🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 13 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

A German SaaS provider plans to migrate its customer relationship database, which contains EU residents' personal data, to Amazon S3 and Amazon RDS. To satisfy GDPR requirements for data locality and the right to erasure while keeping operational overhead low, which approach BEST meets the company's obligations?

  • Use S3 buckets only in eu-central-1 with server-side encryption (SSE-S3) and place all objects under S3 Object Lock in Compliance mode to address the right to be forgotten.

  • Store the data in any convenient AWS Region and enable cross-Region replication to an EU Region, assuming AWS will act as the data controller under GDPR.

  • Host the workloads in AWS GovCloud (US), encrypt data with customer-managed keys located in the United States, and rely on the EU-US Privacy Shield framework for lawful transfer.

  • Keep all S3 buckets and RDS instances in eu-central-1 or eu-west-1, encrypt the data with customer-managed AWS KMS keys that never leave those Regions, and rely on the GDPR Data Processing Addendum already incorporated into the AWS Service Terms.

ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot