TechNuggets Academy

Legal, Risk and Compliance

Free ISC2 Certified Cloud Security Professional (CCSP) practice — 6 questions on Legal, Risk and Compliance, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Legal, Risk and Compliance
A US-based SaaS company transfers customer PII from its EU subsidiary to servers hosted by a US cloud provider that is NOT certified under the EU-US Data Privacy Framework (DPF). Under GDPR Chapter V, which transfer mechanism should the company implement to legally justify this transfer?
Since the receiving entity is not DPF-certified, the adequacy decision does not apply. Post-Schrems II, GDPR requires SCCs paired with a Transfer Impact Assessment and supplementary technical/organizational measures (e.g., encryption with EU-held keys) to address risks of foreign government surveillance.
Question 2 of 6 · Legal, Risk and Compliance
A company involved in civil litigation must preserve and produce virtual machine logs from its IaaS provider under a litigation hold. The legal team initially wants to perform traditional forensic imaging of the underlying physical disks. Given the cloud shared responsibility model, what is the correct approach?
In IaaS, the CSP controls the physical infrastructure layer per the shared responsibility model. Proper cloud forensics relies on virtualized artifacts obtainable through the provider (volume snapshots, control-plane API logs) requested via established legal/contractual channels.
Question 3 of 6 · Legal, Risk and Compliance
A prospective cloud customer wants third-party assurance evidence that maps directly to the Cloud Security Alliance Cloud Controls Matrix (CCM) domains, rather than a generic security attestation. Which report or certification should the CSP provide?
CSA STAR Level 2 combines an independent third-party audit explicitly mapped to the CCM control domains, giving the customer direct visibility into cloud-specific controls that other frameworks do not natively provide.
Question 4 of 6 · Legal, Risk and Compliance
A company runs a mission-critical workload on a public cloud IaaS provider whose SLA guarantees 99.95% availability. The company's business continuity requirements mandate 99.99% availability, and renegotiating the SLA immediately is not feasible. Which action represents the BEST risk treatment strategy?
Architecting redundancy across regions and availability zones with automated failover is a direct mitigation control that reduces the likelihood and impact of downtime beyond what the CSP's SLA alone guarantees, closing the gap to the required 99.99%.
Question 5 of 6 · Legal, Risk and Compliance
A healthcare cloud tenant processes both protected health information (PHI) and cardholder payment data within the same SaaS application. Which statement correctly distinguishes the source and enforceability of the two compliance obligations?
HIPAA is a US federal law enforced by HHS/OCR with regulatory penalties, whereas PCI DSS is a contractual requirement imposed by the payment card brands through merchant/processor agreements, enforced via contractual fines and potential loss of card-processing privileges rather than government statute.
Question 6 of 6 · Legal, Risk and Compliance
A cloud-hosted machine learning system is used by an enterprise to automatically screen and rank job applicants' resumes, with hiring managers reviewing only the top-ranked candidates the system selects. Under the EU AI Act, how should this system likely be classified, and what is the primary compliance obligation?
The EU AI Act's Annex III explicitly lists AI systems used in recruitment and candidate screening as high-risk, requiring providers and deployers to conduct conformity assessments, maintain a risk management system, ensure technical documentation, and implement meaningful human oversight.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →