ISC2 Certified Cloud Security Professional (CCSP) Practice Question

Your U.S.-based organization is finalizing a SaaS agreement that will move large volumes of EU residents' personal data to an American data center. Because the Court of Justice of the European Union struck down the EU-U.S. Privacy Shield, executives want a contractual solution that allows the transfers to continue without first seeking approval from any EU data protection authority. Which contractual mechanism best satisfies this requirement?

  • Invoke GDPR Article 49 derogations based on explicit consent for each EU data subject.

  • Reference compliance with the U.S. CLOUD Act as the legal basis for the transfer.

  • Embed the European Commission's Standard Contractual Clauses (SCCs) into the master service agreement.

  • Implement Binding Corporate Rules (BCRs) for processors to cover the SaaS operations.

ISC2 Certified Cloud Security Professional (CCSP)
Legal, Risk and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot