Courseiva
hardMultiple Select

CCSP Practice Question: Which THREE of the following are typical…

Which THREE of the following are typical requirements for compliance with eDiscovery in a cloud environment?

⚠ Common exam trap

CCSP often tests the confusion between general security controls (encryption, data minimization) and specific eDiscovery requirements (legal hold, chain of custody, search), causing candidates to select security best practices instead of legal discovery capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Documentation of chain of custody

Option A is correct because eDiscovery requires an auditable chain of custody documenting who collected, handled, and preserved electronically stored information (ESI), so its integrity and admissibility can be proven. Option B is correct because compliance demands search and retrieval capabilities across all relevant data sources (mailboxes, SharePoint/OneDrive, Teams, etc.) so responsive ESI can be identified and produced under FRCP rules. Option C is correct because the ability to place a legal hold is essential to prevent deletion or alteration of potentially relevant data once litigation or investigation is reasonably anticipated. Option D does not belong because encryption at rest is a general data-protection control, not an eDiscovery-specific requirement, and Option E does not belong because data minimization is a privacy principle (e.g., GDPR) rather than an eDiscovery capability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Documentation of chain of custody

    Why this is correct

    Documenting chain of custody satisfies eDiscovery's evidentiary integrity requirement: it records who handled data, when, and how, proving collected cloud artefacts were not altered. Without this audit trail, evidence may be ruled inadmissible, so it is a typical compliance requirement for cloud eDiscovery processes.

  • ✓

    Search and retrieval capabilities across data sources

    Why this is correct

    Search and retrieval across data sources satisfies eDiscovery's identification and collection requirement: relevant electronically stored information must be located across cloud repositories, mailboxes and endpoints, then produced. Without this capability, responding to litigation holds or regulatory requests within deadlines is impossible.

  • ✓

    Ability to place legal hold on data

    Why this is correct

    Placing legal hold satisfies eDiscovery's preservation requirement: once litigation is reasonably anticipated, potentially relevant data must be frozen against deletion, including in cloud storage and backups. This prevents spoliation, which would otherwise trigger sanctions and undermine compliance.

  • ✗

    Encryption of data at rest

    Why it's wrong here

    Encryption at rest protects confidentiality but does not satisfy eDiscovery, which requires identification, preservation, collection and production of responsive data. It is tempting because encryption is a standard cloud security control and often a regulatory requirement, so it would be correct for a data-protection or encryption-at-rest question.

  • ✗

    Data minimization principles

    Why it's wrong here

    eDiscovery demands preservation and production of potentially relevant data, so minimisation conflicts with the duty to retain it. It is tempting because minimisation genuinely reduces breach exposure and storage cost under privacy regimes such as GDPR, where deleting data you no longer need is the correct posture.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.