EU to the provider's US-based support team?

Easy
18

A cloud customer is assessing a provider's compliance with the Cloud Security Alliance (CSA) STAR program. Which TWO artifacts are part of the STAR program? (Choose two.)

Medium
19

Under GDPR, what is the maximum time allowed for a data controller to notify the supervisory authority of a personal data breach?

Easy
20

A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The legal team must ensure the policy addresses key contractual and regulatory considerations. Which TWO elements should the policy include? (Choose two.)

Medium
21

Under GDPR, what is the role of a cloud provider that processes personal data solely on behalf of a customer?

Easy
22

A European retail company is migrating its customer analytics platform to a public cloud provider. The dataset contains personal data of EU residents, and the company wants to minimize the risk of regulatory enforcement action if the cloud provider suffers a breach. Which action BEST addresses the shared responsibility for compliance in this scenario?

Medium
23

A cloud customer is negotiating a contract with a new cloud provider. The customer wants to ensure they can maintain control over their data and verify the provider's security posture. Which TWO contractual provisions are most critical for these purposes? (Choose two.)

Medium
24

A cloud customer is subject to a regulatory audit and must provide evidence that the cloud provider's security controls are effective. The customer has no right to audit the provider directly but can rely on third-party attestations. Which report should the customer request to obtain an independent assessment of the provider's controls relevant to security, availability, and confidentiality?

Hard
25

A cloud customer's legal team is reviewing a provider's contract and finds a clause requiring the customer to resolve all disputes through binding arbitration in the provider's home country. The customer operates in several jurisdictions and wants to preserve its options. Which contract provision should the customer negotiate to best address this concern?

Medium
26

Which of the following is a key requirement for data portability under the General Data Protection Regulation (GDPR)?

Easy
27

A cloud customer is negotiating a contract and wants to ensure they have the right to verify the cloud provider's security controls. Which contractual provision is most important?

Hard
28

A healthcare organization stores protected health information (PHI) in a cloud environment. Under HIPAA, what must the organization obtain from the cloud provider before processing PHI?

Medium
29

A cloud service provider wants to demonstrate compliance with ISO/IEC 27017 for cloud services. Which TWO controls are specific additions that this standard introduces beyond ISO/IEC 27002? (Choose two.)

Medium
30

A cloud customer is assessing the risk of using a cloud provider. Which THREE factors are most important in evaluating the inherent risk of migrating data and applications to the cloud?

Hard
31

A company using a SaaS application for HR management receives a data subject access request (DSAR) under GDPR from an employee. The cloud provider is the data processor. The company as data controller must respond within what timeframe?

Medium
32

A cloud customer is subject to eDiscovery requirements in a lawsuit. The data resides in a cloud storage service that uses encryption. What is the primary challenge in collecting this data in a forensically sound manner?

Medium
33

A company wants to export its data from a cloud provider to another provider upon contract termination. Which contract clause is essential to ensure the data can be exported in a usable format?

Medium
34

A global company uses a cloud provider that stores data in multiple jurisdictions. During an eDiscovery request from a US court, which three challenges are most likely to arise? (Choose three.)

Hard
35

A European retailer stores customer personal data in a cloud-hosted e-commerce platform. The cloud provider processes data only on documented instructions from the retailer, which determines the purposes and means of processing. Under the General Data Protection Regulation (GDPR), which role does the cloud provider hold?

Medium
36

A cloud customer is building its compliance monitoring program for a provider-hosted workload that processes regulated data. The customer must ensure it can demonstrate ongoing compliance to regulators between audits. Which TWO provider commitments should the customer secure in the contract to sustain continuous compliance evidence? (Choose two.)

Medium
37

A cloud provider discovers a security incident affecting a customer's personal data stored in its platform. The customer acts as the data controller under the General Data Protection Regulation (GDPR). Which obligation does the provider have regarding notification of this breach?

Hard
38

A cloud customer is subject to a regulatory audit and must provide evidence of the cloud provider's security controls. The provider refuses to allow direct audits of its data centers. Which artifact should the customer rely on to satisfy the auditors?

Hard
39

A cloud customer stores personal data of EU residents in a SaaS application. The customer's contract with the SaaS provider includes a data processing addendum. The customer's legal team wants to understand the allocation of GDPR responsibilities. Which of the following best describes the roles of the customer and the SaaS provider under GDPR?

Medium
40

A healthcare analytics company processes electronic protected health information (ePHI) for multiple covered entities using a public cloud provider. The company signs a Business Associate Agreement (BAA) with each covered entity and also signs a BAA with the cloud provider. A security analyst discovers that the cloud provider stores backups of the ePHI in a region outside the United States and refuses to sign a separate BAA for that region. Which of the following is the MOST appropriate action for the company to take to maintain compliance with HIPAA?

Hard
41

When assessing cloud risk, an organization identifies that if a single cloud provider fails, the organization cannot operate. This risk is known as:

Easy
42

A covered entity under HIPAA is planning to migrate electronic protected health information (ePHI) to a public cloud environment. Which of the following is a mandatory requirement before using the cloud service?

Medium
43

A cloud service provider is expanding into a new jurisdiction and must demonstrate compliance with local data protection laws. The provider's legal team is reviewing the shared responsibilities between the provider and its customers. Which TWO activities are the provider's responsibility under a typical cloud shared responsibility model? (Choose two.)

Medium
44

A multinational bank uses a cloud provider for a system that processes customer transactions. A regulator asks the bank to demonstrate that it maintains effective control over the data and can meet its legal obligations even if the provider fails. Which activity best demonstrates that the bank has retained accountability for the outsourced processing?

Hard
45

Under the General Data Protection Regulation (GDPR), if a cloud service provider (acting as a data processor) suffers a personal data breach, what is the provider's obligation regarding notification?

Easy
46

A company needs to export data from a cloud service in a machine-readable format to comply with a data subject's right to data portability under GDPR. Which format is most appropriate?

Hard
47

A company is evaluating the risk of using a single cloud provider for all critical workloads. Which risk is most directly associated with this scenario?

Medium
48

A company is adopting a multi-cloud strategy to reduce concentration risk. Which two benefits are directly associated with this approach? (Choose two.)

Easy
49

A cloud customer is reviewing its contract with a cloud provider. The customer wants to ensure that if the provider subcontracts any part of the service to a third party, the customer's data remains protected. Which contract provision is most critical to address this risk?

Medium
50

Which of the following best describes the purpose of the Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) program?

Easy
51

A cloud customer requires that its data stored by a provider be irretrievably destroyed after contract termination, even if the provider uses backup tapes and replicated storage. Which contractual and technical provision best supports this requirement?

Medium
52

A company is subject to a legal hold order and uses a cloud storage service with object replication across multiple regions. Which cloud feature should the company use to prevent deletion or modification of relevant data?

Medium
53

A company subject to PCI DSS is considering a cloud provider to process credit card transactions. What must the cloud provider present to demonstrate compliance with PCI DSS?

Medium
54

A cloud provider's data center is located in Country A, but the customer's data is subject to litigation in Country B. The court in Country B orders the cloud provider to produce data. The cloud provider refuses, citing Country A's laws that prohibit disclosure. This situation best illustrates which challenge in eDiscovery?

Medium
55

A cloud customer is reviewing its incident response plan and wants to ensure it can meet regulatory breach notification timelines. The customer's data is hosted by a cloud provider that does not automatically notify customers of security incidents. Which action should the customer take FIRST to address this gap?

Easy
56

A cloud customer wants to ensure that when the contract ends, the cloud provider deletes all customer data, including from backups. Which contractual clause is essential?

Medium
57

A cloud customer is considering adopting a multi-cloud strategy to avoid vendor lock-in. Which risk is this strategy primarily intended to mitigate?

Hard
58

Under GDPR, a cloud data controller must notify the supervisory authority of a personal data breach within what timeframe?

Hard
59

A cloud customer stores regulated data with a provider that uses sub-processors in multiple countries. The customer's legal team wants to ensure that international transfers of personal data remain lawful under the General Data Protection Regulation (GDPR). Which mechanism is the most appropriate to implement with the provider?

Hard
60

A cloud customer is preparing for an audit of its cloud environment. The provider offers a SOC 2 Type II report covering security and availability. What does this report provide to the customer's auditors?

Medium
61

A cloud customer is concerned about the right to erasure under GDPR because the cloud provider replicates data across multiple regions and keeps backups. What technical challenge does this create for complying with a erasure request?

Medium
62

A company is migrating to a public cloud and must ensure compliance with PCI DSS. Which responsibility does the cloud customer retain under the shared responsibility model?

Easy
63

A global enterprise is conducting a cloud risk assessment. Which THREE factors should be considered? (Select three.)

Hard
64

A multinational corporation uses multiple cloud service providers for its critical applications. The board is concerned about concentration risk. Which strategy would best address this risk?

Hard
65

A covered entity under HIPAA is moving electronic protected health information (ePHI) to a public cloud. What is the primary requirement before the cloud provider hosts ePHI?

Hard
66

A cloud customer's security team learns that a provider's subprocessor experienced a breach affecting the customer's data. The customer's contract requires the provider to notify the customer of subprocessor breaches. Under the GDPR, within what timeframe must the cloud provider, acting as a processor, notify the controller of a personal data breach?

Medium
67

A financial institution is required to comply with the Sarbanes-Oxley Act (SOX) for its cloud-hosted financial applications. The cloud provider is responsible for the underlying infrastructure. Which of the following controls is most likely the responsibility of the financial institution as part of IT general controls (ITGC)?

Hard
68

A US-based cloud customer stores EU personal data in a provider's Singapore region and uses the provider's support team located in India. The customer relies on the EU-US Data Privacy Framework (DPF) for its own US transfers. Which action is required to legitimize the support team's access to that EU data?

Hard
69

A cloud customer is concerned about the risk of unauthorized access to data due to the shared infrastructure of a public cloud. What type of risk does this represent?

Easy
70

A company is negotiating a cloud service agreement and wants to ensure it can verify the provider's security controls independently. Which contractual clause is essential for this purpose?

Medium
71

A cloud customer is subject to the EU GDPR and stores personal data with a provider that replicates it across data centers in several countries. The customer's legal team must confirm that appropriate safeguards exist for each international transfer. Which TWO elements are required for a valid transfer under GDPR Chapter V? (Choose two.)

Hard
72

In a cloud environment, a data subject exercises their right to erasure under GDPR. The cloud provider has multiple replicas and backups. What is the primary technical challenge in fulfilling this request?

Hard
73

In the context of eDiscovery, a legal hold must be placed on data stored in a cloud environment. Which THREE actions should the cloud customer take to ensure the legal hold is effective?

Medium
74

A multinational company is evaluating a cloud provider for a workload that processes personal data of employees in several countries. The company wants to ensure that cross-border data transfers comply with legal requirements. Which consideration is MOST important when assessing the provider's data transfer mechanisms?

Hard
75

A company is negotiating a cloud contract and wants to ensure data ownership and deletion. Which TWO clauses should be included? (Select two.)

Medium
76

A cloud customer receives a litigation hold notice requiring preservation of data stored in an object storage service. Which service feature should the customer use to ensure data cannot be modified or deleted until the hold is released?

Easy
77

A multinational corporation is implementing a multi-cloud strategy to avoid concentration risk. The risk management team is evaluating the inherent risks of using multiple cloud providers. Which THREE risks are specifically associated with a multi-cloud strategy? (Choose three.)

Hard
78

A company is using a single cloud provider for all critical services. What is the primary risk this company faces?

Medium
79

A healthcare provider is planning to migrate its electronic health records (EHR) system to a public cloud infrastructure. The system will store protected health information (PHI). Under HIPAA, what must the healthcare provider obtain from the cloud service provider before beginning the migration?

Medium
80

A cloud customer is subject to the Payment Card Industry Data Security Standard (PCI DSS) and uses a cloud provider to store cardholder data. The customer wants to reduce its PCI DSS scope. Which of the following provider attestations would best support scope reduction for the customer?

Hard
81

A cloud provider operates a public IaaS environment. A customer's legal team is reviewing the provider's audit rights clause and wants to ensure the provider will cooperate with a regulatory examination by a financial services regulator. The provider's standard contract currently states that customers may review SOC 2 reports annually but does not grant any right to audit. Which action should the customer's legal team take to best satisfy the regulator's expectations while maintaining a workable relationship with the provider?

Hard
82

A cloud customer operates a SaaS-based HR platform in the EU and receives a data subject access request (DSAR) from an employee. The provider's standard contract states it will only assist with DSARs on a 'reasonable efforts' basis and bills hourly for that assistance. Under GDPR Article 28, which contractual element must the customer ensure is in place before relying on this SaaS platform?

Medium
83

During an eDiscovery process, a company needs to preserve data stored in AWS S3 that may be relevant to a lawsuit. Which AWS feature should be used to implement a legal hold?

Medium
84

A multinational retailer uses a SaaS e-commerce platform hosted in the EU and serves customers in the EU, the UK, and the US. The legal team must determine which cross-border data transfer mechanism can be used to lawfully move customer personal data from the EU entity to the US parent company for analytics. Which mechanism should the legal team select?

Medium

Frequently asked questions

What does the Legal, Risk, and Compliance domain cover on the CCSP exam?
You must map legal duties to cloud controls: know the GDPR 72-hour notification trigger, apply S3 Object Lock legal hold for eDiscovery, and keep PCI DSS customer obligations despite provider assessments. The key is correctly assigning responsibility between provider and customer under shared controls.
How many questions are in this domain?
This page lists all 84 Legal, Risk, and Compliance questions in the CCSP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Legal, Risk, and Compliance questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-ccsp ISC2-CCSP ccsp legal risk compliance Practice Questions