hardMultiple Select
CCSP Practice Question: Which THREE of the following are typical…
Which THREE of the following are typical requirements for compliance with eDiscovery in a cloud environment?
⚠ Common exam trap
CCSP often tests the confusion between general security controls (encryption, data minimization) and specific eDiscovery requirements (legal hold, chain of custody, search), causing candidates to select security best practices instead of legal discovery capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Documentation of chain of custody
Option A is correct because eDiscovery requires an auditable chain of custody documenting who collected, handled, and preserved electronically stored information (ESI), so its integrity and admissibility can be proven. Option B is correct because compliance demands search and retrieval capabilities across all relevant data sources (mailboxes, SharePoint/OneDrive, Teams, etc.) so responsive ESI can be identified and produced under FRCP rules. Option C is correct because the ability to place a legal hold is essential to prevent deletion or alteration of potentially relevant data once litigation or investigation is reasonably anticipated. Option D does not belong because encryption at rest is a general data-protection control, not an eDiscovery-specific requirement, and Option E does not belong because data minimization is a privacy principle (e.g., GDPR) rather than an eDiscovery capability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Documentation of chain of custody
Why this is correct
Documenting chain of custody satisfies eDiscovery's evidentiary integrity requirement: it records who handled data, when, and how, proving collected cloud artefacts were not altered. Without this audit trail, evidence may be ruled inadmissible, so it is a typical compliance requirement for cloud eDiscovery processes.
- ✓
Search and retrieval capabilities across data sources
Why this is correct
Search and retrieval across data sources satisfies eDiscovery's identification and collection requirement: relevant electronically stored information must be located across cloud repositories, mailboxes and endpoints, then produced. Without this capability, responding to litigation holds or regulatory requests within deadlines is impossible.
- ✓
Ability to place legal hold on data
Why this is correct
Placing legal hold satisfies eDiscovery's preservation requirement: once litigation is reasonably anticipated, potentially relevant data must be frozen against deletion, including in cloud storage and backups. This prevents spoliation, which would otherwise trigger sanctions and undermine compliance.
- ✗
Encryption of data at rest
Why it's wrong here
Encryption at rest protects confidentiality but does not satisfy eDiscovery, which requires identification, preservation, collection and production of responsive data. It is tempting because encryption is a standard cloud security control and often a regulatory requirement, so it would be correct for a data-protection or encryption-at-rest question.
- ✗
Data minimization principles
Why it's wrong here
eDiscovery demands preservation and production of potentially relevant data, so minimisation conflicts with the duty to retain it. It is tempting because minimisation genuinely reduces breach exposure and storage cost under privacy regimes such as GDPR, where deleting data you no longer need is the correct posture.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.