ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A German retailer is preparing to migrate its customer relationship data, which includes personally identifiable information, to a U.S.-based SaaS provider whose primary data centers are located in Virginia. During the project's legal risk review, you are asked to identify the most significant legal concern created by this hosting decision. Which issue should you flag for immediate mitigation?

  • Inability to obtain a current SOC 2 Type II report from the U.S. provider.

  • Increased network latency caused by trans-Atlantic data paths.

  • Absence of multi-factor authentication for the provider's administrative accounts.

  • Possible conflict between EU GDPR data-transfer restrictions and U.S. government lawful-access legislation such as the CLOUD Act.

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot