ISC2 Certified Cloud Security Professional (CCSP) Practice Question

A U.S.-based software vendor is preparing to migrate several customer datasets to a public IaaS provider. During the data-classification workshop, four example datasets are identified:

  1. Proprietary source code covered by a non-disclosure agreement (NDA) with the customer.
  2. Spreadsheets containing employees' medical diagnosis and treatment information from the company's on-site clinic.
  3. Logs that store customers' full names, postal addresses, and Social Security numbers captured during account registration.
  4. Web-site clickstream records that have been fully anonymized and cannot be re-identified.

From a cloud-privacy perspective, which dataset is most accurately categorized as contractual private data rather than regulated private data?

  • Proprietary source code provided by a customer and protected solely by a non-disclosure agreement.

  • Fully anonymized web clickstream data that cannot be linked back to individual users.

  • Customer registration logs that record full names, mailing addresses, and Social Security numbers.

  • Employee medical records containing diagnosis and treatment details from the company clinic.

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot