Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Certified Cloud Security Professional

Domain 6Objective 2

Understand Privacy Issues CCSP Practice Questions (Page 4)

Part of the Legal, Risk and Compliance domain, which accounts for 13% of the CCSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~9–16 in this domain), expect 2–3 from this objective — we provide 24 practice questions to prepare you well beyond it. (estimate)

24questions here
5free pages
5concepts
13%of the exam

Questions 16–20

  1. 16application · medium

    A company is implementing a new customer data analytics platform. The company wants to ensure that its privacy practices align with recognized frameworks. Which of the following actions would best demonstrate alignment with the Generally Accepted Privacy Principles (GAPP)?

    Select an answer first
  2. 17expert · hard

    A company is planning to launch a new mobile app that collects location data from users in the EU and the US. The company's legal team is concerned about GDPR compliance. The company wants to conduct a Privacy Impact Assessment (PIA) but is unsure when it is required. Which of the following is a condition that makes a PIA mandatory under GDPR?

    Select an answer first
  3. 18application · medium

    A cloud service provider (CSP) signs a contract with a financial institution to process customer transaction data. The contract includes clauses on confidentiality and data handling, but the data is not subject to a specific privacy regulation. The financial institution later discovers that the CSP subcontracted data processing to a third party without notifying them, violating the contract. What is the primary source of enforcement for this breach?

    Select an answer first
  4. 19application · medium

    A cloud service provider wants to align its privacy practices with ISO/IEC 27018. Which of the following controls is most likely to be required under ISO/IEC 27018?

    Select an answer first
  5. 20application · medium

    A government agency is planning to deploy a new online portal that will collect citizens' personal information for public services. Before launch, the agency wants to identify and mitigate privacy risks associated with the new system. What is the most appropriate action for the agency to take?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CCSP” is a trademark of its owner, used for identification only.