712-50 exam dumps

712-50 practice question 20 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 20

Single answer

A multinational healthcare company headquartered in Germany plans to move a patient analytics platform to a public cloud provider. The platform will process EU patient data, but the provider's standard architecture replicates backups to data centers in multiple regions for resilience, and the provider may use non-EU support personnel for administrative troubleshooting. The board asks the CISO to recommend the MOST appropriate action before approving the migration. What should the CISO do FIRST to address legal and jurisdictional risk while establishing the organization's responsibilities in policy and procedure?

  1. A

    Require the cloud provider to sign a standard SLA and rely on the provider's shared responsibility model documentation as sufficient evidence of compliance ownership

  2. B

    Perform a data residency and cross-border transfer assessment, define policy requirements for approved processing locations and remote administrative access, and ensure contractual controls such as data processing terms and subprocessor restrictions are in place

  3. C

    Encrypt all patient data before sending it to the cloud and treat encryption as eliminating jurisdictional and regulatory exposure regardless of where backups or support access occur

  4. D

    Proceed with the migration if the provider has broad international certifications, since these certifications supersede local privacy and healthcare regulatory obligations

Show answer and explanation

Correct answer: B

Explanation

The best answer is Option 2 because the organization retains accountability for understanding legal and jurisdictional implications in cloud deployments and for translating those obligations into policies, procedures, and contracts. In a cloud model, risks are not limited to where primary data is stored; they also include backup replication, support access, subprocessor involvement, lawful access by foreign governments, and cross-border transfer mechanisms. For EU personal data, GDPR requires clarity around controller-processor responsibilities, international transfers, and appropriate safeguards. In healthcare environments, additional sector-specific obligations may apply depending on the jurisdiction. Best practice is to conduct a formal data classification and transfer impact assessment, define approved hosting and access jurisdictions in policy, require contractual commitments on data processing and subprocessors, and validate operational enforcement with the provider. Relevant guidance includes GDPR controller/processor provisions and international transfer requirements, ISO/IEC 27017 and 27018 cloud security/privacy guidance, and the Cloud Security Alliance Cloud Controls Matrix, all of which reinforce that cloud adoption does not remove the customer's governance and compliance responsibilities.

  • A. Incorrect.

    Incorrect. A standard SLA and generic shared responsibility documentation do not adequately address jurisdiction-specific legal obligations. The shared responsibility model clarifies operational roles, but the customer organization remains accountable for determining whether processing locations, support access, subprocessors, and transfer mechanisms meet applicable laws and internal policy requirements. This option reflects a common misconception that cloud contracts and provider guidance alone transfer compliance accountability.

  • B. Correct.

    Correct. The first priority is to assess where data will be stored, replicated, accessed, and supported, then translate those legal and regulatory requirements into enforceable internal policies and contractual controls. For a Germany-based healthcare organization handling EU patient data, the CISO should ensure that approved regions, cross-border transfer conditions, remote administrative access, logging, subprocessor use, and incident notification requirements are explicitly defined in policy and supported by contract terms. This addresses both jurisdictional implications and the organization's duty to establish governance before migration.

  • C. Incorrect.

    Incorrect. Encryption is an important safeguard, but it does not by itself eliminate legal or jurisdictional obligations. Data location, lawful transfer mechanisms, access by foreign personnel, metadata handling, key management, and legal compulsion issues may still create regulatory exposure. Candidates may choose this because encryption is often treated as a universal control, but in this scenario it is necessary rather than sufficient.

  • D. Incorrect.

    Incorrect. Certifications can provide assurance about control maturity, but they do not override applicable law or guarantee compliance with specific healthcare, privacy, or data localization requirements. A provider may be certified and still operate in ways that create unacceptable cross-border transfer or access risks for the customer. This option reflects the mistaken belief that third-party attestations replace the organization's own legal and risk assessment.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam