Courseiva

CCSP · topic practice

Legal, Risk, and Compliance practice questions

This domain covers how cloud adoption reshapes legal obligations, risk management, and compliance accountability. It tests GDPR breach timelines, PCI DSS shared responsibility, eDiscovery holds on cloud storage, jurisdictional conflicts, and contract/audit artifacts. Expect scenario questions where you must pick the correct AWS control, legal deadline, or compliance responsibility rather than recite definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Legal, Risk, and Compliance

What the exam tests

What to know about Legal, Risk, and Compliance

You must map legal duties to cloud controls: know the GDPR 72-hour notification trigger, apply S3 Object Lock legal hold for eDiscovery, and keep PCI DSS customer obligations despite provider assessments. The key is correctly assigning responsibility between provider and customer under shared controls.

GDPR 72-hour controller notification to supervisory authority after awareness of a personal data breach

AWS S3 Object Lock in legal hold mode to preserve objects for eDiscovery

PCI DSS responsibility split between cloud provider and customer, evidenced by QSA assessment

Cross-border eDiscovery challenges: data sovereignty, conflicting laws, and provider control limits

Watch out for

Common Legal, Risk, and Compliance exam traps

  • ▸Treating the 72-hour GDPR clock as starting at breach discovery by a third party rather than controller awareness.
  • ▸Assuming a QSA-assessed cloud provider transfers all PCI DSS obligations to the provider instead of retaining customer responsibilities.
  • ▸Confusing S3 Object Lock retention modes with legal hold, or believing deletion protection alone satisfies eDiscovery preservation.

Practice set

Legal, Risk, and Compliance questions

20 questions · select your answer, then reveal the explanation

A multinational company operating in the EU uses a cloud service provider based in the US to process personal data of EU data subjects. The company is considered a data controller under the GDPR. Which of the following must the company ensure is in place to lawfully transfer personal data from the EU to the US?

A financial institution subject to SOX is migrating its general ledger system to a SaaS provider. Which of the following IT general controls is most critical to ensure the integrity of financial data in the cloud?

A cloud customer needs to comply with PCI DSS for a cardholder data environment (CDE) hosted on an IaaS platform. According to PCI DSS Appendix A3, which document is critical to define the security responsibilities between the customer and the cloud provider?

Under the CSA STAR program, which tier involves a third-party assessment resulting in a certification based on ISO 27001?

A cloud customer is selecting a cloud provider for hosting payment card data and must comply with PCI DSS. Which THREE of the following are valid considerations when assessing the provider's PCI DSS compliance?

A multinational company headquartered in the US processes personal data of EU data subjects using a cloud service provider hosted in Singapore. Under GDPR, which legal mechanism is most appropriate for lawful transfer of personal data from the EU to Singapore?

A company that must comply with SOX is migrating its financial systems to a cloud service. Which of the following IT general controls is most critical for SOX compliance in the cloud?

Which CSA STAR tier involves a third-party assessment and results in a certification based on ISO 27001?

A cloud customer is evaluating a provider's compliance with PCI DSS. Which two components are part of the PCI DSS shared responsibility model as referenced in Appendix A3? (Choose two.)

A multinational corporation collects personal data of EU residents and uses a cloud provider with data centers in the US and Asia. Under GDPR, which mechanism is appropriate for transferring data from the EU to the US data center, assuming no adequacy decision exists?

Under SOX, which of the following is an IT general control that must be implemented for financial data systems in a cloud environment?

According to GDPR, which THREE are data subject rights? (Select three.)

A multinational corporation with its headquarters in the United States processes personal data of European Union data subjects using a cloud-based customer relationship management (CRM) system hosted in the United States. According to the General Data Protection Regulation (GDPR), which of the following is the company's primary obligation regarding the protection of that data?

A company is subject to PCI DSS because it processes credit card transactions. It plans to use a cloud provider that is not specifically listed as a PCI DSS validated service provider. What is the most important step the company must take to ensure compliance?

A company is drafting a cloud service contract and wants to ensure it can exit the provider without losing access to its data. Which TWO clauses are most important to include?

A financial services company is migrating its customer account management system to a public cloud provider. The company is subject to SOX compliance requirements for internal controls over financial reporting. Which TWO controls are essential for the cloud environment to meet SOX IT general control requirements? (Choose two.)

A healthcare organization is planning to use a cloud provider to host protected health information (PHI) subject to HIPAA. Which THREE requirements must be addressed before the organization can lawfully use the cloud for PHI? (Choose three.)

A European Union-based cloud customer processes personal data of EU residents in a US-based cloud data center. The provider is not certified under the EU-US Data Privacy Framework. The customer's legal team wants to transfer the data legally. Which mechanism should they use to comply with GDPR Chapter V?

A European retail company processes personal data of customers in a public cloud. The company wants to transfer a copy of the data to a cloud region in the United States for analytics. Under the GDPR, which mechanism is most appropriate to ensure an adequate level of data protection for this transfer?

A cloud customer is evaluating a cloud provider's compliance with the Payment Card Industry Data Security Standard (PCI DSS). The customer wants to understand the division of responsibilities for PCI DSS controls in the cloud environment. Which document should the customer request from the provider to clarify which PCI DSS requirements are managed by the provider and which by the customer?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Legal, Risk, and Compliance sessions

Start a Legal, Risk, and Compliance only practice session

Every question in these sessions is drawn from the Legal, Risk, and Compliance domain — nothing else.

Related practice questions

Related CCSP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CCSP exam test about Legal, Risk, and Compliance?
You must map legal duties to cloud controls: know the GDPR 72-hour notification trigger, apply S3 Object Lock legal hold for eDiscovery, and keep PCI DSS customer obligations despite provider assessments. The key is correctly assigning responsibility between provider and customer under shared controls.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Legal, Risk, and Compliance questions in a focused session?
Yes — the session launcher on this page draws every question from the Legal, Risk, and Compliance domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CCSP topics?
Use the topic links above to move to related areas, or go back to the CCSP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CCSP exam covers. They are not copied from any real exam or dump site.