ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A multinational retailer must host EU customers' personally identifiable information (PII) in a public cloud. The preferred provider is headquartered in the United States and therefore subject to the U.S. CLOUD Act, which could compel disclosure of stored content. To minimize exposure created by this potential conflict with the GDPR's cross-border transfer restrictions, which contractual or technical requirement should the cloud security architect insist on?
Accept the provider's SOC 2 Type II attestation as evidence the conflict is sufficiently controlled.
Mandate EU-only storage combined with customer-managed encryption keys that prevent the provider from accessing the plaintext data.
Relocate the EU customer data to a U.S. region so that the CLOUD Act fully governs it.
Rely on the provider's former EU-U.S. Privacy Shield certification to legitimise any compelled disclosure.
Because the CLOUD Act can obligate a U.S.-based provider to turn over data it can access, forcing the provider to design the service so that it never possesses the decryption keys for EU PII removes its practical ability to comply with such orders. Storing the data only in EU locations while the customer retains sole control of the encryption keys satisfies GDPR localisation expectations and avoids an impermissible "transfer" under Schrems II.
Privacy Shield is no longer a valid transfer mechanism, so relying on it does not resolve the conflict.
A SOC 2 Type II report addresses internal controls but says nothing about cross-border legal demands.
Moving the data to a U.S. region would clearly constitute a restricted transfer and increase-not reduce-GDPR risk.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the CLOUD Act and how does it impact data stored in public clouds?
Open an interactive chat with Bash
Why is GDPR's Schrems II decision relevant to cross-border data transfers?
Open an interactive chat with Bash
How does customer-managed encryption mitigate the risks posed by the CLOUD Act and GDPR compliance?
Open an interactive chat with Bash
What is the U.S. CLOUD Act?
Open an interactive chat with Bash
What is Schrems II and why does it matter for GDPR compliance?
Open an interactive chat with Bash
Why is customer-managed encryption key control critical in this scenario?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .