Courseiva
mediumMultiple SelectObjective-mapped

CCSP Practice Question: Which TWO of the following are required for GDPR…

Which TWO of the following are required for GDPR compliance when processing personal data in the cloud?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a Data Protection Impact Assessment (DPIA) when processing is likely to result in high risk

Under GDPR, a Data Protection Impact Assessment (DPIA) is mandatory when processing is likely to result in high risk to individuals' rights and freedoms (Article 35). Additionally, controllers and processors must maintain a record of processing activities (Article 30). Option A is incorrect because a DPO is required only for certain organizations, not all. Option B is incorrect because data can be transferred outside the EU with adequate safeguards (e.g., Standard Contractual Clauses). Option C is incorrect because ISO 27001 certification is not a legal requirement under GDPR, though it can demonstrate compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Appoint a Data Protection Officer (DPO) for all organizations

    Why it's wrong here

    DPO appointment is mandatory only for certain entities.

  • Store data only within the European Union

    Why it's wrong here

    Data can be transferred outside EU with appropriate safeguards.

  • Use only ISO 27001 certified cloud service providers

    Why it's wrong here

    GDPR does not require specific certification.

  • Conduct a Data Protection Impact Assessment (DPIA) when processing is likely to result in high risk

    Why this is correct

    GDPR requires DPIA for high-risk processing.

  • Maintain a record of processing activities

    Why this is correct

    Article 30 requires records of processing.

About these practice questions

This CCSP question is part of Courseiva's 964-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.