← All CCSP Flashcard Decks

Legal, Risk, and Compliance Flashcards

6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Legal, Risk, and Compliance flashcards as text
  1. Which concept in cloud contracts ensures the customer retains ownership of their data and can retrieve it upon contract termination?

    Answer: Data portability and right to return clause

    A data portability and right to return clause contractually guarantees that the customer can export their data in a usable format and that the provider will delete it after contract termination.

  2. What is the primary purpose of conducting a Privacy Impact Assessment (PIA) before deploying a new cloud service?

    Answer: To identify and mitigate privacy risks before the service is deployed, ensuring compliance with applicable privacy regulations

    A PIA (or DPIA under GDPR) systematically identifies privacy risks in a new system or process and documents mitigation measures before deployment.

  3. Under the CCSP CBK, what is the difference between legal holds and data retention policies?

    Answer: A legal hold suspends normal deletion schedules for specific data due to litigation, while retention policies define routine minimum and maximum storage durations

    Retention policies set standard schedules for keeping or deleting data, while a legal hold overrides those policies for specific data sets that may be needed for litigation or investigation.

  4. What is the significance of the EU-US Data Privacy Framework (successor to Privacy Shield) for cloud computing?

    Answer: It provides a legal mechanism for transferring personal data from the EU to certified US organizations in compliance with GDPR

    The EU-US Data Privacy Framework allows US organizations that self-certify to receive EU personal data transfers lawfully under GDPR's requirements for third-country transfers.

  5. Which standard establishes requirements for information security management systems (ISMS) and is commonly pursued by cloud providers to demonstrate security governance maturity?

    Answer: ISO/IEC 27001

    ISO/IEC 27001 is the international standard for ISMS that defines requirements for establishing, implementing, maintaining, and continuously improving an organization's information security program.

  6. In cloud risk assessment, what is the formula for calculating Annual Loss Expectancy (ALE)?

    Answer: ALE = Single Loss Expectancy (SLE) × Annual Rate of Occurrence (ARO)

    ALE is calculated by multiplying the Single Loss Expectancy (the dollar loss from one incident) by the Annual Rate of Occurrence (how often the incident is expected per year).