CCSP Legal, Risk and Compliance: 195 practice questions
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

CCSP Legal, Risk and Compliance: 195 practice questions

CCSP 195 questions 12 shown free

12 of the 195 Legal, Risk and Compliance questions in the Certsqill CCSP bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for CCSP? Take the free 5-min readiness check →

1. Escalate to privacy and legal owners for documented: Which action addresses the demonstrated failure?

Easy
A public agency’s contract prohibits personal records from being accessed by personnel in jurisdiction X without written agency approval. The cloud provider reports that its support team in jurisdiction X accessed those records during troubleshooting, and no approval exists. Which action addresses the demonstrated failure?
  1. Move the records to another region and close the access incident.
    Relocation does not resolve the existing unauthorized access or the provider’s remote-access arrangements.
  2. Enable encryption at rest and treat the access as controlled.
    Encryption may reduce exposure but does not authorize personnel access prohibited by the contract.
  3. Escalate to privacy and legal owners for documented remediation. ✓
    The accountable owners can assess the contractual breach, restrict further access, preserve evidence, and direct remediation.
  4. Accept the access because troubleshooting served the contracted service.
    A service purpose does not replace the contract’s explicit written-approval requirement.
The trap
Storage location alone does not cure a contractual access violation. Operational necessity is not established authorization. A safeguard does not replace required approval.

Escalate the unauthorized jurisdictional access to accountable privacy and legal owners.

2. Specify measurable availability and incident metrics: Which SLA language best verifies the requirement?

Hard
A telecommunications operator is negotiating a cloud contract for customer-service workloads. Management requires measurable availability and incident reporting, while privacy counsel requires evidence covering only the contracted service and agreed processing scope. Which SLA language best verifies the requirement?
  1. Require monthly questionnaires about availability and incidents for the contracted service and agreed processing activities.
    Questionnaires are generally self-reported and do not establish objective thresholds, measurement methods, or enforceable performance terms.
  2. Promise dependable service and prompt incident handling throughout the customer-service deployment.
    These subjective promises lack measurable thresholds, measurement rules, reporting duties, and a precise contractual scope.
  3. Specify measurable availability and incident metrics, measurement windows, reporting duties, service boundaries, and the agreed processing scope. ✓
    These terms create objectively reviewable obligations while limiting evidence to the contracted service and agreed processing activities.
  4. Require an annual provider certification covering the service and reported operational performance.
    Certification may provide assurance, but it does not itself define availability or incident metrics, measurement rules, or reporting obligations.
The trap
Vague commitments cannot be objectively verified. Treats certification alone as a measurable service level. Confuses information requests with testable service levels.

Specify objective metrics, measurement rules, reporting, and bounded service and processing scope.

3. Have the accountable risk owner document residual: Which TWO actions best fit the stated requirement?

Easy
A regional hospital group’s risk appetite permits residual annual loss exposure of $100,000 for this service. A failed control test estimates current ALE at $180,000. Provider A costs $40,000 annually and reduces ALE to $70,000; Provider B costs $20,000 and reduces ALE to $130,000. Which TWO actions best fit the stated requirement? Select TWO.

Select two. More than one option is correct — every correct one is ticked below.

  1. Select Provider B because its lower cost outweighs the $130,000 residual ALE.
    Provider B leaves modeled exposure above the hospital’s stated risk appetite, despite its lower price.
  2. Treat either provider’s modeled ALE as guaranteed elimination of residual risk.
    ALE estimates expected exposure and does not guarantee that controls eliminate legal, safety, or operational risk.
  3. Have the accountable risk owner document residual uncertainty and acceptance rationale. ✓
    The accountable owner must record the decision and acknowledge uncertainty in the modeled residual exposure.
  4. Select Provider A because its modeled residual ALE is $70,000, below appetite. ✓
    Provider A leaves modeled ALE below the stated $100,000 risk appetite.
  5. Let the control tester approve residual risk after documenting the failed test.
    The tester supplies control evidence but is not automatically the accountable risk-acceptance owner.
The trap
Cost does not override the residual-risk requirement. Testing responsibility does not equal risk-acceptance authority. Risk calculations are estimates, not guarantees.

Choose Provider A and require the accountable owner to document residual uncertainty and acceptance.

4. The customer is controller for scheduling: Which role analysis is correct?

Hard
A software provider hosts a customer’s patient scheduling application. The customer determines processing purposes and means, while the provider may process records only under documented customer instructions. The provider proposes using those records to develop an unrelated commercial analytics product. Which role analysis is correct?
  1. The provider may reuse the records because it operates the hosted service.
    Operating the service does not authorize processing for an unrelated purpose outside the customer’s documented instructions.
  2. The parties are joint controllers for scheduling because both influence the service.
    Joint-controller status requires shared determination of the relevant purposes and means, not merely participation in a service relationship.
  3. The customer is controller for scheduling, while the provider is processor under instructions. ✓
    The customer determines the scheduling purposes and means; the provider processes the records for that service under the customer’s instructions.
  4. The provider becomes controller for the scheduling records because it chooses to develop an unrelated analytics product.
    The proposed independent use may require separate authorization and role analysis, but it does not change the provider’s role for the customer’s scheduling activity merely by proposal.
The trap
Technical custody does not authorize independent reuse. Service participation alone does not establish joint control. A proposed secondary purpose does not retroactively redefine the original activity.

The customer determines scheduling purposes and means; the provider acts as processor under instructions.

5. The laboratory’s accountable service owner: Who should decide whether the evidence satisfies the laboratory’s

Medium
A biotechnology laboratory uses a cloud platform to process research data and needs assurance over security, availability, confidentiality, and privacy controls. Procurement presents a SOC 1 Type 2 report covering financial-reporting controls. Who should decide whether the evidence satisfies the laboratory’s requirement?
  1. Any engineer who reviewed the report.
    Technical review contributes evidence, but accountability requires an assigned owner with decision authority.
  2. The cloud provider’s sales representative.
    Sales personnel can describe services, but cannot independently determine whether customer assurance requirements are satisfied.
  3. The laboratory’s accountable service owner. ✓
    That owner evaluates business requirements, report scope, criteria, exceptions, and complementary customer controls.
  4. The SOC report’s issuing auditor.
    The auditor reports against defined criteria and scope, rather than accepting the laboratory’s separate requirement.
The trap
Reviewing evidence is not accountable acceptance. Provider sales cannot decide customer risk acceptance. Auditors do not own customer requirement decisions.

The laboratory’s accountable service owner determines whether report scope and criteria meet its requirements.

6. Determine applicable jurisdiction: Select TWO responsibilities the consortium should address before directing

Easy
A university research consortium receives a foreign authority’s request for participant records held by its cloud provider. The consortium’s counsel has not yet determined applicable jurisdiction, controller or processor roles, or lawful disclosure authority. Select TWO responsibilities the consortium should address before directing disclosure.

Select two. More than one option is correct — every correct one is ticked below.

  1. Assume encryption eliminates transfer concerns because the provider cannot read encrypted records.
    Encryption is a safeguard, not automatic authorization or an exemption from applicable transfer and privacy duties.
  2. Treat storage location as the sole test for whether cross-border disclosure is permissible.
    Storage location does not alone resolve remote access, transfer, jurisdiction, or applicable privacy obligations.
  3. Determine applicable jurisdiction, processing roles, purpose, and lawful basis with privacy and legal owners. ✓
    These facts determine which obligations apply and whether the requested disclosure has an appropriate legal basis.
  4. Coordinate any response with counsel and define the provider’s authorized disclosure responsibilities. ✓
    The consortium must establish authority and instruct or constrain the processor’s response within contractual and legal boundaries.
  5. Require the provider to disclose records immediately because the request came from a government authority.
    Government origin alone does not establish authority, jurisdiction, or permission to disclose consortium-controlled information.
The trap
Encryption does not automatically authorize international transfers. Location alone cannot resolve cross-border disclosure obligations. Government requests still require legal authority and role analysis.

The consortium must establish applicable privacy roles and lawful authority before directing or permitting cross-border disclosure.

7. Preserve relevant evidence under authorized direction: What should the company do?

Medium
An energy company’s MSA requires provider incident cooperation and evidence preservation. A later SOW requires deletion seven days after project completion, but the company’s approved incident procedure requires preserving relevant records during an investigation. What should the company do?
  1. Preserve relevant evidence under authorized direction and reconcile the conflict through contract governance. ✓
    The company should preserve investigation-relevant records within an authorized scope, document the conflict, and obtain clarification or amendment from authorized parties.
  2. Apply the SOW deletion deadline unless the provider agrees to extend it.
    Provider agreement alone does not resolve the customer’s conflicting preservation and contractual obligations.
  3. Let the provider determine which document controls because it operates the retention process.
    The provider may implement authorized instructions but does not unilaterally interpret conflicting customer requirements.
  4. Treat the MSA as authority for indefinite retention of all project records.
    An evidence-preservation requirement does not automatically authorize indefinite retention of every record.
The trap
Operational agreement cannot replace authorized governance. Preservation should be relevant, scoped, and time-bounded where possible. Service execution does not confer contract-governance authority.

Preserve relevant evidence, then reconcile the conflicting requirements through authorized governance.

8. Require designated-owner approval of documented residual: What is the correct decision?

Hard
A cloud migration team proposes an exception to a required control, arguing that cyber insurance transfers the risk. Policy permits exceptions only when the designated risk owner documents residual risk and approves a time limit. What is the correct decision?
  1. Let the migration operator accept the exception after calculating expected annual loss.
    Calculation informs decisions, but policy assigns acceptance to the designated accountable risk owner.
  2. Approve the exception because insurance transfers accountability.
    Risk transfer does not remove the organization’s accountability for its cloud security decision.
  3. Reject every exception because controls cannot be waived under policy.
    The stated policy permits exceptions when its approval, documentation, and time-limit requirements are satisfied.
  4. Require designated-owner approval of documented residual risk and an expiration date. ✓
    Insurance may transfer some financial impact, but policy still requires accountable acceptance of residual risk.
The trap
The policy explicitly allows controlled exceptions. Operators cannot substitute for designated risk owners. Insurance does not transfer organizational accountability.

Risk transfer may reduce financial exposure, but the designated owner must approve documented, time-limited residual risk.

9. Map applicable jurisdictions: Which conclusion best identifies the principal unresolved limitation before the

Hard
An online retailer records this policy and data inventory: “Customer addresses are contract-protected; checkout analytics are stored in Region X; no statute has yet been mapped.” The provider contract restricts disclosure and requires deletion at termination. Which conclusion best identifies the principal unresolved limitation before the retailer claims compliance?
  1. Contractual disclosure restrictions establish that privacy law is inapplicable to the analytics.
    Contractual protections may supplement legal requirements but do not establish that privacy law is inapplicable.
  2. Map applicable jurisdictions, organizational roles, processing purposes, data categories, access pathways, and resulting obligations before asserting compliance. ✓
    The inventory identifies contractual controls and storage location but leaves legal applicability, processing responsibilities, purposes, and obligations unresolved.
  3. Region X determines every jurisdiction governing storage, access, and processing.
    Storage location alone does not determine every applicable jurisdiction, access pathway, processing activity, or legal obligation.
  4. The termination-deletion clause removes any need to assess preservation constraints, access obligations, or competing legal duties.
    Deletion may need to be limited or postponed when an authorized preservation requirement or competing duty applies; the clause does not eliminate that assessment.
The trap
Treats a region label as a complete jurisdiction analysis. Assumes contract terms displace applicable law. Assumes scheduled deletion automatically overrides preservation and other duties.

Map jurisdictions, roles, purposes, data, access, and obligations before claiming compliance.

10. Control design as of a stated date: What does the report establish?

Medium
An insurance business receives a Type 1 assurance report for a cloud service, but management needs evidence that controls operated throughout the previous twelve months. What does the report establish?
  1. The provider’s entire cloud deployment, including excluded subservices.
    The conclusion is limited to the stated service scope, criteria, exceptions, subservices, and responsibilities.
  2. Control design as of a stated date, not operating effectiveness throughout the prior twelve months. ✓
    A Type 1 report evaluates whether controls are suitably designed at a specified point in time; period-based operating evidence requires an appropriate Type 2 report.
  3. Effective operation of every in-scope control during the complete preceding twelve-month reporting period.
    That conclusion requires period-based operating-effectiveness evidence, not a Type 1 report.
  4. Control design at a specified date.
    A Type 1 report does not establish operating effectiveness over a period.
The trap
Confuses design evidence with operating evidence. Treats a scoped report as coverage of everything the provider operates. Assumes a point-in-time report proves year-long operation.

Type 1 establishes control design at a stated date, not operation over twelve months.

11. Suspend deletion for the identified messages and preserve: What should the cloud team do next?

Hard
Counsel issued a legal hold, identified custodians and repositories, notified affected personnel, and defined the hold to cover transaction messages relevant to a dispute. What should the cloud team do next?
  1. Document the hold without changing scheduled deletion.
    Documentation alone does not preserve messages subject to the hold.
  2. Suspend deletion for the identified messages and preserve them under the documented hold. ✓
    After the hold’s scope and affected repositories are established, the team must prevent ordinary deletion of the relevant messages and preserve them.
  3. Ask the provider to decide which records are legally relevant before taking action.
    The customer’s defined hold scope should guide preservation; provider involvement does not justify delaying action.
  4. Preserve every company record indefinitely.
    The established hold covers relevant transaction messages, not every record indefinitely.
The trap
Treats recording the hold as equivalent to executing it. Expands a scoped hold into unsupported universal retention. Shifts the customer’s legal-preservation decision to the infrastructure provider.

Suspend deletion for the identified messages and preserve them under the hold.

12. The manufacturer lacks verified assurance: What control gap should be addressed?

Medium
An industrial manufacturer’s contract permits one annual remote evidence review. The provider refuses onsite testing, and the manufacturer’s assessment team relies only on an unsigned questionnaire. What control gap should be addressed?
  1. The provider must permit unlimited penetration testing regardless of contract restrictions.
    Testing requires authorized scope and rules of engagement; contractual restrictions cannot be ignored unilaterally.
  2. The unsigned questionnaire is sufficient because supplier responses establish operating effectiveness.
    Questionnaires are self-reported and unsigned evidence cannot reliably establish service-specific control operation.
  3. The manufacturer lacks verified assurance that the contracted service controls operate within the agreed scope. ✓
    A self-reported questionnaire does not provide independent, service-specific evidence, while the contract limits direct testing.
  4. The manufacturer should accept the gap because remote reviews provide no useful assurance.
    Remote evidence can provide useful assurance when independently evaluated and matched to service scope and responsibilities.
The trap
Self-reporting does not independently verify control operation. Security testing requires agreed authority and defined limits. Remote assurance can be valid when properly evidenced.

The gap is insufficient independent, scoped assurance, requiring agreed alternative evidence or contractually authorized verification.

183 more Legal, Risk and Compliance questions

The remaining 183 questions in this domain are part of the full CCSP bank — 1500 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your CCSP readiness — free

Other CCSP domains

Part of the Certsqill CCSP question bank · Legal, Risk and Compliance · Every answer, right and wrong, comes with its own explanation.