CCSP Legal, Risk and Compliance: 195 practice questions
12 of the 195 Legal, Risk and Compliance questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CCSP? Take the free 5-min readiness check →
1. Escalate to privacy and legal owners for documented: Which action addresses the demonstrated failure?
- Move the records to another region and close the access incident.Relocation does not resolve the existing unauthorized access or the provider’s remote-access arrangements.
- Enable encryption at rest and treat the access as controlled.Encryption may reduce exposure but does not authorize personnel access prohibited by the contract.
- Escalate to privacy and legal owners for documented remediation. ✓The accountable owners can assess the contractual breach, restrict further access, preserve evidence, and direct remediation.
- Accept the access because troubleshooting served the contracted service.A service purpose does not replace the contract’s explicit written-approval requirement.
Escalate the unauthorized jurisdictional access to accountable privacy and legal owners.
2. Specify measurable availability and incident metrics: Which SLA language best verifies the requirement?
- Require monthly questionnaires about availability and incidents for the contracted service and agreed processing activities.Questionnaires are generally self-reported and do not establish objective thresholds, measurement methods, or enforceable performance terms.
- Promise dependable service and prompt incident handling throughout the customer-service deployment.These subjective promises lack measurable thresholds, measurement rules, reporting duties, and a precise contractual scope.
- Specify measurable availability and incident metrics, measurement windows, reporting duties, service boundaries, and the agreed processing scope. ✓These terms create objectively reviewable obligations while limiting evidence to the contracted service and agreed processing activities.
- Require an annual provider certification covering the service and reported operational performance.Certification may provide assurance, but it does not itself define availability or incident metrics, measurement rules, or reporting obligations.
Specify objective metrics, measurement rules, reporting, and bounded service and processing scope.
3. Have the accountable risk owner document residual: Which TWO actions best fit the stated requirement?
Select two. More than one option is correct — every correct one is ticked below.
- Select Provider B because its lower cost outweighs the $130,000 residual ALE.Provider B leaves modeled exposure above the hospital’s stated risk appetite, despite its lower price.
- Treat either provider’s modeled ALE as guaranteed elimination of residual risk.ALE estimates expected exposure and does not guarantee that controls eliminate legal, safety, or operational risk.
- Have the accountable risk owner document residual uncertainty and acceptance rationale. ✓The accountable owner must record the decision and acknowledge uncertainty in the modeled residual exposure.
- Select Provider A because its modeled residual ALE is $70,000, below appetite. ✓Provider A leaves modeled ALE below the stated $100,000 risk appetite.
- Let the control tester approve residual risk after documenting the failed test.The tester supplies control evidence but is not automatically the accountable risk-acceptance owner.
Choose Provider A and require the accountable owner to document residual uncertainty and acceptance.
4. The customer is controller for scheduling: Which role analysis is correct?
- The provider may reuse the records because it operates the hosted service.Operating the service does not authorize processing for an unrelated purpose outside the customer’s documented instructions.
- The parties are joint controllers for scheduling because both influence the service.Joint-controller status requires shared determination of the relevant purposes and means, not merely participation in a service relationship.
- The customer is controller for scheduling, while the provider is processor under instructions. ✓The customer determines the scheduling purposes and means; the provider processes the records for that service under the customer’s instructions.
- The provider becomes controller for the scheduling records because it chooses to develop an unrelated analytics product.The proposed independent use may require separate authorization and role analysis, but it does not change the provider’s role for the customer’s scheduling activity merely by proposal.
The customer determines scheduling purposes and means; the provider acts as processor under instructions.
5. The laboratory’s accountable service owner: Who should decide whether the evidence satisfies the laboratory’s
- Any engineer who reviewed the report.Technical review contributes evidence, but accountability requires an assigned owner with decision authority.
- The cloud provider’s sales representative.Sales personnel can describe services, but cannot independently determine whether customer assurance requirements are satisfied.
- The laboratory’s accountable service owner. ✓That owner evaluates business requirements, report scope, criteria, exceptions, and complementary customer controls.
- The SOC report’s issuing auditor.The auditor reports against defined criteria and scope, rather than accepting the laboratory’s separate requirement.
The laboratory’s accountable service owner determines whether report scope and criteria meet its requirements.
6. Determine applicable jurisdiction: Select TWO responsibilities the consortium should address before directing
Select two. More than one option is correct — every correct one is ticked below.
- Assume encryption eliminates transfer concerns because the provider cannot read encrypted records.Encryption is a safeguard, not automatic authorization or an exemption from applicable transfer and privacy duties.
- Treat storage location as the sole test for whether cross-border disclosure is permissible.Storage location does not alone resolve remote access, transfer, jurisdiction, or applicable privacy obligations.
- Determine applicable jurisdiction, processing roles, purpose, and lawful basis with privacy and legal owners. ✓These facts determine which obligations apply and whether the requested disclosure has an appropriate legal basis.
- Coordinate any response with counsel and define the provider’s authorized disclosure responsibilities. ✓The consortium must establish authority and instruct or constrain the processor’s response within contractual and legal boundaries.
- Require the provider to disclose records immediately because the request came from a government authority.Government origin alone does not establish authority, jurisdiction, or permission to disclose consortium-controlled information.
The consortium must establish applicable privacy roles and lawful authority before directing or permitting cross-border disclosure.
7. Preserve relevant evidence under authorized direction: What should the company do?
- Preserve relevant evidence under authorized direction and reconcile the conflict through contract governance. ✓The company should preserve investigation-relevant records within an authorized scope, document the conflict, and obtain clarification or amendment from authorized parties.
- Apply the SOW deletion deadline unless the provider agrees to extend it.Provider agreement alone does not resolve the customer’s conflicting preservation and contractual obligations.
- Let the provider determine which document controls because it operates the retention process.The provider may implement authorized instructions but does not unilaterally interpret conflicting customer requirements.
- Treat the MSA as authority for indefinite retention of all project records.An evidence-preservation requirement does not automatically authorize indefinite retention of every record.
Preserve relevant evidence, then reconcile the conflicting requirements through authorized governance.
8. Require designated-owner approval of documented residual: What is the correct decision?
- Let the migration operator accept the exception after calculating expected annual loss.Calculation informs decisions, but policy assigns acceptance to the designated accountable risk owner.
- Approve the exception because insurance transfers accountability.Risk transfer does not remove the organization’s accountability for its cloud security decision.
- Reject every exception because controls cannot be waived under policy.The stated policy permits exceptions when its approval, documentation, and time-limit requirements are satisfied.
- Require designated-owner approval of documented residual risk and an expiration date. ✓Insurance may transfer some financial impact, but policy still requires accountable acceptance of residual risk.
Risk transfer may reduce financial exposure, but the designated owner must approve documented, time-limited residual risk.
9. Map applicable jurisdictions: Which conclusion best identifies the principal unresolved limitation before the
- Contractual disclosure restrictions establish that privacy law is inapplicable to the analytics.Contractual protections may supplement legal requirements but do not establish that privacy law is inapplicable.
- Map applicable jurisdictions, organizational roles, processing purposes, data categories, access pathways, and resulting obligations before asserting compliance. ✓The inventory identifies contractual controls and storage location but leaves legal applicability, processing responsibilities, purposes, and obligations unresolved.
- Region X determines every jurisdiction governing storage, access, and processing.Storage location alone does not determine every applicable jurisdiction, access pathway, processing activity, or legal obligation.
- The termination-deletion clause removes any need to assess preservation constraints, access obligations, or competing legal duties.Deletion may need to be limited or postponed when an authorized preservation requirement or competing duty applies; the clause does not eliminate that assessment.
Map jurisdictions, roles, purposes, data, access, and obligations before claiming compliance.
10. Control design as of a stated date: What does the report establish?
- The provider’s entire cloud deployment, including excluded subservices.The conclusion is limited to the stated service scope, criteria, exceptions, subservices, and responsibilities.
- Control design as of a stated date, not operating effectiveness throughout the prior twelve months. ✓A Type 1 report evaluates whether controls are suitably designed at a specified point in time; period-based operating evidence requires an appropriate Type 2 report.
- Effective operation of every in-scope control during the complete preceding twelve-month reporting period.That conclusion requires period-based operating-effectiveness evidence, not a Type 1 report.
- Control design at a specified date.A Type 1 report does not establish operating effectiveness over a period.
Type 1 establishes control design at a stated date, not operation over twelve months.
11. Suspend deletion for the identified messages and preserve: What should the cloud team do next?
- Document the hold without changing scheduled deletion.Documentation alone does not preserve messages subject to the hold.
- Suspend deletion for the identified messages and preserve them under the documented hold. ✓After the hold’s scope and affected repositories are established, the team must prevent ordinary deletion of the relevant messages and preserve them.
- Ask the provider to decide which records are legally relevant before taking action.The customer’s defined hold scope should guide preservation; provider involvement does not justify delaying action.
- Preserve every company record indefinitely.The established hold covers relevant transaction messages, not every record indefinitely.
Suspend deletion for the identified messages and preserve them under the hold.
12. The manufacturer lacks verified assurance: What control gap should be addressed?
- The provider must permit unlimited penetration testing regardless of contract restrictions.Testing requires authorized scope and rules of engagement; contractual restrictions cannot be ignored unilaterally.
- The unsigned questionnaire is sufficient because supplier responses establish operating effectiveness.Questionnaires are self-reported and unsigned evidence cannot reliably establish service-specific control operation.
- The manufacturer lacks verified assurance that the contracted service controls operate within the agreed scope. ✓A self-reported questionnaire does not provide independent, service-specific evidence, while the contract limits direct testing.
- The manufacturer should accept the gap because remote reviews provide no useful assurance.Remote evidence can provide useful assurance when independently evaluated and matched to service scope and responsibilities.
The gap is insufficient independent, scoped assurance, requiring agreed alternative evidence or contractually authorized verification.
183 more Legal, Risk and Compliance questions
The remaining 183 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CCSP readiness — freeOther CCSP domains
- Cloud Data Security — 300 questions →
- Cloud Concepts, Architecture and Design — 255 questions →
- Cloud Platform and Infrastructure Security — 255 questions →
- Cloud Security Operations — 255 questions →
- Cloud Application Security — 240 questions →
- All 1500 CCSP questions →
- CCSP certification: requirements, cost and exam format →