ISC2 Certified Cloud Security Professional (CCSP) Practice Question
During a GDPR readiness review, a cloud security engineer is building a data flow map for a SaaS application that stores EU resident PII in a provider-managed object storage service which automatically replicates objects to a secondary region for durability. To demonstrate effective data classification and cross-border controls, which information must the engineer include in the data map to satisfy regulators?
The specific cryptographic ciphers and key lengths used to encrypt the stored objects
The version and patch level of the operating system supporting the storage service
Every IAM role and privilege granted to application developers accessing the bucket
The geographic locations where the provider stores all primary and replicated copies of the personal data
Data mapping focuses on showing where personal data is stored and how it moves through and beyond the cloud environment. Under GDPR and other privacy regimes, organisations must document any transfer of personal data to other countries or locations, including backups and replicas created by cloud providers. Listing every geographic storage and replication point therefore satisfies the requirement for transparency and supports lawful basis assessments. While encryption details, IAM role assignments, and OS patch levels are important security controls, they are not the primary data-location elements that regulators expect in a data mapping record intended for classification and cross-border compliance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is GDPR and why does it focus on data location?
Open an interactive chat with Bash
Why isn't encryption information included in the data map for GDPR compliance?
Open an interactive chat with Bash
What are the key elements of a data flow map under GDPR?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Data Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .