Courseiva

CCNA Legal, Risk, and Compliance Questions

75 of 84 questions · Page 1/2 · Legal, Risk, and Compliance · Answers revealed

1
MCQmedium

A company is subject to PCI DSS and plans to use a cloud provider to process credit card transactions. The cloud provider has been assessed by a Qualified Security Assessor (QSA). According to PCI DSS, what must the company obtain from the provider to demonstrate compliance?

A.The provider's PCI DSS Attestation of Compliance (AOC) and Responsibility Matrix
B.A signed Business Associate Agreement
C.An ISO 27001 certificate
D.A SOC 2 Type II report
AnswerA

The PCI DSS Attestation of Compliance evidences the provider's assessed compliance status, while the Responsibility Matrix defines which requirements the provider covers versus the customer. Together they satisfy the obligation to demonstrate compliance for card processing.

Why this answer

Under PCI DSS, when a customer uses a cloud provider to process cardholder data, the provider must be assessed by a QSA and issue an Attestation of Compliance (AOC) along with a Responsibility Matrix (also called a Shared Responsibility Matrix or PCI DSS Responsibility Matrix). The AOC documents the provider's validated compliance status, and the Responsibility Matrix defines which PCI DSS requirements are met by the provider versus the customer. Together they let the customer demonstrate its own compliance to its acquirer or QSA.

Exam trap

CCSP often tests the confusion between compliance frameworks — candidates see 'cloud provider' and 'compliance' and reach for SOC 2 or ISO 27001, but PCI DSS specifically requires a QSA-issued AOC and Responsibility Matrix from the service provider.

How to eliminate wrong answers

Option B is wrong because a Business Associate Agreement is a HIPAA construct governing protected health information, not a PCI DSS artifact — it has no bearing on cardholder data compliance. Option C is wrong because an ISO 27001 certificate attests to an information security management system, not to PCI DSS controls; it is useful evidence but does not satisfy PCI DSS's specific requirement for a QSA-assessed AOC. Option D is wrong because a SOC 2 Type II report covers the Trust Services Criteria (security, availability, etc.) and, while often used as supporting evidence, is not the PCI DSS-specific attestation the standard requires from a service provider.

2
MCQhard

A cloud customer is preparing for litigation and needs to place a legal hold on specific data stored in an object storage service. The cloud provider offers features such as object lock and retention policies. What is the primary challenge the customer must address to ensure the legal hold is effective across all copies of the data?

A.Ensuring that the legal hold is time-limited and automatically expires after 90 days.
B.Ensuring that the legal hold is applied to all copies of the data, including replicas and backups, and that the hold prevents modification as well as deletion.
C.Verifying that the cloud provider has a backup of the data in a different geographic region.
D.Obtaining a court order that specifically authorizes the cloud provider to preserve the data.
AnswerB

Object lock and retention policies apply per object or bucket, so the challenge is propagating the hold to every replica and backup copy and enforcing immutability against both modification and deletion, ensuring no copy escapes the hold.

Why this answer

In cloud environments, data may be replicated across multiple regions or stored in backups. A legal hold must prevent deletion or alteration of all copies, including replicas and backups. Failure to apply hold to all copies can result in spoliation.

3
MCQhard

A cloud customer's provider announces that a sub-processor in a new jurisdiction will begin handling EU personal data next month. The customer's DPA gives it a right to object but states that continued use of the service constitutes acceptance. Which action best preserves the customer's legal position under GDPR Article 28(2)?

A.Accept the change and rely on the provider's downstream SCCs with the new sub-processor as sufficient protection for the customer.
B.Perform a new data protection impact assessment covering the sub-processor and treat a favorable outcome as consent to the change.
C.Exercise the objection right in writing before the change takes effect and document the outcome, escalating to termination if the provider cannot accommodate it.
D.Notify the supervisory authority of the sub-processor change and request a formal opinion before responding to the provider.
AnswerC

Article 28(2) requires the controller to have the opportunity to object to sub-processor changes, and Article 28(4) makes the processor liable for sub-processors. A timely written objection preserves the contractual right, creates evidence of the objection, and forces a documented resolution. Silent acceptance by continued use would waive the objection and lock in the new sub-processor.

Why this answer

Article 28(2) gives the controller the right to object to new sub-processors, and Article 28(4) holds the processor liable for sub-processor performance. Exercising the objection in writing before the change takes effect preserves the remedy and creates an auditable record. Remaining silent while continuing to use the service typically constitutes acceptance and extinguishes the objection right.

Exam trap

The trap here is believing that a DPIA, a regulator notification, or downstream SCCs can substitute for formally exercising the contractual right to object before the acceptance-by-continued-use deadline.

4
MCQeasy

A cloud customer is preparing for an audit of its provider and wants to rely on the provider's existing independent attestation rather than conduct its own on-site review. Which document should the customer request to evaluate the provider's controls over security, availability, and confidentiality?

A.An ISO/IEC 27001 certificate listing the provider's statement of applicability for its corporate IT systems.
B.A completed CSA CAIQ self-assessment submitted by the provider's security team.
C.A SOC 2 Type II report covering the trust services criteria relevant to the customer's use of the service.
D.A SOC 1 Type II report covering controls relevant to the customer's internal control over financial reporting.
AnswerC

A SOC 2 Type II report provides an independent auditor's opinion on the design and operating effectiveness of controls against the trust services criteria over a period of time. It lets the customer evaluate security, availability, and confidentiality without an on-site visit. The customer must still verify the report's period, scope, and complementary user entity controls.

Why this answer

A SOC 2 Type II report is the standard independent attestation for security, availability, and confidentiality controls over a period of time, allowing a customer to evaluate a provider without an on-site review. The customer should confirm the report's scope covers the in-use service, the audit period is recent, and any listed complementary user entity controls are implemented on its side.

Exam trap

The trap here is confusing SOC 1, which addresses financial reporting controls, or unverified self-assessments such as the CAIQ, with the independent trust services attestation a cloud security audit requires.

5
Multi-Selectmedium

A company subject to SOX is using a cloud ERP system. Which THREE of the following IT general controls are essential for SOX compliance?

Select 3 answers
A.Audit logging of user activities and system changes
B.Physical security of the cloud provider's data centers
C.Access controls to ensure segregation of duties
D.Change management procedures for the ERP system
E.Multi-factor authentication for all cloud provider administrators
AnswersA, C, D

Audit logging captures user activity and system changes in the cloud ERP, creating the tamper-evident trail auditors need to evidence financial reporting integrity. This satisfies SOX's requirement for reliable, reviewable records supporting assertions about transactions and controls over financial systems.

Why this answer

Option A is correct because SOX ITGC requires audit logging of user activities and system changes to provide an evidentiary trail for financial reporting controls, enabling detection of unauthorized or anomalous activity and supporting audit testing. Option C is correct because access controls that enforce segregation of duties prevent any single user from initiating, approving, and recording financial transactions, which is a core SOX requirement to reduce fraud risk over financial data in the ERP. Option D is correct because change management procedures ensure that modifications to the ERP system are authorized, tested, approved, and documented, protecting the integrity and availability of financially relevant applications and data.

Option B is not correct because physical security of the cloud provider's data centers is the provider's responsibility under the shared responsibility model and is typically addressed through SOC 1/SOC 2 reports rather than being an essential control the customer must implement for SOX. Option E is not correct because, while MFA for cloud provider administrators is a good practice, SOX ITGC focuses on the customer's controls over its own users and privileged access to the ERP, not on the cloud provider's internal administrative accounts.

Exam trap

CCSP often tests the shared responsibility boundary — candidates incorrectly select provider-side controls (physical security, CSP admin MFA) as customer SOX controls.

6
MCQmedium

A cloud customer's legal team must decide which party bears responsibility for generating audit evidence that demonstrates regulatory compliance. The customer uses IaaS from a provider. According to the CSA Cloud Controls Matrix and shared responsibility principles, how should audit evidence obligations be divided?

A.The cloud provider is solely responsible for producing all audit evidence because it operates the physical infrastructure and hypervisor.
B.A third-party auditor engaged by the customer must independently verify every control across both the provider and customer environments, regardless of who operates them.
C.The customer must obtain evidence for controls it operates, while the provider supplies evidence for controls it operates, with each party relying on the other's attestations where appropriate.
D.The provider is responsible only for evidence related to its own internal corporate compliance, not for any controls that support customer workloads.
AnswerC

Under the shared responsibility model, each party is accountable for the controls it implements. In IaaS, the provider evidences physical, network, and hypervisor controls, often through SOC 2 or ISO/IEC 27001 reports; the customer evidences guest OS, application, and data controls. This division is the basis for CSA CCM and contractual audit rights, ensuring complete coverage without duplicating effort.

Why this answer

In a shared responsibility model, audit evidence must map to who operates each control. For IaaS, the provider evidences the physical, network, and hypervisor layers, while the customer evidences the guest OS, applications, and data. Contractual audit rights and provider attestations like SOC 2 reports bridge the gap, allowing each party to rely on the other's evidence for controls outside its own scope.

Exam trap

The trap here is assuming that the cloud provider is responsible for all audit evidence because it owns the infrastructure, when in fact the customer must evidence the controls it operates.

7
Multi-Selectmedium

A cloud customer must comply with GDPR's right to erasure (right to be forgotten). Which TWO of the following are technical challenges the customer faces when the data is stored in a cloud object storage service with versioning and cross-region replication?

Select 2 answers
A.Ensuring data is accessible only via a specific IP range
B.Removing previous versions of objects
C.Encrypting the data at rest with customer-managed keys
D.Exporting data in a machine-readable format
E.Deleting data from all replicated copies across regions
AnswersB, E

Versioning retains every prior iteration of an object, so erasure requires enumerating and deleting each version individually rather than the current object alone. This satisfies the stem's versioning constraint, since residual versions still contain the personal data subject to the erasure request.

Why this answer

Option B is correct because object storage versioning retains every prior version of an object, so a GDPR erasure request cannot be satisfied by simply deleting the current object; the customer must also enumerate and permanently remove all noncurrent versions (e.g., via S3 versioning delete markers plus explicit version deletion or lifecycle expiration). Option E is correct because cross-region replication creates additional copies in other regions, and the right to erasure requires those replicas to be deleted as well, which is technically challenging due to replication lag, delete-marker propagation behavior, and the need to verify deletion in every target region. Option A is not a right-to-erasure challenge but an access-control/network-restriction concern, typically handled with bucket policies, VPC endpoints, or IP conditions.

Option C concerns encryption key management and confidentiality, not the deletion of data. Option D relates to data portability under GDPR Article 20, not the right to erasure under Article 17.

Exam trap

CCSP often tests GDPR data subject rights — candidates confuse the right to erasure (Article 17) with the right to data portability (Article 20) or pick encryption controls that address confidentiality rather than deletion.

8
MCQeasy

Which CSA STAR tier involves a third-party assessment against ISO 27001?

A.Tier 4 – Peer review
B.Tier 1 – Self-assessment
C.Tier 3 – Continuous monitoring
D.Tier 2 – Third-party assessment
AnswerD

Tier 2 requires an independent third-party assessment against a recognised standard, specifically ISO/IEC 27001, plus the CSA Cloud Controls Matrix. Tier 1 is self-assessment only, so it cannot satisfy the third-party assessment constraint stated in the stem.

Why this answer

The CSA STAR (Security, Trust, Assurance, and Risk) program has three tiers: Tier 1 (Self-Assessment), Tier 2 (Third-Party Assessment), and Tier 3 (Continuous Monitoring). Tier 2 specifically requires a third-party assessment against the ISO/IEC 27001 standard, where an accredited certification body audits the cloud service provider's Information Security Management System (ISMS) for compliance. This tier provides a higher level of assurance than self-assessment, as it involves independent validation of security controls.

Exam trap

ISC2 often tests the misconception that Tier 2 is the 'self-assessment' tier, confusing it with Tier 1, or that there is a Tier 4 for peer review, which does not exist in the CSA STAR framework.

How to eliminate wrong answers

Option A is wrong because Tier 4 does not exist in the CSA STAR program; the tiers are limited to 1, 2, and 3, and 'Peer review' is not a defined tier. Option B is wrong because Tier 1 is the Self-Assessment tier, which involves the cloud provider completing a Consensus Assessments Initiative Questionnaire (CAIQ) without any third-party involvement or ISO 27001 audit. Option C is wrong because Tier 3 is Continuous Monitoring, which focuses on ongoing security telemetry and automated reporting (e.g., via the CSA STAR Watch program), not a one-time third-party assessment against ISO 27001.

9
MCQmedium

A cloud customer stores data in a SaaS application that replicates across multiple jurisdictions. The customer's legal team must respond to a subpoena for data stored in a specific region. Which concept determines the legal authority over the data?

A.Data residency
B.Data localization
C.Data sovereignty
D.Data portability
AnswerC

Data sovereignty refers to the principle that data is subject to the laws and regulations of the country in which it is stored. In this scenario, the replication across jurisdictions means the data may be subject to multiple legal authorities. The subpoena's enforceability depends on which jurisdiction has sovereignty over the data at the time of the request, making this the key concept.

Why this answer

Data sovereignty is the legal principle that data is governed by the laws of the country where it resides. When data is replicated across regions, each copy may fall under different sovereign laws. A subpoena from one jurisdiction may not be enforceable in another, and the cloud provider may be caught between conflicting legal demands.

Understanding sovereignty helps legal teams navigate cross-border data requests and design compliance strategies.

Exam trap

The trap here is equating data residency with data sovereignty; residency is about physical location, while sovereignty is about which laws apply.

10
MCQeasy

A cloud customer is evaluating a provider's compliance with the Payment Card Industry Data Security Standard (PCI DSS). The customer plans to store cardholder data in the provider's IaaS environment. Which responsibility does the customer retain under PCI DSS?

A.The customer is responsible only for physical security of the data center because the provider handles all logical controls.
B.The customer is responsible for configuring and managing the guest operating system, applications, and cardholder data environment, including access controls and encryption.
C.The customer is responsible for nothing because the provider's PCI DSS attestation covers all systems storing cardholder data.
D.The customer is responsible for all PCI DSS requirements because PCI DSS does not recognize shared responsibility models.
AnswerB

In IaaS, the customer controls the guest OS and above, so it must implement PCI DSS requirements for those layers, such as access control, encryption of cardholder data, and vulnerability management. The provider is responsible for the physical and hypervisor layers. PCI DSS requires each party to attest to the controls it operates, and the customer cannot outsource its compliance obligations for its own cardholder data environment.

Why this answer

Under PCI DSS in IaaS, the customer is responsible for the guest operating system, applications, and cardholder data environment, including access controls and encryption. The provider secures the physical and hypervisor layers. Each party must validate its own controls, and the customer cannot rely solely on the provider's attestation for its own compliance obligations.

Exam trap

The trap here is assuming that the provider's PCI DSS attestation absolves the customer of all responsibility, when the customer must still secure its own cardholder data environment.

11
Multi-Selecthard

A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The customer must ensure compliance with legal and regulatory requirements. Which TWO factors are most important to address in the contract with the provider? (Choose two.)

Select 2 answers
A.Require the provider to delete data from all backups and replicas within a specified timeframe
B.Require the provider to notify the customer before deleting data due to a legal hold
C.Specify the retention period and deletion timeline for data upon contract termination
D.Allow the provider to retain data for its own analytics purposes
E.Ensure the provider gives the customer a discount for early deletion
AnswersA, C

Cloud data is often replicated across multiple locations and backups. If deletion does not cover all copies, residual data could remain accessible or subject to legal discovery. Requiring deletion from all backups and replicas ensures complete data destruction, which is essential for meeting regulatory erasure requirements and avoiding unintended data retention.

Why this answer

The two most important factors are specifying retention and deletion timelines and ensuring deletion covers all backups and replicas. These directly address legal requirements for data minimization and secure disposal. The other options introduce financial incentives, provider data use, or legal hold notifications, which do not ensure compliant deletion and could create additional risks.

Exam trap

The trap here is focusing on cost or provider convenience instead of the legal necessity to delete all copies of data within defined timelines.

12
MCQhard

A cloud customer is subject to an eDiscovery request and stores business records in a cloud object storage service. The legal team needs to preserve potentially relevant data and prevent it from being altered or deleted while the matter is active. Which cloud capability should the customer configure to meet this obligation?

A.Enable versioning on the bucket so previous object versions remain available after overwrite or deletion.
B.Enable cross-region replication so a secondary copy exists in another region if the primary copy is deleted.
C.Apply an object lock with a retention mode and legal hold to prevent deletion or overwrite for the required period.
D.Configure a lifecycle policy that transitions objects to cold storage after 30 days to reduce cost.
AnswerC

Object lock provides write-once-read-many (WORM) protection and, in governance or compliance mode, prevents objects from being deleted or overwritten until the retention period expires. A legal hold can also be applied independently to prevent deletion. This directly satisfies the duty to preserve data during active litigation.

Why this answer

A legal hold requires that potentially relevant data be preserved and protected from alteration or deletion. Object lock, especially in compliance mode, enforces immutability for a defined retention period, and a legal hold flag prevents deletion regardless of retention expiry. These controls give the customer a defensible preservation mechanism that survives administrative actions and supports eDiscovery obligations.

Exam trap

The trap here is confusing backup or replication features, which aid recovery, with immutability controls that legally prevent deletion or modification.

13
MCQhard

A U.S. financial services firm uses a cloud provider with data centers in the EU. The firm must comply with both SEC regulations requiring books and records preservation and the GDPR. A data subject requests erasure of personal data that is also subject to a legal hold. What should the firm do?

A.Immediately erase all personal data to comply with the GDPR erasure request, because data subject rights override legal retention obligations.
B.Assess the scope of the legal hold, retain only the data subject to the hold under restricted processing, and erase or anonymize other personal data as required by the GDPR request.
C.Transfer all personal data to a third country outside the EU to avoid GDPR jurisdiction, then erase it there.
D.Deny the erasure request entirely and retain all data indefinitely, because legal holds always supersede data subject rights.
AnswerB

This approach respects both regimes. GDPR Article 17(3)(b) permits retention when necessary for legal obligations, but the firm should limit retention to data actually subject to the hold and restrict its processing. Data outside the hold should be erased or anonymized to satisfy the erasure request. This balanced, documented approach is the legally sound method for conflicting obligations.

Why this answer

When GDPR erasure requests conflict with legal holds, the firm must apply GDPR Article 17(3)(b), which permits retention when necessary to comply with a legal obligation. The correct approach is to scope the hold, retain only the data subject to it under restricted processing, and erase or anonymize the rest. This satisfies both the legal hold and the data subject's rights to the extent possible.

Exam trap

The trap here is assuming either that GDPR erasure always overrides legal holds or that legal holds always override erasure; the correct approach requires scoping and balancing both obligations.

14
MCQhard

A cloud customer wants to ensure they can audit their cloud provider's security controls annually. Which contractual provision should be included in the cloud service agreement?

A.Service level agreement (SLA) with uptime guarantees
B.Data deletion clause
C.Data portability clause
D.Right to audit clause
AnswerD

A right to audit clause grants the customer contractual permission to assess the provider's security controls, typically annually, either directly or via an independent third party. Without it, the customer has no enforceable means to verify controls beyond provider-supplied reports.

Why this answer

A right to audit clause contractually grants the cloud customer the ability to audit the provider's security controls, either directly or through third-party assessments, on a defined schedule. This is the specific provision that ensures annual audit capability, so D is correct.

Exam trap

CCSP often tests whether candidates confuse the right to audit with SLAs, data deletion, or portability clauses — the key is recognizing that only the right to audit grants control verification access.

How to eliminate wrong answers

Option A is wrong because an SLA with uptime guarantees addresses availability commitments and remedies (service credits), not the customer's ability to audit security controls. Option B is wrong because a data deletion clause specifies how data is destroyed at contract termination, which is a data lifecycle concern, not an audit right. Option C is wrong because a data portability clause governs the customer's ability to export their data to another provider, addressing lock-in, not audit access.

15
MCQmedium

A cloud customer is terminating its contract with a cloud provider and needs to ensure all data, including backups, is permanently deleted. Which contractual clause is most relevant?

A.Service Level Agreement
B.Data deletion clause
C.Data portability clause
D.Right to audit clause
AnswerB

A data deletion clause contractually obliges the provider to permanently erase all customer data, including backups, on termination. It directly satisfies the requirement for assured destruction of residual copies rather than merely returning primary data.

Why this answer

A data deletion clause contractually obligates the provider to permanently delete customer data, including backups, upon termination, which is exactly what the customer needs. It specifies timelines, methods, and certification of deletion, giving the customer enforceable assurance. This is the most directly relevant clause for ensuring no residual copies remain.

Exam trap

CCSP often tests the confusion between data portability (getting data out) and data deletion (ensuring data is destroyed), so candidates pick portability when the scenario demands permanent deletion.

How to eliminate wrong answers

Option A is wrong because an SLA defines availability and performance commitments, not data destruction obligations. Option C is wrong because data portability covers exporting data in a usable format, not deleting it. Option D is wrong because the right to audit allows inspection of provider controls, but does not itself mandate deletion of data or backups.

16
MCQmedium

A company is negotiating a cloud service agreement and wants to ensure it can periodically assess the security of the cloud provider's operations. Which contractual clause is most directly relevant to this requirement?

A.Right to Audit clause permitting the customer to review the provider's security controls and certifications
B.Data portability clause ensuring data can be exported in a usable format
C.Service Level Agreement (SLA) with uptime guarantees
D.Data deletion clause specifying how data is deleted after contract termination
AnswerA

A Right to Audit clause directly grants the customer contractual authority to examine the provider's security controls and certifications, satisfying the requirement for periodic assessment of the provider's operations. Without this clause, the customer relies solely on the provider's self-reported attestations, losing independent verification rights.

Why this answer

A Right to Audit clause explicitly grants the customer the contractual right to assess the cloud provider's security controls, certifications, and compliance through audits or inspections. This directly addresses the requirement to periodically assess the provider's operations. Other clauses address different concerns such as data portability, performance, or data deletion, but not security assessment.

Exam trap

CCSP often tests confusion between Right to Audit and other contractual clauses like SLA or data portability, but the key is that only Right to Audit directly enables security assessment.

How to eliminate wrong answers

Option B is wrong because data portability focuses on the ability to export data, not on assessing security controls. Option C is wrong because an SLA with uptime guarantees addresses availability, not security assessment. Option D is wrong because a data deletion clause specifies how data is removed after contract termination, not ongoing security evaluation.

17
MCQeasy

A US-based retail company stores customer personal data in a cloud provider's data center located in Germany. The company is subject to GDPR because it offers goods to EU residents. Which legal mechanism most directly establishes that the controller and the cloud provider may lawfully transfer personal data from the EU to the provider's US-based support team?

A.Standard Contractual Clauses (SCCs) executed between the controller and the cloud provider
B.A data processing agreement (DPA) alone, without any additional transfer safeguard
C.A Binding Corporate Rules (BCR) approval granted to the cloud provider by its lead supervisory authority
D.The provider's ISO/IEC 27001 certification covering its German data center
AnswerA

SCCs are pre-approved contractual terms adopted by the European Commission that provide an Article 46 transfer safeguard when personal data leaves the EEA. Because the provider's US support staff can access EU personal data, the controller needs a valid transfer tool, and SCCs are the most common and directly applicable mechanism for controller-to-processor transfers in a cloud engagement.

Why this answer

When EU personal data is accessible from a third country such as the United States, the controller needs a valid Chapter V transfer mechanism. Standard Contractual Clauses are pre-approved by the European Commission and are the most direct, widely used tool for controller-to-processor cloud transfers. A DPA governs processing but does not authorize the transfer, and security certifications or corporate-group rules do not fill that gap.

Exam trap

The trap here is assuming that a data processing agreement or a security certification alone satisfies GDPR cross-border transfer requirements, when an Article 46 mechanism such as SCCs is also needed.

18
Multi-Selectmedium

A cloud customer is assessing a provider's compliance with the Cloud Security Alliance (CSA) STAR program. Which TWO artifacts are part of the STAR program? (Choose two.)

Select 2 answers
A.ISO/IEC 27017 certificate
B.Cloud Controls Matrix (CCM)
C.GDPR compliance statement
D.SOC 2 Type II report
E.Consensus Assessments Initiative Questionnaire (CAIQ)
AnswersB, E

The CCM is a cybersecurity control framework specifically for cloud computing, developed by the CSA. It is a foundational component of the STAR program, providing the controls against which providers are assessed. The CCM helps customers understand necessary controls and is integral to STAR.

Why this answer

The CSA STAR program includes the Cloud Controls Matrix (CCM) as the control framework and the Consensus Assessments Initiative Questionnaire (CAIQ) as the assessment tool. These artifacts enable cloud providers to document their security controls and customers to evaluate them. Other reports like SOC 2 or ISO certifications are separate and not unique to STAR, though they may be used in conjunction.

Exam trap

The trap here is assuming that any security certification or report is part of the STAR program, when STAR specifically offers the CCM and CAIQ as its own tools.

19
MCQeasy

Under GDPR, what is the maximum time allowed for a data controller to notify the supervisory authority of a personal data breach?

A.7 days
B.24 hours
C.72 hours
D.48 hours
AnswerC

GDPR Article 33 requires controllers to notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in risk to individuals' rights and freedoms.

Why this answer

GDPR Article 33 requires notification within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to rights and freedoms.

20
Multi-Selectmedium

A cloud customer is developing a data retention and deletion policy for data stored with a cloud provider. The legal team must ensure the policy addresses key contractual and regulatory considerations. Which TWO elements should the policy include? (Choose two.)

Select 2 answers
A.A provision allowing the provider to retain customer data indefinitely for its own business purposes
B.A right for the provider to retain data beyond the agreed retention period if it is technically difficult to delete
C.A process for the customer to request early deletion of specific data during the contract term and for the provider to confirm deletion
D.A clause stating that the provider may use customer data for marketing purposes after anonymization without customer consent
E.A requirement that the provider delete all customer data within a specified period after contract termination, including from backups, and provide a certificate of destruction
AnswersC, E

Customers often need to delete specific data before contract end, such as when a data subject exercises the right to erasure or when data is no longer needed. A defined process with confirmation ensures the provider acts on these requests and provides auditability. This supports compliance with GDPR and other privacy laws that require timely deletion. It also helps manage storage costs and reduce risk.

Why this answer

A robust data retention and deletion policy must include a contractual commitment for the provider to delete all customer data, including backups, after termination and to certify destruction. It should also define a process for early deletion during the contract term. These elements ensure the customer can meet regulatory retention limits and respond to data subject requests.

Exam trap

The trap here is focusing only on deletion at contract end and forgetting the need for a process to delete specific data during the contract, or accepting provider-friendly clauses that allow indefinite retention for business purposes.

21
MCQeasy

Under GDPR, what is the role of a cloud provider that processes personal data solely on behalf of a customer?

A.Data controller
B.Supervisory authority
C.Data subject
D.Data processor
AnswerD

A processor handles personal data only on documented instructions from the controller, which is precisely the cloud provider's position here. The controller determines purposes and means; the processor bears no such determination, matching the stem's solely-on-behalf wording.

Why this answer

Under GDPR, a data processor is an entity that processes personal data on behalf of a data controller. The cloud provider, in this scenario, acts as a processor because it processes data solely on behalf of the customer (the controller). The processor must follow the controller's instructions and comply with GDPR obligations.

Exam trap

CCSP often tests confusion between controller and processor roles, but the key is that a cloud provider processing data solely on behalf of a customer is a processor, not a controller.

How to eliminate wrong answers

Option A is wrong because the data controller determines the purposes and means of processing; here, the customer is the controller. Option B is wrong because a supervisory authority is a regulatory body, not a role in the processing relationship. Option C is wrong because a data subject is the individual whose data is processed, not the cloud provider.

22
MCQmedium

A European retail company is migrating its customer analytics platform to a public cloud provider. The dataset contains personal data of EU residents, and the company wants to minimize the risk of regulatory enforcement action if the cloud provider suffers a breach. Which action BEST addresses the shared responsibility for compliance in this scenario?

A.Execute a data processing agreement with the provider and independently verify the technical and organizational measures applied to the personal data.
B.Encrypt the data at rest with provider-managed keys and consider the compliance obligation fully transferred to the cloud provider.
C.Rely on the cloud provider's ISO/IEC 27001 certification as full evidence of GDPR compliance for the workload.
D.Transfer all personal data to the provider's infrastructure and let the provider determine the lawful basis for processing.
AnswerA

Under GDPR, a controller engaging a processor must have a data processing agreement in place, and the controller remains accountable for demonstrating compliance. Independently verifying the provider's technical and organizational measures ensures the contractual commitments are actually implemented, which directly reduces enforcement risk if a breach occurs.

Why this answer

The customer remains the data controller and therefore accountable under GDPR, even when using a public cloud. A data processing agreement establishes the required contractual framework, and independent verification confirms that the provider's technical and organizational measures are effective. Together these actions address the shared responsibility model and reduce the risk of regulatory enforcement after a breach.

Exam trap

The trap here is assuming that a provider's security certification or encryption automatically transfers GDPR accountability to the cloud provider.

23
Multi-Selectmedium

A cloud customer is negotiating a contract with a new cloud provider. The customer wants to ensure they can maintain control over their data and verify the provider's security posture. Which TWO contractual provisions are most critical for these purposes? (Choose two.)

Select 2 answers
A.Data portability clause to export data in a usable format
B.Data ownership clause specifying customer retains all rights to data
C.Data deletion clause for removal upon contract termination
D.Service Level Agreement (SLA) for uptime and performance
E.Right to audit the cloud provider's security controls
AnswersB, E

A data ownership clause contractually confirms the customer retains all rights to their data, preserving control and preventing the provider from claiming or repurposing it. This directly satisfies the requirement to maintain control over data.

Why this answer

Option B is correct because a data ownership clause explicitly stating that the customer retains all rights to their data directly addresses the customer's goal of maintaining control over their data, removing ambiguity about who owns the information stored with the provider. Option E is correct because a right-to-audit provision lets the customer independently verify the provider's security posture through assessments, certifications, or on-site audits, which is exactly the verification capability the customer wants. Option A is not the best fit because data portability addresses avoiding lock-in and migrating data, not ownership control or security verification.

Option C is not selected because deletion on termination concerns data disposal, not ongoing control or security posture verification. Option D is not selected because an SLA for uptime and performance covers availability and service quality, not data control or security assurance.

Exam trap

ISC2 often tests the distinction between contractual clauses that provide legal ownership (data ownership) versus operational capabilities (data portability, deletion) versus performance guarantees (SLA), and candidates frequently confuse the right to audit with a general SLA or data portability clause.

24
MCQhard

A cloud customer is subject to a regulatory audit and must provide evidence that the cloud provider's security controls are effective. The customer has no right to audit the provider directly but can rely on third-party attestations. Which report should the customer request to obtain an independent assessment of the provider's controls relevant to security, availability, and confidentiality?

A.Cloud Security Alliance STAR Level 1 self-assessment
B.SOC 1 Type II report
C.SOC 2 Type II report
D.ISO/IEC 27001 certificate
AnswerC

SOC 2 Type II reports provide an independent auditor's opinion on the effectiveness of controls over security, availability, processing integrity, confidentiality, and privacy. They cover a period of time, demonstrating sustained control operation. For a cloud customer needing evidence of security controls, this report is the most appropriate because it directly addresses the trust services criteria relevant to cloud services.

Why this answer

SOC 2 Type II is specifically designed to report on the effectiveness of controls related to security, availability, and confidentiality over a period. It is produced by an independent CPA firm and is widely accepted in regulatory audits. Other options either focus on financial controls, lack detailed period-based evidence, or are self-assessed, making SOC 2 Type II the correct choice.

Exam trap

The trap here is confusing a point-in-time certification like ISO 27001 with a period-based attestation like SOC 2 Type II.

25
MCQmedium

A cloud customer's legal team is reviewing a provider's contract and finds a clause requiring the customer to resolve all disputes through binding arbitration in the provider's home country. The customer operates in several jurisdictions and wants to preserve its options. Which contract provision should the customer negotiate to best address this concern?

A.A choice-of-law and choice-of-forum clause naming a neutral jurisdiction
B.A right to audit the provider's security controls annually
C.A service-level agreement with credits for availability shortfalls
D.A data residency clause requiring storage only in the customer's home country
AnswerA

A choice-of-law and choice-of-forum clause determines which jurisdiction's law applies and where disputes are heard. Naming a neutral jurisdiction, or at least one acceptable to both parties, counteracts a mandatory arbitration clause tied to the provider's home country. This directly addresses the customer's desire to preserve legal options across multiple operating jurisdictions.

Why this answer

A choice-of-law and choice-of-forum clause determines the governing law and the venue for disputes, directly countering a one-sided mandatory arbitration provision. Naming a neutral jurisdiction protects the customer's ability to pursue remedies across multiple operating regions. Audit rights, SLAs, and data residency provisions serve different purposes and do not affect where disputes are heard.

Exam trap

The trap here is confusing a data residency requirement, which limits where data is stored, with a forum selection clause, which determines where legal disputes are adjudicated.

26
MCQeasy

Which of the following is a key requirement for data portability under the General Data Protection Regulation (GDPR)?

A.Data must be transferred directly to the data subject's own device.
B.Data must be provided in a structured, commonly used, and machine-readable format.
C.Data portability applies only to pseudonymized data.
D.Data must be deleted within 30 days of a portability request.
AnswerB

GDPR Article 20 requires portability in a structured, commonly used and machine-readable format, enabling the data subject to transmit data to another controller without hindrance. This format requirement is the specific technical condition the regulation imposes.

Why this answer

GDPR Article 20 requires that when data portability applies, the controller must provide the personal data 'in a structured, commonly used and machine-readable format.' This ensures the data can be transmitted to another controller without hindrance, typically using formats such as JSON, XML, or CSV. The right applies to data processed by automated means based on consent or contract.

Exam trap

The trap here is confusing data portability with the right of access or erasure, leading candidates to pick deletion timelines or device-transfer requirements that GDPR does not mandate.

How to eliminate wrong answers

Option A is wrong because GDPR does not require direct transfer to the data subject's own device; the data subject may receive the data or have it transmitted directly to another controller. Option C is wrong because portability applies to personal data provided by the data subject, not only pseudonymized data; pseudonymized data may still be within scope if it relates to an identifiable person. Option D is wrong because GDPR does not impose a 30-day deletion requirement tied to portability requests; deletion timelines are governed by other principles such as storage limitation and the right to erasure.

27
MCQhard

A cloud customer is negotiating a contract and wants to ensure they have the right to verify the cloud provider's security controls. Which contractual provision is most important?

A.Data portability clause
B.Data deletion clause
C.Right to audit clause
D.Service Level Agreement (SLA) for uptime
AnswerC

A right to audit clause contractually grants the customer the ability to verify the provider's security controls, whether directly or via an independent assessor. This directly satisfies the stated requirement to secure verification rights during contract negotiation.

Why this answer

The right to audit clause is a contractual provision that grants the cloud customer the ability to verify the provider's security controls, either through direct audits or by accepting third-party audit reports. It is essential for ensuring compliance and trust in the cloud provider's security posture.

Exam trap

The trap is confusing the right to audit with other contractual clauses like SLAs or data portability; candidates may pick SLA because it sounds like it ensures performance, but it does not cover security verification.

How to eliminate wrong answers

Option A is wrong because data portability clauses address the ability to move data, not verify security controls. Option B is wrong because data deletion clauses specify how data is destroyed at contract termination, not security verification. Option D is wrong because an SLA for uptime guarantees availability, not security control effectiveness.

28
MCQmedium

A healthcare organization stores protected health information (PHI) in a cloud environment. Under HIPAA, what must the organization obtain from the cloud provider before processing PHI?

A.A Data Processing Agreement (DPA) under GDPR
B.A Business Associate Agreement (BAA)
C.A Service Organization Control (SOC) 2 report
D.An ISO 27001 certification
AnswerB

A BAA is mandatory under HIPAA before a covered entity may disclose PHI to a cloud provider, which acts as a business associate. It contractually binds the provider to safeguard PHI, satisfying the stem's requirement to obtain an agreement prior to processing.

Why this answer

Under HIPAA, a covered entity must obtain a Business Associate Agreement (BAA) from any cloud provider that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. The BAA establishes the permitted uses and disclosures of PHI and requires the business associate to implement safeguards.

Exam trap

The trap is confusing GDPR's DPA with HIPAA's BAA; candidates may think any data processing agreement suffices, but HIPAA specifically requires a BAA for PHI.

How to eliminate wrong answers

Option A is wrong because a DPA under GDPR is for EU personal data, not HIPAA PHI; while a DPA may be needed for GDPR compliance, it does not satisfy HIPAA. Option C is wrong because a SOC 2 report is an audit report that provides assurance but is not a contractual requirement under HIPAA. Option D is wrong because ISO 27001 certification is a voluntary security standard, not a HIPAA requirement.

29
Multi-Selectmedium

A cloud service provider wants to demonstrate compliance with ISO/IEC 27017 for cloud services. Which TWO controls are specific additions that this standard introduces beyond ISO/IEC 27002? (Choose two.)

Select 2 answers
A.A mandate that all cloud personnel hold a Certified Cloud Security Professional (CCSP) certification.
B.A requirement to publish real-time security incident dashboards to all customers.
C.Guidance on shared roles and responsibilities between cloud service customers and cloud service providers.
D.Requirements for the removal or return of cloud service customer assets upon contract termination.
E.Mandatory encryption of all data at rest using AES-256 or an equivalent algorithm.
AnswersC, D

ISO/IEC 27017 explicitly addresses the division of security responsibilities between cloud service customers and providers. This guidance clarifies who handles which controls in the shared responsibility model, reducing ambiguity. It is one of the cloud-specific additions not found in the base ISO/IEC 27002 control set.

Why this answer

ISO/IEC 27017 extends ISO/IEC 27002 with cloud-specific implementation guidance, notably clarifying shared roles and responsibilities between customers and providers, and addressing the return or removal of customer assets at service termination. These additions target the unique risks of cloud arrangements rather than imposing technology mandates or certification requirements.

Exam trap

The trap here is assuming ISO/IEC 27017 mandates specific technologies or certifications, when it actually adds cloud-specific guidance and controls.

30
Multi-Selecthard

A cloud customer is assessing the risk of using a cloud provider. Which THREE factors are most important in evaluating the inherent risk of migrating data and applications to the cloud?

Select 3 answers
A.Data leaving the customer's direct control and being stored on shared infrastructure
B.Dependence on the provider's security controls and the risk of a provider-side breach affecting multiple tenants
C.The provider's compliance certifications (e.g., ISO 27001, SOC 2)
D.The shared responsibility model and potential for misconfiguration by the customer
E.The provider's physical security controls at data centers
AnswersA, B, D

Data leaving direct control removes the customer's ability to enforce physical and logical safeguards, while shared infrastructure introduces multi-tenancy risks such as side-channel exposure and noisy-neighbour contention. These are inherent to cloud migration, satisfying the stem's focus on risks arising from the provider's model rather than contractual or operational controls.

Why this answer

Option A is correct because migrating to the cloud inherently means data leaves the customer's direct physical and logical control and resides on multi-tenant shared infrastructure, which is a fundamental source of inherent risk regardless of any controls the provider implements. Option B is correct because the customer becomes dependent on the provider's security controls, and a provider-side breach or compromise can affect multiple tenants simultaneously, creating concentration and supply-chain risk that the customer cannot fully mitigate alone. Option D is correct because the shared responsibility model defines which security duties remain with the customer, and customer-side misconfiguration (for example, an exposed S3 bucket or overly permissive IAM role) is a leading cause of cloud incidents, making it a core inherent risk factor.

Option C is not selected because compliance certifications are assurance artifacts that help evaluate the provider's control environment rather than inherent risk factors of the migration itself. Option E is not selected because the provider's physical data center security is a control the provider manages and is largely inherited by the customer, so it is not one of the most important inherent risk factors in this assessment.

Exam trap

The trap is selecting provider certifications or physical security as 'inherent risk' factors; candidates must distinguish inherent risks (introduced by the cloud model) from mitigating controls or assurances that reduce risk.

31
MCQmedium

A company using a SaaS application for HR management receives a data subject access request (DSAR) under GDPR from an employee. The cloud provider is the data processor. The company as data controller must respond within what timeframe?

A.One month
B.90 days
C.45 days
D.72 hours
AnswerA

Under GDPR Article 12(3), the controller must respond to a data subject access request without undue delay and in any event within one month of receipt, extendable by two further months for complex requests. The processor's role does not alter this controller deadline.

Why this answer

Under GDPR Article 12(3), the data controller must respond to a data subject access request (DSAR) without undue delay and in any event within one month of receipt of the request. This one-month period can be extended by two further months for complex requests, but the baseline deadline is one month. The cloud provider as processor must assist the controller, but the controller bears the legal obligation to respond within that timeframe.

Exam trap

CCSP often tests the confusion between GDPR timelines: 72 hours for breach notification, one month for DSAR response, and other jurisdictions' deadlines like 45 or 90 days; candidates must distinguish the specific obligation.

How to eliminate wrong answers

Option B is wrong because 90 days is not a GDPR DSAR deadline; it resembles other regulatory timelines (e.g., some US state privacy laws) but does not apply here. Option C is wrong because 45 days is also not a GDPR deadline; it is used in some other privacy frameworks (e.g., certain US state laws) but not GDPR. Option D is wrong because 72 hours is the GDPR deadline for notifying a supervisory authority of a personal data breach under Article 33, not for responding to a DSAR.

32
MCQmedium

A cloud customer is subject to eDiscovery requirements in a lawsuit. The data resides in a cloud storage service that uses encryption. What is the primary challenge in collecting this data in a forensically sound manner?

A.Obtaining a search warrant for data stored in the cloud
B.Decrypting the data without the encryption keys
C.Ensuring the integrity and chain of custody when data is collected via API or provider tools rather than physical seizure
D.Identifying the specific geographic location of the data
AnswerC

Collecting via API or provider tooling bypasses physical seizure, so forensic soundness hinges on verifiable integrity and an unbroken chain of custody. Provider-mediated exports may omit metadata, alter timestamps, or lack cryptographic hashes, undermining admissibility under eDiscovery rules. Microsoft Entra ID access logs and immutable audit trails help evidence who accessed the export.

Why this answer

In cloud eDiscovery, data is collected via APIs or provider-native tools rather than by seizing physical media, so the primary forensic challenge is preserving integrity and demonstrating an unbroken chain of custody. Unlike physical seizure where a disk can be hashed and sealed, API-based collection must be logged, hashed, and authenticated to withstand legal scrutiny. The encryption itself is not the main obstacle if the customer holds the keys; the procedural integrity of the collection is what courts and opposing counsel will challenge.

Exam trap

The trap is focusing on encryption or warrants as the main obstacle; candidates must recognize that in cloud eDiscovery the forensic challenge is maintaining integrity and chain of custody through API-based collection rather than physical seizure.

How to eliminate wrong answers

Option A is wrong because obtaining a search warrant is a legal process issue, not a forensic soundness challenge — and in many eDiscovery scenarios the data is the customer's own, so no warrant is needed. Option B is wrong because if the customer controls the encryption keys (common in cloud storage with customer-managed keys), decryption is straightforward; the challenge is not cryptographic access but proving the collection was tamper-free. Option D is wrong because while data location matters for jurisdiction, providers expose region information and it is a compliance consideration rather than the core forensic integrity challenge in collecting the data.

33
MCQmedium

A company wants to export its data from a cloud provider to another provider upon contract termination. Which contract clause is essential to ensure the data can be exported in a usable format?

A.Service level agreement
B.Data portability clause
C.Right to audit
D.Data deletion clause
AnswerB

A data portability clause contractually obliges the provider to return customer data in a structured, commonly used, machine-readable format on termination, enabling migration to another provider. This satisfies the stem's requirement for export in a usable format.

Why this answer

A data portability clause contractually obligates the cloud provider to return customer data in a structured, commonly used, and machine-readable format upon termination, ensuring the data can be migrated to another provider. Without this clause, the provider might only offer data in a proprietary or non-standard format, making export impractical. This is a key requirement under GDPR Article 20 and other data protection regulations.

Exam trap

CCSP often tests the distinction between data portability (export rights) and data deletion (destruction rights), as both are termination-related clauses but serve opposite purposes.

How to eliminate wrong answers

Option A is wrong because an SLA defines performance metrics like uptime and latency, not data export rights. Option C is wrong because the right to audit allows customer inspection of provider controls, not data retrieval. Option D is wrong because a data deletion clause ensures data is destroyed after termination, which is the opposite of enabling export.

34
Multi-Selecthard

A global company uses a cloud provider that stores data in multiple jurisdictions. During an eDiscovery request from a US court, which three challenges are most likely to arise? (Choose three.)

Select 3 answers
A.Jurisdictional conflicts over which court has authority
B.Lack of encryption options
C.Ensuring data is preserved without alteration (legal hold)
D.Inability to perform forensically sound collection due to lack of physical access
E.Excessive cost of cloud storage
AnswersA, C, D

Data spanning multiple jurisdictions triggers conflicting legal demands, as foreign privacy or blocking statutes may prohibit disclosure that a US court orders. This jurisdictional conflict over authority is a primary eDiscovery challenge in cross-border cloud environments.

Why this answer

Option A is correct because when data resides in multiple jurisdictions, US court orders can conflict with local data-protection or blocking statutes (e.g., GDPR or foreign blocking laws), creating disputes over which court or legal regime has authority over the data. Option C is correct because eDiscovery requires a legal hold to preserve potentially relevant data in place, and in multi-jurisdiction cloud environments this is complicated by distributed storage, automated lifecycle deletion, and differing retention rules that can alter or destroy evidence. Option D is correct because cloud tenants typically lack physical access to the provider's hardware, so forensically sound collection must rely on provider APIs, snapshots, and chain-of-custody documentation rather than direct disk imaging, which can be challenged in court.

Option B is not correct because major cloud providers offer extensive encryption options (at rest, in transit, and customer-managed keys), so lack of encryption is not an inherent eDiscovery challenge. Option E is not correct because while cloud storage costs exist, excessive cost is not a legal or forensic challenge specific to cross-jurisdiction eDiscovery and is not among the primary issues courts focus on.

Exam trap

The trap is assuming that encryption or cost are major eDiscovery challenges, when the real issues are legal jurisdiction, data preservation, and forensic collection limitations.

35
MCQmedium

A European retailer stores customer personal data in a cloud-hosted e-commerce platform. The cloud provider processes data only on documented instructions from the retailer, which determines the purposes and means of processing. Under the General Data Protection Regulation (GDPR), which role does the cloud provider hold?

A.Independent controller, because it makes technical decisions about storage locations and backup schedules.
B.Data processor, because it processes personal data on behalf of, and only on documented instructions from, the retailer.
C.Data controller, because it operates the physical infrastructure where the personal data resides.
D.Joint controller, because both organizations participate in the processing activity.
AnswerB

GDPR defines a processor as a natural or legal person that processes personal data on behalf of the controller. Because the retailer sets the purposes and means and the provider acts only on documented instructions, the provider is the processor, and Article 28 requires a binding data processing agreement between the two parties.

Why this answer

The GDPR distinguishes controllers, who determine the purposes and means of processing, from processors, who act on the controller's behalf. The retailer decides why and how personal data is processed, while the cloud provider follows documented instructions, making it a processor. This triggers Article 28 obligations, including a mandatory data processing agreement and appropriate technical and organizational measures.

Exam trap

The trap here is assuming that owning or operating the underlying infrastructure automatically makes the cloud provider a controller rather than a processor.

36
Multi-Selectmedium

A cloud customer is building its compliance monitoring program for a provider-hosted workload that processes regulated data. The customer must ensure it can demonstrate ongoing compliance to regulators between audits. Which TWO provider commitments should the customer secure in the contract to sustain continuous compliance evidence? (Choose two.)

Select 2 answers
A.A right to obtain current independent audit reports, bridge letters, and certification evidence at least annually and after significant changes.
B.A right to receive the provider's internal penetration test raw findings and unfiltered vulnerability backlog for continuous review.
C.A right to require the provider to adopt the customer's internal control framework verbatim across all its tenants.
D.A right to embed the customer's own auditors full-time inside the provider's data centers to observe live operations.
E.A right to receive timely notification of material changes to the provider's control environment, sub-processors, and security certifications.
AnswersA, E

Regulators expect current evidence, and audit reports are point-in-time. Contractual access to updated SOC 2 reports, bridge letters covering gaps, and renewed certifications ensures the customer can refresh its compliance file without renegotiating each time. This right also supports due diligence when the provider changes its architecture or service scope.

Why this answer

Sustaining compliance between audits requires current evidence and early awareness of change. Contractual rights to timely notification of material changes and to updated audit reports, bridge letters, and certification evidence let the customer refresh its compliance file, reassess risk, and respond to regulator requests without waiting for the next scheduled audit cycle or renegotiating access each year.

Exam trap

The trap here is assuming that continuous compliance requires intrusive continuous access, such as on-site auditors or raw vulnerability data, when the workable contractual levers are change notification and periodic refreshed attestation evidence.

37
MCQhard

A cloud provider discovers a security incident affecting a customer's personal data stored in its platform. The customer acts as the data controller under the General Data Protection Regulation (GDPR). Which obligation does the provider have regarding notification of this breach?

A.Notify affected data subjects directly, because the provider holds the data and knows which records were exposed.
B.Notify the customer without undue delay after becoming aware of the personal data breach.
C.Notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
D.Publish a public incident report within 24 hours and wait for the customer to respond.
AnswerB

Under GDPR Article 33(2), a processor must notify the controller without undue delay after becoming aware of a personal data breach. The controller then decides whether to notify the supervisory authority within 72 hours. The processor does not notify the authority or data subjects directly in this scenario; its duty runs to the controller.

Why this answer

GDPR splits breach notification duties: processors must notify controllers without undue delay after becoming aware of a personal data breach, while controllers assess risk and handle authority and data subject notifications. The cloud provider, acting as processor, therefore owes prompt notice to its customer, enabling the customer to meet the 72-hour authority deadline if required.

Exam trap

The trap here is assuming the processor must notify the supervisory authority or data subjects directly, when GDPR places those duties on the controller.

38
MCQhard

A cloud customer is subject to a regulatory audit and must provide evidence of the cloud provider's security controls. The provider refuses to allow direct audits of its data centers. Which artifact should the customer rely on to satisfy the auditors?

A.Provider's self-assessment questionnaire
B.Penetration test summary
C.ISO/IEC 27001 certificate
D.SOC 2 Type II report
AnswerD

A SOC 2 Type II report provides independent attestation of a service organization's controls over security, availability, processing integrity, confidentiality, and privacy over a period. It is designed for cloud providers to share with customers to demonstrate effective controls without granting direct audit rights. Auditors typically accept SOC 2 Type II as sufficient evidence, making it the appropriate artifact in this scenario.

Why this answer

A SOC 2 Type II report is specifically designed to provide independent assurance over a period, covering the Trust Services Criteria. It is widely accepted by auditors as evidence of a cloud provider's security controls when direct audits are not feasible. Other artifacts like ISO 27001 certificates or self-assessments do not offer the same level of detailed, independent validation of control operation.

Exam trap

The trap here is confusing an ISO/IEC 27001 certificate, which certifies the management system, with a SOC 2 Type II report, which attests to the effectiveness of specific controls over time.

39
MCQmedium

A cloud customer stores personal data of EU residents in a SaaS application. The customer's contract with the SaaS provider includes a data processing addendum. The customer's legal team wants to understand the allocation of GDPR responsibilities. Which of the following best describes the roles of the customer and the SaaS provider under GDPR?

A.The customer is the processor and the SaaS provider is the controller because the provider hosts the data
B.The SaaS provider is the sole controller because it owns the infrastructure and determines the security measures
C.The customer is the controller and the SaaS provider is the processor, unless the provider processes data for its own purposes, in which case it may also be a controller for those specific activities
D.Both the customer and the SaaS provider are joint controllers for all processing activities
AnswerC

Under GDPR, the customer typically determines the purposes and means of processing and is the controller. The SaaS provider acts as a processor when it processes personal data solely on the customer's instructions. However, if the provider uses data for its own purposes, such as improving its services or marketing, it becomes a controller for those activities. This nuanced allocation is common in cloud contracts and data processing addenda.

Why this answer

In a typical SaaS arrangement, the customer is the controller and the provider is the processor. The provider may become a controller for specific processing done for its own purposes, such as service analytics or marketing. This dual role is recognized in GDPR and should be addressed in the data processing addendum.

Exam trap

The trap here is assuming that the cloud provider is always just a processor, when in fact it can also be a controller for certain activities, or conversely assuming that hosting data makes the provider the controller.

40
MCQhard

A healthcare analytics company processes electronic protected health information (ePHI) for multiple covered entities using a public cloud provider. The company signs a Business Associate Agreement (BAA) with each covered entity and also signs a BAA with the cloud provider. A security analyst discovers that the cloud provider stores backups of the ePHI in a region outside the United States and refuses to sign a separate BAA for that region. Which of the following is the MOST appropriate action for the company to take to maintain compliance with HIPAA?

A.Encrypt the ePHI backups in the offshore region and continue operations without a BAA for that region.
B.Terminate the BAA with the cloud provider and migrate all ePHI to an on-premises data center.
C.Require the cloud provider to sign a BAA that covers all regions where ePHI is stored, including the offshore region, or disable backup replication to that region.
D.Report the cloud provider to the HHS Office for Civil Rights (OCR) and continue using the service while awaiting guidance.
AnswerC

Under HIPAA, a covered entity or business associate must have a BAA with any subcontractor that creates, receives, maintains, or transmits ePHI. The cloud provider is a business associate, and its offshore backup storage is a subcontractor relationship. The company must ensure the BAA covers all locations where ePHI is stored, or prevent storage in non-covered regions. This is the most direct and compliant action.

Why this answer

HIPAA requires a Business Associate Agreement (BAA) with any entity that creates, receives, maintains, or transmits ePHI on behalf of a covered entity or another business associate. A cloud provider storing ePHI backups in an offshore region acts as a subcontractor, so a BAA must cover that region. If the provider refuses, the company must either negotiate an expanded BAA or disable replication to that region to maintain compliance.

Exam trap

The trap here is assuming that encrypting ePHI or reporting the provider to OCR eliminates the need for a BAA with the cloud provider for all regions where ePHI is stored.

41
MCQeasy

When assessing cloud risk, an organization identifies that if a single cloud provider fails, the organization cannot operate. This risk is known as:

A.Third-party risk
B.Inherent risk
C.Concentration risk
D.Residual risk
AnswerC

Concentration risk arises when dependency on a single provider creates correlated failure exposure, so one outage halts all operations. Unlike operational or compliance risk, it specifically measures over-reliance on one entity, matching the stem's single-provider failure scenario.

Why this answer

Concentration risk is the risk that arises from over-reliance on a single provider, system, or counterparty — in cloud terms, if one provider fails and the organization cannot operate, that dependency is a concentration risk. It is a well-known concept in financial services (e.g., reliance on a single clearing bank) and applies directly to cloud, where multi-cloud or hybrid strategies are often adopted specifically to mitigate it. The scenario describes exactly this single-point-of-failure dependency.

Exam trap

CCSP often tests the distinction between concentration risk and general third-party risk — candidates pick 'third-party risk' because a cloud provider is a third party, but the specific scenario of single-provider dependency is concentration risk, a narrower and more precise term.

How to eliminate wrong answers

Option A is wrong because third-party risk is the broader category of risks introduced by using external vendors (security, compliance, operational) — concentration risk is a specific subtype of third-party risk focused on over-dependence on one provider. Option B is wrong because inherent risk is the level of risk that exists before any controls are applied — it describes risk exposure in the absence of mitigation, not the dependency on a single provider. Option D is wrong because residual risk is the risk that remains after controls and mitigations have been applied — it is a post-treatment measure, not the description of single-provider dependency.

42
MCQmedium

A covered entity under HIPAA is planning to migrate electronic protected health information (ePHI) to a public cloud environment. Which of the following is a mandatory requirement before using the cloud service?

A.Encrypt all ePHI with keys managed solely by the covered entity
B.Conduct a physical on-site audit of the cloud provider's data centers
C.Obtain a signed Business Associate Agreement from the cloud provider
D.Ensure the cloud provider is certified under the Privacy Shield framework
AnswerC

HIPAA requires a Business Associate Agreement before any covered entity shares ePHI with a cloud provider, since the provider qualifies as a business associate. The signed BAA contractually binds the provider to safeguard ePHI and satisfies the mandatory prerequisite for cloud migration.

Why this answer

HIPAA requires covered entities to obtain satisfactory assurances that PHI will be protected, typically through a Business Associate Agreement (BAA) with the cloud provider.

43
Multi-Selectmedium

A cloud service provider is expanding into a new jurisdiction and must demonstrate compliance with local data protection laws. The provider's legal team is reviewing the shared responsibilities between the provider and its customers. Which TWO activities are the provider's responsibility under a typical cloud shared responsibility model? (Choose two.)

Select 2 answers
A.Securing the physical facilities, hardware, and network infrastructure that host the cloud services.
B.Configuring encryption for the customer's data at rest using customer-managed keys stored in the customer's environment.
C.Classifying the customer's data and determining which regulatory requirements apply to that data.
D.Providing the hypervisor, storage virtualization, and network isolation controls that separate tenant environments.
E.Managing the customer's identity and access policies for the customer's own users and applications.
AnswersA, D

The provider owns and operates the underlying data centers, servers, and network fabric, so it is responsible for physical security, hardware maintenance, and infrastructure-level network controls. These are foundational controls that customers cannot implement themselves and form the provider's side of the shared responsibility model.

Why this answer

In a cloud shared responsibility model, the provider secures the infrastructure that delivers the service, including physical facilities, hardware, and the virtualization layer that isolates tenants. The customer remains responsible for its data, identity management, and customer-side encryption key custody. Understanding this division is essential for meeting regulatory obligations in any jurisdiction.

Exam trap

The trap here is assuming the provider handles all security controls, when data classification, IAM, and customer-managed encryption keys remain customer responsibilities.

44
MCQhard

A multinational bank uses a cloud provider for a system that processes customer transactions. A regulator asks the bank to demonstrate that it maintains effective control over the data and can meet its legal obligations even if the provider fails. Which activity best demonstrates that the bank has retained accountability for the outsourced processing?

A.Relying on the provider's SOC 2 Type II report as the sole evidence of control effectiveness
B.Maintaining a documented risk assessment and control mapping that assigns responsibility for each obligation
C.Requiring the provider to store all data in the bank's home country to simplify oversight
D.Transferring all security responsibility to the provider through an indemnification clause
AnswerB

Accountability means the bank can show it identified its legal and regulatory obligations, assessed the risks of outsourcing, and mapped each control to a responsible party. This documentation demonstrates that the bank governs the relationship rather than delegating responsibility. It also supports regulatory examination because the bank can evidence continuous oversight and remediation.

Why this answer

Retaining accountability requires documented governance: a risk assessment covering the outsourced activity, a mapping of legal obligations to controls, and clear assignment of responsibility between the bank and provider. This evidence shows the regulator that the bank governs the relationship and can meet its obligations even if the provider fails. Assurance reports, indemnities, and data localization support the program but do not replace accountability.

Exam trap

The trap here is equating contractual liability transfer, such as an indemnification clause, with regulatory accountability, which remains with the regulated entity.

45
MCQeasy

Under the General Data Protection Regulation (GDPR), if a cloud service provider (acting as a data processor) suffers a personal data breach, what is the provider's obligation regarding notification?

A.The processor must notify the data controller without undue delay upon becoming aware of the breach.
B.The processor must notify the supervisory authority within 72 hours.
C.The processor does not have any notification obligation under GDPR.
D.The processor must notify the affected data subjects directly within 72 hours.
AnswerA

Article 33 obliges the processor to notify the controller without undue delay after becoming aware of a personal data breach. The controller then assesses and notifies the supervisory authority within 72 hours; the processor holds no direct regulator notification duty.

Why this answer

Under GDPR Article 33(2), a processor must notify the controller without undue delay after becoming aware of a personal data breach. The controller — not the processor — is the party responsible for notifying the supervisory authority within 72 hours (Article 33(1)) and, where required, the data subjects (Article 34). The processor's obligation is limited to informing the controller so the controller can meet its own regulatory deadlines.

Exam trap

CCSP often tests the controller-versus-processor notification chain, baiting candidates with the familiar 72-hour supervisory authority deadline that actually belongs to the controller, not the processor.

How to eliminate wrong answers

Option B is wrong because the 72-hour supervisory authority notification duty belongs to the controller under Article 33(1), not the processor; a processor has no direct reporting line to the DPA. Option C is wrong because Article 33(2) explicitly imposes a notification obligation on processors toward controllers, so claiming no obligation exists misreads the regulation. Option D is wrong because direct notification of data subjects is a controller responsibility under Article 34 and only applies when the breach poses a high risk to rights and freedoms.

46
MCQhard

A company needs to export data from a cloud service in a machine-readable format to comply with a data subject's right to data portability under GDPR. Which format is most appropriate?

A.HTML
B.PDF
C.CSV (Comma-Separated Values)
D.JPEG
AnswerC

CSV is machine-readable and commonly used for data portability.

Why this answer

GDPR Article 20 grants data subjects the right to receive their personal data in a 'structured, commonly used and machine-readable format.' CSV satisfies all three criteria: it is structured (tabular rows/columns), widely used, and easily parsed by software. It also supports transmission to another controller without hindrance, which is the core purpose of portability.

Exam trap

The trap here is confusing 'human-readable' with 'machine-readable' — PDF and HTML look readable to a person but fail GDPR's structured, machine-parseable requirement.

How to eliminate wrong answers

Option A is wrong because HTML is a presentation markup language designed for rendering in browsers, not a structured data-interchange format, so it fails the 'structured and machine-readable' test. Option B is wrong because PDF is a fixed-layout document format optimized for visual fidelity, and extracting structured fields from it is unreliable. Option D is wrong because JPEG is a lossy image format that cannot represent structured personal data records at all.

47
MCQmedium

A company is evaluating the risk of using a single cloud provider for all critical workloads. Which risk is most directly associated with this scenario?

A.Inherent risk of shared infrastructure
B.Third-party risk
C.Concentration risk
D.Control effectiveness risk
AnswerC

Concentration risk arises when dependence on one provider means a single outage, failure or contractual dispute simultaneously affects all critical workloads, with no failover alternative. This directly matches the stem's scenario of using a single cloud provider for everything.

Why this answer

Concentration risk is the danger that over-reliance on a single provider, service, or region creates a single point of failure whose disruption affects all dependent workloads simultaneously. Using one cloud provider for all critical workloads concentrates operational, financial, and availability exposure in that vendor, so an outage, contract dispute, or bankruptcy cascades across the entire estate. This is precisely the risk regulators and frameworks like the EBA and DORA flag for cloud concentration.

Exam trap

CCSP often tests the distinction between generic third-party risk and concentration risk — candidates pick 'third-party risk' because it sounds broader, missing that the scenario's single-provider dependency is the textbook definition of concentration risk.

How to eliminate wrong answers

Option A is wrong because shared infrastructure risk (noisy neighbors, hypervisor vulnerabilities, multi-tenancy) exists regardless of how many providers you use and is not specific to single-provider reliance. Option B is wrong because third-party risk applies to any external dependency, including in multi-cloud, so it is not the risk most directly tied to using one provider. Option D is wrong because control effectiveness risk concerns whether your own controls work as designed, not the structural exposure created by vendor concentration.

48
Multi-Selecteasy

A company is adopting a multi-cloud strategy to reduce concentration risk. Which two benefits are directly associated with this approach? (Choose two.)

Select 2 answers
A.Reduced vendor lock-in
B.Increased resilience
C.Simplified compliance management
D.Unified security controls
E.Lower network latency
AnswersA, B

Spreading workloads across multiple providers means no single vendor's proprietary interfaces or commercial terms dictate the estate, directly reducing vendor lock-in. This satisfies the stated concentration-risk reduction goal by removing dependency on one provider's ecosystem.

Why this answer

Option A (Reduced vendor lock-in) is correct because spreading workloads across multiple providers means the company is not dependent on a single vendor's proprietary services, pricing, or roadmap, making it easier to migrate or renegotiate. Option B (Increased resilience) is correct because a multi-cloud strategy reduces concentration risk: an outage, regional failure, or service disruption at one provider does not take down the entire estate, since workloads can fail over to another cloud. Option C is not directly associated because compliance obligations (e.g., GDPR, HIPAA, PCI DSS) must still be met per provider and per region, and multi-cloud often complicates rather than simplifies compliance management.

Option D is not directly associated because each cloud has its own IAM, logging, and security tooling, so unified security controls typically require additional third-party tooling or significant integration effort. Option E is not directly associated because adding more providers and cross-cloud traffic generally increases network latency and complexity rather than lowering it.

Exam trap

The trap is assuming multi-cloud simplifies everything — candidates pick 'simplified compliance' or 'unified security controls' because they sound like benefits, when in fact multi-cloud multiplies compliance and security complexity.

49
MCQmedium

A cloud customer is reviewing its contract with a cloud provider. The customer wants to ensure that if the provider subcontracts any part of the service to a third party, the customer's data remains protected. Which contract provision is most critical to address this risk?

A.Requirement for provider to flow down data protection obligations to subcontractors
B.Right to terminate for convenience
C.Service level agreement (SLA) with penalties for downtime
D.Right to audit the provider's subcontractors
AnswerA

This provision ensures that any subcontractor engaged by the provider is bound by the same data protection and security obligations as the provider. It creates a chain of responsibility, so the customer's data remains protected even when handled by third parties. It is a fundamental requirement in cloud contracts, especially under regulations like GDPR, to maintain compliance throughout the supply chain.

Why this answer

Flow-down obligations ensure that subcontractors are contractually bound to the same data protection standards as the primary provider. This maintains protection throughout the cloud supply chain and is often a regulatory requirement. Other options focus on audit rights, availability, or exit, which do not directly ensure subcontractor compliance with data protection obligations.

Exam trap

The trap here is thinking that a right to audit subcontractors is sufficient, when the more fundamental control is contractual flow-down of obligations.

50
MCQeasy

Which of the following best describes the purpose of the Cloud Security Alliance (CSA) Security, Trust, Assurance, and Risk (STAR) program?

A.To offer a certification program for cloud security professionals
B.To define mandatory security requirements for all cloud services
C.To provide a legal framework for cloud contracts
D.To allow cloud providers to publicly document their security controls and achieve different levels of assurance
AnswerD

The CSA STAR program lets cloud providers publish security control documentation through self-assessment, third-party audit or certification, satisfying the stem's requirement to describe its purpose. Its three assurance tiers — Level 1 self-assessment, Level 2 third-party audit, and continuous monitoring — directly match "different levels of assurance".

Why this answer

The CSA STAR program allows cloud providers to publicly document their security controls and achieve different levels of assurance through self-assessment, third-party audits, or certifications. It provides transparency and trust by mapping controls to recognized standards like ISO 27001 and SOC 2.

Exam trap

CCSP often tests the confusion between CSA STAR as a cloud provider assurance program and other CSA offerings like the CCSK certification, leading candidates to select options about professional certification or mandatory standards.

How to eliminate wrong answers

Option A is wrong because CSA STAR is not a certification program for individuals; it is for cloud service providers to demonstrate security posture. Option B is wrong because CSA STAR does not define mandatory requirements; it offers a framework for voluntary disclosure. Option C is wrong because CSA STAR is not a legal framework for contracts; it focuses on security assurance and transparency.

51
MCQmedium

A cloud customer requires that its data stored by a provider be irretrievably destroyed after contract termination, even if the provider uses backup tapes and replicated storage. Which contractual and technical provision best supports this requirement?

A.A right-to-audit clause that allows the customer to inspect the provider's data centers annually.
B.A clause requiring the provider to sanitize or crypto-shred all customer data, including backups and replicas, and to provide a certificate of destruction upon termination.
C.A service level agreement that guarantees 99.99% data durability during the contract term.
D.A data retention schedule that specifies how long the provider may keep customer data before automatic deletion.
AnswerB

This directly addresses irretrievable destruction by requiring sanitization or crypto-shredding across all copies, including backups and replicas, and by demanding a certificate of destruction. Crypto-shredding destroys the encryption keys, rendering data unreadable. The certificate provides evidence. This combination is the standard contractual and technical mechanism to meet secure deletion requirements in cloud contracts.

Why this answer

Irretrievable destruction requires more than retention limits or audit rights; it demands a contractual obligation to sanitize or crypto-shred all copies, including backups and replicas, and to certify destruction. Crypto-shredding is effective when data is encrypted and keys can be destroyed. The certificate of destruction provides verifiable evidence that the obligation was met.

Exam trap

The trap here is confusing data retention limits or audit rights with actual secure deletion obligations, which require explicit sanitization and certification clauses.

52
MCQmedium

A company is subject to a legal hold order and uses a cloud storage service with object replication across multiple regions. Which cloud feature should the company use to prevent deletion or modification of relevant data?

A.Versioning of objects
B.Cross-region replication
C.Backup to another provider
D.Legal hold policies (e.g., S3 Object Lock)
AnswerD

S3 Object Lock enforces write-once-read-many (WORM) protection at the object level, blocking deletion or modification for a defined retention period even by root users. This directly satisfies the legal hold constraint, unlike replication, which merely copies data and propagates deletions across regions.

Why this answer

Legal hold policies, such as Amazon S3 Object Lock in compliance mode, prevent objects from being deleted or overwritten for a specified retention period, even by privileged users. This directly satisfies a legal hold order requiring preservation of data against alteration or destruction. Object Lock uses a write-once-read-many (WORM) model that is purpose-built for litigation holds and regulatory retention.

Exam trap

CCSP often tests immutability versus durability — candidates pick 'versioning' or 'cross-region replication' because they sound protective, but only Object Lock/legal hold provides true WORM protection against deletion or modification.

How to eliminate wrong answers

Option A is wrong because versioning alone does not prevent deletion — a user can still delete objects or delete versions, and without MFA delete or Object Lock, versioning is not a legal hold. Option B is wrong because cross-region replication improves durability and availability but does not prevent modification or deletion of the source or replica objects. Option C is wrong because backing up to another provider is a resilience measure, not an immutable retention control, and backups can also be altered or deleted unless separately protected.

53
MCQmedium

A company subject to PCI DSS is considering a cloud provider to process credit card transactions. What must the cloud provider present to demonstrate compliance with PCI DSS?

A.A CSA STAR Level 1 self-assessment
B.A PCI DSS Attestation of Compliance (AOC) from a QSA
C.A SOC 2 Type II report
D.An ISO 27001 certificate
AnswerB

A PCI DSS Attestation of Compliance issued by a Qualified Security Assessor formally documents the provider's validated compliance status, giving the customer the evidence needed for its own PCI DSS obligations when processing card transactions.

Why this answer

PCI DSS compliance for a cloud provider is demonstrated through a PCI DSS Attestation of Compliance (AOC) validated by a Qualified Security Assessor (QSA) or, for service providers, a Report on Compliance (ROC). The AOC is the formal document that attests the provider meets the 12 PCI DSS requirements for the services in scope. Customers rely on the provider's AOC to inherit controls and reduce their own assessment scope.

Exam trap

CCSP often tests the difference between general security certifications (SOC 2, ISO 27001, CSA STAR) and payment-specific validation — candidates pick SOC 2 or ISO 27001 because they sound rigorous, but only a QSA-validated AOC demonstrates PCI DSS compliance.

How to eliminate wrong answers

Option A is wrong because CSA STAR Level 1 is a self-assessment of cloud security controls, not a PCI DSS validation, and self-attestation carries far less assurance than a QSA-validated AOC. Option C is wrong because a SOC 2 Type II report covers trust services criteria (security, availability, confidentiality) but does not map to or satisfy PCI DSS requirements. Option D is wrong because ISO 27001 certifies an information security management system, not cardholder data protection, and is not accepted as PCI DSS evidence.

54
MCQmedium

A cloud provider's data center is located in Country A, but the customer's data is subject to litigation in Country B. The court in Country B orders the cloud provider to produce data. The cloud provider refuses, citing Country A's laws that prohibit disclosure. This situation best illustrates which challenge in eDiscovery?

A.Data portability
B.Jurisdiction issues
C.Data preservation
D.Forensic soundness
AnswerB

Two sovereign legal regimes impose conflicting obligations: Country B compels production while Country A prohibits disclosure. This clash of laws governing the same data is a jurisdiction issue, exactly the eDiscovery challenge the stem describes when the provider refuses the court order.

Why this answer

Jurisdictional issues arise when data is stored in multiple legal jurisdictions, and courts in one country may not have authority over data in another, leading to conflicts of law.

55
MCQeasy

A cloud customer is reviewing its incident response plan and wants to ensure it can meet regulatory breach notification timelines. The customer's data is hosted by a cloud provider that does not automatically notify customers of security incidents. Which action should the customer take FIRST to address this gap?

A.Include a contractual clause requiring the provider to notify the customer of security incidents within a specified timeframe.
B.Purchase cyber insurance to cover the costs of a breach notification and any regulatory fines.
C.Deploy a third-party vulnerability scanner to continuously monitor the provider's infrastructure for signs of compromise.
D.Rely on the provider's public status dashboard and security blog to learn about incidents affecting the customer's data.
AnswerA

Regulatory breach notification timelines often start when the customer becomes aware of an incident. A contract clause that obligates the provider to notify the customer within a defined period ensures the customer receives timely information and can start its own assessment and notification process. This directly closes the gap.

Why this answer

The customer cannot meet regulatory breach notification deadlines if it learns about a provider-side incident too late. A contractual notification clause with a defined timeframe creates an enforceable obligation and ensures the customer receives timely information to begin its own incident assessment and notification process. This is the foundational step before technical monitoring or insurance can be effective.

Exam trap

The trap here is assuming that public status pages, monitoring tools, or insurance can substitute for a contractual notification requirement from the provider.

56
MCQmedium

A cloud customer wants to ensure that when the contract ends, the cloud provider deletes all customer data, including from backups. Which contractual clause is essential?

A.Right to audit clause
B.Data deletion clause
C.Data portability clause
D.Service Level Agreement
AnswerB

A data deletion clause contractually obliges the provider to erase all customer data, explicitly including backups, once the contract ends. Without it, residual copies may persist indefinitely, breaching the customer's data lifecycle and privacy obligations.

Why this answer

A data deletion clause is essential because it contractually obligates the cloud provider to securely erase all customer data—including replicas and backups—upon contract termination or at the customer's request. Without this clause, data may persist indefinitely in provider backups, snapshots, or archival storage, creating confidentiality and compliance exposure. CCSP emphasizes that the right to deletion must be explicitly negotiated, since default provider terms rarely guarantee backup purging.

Exam trap

CCSP often tests the distinction between contractual clauses that grant visibility (audit) or flexibility (portability) versus those that enforce data lifecycle termination (deletion), so candidates must map each clause to its actual legal obligation.

How to eliminate wrong answers

Option A is wrong because a right to audit clause grants the customer permission to inspect provider controls and processes, but it does not compel deletion of data at contract end. Option C is wrong because data portability addresses the customer's ability to retrieve or migrate their data in a usable format, not the provider's obligation to destroy it. Option D is wrong because an SLA defines availability, performance, and support commitments—not data lifecycle or destruction obligations.

57
MCQhard

A cloud customer is considering adopting a multi-cloud strategy to avoid vendor lock-in. Which risk is this strategy primarily intended to mitigate?

A.Third-party risk from a specific provider
B.Concentration risk
C.Residual risk after controls
D.Inherent risk of data leaving premises
AnswerB

Multi-cloud spreads workloads across independent providers, so an outage, pricing change, or failure at one provider cannot disrupt all services. This directly reduces concentration risk—dependence on a single vendor—rather than portability, compliance, or interoperability concerns.

Why this answer

A multi-cloud strategy is primarily intended to mitigate concentration risk—the risk of over-reliance on a single provider, which can lead to systemic failures, vendor lock-in, and limited negotiating power. By distributing workloads across multiple providers, an organization reduces the impact of an outage, pricing change, or security incident at any one provider. This diversification is a classic risk management technique.

Exam trap

CCSP often tests the difference between concentration risk and third-party risk, so candidates must recognize that multi-cloud is a diversification strategy specifically aimed at reducing dependence on one provider.

How to eliminate wrong answers

Option A is wrong because third-party risk from a specific provider is a broader category that includes many factors (security, compliance, performance), and multi-cloud does not eliminate third-party risk—it merely spreads it across more providers. Option C is wrong because residual risk is the risk remaining after controls are applied; multi-cloud is a strategy to reduce concentration risk, not a control that directly addresses residual risk. Option D is wrong because inherent risk of data leaving premises relates to data residency and sovereignty concerns, which multi-cloud may exacerbate rather than mitigate if data is spread across jurisdictions.

58
MCQhard

Under GDPR, a cloud data controller must notify the supervisory authority of a personal data breach within what timeframe?

A.24 hours
B.72 hours
C.7 days
D.48 hours
AnswerB

GDPR Article 33 requires controllers to notify the supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms.

Why this answer

GDPR Article 33 mandates that a data controller notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. This 72-hour window is a strict requirement unless the breach is unlikely to result in a risk to data subjects' rights and freedoms.

Exam trap

CCSP often tests the specific 72-hour GDPR breach notification window, and candidates may confuse it with other timelines such as the 24-hour notification for NIS2 or the 30-day notification for HIPAA, leading to wrong answer choices.

How to eliminate wrong answers

Option A is wrong because 24 hours is not the GDPR requirement; it may be a stricter internal policy or apply under other regulations, but not GDPR. Option C is wrong because 7 days exceeds the GDPR limit and would constitute non-compliance. Option D is wrong because 48 hours is not specified in GDPR; the regulation explicitly sets 72 hours.

59
MCQhard

A cloud customer stores regulated data with a provider that uses sub-processors in multiple countries. The customer's legal team wants to ensure that international transfers of personal data remain lawful under the General Data Protection Regulation (GDPR). Which mechanism is the most appropriate to implement with the provider?

A.A binding corporate rules framework filed only by the cloud provider with its own supervisory authority.
B.Standard Contractual Clauses approved by the European Commission, supported by a transfer impact assessment.
C.A verbal assurance from the provider that data will remain within the European Economic Area.
D.A data processing agreement alone, because it binds the provider to GDPR terms regardless of where processing occurs.
AnswerB

For transfers to third countries without an adequacy decision, Standard Contractual Clauses are a recognized Chapter V mechanism. Following Schrems II, they should be paired with a transfer impact assessment and supplementary measures where laws create undue access risk. This combination directly addresses lawful transfer obligations in the cloud supply chain.

Why this answer

Transfers of personal data outside the European Economic Area require a Chapter V mechanism. Standard Contractual Clauses are a widely used appropriate safeguard, and after Schrems II they must be supported by a transfer impact assessment and, where needed, supplementary measures. This pairing best satisfies the customer's need for lawful, defensible international transfers.

Exam trap

The trap here is treating a data processing agreement as sufficient for international transfers, when Article 28 agreements and Chapter V transfer tools are separate requirements.

60
MCQmedium

A cloud customer is preparing for an audit of its cloud environment. The provider offers a SOC 2 Type II report covering security and availability. What does this report provide to the customer's auditors?

A.A certification issued by the AICPA that the provider fully complies with all applicable laws and regulations.
B.An opinion on the design and operating effectiveness of the provider's controls over a period of time.
C.A guarantee that the provider's controls will remain effective for the next twelve months.
D.A point-in-time description of controls without any testing of operating effectiveness.
AnswerB

A SOC 2 Type II report covers a period and includes the service auditor's opinion on both the suitability of design and the operating effectiveness of controls. This gives the customer's auditors evidence that controls functioned consistently, which is more persuasive than a point-in-time description.

Why this answer

A SOC 2 Type II report is an attestation covering a period, with the service auditor opining on the design and operating effectiveness of controls against selected trust services criteria. For the customer's auditors, it supplies independent evidence of sustained control operation, though they must still consider scope, period, and complementary user entity controls.

Exam trap

The trap here is conflating SOC 2 Type I and Type II reports, treating a point-in-time design description as evidence of operating effectiveness over time.

61
MCQmedium

A cloud customer is concerned about the right to erasure under GDPR because the cloud provider replicates data across multiple regions and keeps backups. What technical challenge does this create for complying with a erasure request?

A.The data must be anonymized instead of deleted.
B.The customer must notify all other users who may have accessed the data.
C.The cloud provider may not be able to delete data from all replicas and backups within the required time frame.
D.The cloud provider must retain the data for audit purposes.
AnswerC

Replication across regions and retained backups mean erasure cannot propagate instantly; the provider must locate and purge every copy, including immutable or archived backups, within GDPR's one-month response window, which is the technical obstacle the stem describes.

Why this answer

The right to erasure (Article 17) requires controllers to delete personal data without undue delay. However, in cloud environments, data is often replicated across multiple regions for availability and durability, and backups may be retained for disaster recovery or legal compliance. Ensuring deletion from all replicas and backups within the required timeframe is technically challenging because backups are typically immutable and may not be immediately overwritten.

Exam trap

CCSP often tests the technical limitations of erasure in distributed cloud systems, and candidates may incorrectly assume that deletion is instantaneous or that anonymization is always an acceptable substitute, missing the nuance of backup and replication challenges.

How to eliminate wrong answers

Option A is wrong because anonymization is an alternative to deletion only in specific cases (e.g., for research or statistical purposes) and does not satisfy an erasure request when deletion is technically feasible. Option B is wrong because notifying other users who accessed the data is not a GDPR requirement for erasure; it may be relevant for data portability or access requests, but not for erasure. Option D is wrong because while audit retention may be a legal obligation, it does not override the right to erasure unless a specific exemption applies; the primary challenge is technical, not a blanket retention requirement.

62
MCQeasy

A company is migrating to a public cloud and must ensure compliance with PCI DSS. Which responsibility does the cloud customer retain under the shared responsibility model?

A.Patching the hypervisor and underlying host operating systems
B.Configuring security groups and access controls for its workloads
C.Managing physical security of the data center
D.Ensuring the cloud provider's network is segmented from other tenants
AnswerB

Under the shared responsibility model, the cloud customer is always responsible for securing its own data, applications, and configurations, including security groups and access controls. The provider secures the infrastructure, but the customer must manage logical access to its instances and data. This is a fundamental tenet of cloud security and PCI DSS compliance.

Why this answer

In the shared responsibility model, the cloud customer is responsible for security 'in' the cloud, which includes configuring security groups, identity and access management, and application-level controls. The provider is responsible for security 'of' the cloud, such as physical security, hypervisor patching, and network infrastructure. For PCI DSS, the customer must ensure its configurations meet the standard's requirements.

Exam trap

The trap here is assuming that the cloud provider's PCI DSS compliance covers the customer's own configurations; the customer must still secure its own environment.

63
Multi-Selecthard

A global enterprise is conducting a cloud risk assessment. Which THREE factors should be considered? (Select three.)

Select 3 answers
A.Color of the provider's logo
B.Inherent risk of data leaving the on-premises environment
C.Provider's stock price
D.Concentration risk from using a single cloud provider
E.Effectiveness of provider controls as evidenced by audit reports
AnswersB, D, E

Moving data to a provider transfers it outside the customer's direct control, introducing exposure from shared infrastructure, provider personnel and cross-border transfer. This inherent risk of data leaving the on-premises environment is a core factor in the cloud risk assessment the enterprise is conducting.

Why this answer

Option B is correct because moving data off-premises introduces inherent risk—loss of direct physical and logical control, jurisdictional exposure, and reliance on the provider's network and encryption—which is a core element of any cloud risk assessment. Option D is correct because concentration risk (vendor lock-in and dependence on a single provider) can create systemic exposure; if that provider suffers an outage, breach, or business failure, the enterprise's operations are broadly impacted, so it must be evaluated. Option E is correct because the effectiveness of the provider's controls must be verified through independent audit reports (e.g., SOC 2 Type II, ISO/IEC 27001 certifications, or CSA STAR), which provide evidence that security, availability, and confidentiality controls actually operate as claimed.

Option A is not relevant because a logo's color has no bearing on security, compliance, or operational risk. Option C is not relevant because stock price reflects market performance, not the provider's control effectiveness or the enterprise's risk exposure.

64
MCQhard

A multinational corporation uses multiple cloud service providers for its critical applications. The board is concerned about concentration risk. Which strategy would best address this risk?

A.Negotiating a longer contract with the primary cloud provider to ensure stability
B.Implementing a hybrid cloud model with on-premises infrastructure only
C.Adopting a multi-cloud strategy that distributes applications across multiple cloud providers
D.Requiring each business unit to use the same cloud provider for consistency
AnswerC

Distributing workloads across several providers directly reduces concentration risk by removing dependence on any single vendor's availability, pricing, or failure domain. Because the corporation already uses multiple cloud service providers, this approach satisfies the board's concern about over-reliance, ensuring no single provider outage or policy change can disrupt all critical applications simultaneously.

Why this answer

Concentration risk refers to over-reliance on a single provider. A multi-cloud strategy reduces this risk by distributing workloads across multiple providers, avoiding a single point of failure.

65
MCQhard

A covered entity under HIPAA is moving electronic protected health information (ePHI) to a public cloud. What is the primary requirement before the cloud provider hosts ePHI?

A.The cloud provider must be located within the United States
B.The cloud provider must sign a Business Associate Agreement (BAA)
C.The cloud provider must be certified under ISO 27001
D.The covered entity must obtain written authorization from each patient
AnswerB

HIPAA requires a Business Associate Agreement before a cloud provider creates, receives, maintains or transmits ePHI on behalf of the covered entity. The BAA contractually binds the provider to safeguard ePHI and report breaches, satisfying the Privacy and Security Rules.

Why this answer

Under HIPAA, a cloud provider that creates, receives, maintains, or transmits ePHI on behalf of a covered entity is a Business Associate, and the covered entity must have a signed Business Associate Agreement (BAA) in place before ePHI is hosted. The BAA contractually obligates the provider to safeguard ePHI and comply with applicable HIPAA Privacy and Security Rule provisions.

Exam trap

CCSP often tests the misconception that geographic location or a generic security certification (ISO 27001) satisfies HIPAA — the legally required mechanism is the BAA, not location or certification.

How to eliminate wrong answers

Option A is wrong because HIPAA does not require the cloud provider to be physically located in the United States — it requires appropriate safeguards regardless of location, though cross-border data transfer may raise other legal issues. Option C is wrong because ISO 27001 certification is a voluntary security management standard and is not a HIPAA legal prerequisite, even though it can support compliance. Option D is wrong because obtaining patient authorization is required for uses/disclosures of PHI for purposes like marketing or research, not for engaging a business associate to host ePHI for treatment, payment, or operations.

66
MCQmedium

A cloud customer's security team learns that a provider's subprocessor experienced a breach affecting the customer's data. The customer's contract requires the provider to notify the customer of subprocessor breaches. Under the GDPR, within what timeframe must the cloud provider, acting as a processor, notify the controller of a personal data breach?

A.Without undue delay after becoming aware of the breach
B.Within 30 calendar days of completing its internal forensic investigation
C.Within 72 hours of becoming aware of the breach
D.Within 24 hours of confirming that the breach involves personal data
AnswerA

Article 33(2) requires a processor to notify the controller without undue delay after becoming aware of a personal data breach. 'Without undue delay' is deliberately not a fixed number of hours; it means as soon as reasonably possible given the circumstances. The controller then decides whether to notify the supervisory authority within its own 72-hour window.

Why this answer

GDPR Article 33(2) requires a processor to inform the controller without undue delay after becoming aware of a personal data breach. The 72-hour clock applies to the controller's notification to the supervisory authority, not to the processor's notice to the controller. This sequencing lets the controller assess the breach and meet its own regulatory and contractual duties.

Exam trap

The trap here is applying the controller's 72-hour supervisory authority deadline to the processor's obligation to notify the controller, which is instead 'without undue delay.'

67
MCQhard

A financial institution is required to comply with the Sarbanes-Oxley Act (SOX) for its cloud-hosted financial applications. The cloud provider is responsible for the underlying infrastructure. Which of the following controls is most likely the responsibility of the financial institution as part of IT general controls (ITGC)?

A.Physical security of the data center housing the cloud servers
B.Logical access controls to the financial application, including user provisioning and segregation of duties
C.Network intrusion detection at the cloud perimeter
D.Patching of the hypervisor that hosts the virtual machines
AnswerB

Under the shared responsibility model, the financial institution owns application-layer ITGCs: provisioning users, enforcing least privilege and separating duties. Infrastructure controls sit with the provider, but logical access to the financial application remains the institution's SOX responsibility.

Why this answer

Under the shared responsibility model, the cloud provider secures the infrastructure (data centers, hypervisors, network fabric), while the customer is responsible for controls over their own data, applications, and access. Logical access controls — user provisioning, authentication, authorization, and segregation of duties — are IT general controls that the financial institution must implement and evidence for SOX compliance, since they directly affect the integrity of financial reporting systems.

Exam trap

CCSP often tests the shared responsibility boundary — candidates incorrectly assign infrastructure controls (physical security, hypervisor patching) to the customer, when those belong to the provider.

How to eliminate wrong answers

Option A is wrong because physical security of the data center is the cloud provider's responsibility under the shared responsibility model — the customer cannot control who enters a Google or AWS facility. Option C is wrong because network intrusion detection at the cloud perimeter is typically part of the provider's infrastructure security, though customers may add their own IDS for their workloads; it is not the primary ITGC the institution owns. Option D is wrong because hypervisor patching is the provider's responsibility — the hypervisor is part of the managed infrastructure layer, not the customer's application stack.

68
MCQhard

A US-based cloud customer stores EU personal data in a provider's Singapore region and uses the provider's support team located in India. The customer relies on the EU-US Data Privacy Framework (DPF) for its own US transfers. Which action is required to legitimize the support team's access to that EU data?

A.Verify the provider's DPF certification covers the Indian support entity and the Singapore processing, or put an Article 46 transfer tool in place for the India access.
B.Obtain a derogation under Article 49 for occasional support access, since break-fix support is by definition non-repetitive.
C.Rely on the provider's Singapore data residency commitment because data stored in-region never leaves the jurisdiction.
D.Adopt binding corporate rules covering the customer's own corporate group, which automatically extends to provider personnel.
AnswerA

DPF certification is entity- and scope-specific: it only covers the certified US entity and the data categories and purposes listed. Remote access by a support team in India is itself a transfer to a third country, so the customer must confirm the certification's coverage or rely on an Article 46 mechanism such as SCCs for that access. Coverage cannot be assumed.

Why this answer

A transfer occurs whenever personal data is made accessible to an entity in a third country, including remote support access. DPF certification only covers the certified entity and the data categories it lists, so the customer must confirm the Indian support team is covered or execute a valid Article 46 mechanism such as SCCs. Storage location alone does not resolve the transfer question.

Exam trap

The trap here is treating data residency or a provider's DPF certification as covering all global support access, when remote access from a non-certified third country is itself a regulated transfer.

69
MCQeasy

A cloud customer is concerned about the risk of unauthorized access to data due to the shared infrastructure of a public cloud. What type of risk does this represent?

A.Control risk
B.Detection risk
C.Inherent risk
D.Residual risk
AnswerC

Inherent risk is the risk that exists before any controls are applied, arising here from the public cloud's shared infrastructure exposing data to unauthorised access. It reflects the exposure intrinsic to the chosen architecture, not residual or control risk.

Why this answer

Inherent risk is the level of risk that exists before any controls are applied, arising from the nature of the activity or environment itself. The shared infrastructure of a public cloud introduces exposure to unauthorized access due to multi-tenancy, and this exposure exists inherently before the customer implements mitigating controls — making it an inherent risk.

Exam trap

CCSP often tests the distinction between inherent, residual, control, and detection risk — candidates must recognize that the question describes exposure before mitigation, which is inherent risk, not residual risk.

How to eliminate wrong answers

Option A is wrong because control risk refers to the risk that controls fail to prevent or detect a problem, not the baseline exposure from the environment. Option B is wrong because detection risk is the risk that monitoring or audit procedures fail to detect a material issue, which is a subset of control effectiveness, not the baseline exposure. Option D is wrong because residual risk is what remains after controls are applied — the question describes the risk before mitigation, not after.

70
MCQmedium

A company is negotiating a cloud service agreement and wants to ensure it can verify the provider's security controls independently. Which contractual clause is essential for this purpose?

A.Data deletion clause
B.Right to audit clause
C.Service Level Agreement (SLA) on uptime
D.Data portability clause
AnswerB

A right to audit clause contractually grants the customer the ability to independently verify the provider's security controls, through assessments or evidence review. Without it, assurance rests solely on provider assertions, so it directly satisfies the requirement for independent verification.

Why this answer

A right to audit clause is essential because it contractually grants the customer the ability to independently verify the provider's security controls, either through direct audits or by accepting third-party audit reports. This clause ensures transparency and accountability, which is critical for compliance and risk management in cloud services.

Exam trap

CCSP often tests the distinction between contractual clauses, and candidates may confuse the right to audit with SLAs or data deletion, overlooking that only the right to audit enables independent verification.

How to eliminate wrong answers

Option A is wrong because a data deletion clause specifies how data is removed at contract termination, but it does not enable verification of security controls. Option C is wrong because an SLA on uptime focuses on availability guarantees, not security control verification. Option D is wrong because data portability ensures the ability to move data, but it does not provide audit rights.

71
Multi-Selecthard

A cloud customer is subject to the EU GDPR and stores personal data with a provider that replicates it across data centers in several countries. The customer's legal team must confirm that appropriate safeguards exist for each international transfer. Which TWO elements are required for a valid transfer under GDPR Chapter V? (Choose two.)

Select 2 answers
A.A transfer impact assessment documenting the destination country's laws and any supplementary measures
B.A lawful transfer mechanism such as an adequacy decision or Standard Contractual Clauses
C.A SOC 2 Type II report covering the provider's security controls in each region
D.Registration of the cloud provider as a data controller with the customer's supervisory authority
E.An ISO/IEC 27701 certification held by the cloud provider
AnswersA, B

Following the Schrems II judgment, controllers must assess whether the destination country's surveillance and access laws undermine the chosen safeguard, and if so, adopt supplementary measures such as encryption or pseudonymization. This assessment must be documented and reviewed, especially when data is replicated to several countries with differing legal regimes.

Why this answer

A valid Chapter V transfer needs a legal mechanism, such as an adequacy decision or Standard Contractual Clauses, plus a documented transfer impact assessment that evaluates destination-country laws and any supplementary measures. Certifications and registrations may support due diligence but are not transfer mechanisms. When data is replicated across several countries, both elements must cover every jurisdiction where personal data resides or is accessible.

Exam trap

The trap here is treating a security or privacy certification as a substitute for a Chapter V transfer mechanism, when certifications support due diligence but do not authorize the transfer.

72
MCQhard

In a cloud environment, a data subject exercises their right to erasure under GDPR. The cloud provider has multiple replicas and backups. What is the primary technical challenge in fulfilling this request?

A.Transferring data to another controller
B.Ensuring deletion from backups and replicas within retention periods
C.Obtaining consent from other data subjects
D.Identifying the data subject's data across all systems
AnswerB

Erasure must propagate across every replica and backup copy, yet immutable or air-gapped backups and fixed retention schedules often prevent immediate purging. Satisfying the GDPR right to erasure therefore depends on deletion mechanisms that reach archived copies within their retention windows.

Why this answer

The primary technical challenge is ensuring deletion from backups and replicas within retention periods because GDPR's right to erasure (Article 17) requires data to be erased without undue delay, but cloud environments often have multiple replicas and backups that may not be immediately deletable due to retention policies or immutability. This creates a conflict between the legal obligation to erase and the technical reality that backups are typically retained for disaster recovery, requiring mechanisms to ensure data is not restored or that deletion is propagated once backups are restored. Thus, the correct answer focuses on the complexity of coordinating deletion across all copies while respecting retention schedules.

Exam trap

CCSP often tests the misconception that data deletion is straightforward in the cloud, but the presence of backups and replicas introduces complexity; candidates may overlook the retention period constraint and choose identification as the primary challenge.

How to eliminate wrong answers

Option A is wrong because transferring data to another controller relates to data portability (Article 20), not erasure, and does not address the challenge of deleting data from backups and replicas. Option C is wrong because obtaining consent from other data subjects is irrelevant to the right to erasure; erasure requests are made by the data subject whose data is being erased, and consent from others is not required. Option D is wrong because identifying the data subject's data across all systems, while a challenge, is not the primary technical challenge in this scenario; the question specifically highlights multiple replicas and backups, which points to the deletion propagation issue rather than identification.

73
Multi-Selectmedium

In the context of eDiscovery, a legal hold must be placed on data stored in a cloud environment. Which THREE actions should the cloud customer take to ensure the legal hold is effective?

Select 3 answers
A.Ensure the legal hold prevents both deletion and modification of the data.
B.Delete any non-relevant data to reduce storage costs.
C.Rely solely on the cloud provider's default backup retention policies.
D.Apply the legal hold to all copies of the data, including backups and replicas in different regions.
E.Notify the cloud provider of the legal hold and request technical enforcement such as object lock.
AnswersA, D, E

A legal hold must preserve data in its original state, so the mechanism must block both deletion and alteration; otherwise spoliation occurs and the evidence loses integrity. Ensuring the hold prevents deletion and modification satisfies the stem's requirement that the cloud legal hold be effective.

Why this answer

Option A is correct because an effective legal hold must preserve data in its original state, meaning it must block both deletion and modification (e.g., via WORM/immutability controls) so the evidence remains authentic and unaltered for litigation. Option D is correct because eDiscovery obligations extend to every copy of potentially relevant data, so the hold must cover backups, snapshots, and cross-region replicas, otherwise a spoliation risk remains in those secondary locations. Option E is correct because the customer typically does not control the underlying cloud infrastructure, so notifying the provider and requesting technical enforcement such as S3 Object Lock, retention policies, or legal-hold flags ensures the hold is actually implemented at the platform level.

Option B is wrong because deleting non-relevant data during a hold risks destroying potentially relevant evidence and can constitute spoliation. Option C is wrong because default backup retention policies are provider-controlled, time-limited, and not a substitute for a case-specific legal hold.

Exam trap

CCSP often tests legal hold requirements, and candidates may overlook the need to apply holds to backups and replicas or to notify the provider for technical enforcement.

74
MCQhard

A multinational company is evaluating a cloud provider for a workload that processes personal data of employees in several countries. The company wants to ensure that cross-border data transfers comply with legal requirements. Which consideration is MOST important when assessing the provider's data transfer mechanisms?

A.Whether the provider's employees who may access the data are located in the same country as the data subjects.
B.Whether the provider can contractually commit to a recognized transfer mechanism, such as standard contractual clauses or an approved certification, for each transfer.
C.Whether the provider offers the lowest latency by storing data in the region closest to each employee.
D.Whether the provider's data centers are certified to ISO/IEC 27001 in every region where data is stored.
AnswerB

Cross-border transfers of personal data require a valid legal mechanism. Standard contractual clauses, adequacy decisions, or approved certification mechanisms provide that basis. The provider must be able to commit contractually to the applicable mechanism for each transfer path, and the customer must verify that the mechanism covers all countries where data is processed or stored.

Why this answer

Cross-border data transfers require a recognized legal mechanism, such as standard contractual clauses, an adequacy decision, or an approved certification. The provider must be able to contractually commit to the applicable mechanism for every country where personal data is processed or stored. Technical factors like latency or staff location do not satisfy the legal requirement, and security certifications alone do not authorize a transfer.

Exam trap

The trap here is confusing security certifications or performance factors with the legal transfer mechanisms required for cross-border personal data flows.

75
Multi-Selectmedium

A company is negotiating a cloud contract and wants to ensure data ownership and deletion. Which TWO clauses should be included? (Select two.)

Select 2 answers
A.Right to audit clause
B.Non-disclosure agreement
C.Data ownership clause
D.Service level agreement
E.Data deletion clause
AnswersC, E

A data ownership clause contractually confirms the customer retains all rights to its data stored or processed in the cloud, preventing the provider from claiming or exploiting it. This directly satisfies the stated requirement to ensure data ownership.

Why this answer

Option C, the data ownership clause, is correct because it contractually establishes that the company retains legal ownership of its data stored or processed by the cloud provider, preventing the provider from claiming rights over that data. Option E, the data deletion clause, is correct because it specifies the provider's obligations to securely and verifiably delete the company's data upon contract termination or on request, including timelines and certification of destruction. Option A, the right to audit clause, is not among the marked correct answers because while it supports compliance verification, it does not directly address ownership or deletion of data.

Option B, the non-disclosure agreement, is not marked correct because it protects confidentiality of shared information but does not establish data ownership or mandate deletion. Option D, the service level agreement, is not marked correct because it defines performance metrics such as uptime and availability, not data ownership or deletion rights.

Exam trap

The trap is selecting clauses that are generally important (like right to audit or SLA) but do not specifically address the question's focus on data ownership and deletion.

Page 1 of 2 · 84 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Legal, Risk, and Compliance questions.