ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your U.S.-based company is migrating its cloud-hosted HR system, which processes the personal data of employees located in the European Union, to a SaaS provider whose data centers are all in the United States. Under the GDPR you must ensure that the cross-border transfer of this personal data remains lawful once the service goes live. Which contractual mechanism should you insist on adding to the master service agreement with the provider to satisfy this requirement?

  • Rely on the provider's ISO/IEC 27001 and ISO/IEC 27018 certifications as the lawful basis for transfer.

  • Include the European Commission's Standard Contractual Clauses between the EU entity and the SaaS provider.

  • Encrypt all personal data in transit with TLS 1.2 or higher to eliminate the need for additional safeguards.

  • Obtain a SOC 2 Type II report from the provider covering the Security and Privacy trust services criteria.

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot