mediumMultiple Choice
CCSP Practice Question: During a cloud migration, a company discovers…
During a cloud migration, a company discovers that data stored in a specific region must remain there per contract. The cloud provider offers data replication across regions. What is the best practice to ensure compliance?
⚠ Common exam trap
Test-takers frequently confuse data protection (encryption) with data location control — candidates often pick encryption because it sounds like a compliance measure, but residency is about where data lives, not how it's protected.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use data residency controls provided by the cloud provider
Data residency controls (such as AWS SCPs, Azure Policy, or GCP Organization Policies with location constraints) are the cloud-native mechanism designed to enforce where data can be stored and replicated. They provide policy-based guardrails that prevent replication to unauthorized regions, satisfying the contractual requirement without disabling legitimate functionality. This is the standard best practice because it enforces compliance at the platform level rather than relying on manual processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use data residency controls provided by the cloud provider
Why this is correct
Data residency controls pin storage and replication to the contracted region, preventing the provider's cross-region replication from moving data outside its required jurisdiction. This directly satisfies the contractual constraint that data must remain in a specific region.
- ✗
Negotiate a new contract to allow replication
Why it's wrong here
Renegotiating the contract abandons the residency obligation rather than meeting it; the requirement is to keep data in-region, which regional replication settings achieve without contractual change. It tempts as a commercial fix, but the scenario asks for technical compliance, and a new contract would be correct only if residency were genuinely negotiable.
- ✗
Disable all data replication features
Why it's wrong here
Disabling replication entirely removes the provider's cross-region copies, but the contract requires data to remain in-region, not that replication be switched off; replication confined to that region satisfies residency. It tempts because replication is the perceived risk, yet disabling it also forfeits in-region redundancy and availability.
- ✗
Encrypt data before storing it
Why it's wrong here
Encryption protects confidentiality but does not constrain where replicas reside; ciphertext copied to another region still breaches the residency clause. It tempts because encryption is a common data-protection control, yet it addresses disclosure, not location. It would be correct where the requirement is protecting data at rest, not geographic containment.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.