nerdexam
CIW

1D0-610 · Question #44

SuperBank is considering a cloud service from Local Data Center, Inc., to support the bank's expanding needs. SuperBank's managers are concerned about security. What can SuperBank request to protect…

The correct answer is D. For SuperBank to perform background checks on the staff at Local Data Center, Inc. Option D is correct because background checks on third-party staff directly address a key human security threat: insider access. When SuperBank's sensitive financial data is stored at an external facility, the employees at that facility have physical and/or logical access to…

CIW Network Technology Associate

Question

SuperBank is considering a cloud service from Local Data Center, Inc., to support the bank's expanding needs. SuperBank's managers are concerned about security. What can SuperBank request to protect its data from security threats?

Options

  • AFor Local Data Center to run multiple hypervisors
  • BFor Local Data Center to install a DDoS mitigation system
  • CFor SuperBank staff to manage the servers at Local Data Center, Inc.
  • DFor SuperBank to perform background checks on the staff at Local Data Center, Inc.

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    11% (3)
  • C
    4% (1)
  • D
    82% (23)

Explanation

Option D is correct because background checks on third-party staff directly address a key human security threat: insider access. When SuperBank's sensitive financial data is stored at an external facility, the employees at that facility have physical and/or logical access to that infrastructure - vetting them reduces the risk of malicious insiders or social engineering.

Why the distractors are wrong:

  • A (multiple hypervisors): Running extra hypervisors adds complexity and cost but doesn't meaningfully reduce security threats - it's not a recognized security control for data protection.
  • B (DDoS mitigation): A DDoS system defends against availability attacks from external sources; it does nothing to protect data confidentiality or integrity, which is the core concern here.
  • C (SuperBank staff managing servers): While this sounds appealing, it's logistically impractical and contractually unusual in a cloud/co-location arrangement, and it doesn't scale as a standard security request.

Memory tip: Think of the scenario as "trust but verify the humans." In third-party arrangements, your biggest uncontrolled variable is people, not technology - background checks are the standard contractual lever banks use to extend their HR security policies to vendors. When the question is about data at a third-party facility, look for the answer that controls human risk.

Topics

#Cloud Security#Personnel Security#Access Control#Data Protection

Community Discussion

No community discussion yet for this question.

Full 1D0-610 Practice