CCSP Legal, Risk, and Compliance Practice Question
In a cloud environment, a data subject exercises their right to erasure under GDPR. The cloud provider has multiple replicas and backups. What is the primary technical challenge in fulfilling this request?
⚠ Common exam trap
CCSP often tests the misconception that data deletion is straightforward in the cloud, but the presence of backups and replicas introduces complexity; candidates may overlook the retention period constraint and choose identification as the primary challenge.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensuring deletion from backups and replicas within retention periods
The primary technical challenge is ensuring deletion from backups and replicas within retention periods because GDPR's right to erasure (Article 17) requires data to be erased without undue delay, but cloud environments often have multiple replicas and backups that may not be immediately deletable due to retention policies or immutability. This creates a conflict between the legal obligation to erase and the technical reality that backups are typically retained for disaster recovery, requiring mechanisms to ensure data is not restored or that deletion is propagated once backups are restored. Thus, the correct answer focuses on the complexity of coordinating deletion across all copies while respecting retention schedules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transferring data to another controller
Why it's wrong here
Transferring data to another controller concerns portability under Article 20, not erasure under Article 17. It is tempting because both rights involve the data subject's control over personal data, but portability addresses moving data, whereas erasure addresses deleting it.
- ✓
Ensuring deletion from backups and replicas within retention periods
Why this is correct
Erasure must propagate across every replica and backup copy, yet immutable or air-gapped backups and fixed retention schedules often prevent immediate purging. Satisfying the GDPR right to erasure therefore depends on deletion mechanisms that reach archived copies within their retention windows.
- ✗
Obtaining consent from other data subjects
Why it's wrong here
Erasure of one subject's data does not require consent from other data subjects; their data is unaffected unless it is commingled. It is tempting because consent is a lawful basis under GDPR, but it governs processing, not the mechanics of deleting a specific individual's records.
- ✗
Identifying the data subject's data across all systems
Why it's wrong here
Locating every copy of a subject's personal data is difficult, but discovery is a prerequisite rather than the primary obstacle; deletion across immutable replicas and backups is the harder technical problem. It is tempting because data mapping is genuinely the first step in any erasure workflow.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.