ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question

During an operational risk analysis for a cloud-hosted application that will serve EU customers, engineers propose copying full production user data to a development environment located in the United States, where third-party support staff will troubleshoot incidents. Which GDPR obligation is most at risk of being violated by this plan?

  • Transferring EU personal data to a country outside the EEA without first implementing an approved safeguard or adequacy mechanism

  • Storing the replicated data unencrypted at rest in the development environment

  • Not notifying the supervisory authority within 72 hours if the development database is later breached

  • Failing to provide data subjects with their information in a portable format within the statutory time frame

ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Deployment, Operations, Maintenance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot