ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A U.S.-based SaaS provider stores European customers' medical records exclusively in its cloud tenant located in Frankfurt, Germany. One morning it receives a subpoena issued under the U.S. CLOUD Act that demands a copy of a German patient's data for an ongoing criminal investigation in the United States. Which response gives the provider the BEST chance of complying with legal obligations in both jurisdictions?

  • Comply immediately with the subpoena because the CLOUD Act overrides foreign privacy laws when the provider is U.S.-based.

  • Notify the German data-protection authority and contest the subpoena while requesting that U.S. investigators use a Mutual Legal Assistance Treaty (MLAT) or equivalent EU-approved mechanism before any disclosure.

  • Refuse to provide the data because GDPR bans any transfer of EU personal data to U.S. authorities without the data subject's explicit consent.

  • Permanently delete the requested records so the data are neither held in Germany nor available to U.S. law enforcement, eliminating conflict.

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot