ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A German retailer is negotiating a long-term contract with a U.S.-based SaaS provider that will store customer purchase histories (which include names, addresses, and loyalty card numbers) in data centers located in Virginia and replicate encrypted backups to a facility in Singapore. Before approving the design, the company's legal team asks the cloud security professional to identify the primary legal risk that must be evaluated for this architecture. Which risk should be highlighted first?
Cross-border transfer of EU personal data to a non-adequate jurisdiction, creating potential non-compliance with GDPR requirements.
Violation of U.S. export control regulations governing strong cryptographic functionality embedded in the SaaS application.
Failure of the cloud provider's overseas facilities to maintain ISO/IEC 27001 certification for information security management.
Non-compliance with international data-center energy efficiency directives applicable outside the European Union.
Because the data set contains personally identifiable information about EU residents, it is subject to the General Data Protection Regulation (GDPR). Replicating that data from the United States to Singapore constitutes a transfer of EU personal data to a third country that the European Commission does not recognize as providing an adequate level of protection. Without appropriate safeguards-such as Standard Contractual Clauses, Binding Corporate Rules, or another lawful transfer mechanism-the organization could face significant GDPR enforcement actions. While certifications, export controls, or energy-efficiency rules may be considerations, they are not the foremost legal exposure raised by this multi-jurisdictional storage plan.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is GDPR and why does it matter in cross-border data transfers?
Open an interactive chat with Bash
What are Standard Contractual Clauses (SCCs) and how do they help ensure GDPR compliance?
Open an interactive chat with Bash
Why is Singapore not considered an ‘adequate jurisdiction’ under GDPR?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .