ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your company, now involved in a U.S. civil lawsuit, keeps customer records in a multitenant object-storage SaaS offering that automatically deletes files 90 days after upload. The legal department has issued a litigation hold and wants written assurance that no potentially responsive data will be altered or purged while the case is pending. According to ISO/IEC 27050 guidance on eDiscovery, which contractual control with the cloud provider is most critical to meet this obligation?
Require the provider to replicate all stored data to a second geographic region for redundancy.
Include a clause obligating the provider to offer an on-demand legal-hold feature that freezes retention and deletion policies for designated tenant data.
Mandate that the provider return all stored records to the customer on physical media within 30 days of a request.
Demand that the provider allow customer-managed encryption keys held in a hardware security module (HSM).
ISO/IEC 27050 identifies preservation as an early phase of eDiscovery and stresses that data subject to legal hold must remain complete, unaltered, and protected from routine disposition. A contract term requiring the provider to support a granular legal-hold or preservation lock directly suspends normal retention or deletion rules for specified data, ensuring compliance. Replicating data to another region, exporting it on physical media, or using customer-managed encryption keys may support resiliency or confidentiality, but they do not, by themselves, stop the provider's automated deletion process or guarantee that the data remains intact for the duration of the hold.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is ISO/IEC 27050 and how does it relate to eDiscovery?
Open an interactive chat with Bash
What is a litigation/legal hold in the context of cloud storage?
Open an interactive chat with Bash
Why is offering an on-demand legal-hold feature critical for compliance?
Open an interactive chat with Bash
What is eDiscovery in the context of ISO/IEC 27050?
Open an interactive chat with Bash
Why is a legal-hold feature critical in cloud environments?
Open an interactive chat with Bash
What are the limitations of customer-managed encryption keys for legal holds?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .