easyMultiple Choice
CCSP Practice Question: The primary purpose of a Data Processing…
What is the primary purpose of a Data Processing Agreement (DPA) between a data controller and a cloud service provider?
⚠ Common exam trap
ISC2 often tests the distinction between legal/compliance documents (DPA) and operational/technical documents (SLA, security policies), so the trap here is confusing the DPA's role in defining processing roles with specific technical controls like encryption or backup procedures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To define roles and responsibilities for data processing
A Data Processing Agreement (DPA) is a legally binding contract required under regulations like GDPR. Its primary purpose is to define the roles and responsibilities of the data controller and the data processor (the cloud service provider), ensuring the processor acts only on the controller's documented instructions and meets compliance obligations. Without a DPA, the controller cannot legally transfer data to the processor, as the agreement establishes the lawful basis and accountability for processing activities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To set data retention periods for processed data
Why it's wrong here
Retention periods are set by the controller's records-retention policy and legal obligations, then communicated to the processor; they are not the DPA's primary purpose. A DPA establishes the lawful processor-controller relationship and processing instructions under GDPR Article 28. Setting retention schedules is correct when building an information lifecycle governance policy.
- ✗
To specify encryption algorithms to be used
Why it's wrong here
A DPA is a contractual instrument satisfying GDPR Article 28, governing lawful processing instructions, sub-processors and audit rights. Encryption algorithm selection belongs in technical security schedules or configuration baselines, not the DPA's core purpose. Specifying ciphers is correct when drafting cryptographic standards or a security addendum.
- ✗
To establish data backup and recovery procedures
Why it's wrong here
Backup and recovery procedures are operational resilience controls documented in business continuity and disaster recovery plans, not the DPA's purpose. A DPA contractually binds the processor to the controller's documented processing instructions under GDPR Article 28. Defining RPO and RTO targets is correct when designing a cloud resilience strategy.
- ✓
To define roles and responsibilities for data processing
Why this is correct
A DPA contractually allocates controller and processor obligations, covering scope, security, sub-processing and data subject rights. Defining these roles and responsibilities satisfies the scenario's core purpose, establishing accountability and lawful processing boundaries between the controller and the cloud service provider.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.