CCSP Legal, Risk, and Compliance Practice Question
In the context of eDiscovery, a legal hold must be placed on data stored in a cloud environment. Which THREE actions should the cloud customer take to ensure the legal hold is effective?
⚠ Common exam trap
CCSP often tests legal hold requirements, and candidates may overlook the need to apply holds to backups and replicas or to notify the provider for technical enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the legal hold prevents both deletion and modification of the data.
Option A is correct because an effective legal hold must preserve data in its original state, meaning it must block both deletion and modification (e.g., via WORM/immutability controls) so the evidence remains authentic and unaltered for litigation. Option D is correct because eDiscovery obligations extend to every copy of potentially relevant data, so the hold must cover backups, snapshots, and cross-region replicas, otherwise a spoliation risk remains in those secondary locations. Option E is correct because the customer typically does not control the underlying cloud infrastructure, so notifying the provider and requesting technical enforcement such as S3 Object Lock, retention policies, or legal-hold flags ensures the hold is actually implemented at the platform level. Option B is wrong because deleting non-relevant data during a hold risks destroying potentially relevant evidence and can constitute spoliation. Option C is wrong because default backup retention policies are provider-controlled, time-limited, and not a substitute for a case-specific legal hold.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure the legal hold prevents both deletion and modification of the data.
Why this is correct
A legal hold must preserve data in its original state, so the mechanism must block both deletion and alteration; otherwise spoliation occurs and the evidence loses integrity. Ensuring the hold prevents deletion and modification satisfies the stem's requirement that the cloud legal hold be effective.
- ✗
Delete any non-relevant data to reduce storage costs.
Why it's wrong here
Deleting data during a legal hold destroys potentially relevant evidence and may constitute spoliation, defeating the hold's purpose. It is tempting as routine storage-cost hygiene, which is sensible outside litigation, but preservation obligations suspend normal deletion practises for all potentially relevant data.
- ✗
Rely solely on the cloud provider's default backup retention policies.
Why it's wrong here
Provider default backup retention typically follows short, provider-defined cycles and cannot guarantee preservation for the matter's duration or scope. It is tempting because backups exist and require no customer effort, but an effective hold needs customer-controlled preservation, verification and documented custodian acknowledgement.
- ✓
Apply the legal hold to all copies of the data, including backups and replicas in different regions.
Why this is correct
Cloud data is replicated across regions, snapshots and backups, so a hold applied only to the primary copy leaves discoverable duplicates unprotected. Extending the legal hold to all copies, including backups and replicas in different regions, satisfies the stem's requirement for an effective cloud legal hold.
- ✓
Notify the cloud provider of the legal hold and request technical enforcement such as object lock.
Why this is correct
Notifying the provider secures the tenant-side obligation, while object lock enforces WORM immutability at the storage layer, preventing deletion or alteration for the retention period. This satisfies the stem's requirement that the hold remain effective even against privileged users or compromised credentials.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.