Courseiva

CCNA Legal, Risk, and Compliance Questions

9 of 84 questions · Page 2/2 · Legal, Risk, and Compliance · Answers revealed

76
MCQeasy

A cloud customer receives a litigation hold notice requiring preservation of data stored in an object storage service. Which service feature should the customer use to ensure data cannot be modified or deleted until the hold is released?

A.Apply a retention policy using Object Lock
B.Set a lifecycle policy to transition to archival storage
C.Enable versioning on the bucket
D.Configure server-side encryption
AnswerA

Object Lock enforces write-once-read-many (WORM) protection at the object level, preventing modification or deletion for a defined retention period. This directly satisfies the litigation hold's requirement that data remain immutable until the hold is formally released, independent of user permissions.

Why this answer

Object Lock is the S3-compatible feature that enforces WORM (Write Once, Read Many) protection by applying a retention policy (governance or compliance mode) or a legal hold to objects. When a retention period or legal hold is in place, the object cannot be overwritten or deleted by any user, including the root account, until the hold is released. This directly satisfies the litigation hold requirement to preserve data in an immutable state.

Exam trap

CCSP often tests the misconception that versioning or encryption provides immutability; candidates must recognize that only Object Lock (WORM) enforces non-modification and non-deletion for litigation holds.

How to eliminate wrong answers

Option B is wrong because lifecycle policies only move or expire objects (e.g., transition to Glacier or delete after N days) and do not prevent modification or deletion; in fact, a lifecycle rule could delete the very data under hold. Option C is wrong because versioning only preserves prior versions of an object — a user can still delete the current version or overwrite it, and without Object Lock a delete marker can be placed, so it does not guarantee immutability. Option D is wrong because server-side encryption protects confidentiality of data at rest but does nothing to prevent an authorized user from modifying or deleting the object.

77
Multi-Selecthard

A multinational corporation is implementing a multi-cloud strategy to avoid concentration risk. The risk management team is evaluating the inherent risks of using multiple cloud providers. Which THREE risks are specifically associated with a multi-cloud strategy? (Choose three.)

Select 3 answers
A.Higher likelihood of vendor lock-in due to proprietary services
B.Expanded attack surface due to more entry points and APIs
C.Increased complexity in managing consistent security policies across providers
D.Greater difficulty in meeting data sovereignty requirements across jurisdictions
E.Need for specialized skills and expertise for each cloud platform
AnswersB, C, E

Each additional provider introduces its own public endpoints, management APIs and identity planes, multiplying the number of exploitable entry points an attacker can target. This directly reflects the expanded attack surface inherent to spanning multiple cloud environments.

Why this answer

Option B is correct because a multi-cloud strategy adds more entry points and APIs, since each provider exposes its own management consoles, IAM endpoints, and service APIs, expanding the attack surface that must be monitored and secured. Option C is correct because consistent security policies must be enforced across heterogeneous providers with different native controls, identity models, and configuration semantics, making uniform governance and compliance far more complex. Option E is correct because each cloud platform has its own tooling, services, and operational model, so the organization needs specialized skills and expertise for each provider rather than a single unified skill set.

Option A is not correct because multi-cloud generally reduces vendor lock-in rather than increasing it, since workloads can be distributed and portability is improved. Option D is not correct because data sovereignty challenges stem from where data is stored and processed across jurisdictions, which is not inherently a risk specific to using multiple cloud providers.

Exam trap

The trap is confusing single-cloud risks (lock-in, sovereignty) with multi-cloud-specific risks; candidates must distinguish risks that are amplified or introduced by using multiple providers from those that exist regardless.

78
MCQmedium

A company is using a single cloud provider for all critical services. What is the primary risk this company faces?

A.Data sovereignty risk
B.Compliance risk
C.Insider threat risk
D.Concentration risk
AnswerD

Relying on a single cloud provider creates concentration risk: an outage, breach, or provider failure disrupts all critical services simultaneously, with no failover path. This dependency, rather than portability or lock-in alone, is the primary risk.

Why this answer

Concentration risk is the risk that reliance on a single provider, vendor, region, or service creates a single point of failure — an outage, bankruptcy, or contractual dispute with that provider can disrupt all critical services simultaneously. Using one cloud provider for all critical services is the textbook definition of concentration risk in cloud governance.

Exam trap

The trap is selecting a risk that sounds severe (sovereignty, compliance) when the question specifically describes reliance on a single provider — the key signal is 'single' or 'all critical services,' which maps to concentration risk.

How to eliminate wrong answers

Option A is wrong because data sovereignty risk relates to where data is stored and which laws apply, not to the number of providers; a single provider can still host data in compliant jurisdictions. Option B is wrong because compliance risk depends on whether the provider and configuration meet regulatory requirements, which is independent of provider count. Option C is wrong because insider threat risk exists in any environment, single or multi-cloud, and is not specifically caused by using one provider.

79
MCQmedium

A healthcare provider is planning to migrate its electronic health records (EHR) system to a public cloud infrastructure. The system will store protected health information (PHI). Under HIPAA, what must the healthcare provider obtain from the cloud service provider before beginning the migration?

A.A Business Associate Agreement (BAA) that outlines the permitted uses of PHI and the security safeguards in place
B.A signed letter of attestation that the cloud provider is HIPAA-compliant
C.A Data Processing Agreement (DPA) as defined under GDPR
D.A Service Organization Control (SOC) 2 Type II report
AnswerA

HIPAA requires a Business Associate Agreement before a covered entity shares PHI with a business associate such as a cloud provider. The BAA contractually binds permitted uses and required safeguards, satisfying the pre-migration obligation the stem describes.

Why this answer

Under HIPAA, a covered entity must enter into a Business Associate Agreement (BAA) with any vendor that creates, receives, maintains, or transmits protected health information on its behalf. A cloud provider hosting an EHR system is a business associate, so a BAA is legally required before PHI can be migrated to the cloud.

Exam trap

CCSP often tests whether candidates confuse a BAA with a DPA or SOC 2 report — only the BAA is the legally required HIPAA contract with a cloud provider handling PHI.

How to eliminate wrong answers

Option B is wrong because a letter of attestation is not a recognized HIPAA legal instrument — only a BAA establishes the required contractual obligations and safeguards. Option C is wrong because a GDPR Data Processing Agreement addresses EU data protection law, not HIPAA, and does not satisfy HIPAA's business associate requirements. Option D is wrong because a SOC 2 Type II report is an audit attestation of controls, not a contract — it can support due diligence but does not replace the BAA.

80
MCQhard

A cloud customer is subject to the Payment Card Industry Data Security Standard (PCI DSS) and uses a cloud provider to store cardholder data. The customer wants to reduce its PCI DSS scope. Which of the following provider attestations would best support scope reduction for the customer?

A.A self-assessment questionnaire completed by the cloud provider
B.A PCI DSS Attestation of Compliance (AOC) and Report on Compliance (ROC) for the relevant services
C.A SOC 2 Type I report covering security
D.An ISO/IEC 27001 certificate covering the provider's data centers
AnswerB

The PCI DSS Attestation of Compliance and Report on Compliance are the formal documents that demonstrate a provider's compliance with PCI DSS. When a provider is a PCI DSS validated service provider, the customer can leverage that validation to reduce its own scope, provided the services used are within the provider's assessment. This is the most direct and recognized evidence for PCI DSS scope reduction.

Why this answer

To reduce PCI DSS scope, the customer needs evidence that the provider's environment meets PCI DSS requirements for the services used. A PCI DSS Attestation of Compliance and Report on Compliance provide that assurance. SOC 2 Type I, ISO 27001, and self-assessments do not specifically demonstrate PCI DSS compliance and are not sufficient for scope reduction.

Exam trap

The trap here is assuming that any security certification, such as ISO 27001 or SOC 2, is enough for PCI DSS scope reduction, when PCI DSS specifically requires its own attestation and report.

81
MCQhard

A cloud provider operates a public IaaS environment. A customer's legal team is reviewing the provider's audit rights clause and wants to ensure the provider will cooperate with a regulatory examination by a financial services regulator. The provider's standard contract currently states that customers may review SOC 2 reports annually but does not grant any right to audit. Which action should the customer's legal team take to best satisfy the regulator's expectations while maintaining a workable relationship with the provider?

A.Request that the provider undergo a third-party audit against a recognized framework and share the resulting report under NDA, supplemented by a right to receive audit summaries and to conduct audits only when required by the regulator
B.Rely solely on the provider's published marketing materials and self-assessment questionnaires
C.Demand an unlimited right to audit the provider's data centers at any time without notice
D.Insist that the regulator conduct the audit directly against the provider without any customer involvement
AnswerA

This approach balances regulatory expectations with cloud operational realities. Independent third-party attestations such as SOC 2 Type II or ISO/IEC 27001 certificates provide assurance without disrupting the provider. A contractual right to receive summaries and to conduct audits when a regulator specifically requires it ensures cooperation. This is a common and defensible cloud contract structure that regulators accept.

Why this answer

A practical audit rights clause in cloud contracts usually combines independent third-party attestations with a limited right for the customer to audit or receive audit results when required by a regulator. This satisfies oversight without demanding unlimited access. The other options either overreach, rely on insufficient evidence, or misunderstand the regulator's role.

Exam trap

The trap here is believing that a customer must have an unrestricted right to audit the provider's premises, when in public cloud the standard and more realistic approach is to rely on independent attestations and a regulator-triggered audit right.

82
MCQmedium

A cloud customer operates a SaaS-based HR platform in the EU and receives a data subject access request (DSAR) from an employee. The provider's standard contract states it will only assist with DSARs on a 'reasonable efforts' basis and bills hourly for that assistance. Under GDPR Article 28, which contractual element must the customer ensure is in place before relying on this SaaS platform?

A.A Standard Contractual Clause (SCC) module three signed with the SaaS provider to legitimize onward transfers.
B.A data processing agreement (DPA) that obligates the processor to assist the controller in responding to data subject requests.
C.A binding corporate rules (BCR) approval from the lead supervisory authority covering the provider's intra-group transfers.
D.A certification under an approved Article 42 code of conduct demonstrating the provider's accountability framework.
AnswerB

Article 28(3)(e) requires the processor to assist the controller by appropriate technical and organisational measures in responding to data subject requests, and Article 28(3) requires the processing to be governed by a binding contract. A DPA is therefore the mandatory instrument, and reasonable-efforts language plus hourly billing does not discharge the provider's Article 28 duty to assist.

Why this answer

GDPR Article 28(3) requires the controller and processor to be bound by a contract or other legal act that sets out the processor's obligations, including assisting the controller with data subject requests. Without a DPA containing that assistance obligation, the customer has no enforceable basis to compel the provider's help, regardless of the provider's internal practices or certification status.

Exam trap

The trap here is assuming that a transfer mechanism such as SCCs or BCRs, or a voluntary certification, substitutes for the mandatory Article 28 processing contract that establishes the processor's assistance duties to the controller.

83
MCQmedium

During an eDiscovery process, a company needs to preserve data stored in AWS S3 that may be relevant to a lawsuit. Which AWS feature should be used to implement a legal hold?

A.AWS CloudTrail
B.S3 Object Lock
C.S3 Versioning
D.AWS Config
AnswerB

S3 Object Lock enforces a write-once-read-many retention period or legal hold on individual object versions, preventing deletion or alteration for the hold's duration. This preserves potentially relevant S3 data against tampering or removal during eDiscovery.

Why this answer

S3 Object Lock is the AWS feature designed to implement legal holds. It allows you to place a legal hold on an object version, preventing it from being overwritten or deleted for a specified period or indefinitely. This is specifically used for compliance and legal scenarios like eDiscovery.

Exam trap

CCSP often tests the confusion between versioning and object lock, where candidates think versioning alone provides legal hold capabilities.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity but does not preserve data; it is for auditing, not legal holds. Option C is wrong because S3 Versioning protects against accidental deletion by keeping versions, but it does not prevent deletion of the object or versions; a legal hold requires explicit prevention. Option D is wrong because AWS Config assesses resource configurations and compliance, but it does not enforce data retention or legal holds.

84
MCQmedium

A multinational retailer uses a SaaS e-commerce platform hosted in the EU and serves customers in the EU, the UK, and the US. The legal team must determine which cross-border data transfer mechanism can be used to lawfully move customer personal data from the EU entity to the US parent company for analytics. Which mechanism should the legal team select?

A.Binding Corporate Rules (BCRs) approved only by the US Federal Trade Commission
B.EU-U.S. Data Privacy Framework (DPF) certification of the US parent company
C.The APEC Cross-Border Privacy Rules (CBPR) system certification of the US parent
D.A self-attestation of GDPR compliance signed by the US parent's Chief Privacy Officer
AnswerB

The EU-U.S. Data Privacy Framework is a current adequacy decision adopted by the European Commission in July 2023, allowing personal data to flow from the EU to US companies that self-certify to the US Department of Commerce. If the US parent holds a valid DPF certification covering the relevant data categories, this is the most direct transfer mechanism and avoids the need for SCCs or a TIA.

Why this answer

For an EU-to-US transfer of personal data, the most current and straightforward mechanism is the EU-U.S. Data Privacy Framework, provided the US recipient is certified for the relevant data. BCRs must be approved by EU supervisory authorities, internal attestations have no legal force, and APEC CBPR is not a GDPR transfer mechanism.

The DPF certification directly addresses the scenario.

Exam trap

The trap here is assuming that any privacy certification or internal policy from the US company is enough to legitimize the transfer, when GDPR requires a specific Chapter V mechanism such as an adequacy decision, SCCs, BCRs, or a derogation.

← PreviousPage 2 of 2 · 84 questions total

Ready to test yourself?

Try a timed practice session using only Legal, Risk, and Compliance questions.