1D0-61C · Question #34
SuperBank is considering a cloud service from Local Data Center, Inc., to support the bank's expanding needs. SuperBank's managers are concerned about security. What can SuperBank request to protect…
The correct answer is D. For SuperBank to perform background checks on the staff at Local Data Center, Inc. D is correct because when entrusting sensitive banking data to a third-party data center, the most direct human-layer security control is vetting the people who have physical and logical access to that data. Background checks are a standard, contractually enforceable personnel…
Question
SuperBank is considering a cloud service from Local Data Center, Inc., to support the bank's expanding needs. SuperBank's managers are concerned about security. What can SuperBank request to protect its data from security threats?
Options
- AFor Local Data Center to run multiple hypervisors
- BFor Local Data Center to install a DDoS mitigation system
- CFor SuperBank staff to manage the servers at Local Data Center, Inc.
- DFor SuperBank to perform background checks on the staff at Local Data Center, Inc.
How the community answered
(34 responses)- A3% (1)
- B3% (1)
- C6% (2)
- D88% (30)
Explanation
D is correct because when entrusting sensitive banking data to a third-party data center, the most direct human-layer security control is vetting the people who have physical and logical access to that data. Background checks are a standard, contractually enforceable personnel security measure in vendor risk management - and financial institutions are often required by regulations to ensure third-party staff are screened.
Option A is wrong because running multiple hypervisors is a virtualization/redundancy choice, not a security control against data threats - it addresses isolation or availability, not personnel or access risk.
Option B is wrong because DDoS mitigation protects availability (keeping services online), not data confidentiality or integrity - it prevents downtime, not data breaches.
Option C is wrong because having SuperBank's own staff manage the physical servers blurs the vendor relationship, is operationally impractical in a cloud service model, and isn't a standard security request - it would effectively make SuperBank the operator, not the customer.
Memory tip: "You can't lock the door if you don't know who has the key." When data leaves your building, the biggest risk shifts to people - so the first security question is always who has access?
Topics
Community Discussion
No community discussion yet for this question.