ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your company hosts an EU customer-facing SaaS on a U.S. IaaS region and replicates its database daily to an Asian region run by a second cloud provider. During the annual compliance audit for GDPR, the auditor asks how you mitigate the risks of operating this distributed multi-jurisdiction environment. Which control should you emphasize to address the primary jurisdictional risk created by the cross-region data flow?

  • Deploy customer-managed hardware security modules to ensure all replicated data is encrypted at rest in every provider's region.

  • Apply CIS-aligned hypervisor hardening baselines across all cloud regions to reduce co-tenancy attack surfaces.

  • Maintain up-to-date data-flow maps and implement Standard Contractual Clauses governing transfers between the U.S. and APAC regions.

  • Negotiate stricter recovery time objectives and penalty clauses in each provider's service-level agreement.

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot