ISO/IEC 27018:2019 Protection of Personal Data in the Cloud Exam (Get info) Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A cloud service provider (CSP) operating under ISO/IEC 27018:2019 is contracted by a multinational corporation to host sensitive customer information. The CSP\'s internal marketing department proposes leveraging anonymized or pseudonymized versions of this data to identify emerging market trends for their own business development. Which of the following best aligns with the CSP\'s obligations under ISO/IEC 27018:2019 concerning the processing of personal data?

The CSP must ensure that personal data is processed solely on behalf of the data controller and in accordance with their documented instructions, prohibiting any independent use of the data for the CSP's own business development activities.
The CSP may process anonymized or pseudonymized versions of the data for their own marketing purposes, provided they have a clear internal policy stating such usage.
The CSP is permitted to use aggregated data derived from customer information for their own market analysis, as long as it does not directly identify individuals.
The CSP can use the personal data for their own business development if they obtain consent from a representative sample of the data subjects whose information is being processed.

About the ISO/IEC 27018:2019 Protection of Personal Data in the Cloud Exam (Get info) Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27018:2019 Protection of Personal Data in the Cloud Exam (Get info) exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.