ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your company hosts an EU customer-facing SaaS on a U.S. IaaS region and replicates its database daily to an Asian region run by a second cloud provider. During the annual compliance audit for GDPR, the auditor asks how you mitigate the risks of operating this distributed multi-jurisdiction environment. Which control should you emphasize to address the primary jurisdictional risk created by the cross-region data flow?
Maintain up-to-date data-flow maps and implement Standard Contractual Clauses governing transfers between the U.S. and APAC regions.
Deploy customer-managed hardware security modules to ensure all replicated data is encrypted at rest in every provider's region.
Negotiate stricter recovery time objectives and penalty clauses in each provider's service-level agreement.
Apply CIS-aligned hypervisor hardening baselines across all cloud regions to reduce co-tenancy attack surfaces.
When personal data about EU residents is transferred outside the European Economic Area, GDPR requires appropriate cross-border transfer mechanisms and clear documentation of where data resides. Implementing and maintaining Standard Contractual Clauses (SCCs) or other approved safeguards, together with accurate data-flow mapping that shows exactly which jurisdictions host the data, directly addresses the legal and compliance risk of data sovereignty. While encryption, hypervisor security, and stringent SLAs are important for confidentiality, integrity, availability, and service assurance, they do not in themselves resolve the legal requirements tied to data location and international transfers, which are the auditor's primary concern in this scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are Standard Contractual Clauses (SCCs) and how do they help with GDPR compliance?
Open an interactive chat with Bash
Why is data-flow mapping important for GDPR compliance in cloud environments?
Open an interactive chat with Bash
What other GDPR cross-border transfer mechanisms exist besides SCCs?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .