Courseiva
easyMultiple Choice

CCSP Practice Question: The primary purpose of a Data Processing…

What is the primary purpose of a Data Processing Agreement (DPA) between a data controller and a cloud service provider?

⚠ Common exam trap

ISC2 often tests the distinction between legal/compliance documents (DPA) and operational/technical documents (SLA, security policies), so the trap here is confusing the DPA's role in defining processing roles with specific technical controls like encryption or backup procedures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To define roles and responsibilities for data processing

A Data Processing Agreement (DPA) is a legally binding contract required under regulations like GDPR. Its primary purpose is to define the roles and responsibilities of the data controller and the data processor (the cloud service provider), ensuring the processor acts only on the controller's documented instructions and meets compliance obligations. Without a DPA, the controller cannot legally transfer data to the processor, as the agreement establishes the lawful basis and accountability for processing activities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To set data retention periods for processed data

    Why it's wrong here

    Retention periods are set by the controller's records-retention policy and legal obligations, then communicated to the processor; they are not the DPA's primary purpose. A DPA establishes the lawful processor-controller relationship and processing instructions under GDPR Article 28. Setting retention schedules is correct when building an information lifecycle governance policy.

  • ✗

    To specify encryption algorithms to be used

    Why it's wrong here

    A DPA is a contractual instrument satisfying GDPR Article 28, governing lawful processing instructions, sub-processors and audit rights. Encryption algorithm selection belongs in technical security schedules or configuration baselines, not the DPA's core purpose. Specifying ciphers is correct when drafting cryptographic standards or a security addendum.

  • ✗

    To establish data backup and recovery procedures

    Why it's wrong here

    Backup and recovery procedures are operational resilience controls documented in business continuity and disaster recovery plans, not the DPA's purpose. A DPA contractually binds the processor to the controller's documented processing instructions under GDPR Article 28. Defining RPO and RTO targets is correct when designing a cloud resilience strategy.

  • ✓

    To define roles and responsibilities for data processing

    Why this is correct

    A DPA contractually allocates controller and processor obligations, covering scope, security, sub-processing and data subject rights. Defining these roles and responsibilities satisfies the scenario's core purpose, establishing accountability and lawful processing boundaries between the controller and the cloud service provider.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.