Courseiva
hardMultiple SelectObjective-mapped

CCSP Practice Question: Which TWO of the following are requirements for a…

Which TWO of the following are requirements for a cloud service agreement to comply with the European Data Protection Board (EDPB) guidelines on data processing?

⚠ Common exam trap

ISC2 often tests the distinction between controller and processor responsibilities, so candidates may mistakenly think the controller must agree to audit rights (Option C) rather than recognizing that the processor must agree to them in the agreement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The processor must only process data on documented instructions from the controller

The EDPB guidelines mandate that a processor may only process personal data on documented instructions from the controller. This ensures the processor’s actions are strictly controlled and auditable, preventing unauthorized processing that could violate GDPR Article 28(3)(a).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The processor may subcontract processing without notification

    Why it's wrong here

    Subcontracting requires prior notification and authorization.

  • The processor must only process data on documented instructions from the controller

    Why this is correct

    Correct. The agreement must ensure processing is only on documented instructions.

  • The controller must ensure the processor agrees to audit rights

    Why it's wrong here

    Audit rights are recommended but not a mandatory requirement in the EDPB guidelines.

  • The agreement must specify the duration of processing

    Why this is correct

    Correct. The duration of processing must be defined in the agreement.

  • The processor must retain data indefinitely

    Why it's wrong here

    Data retention should be limited and specified; indefinite retention is not compliant.

About these practice questions

One of 964 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.