CAS-001 · Question #307
The organization has an IT driver on cloud computing to improve delivery times for IT solution provisioning. Separate to this initiative, a business case has been approved for replacing the existing…
The correct answer is C. There may be regulatory restrictions with credit cards being processed out of country or processed by. While cloud computing is beneficial for many IT workloads, credit card processing is subject to strict regulatory requirements - most notably PCI DSS (Payment Card Industry Data Security Standard). Answer C is correct because it identifies the critical concern: regulatory…
Question
The organization has an IT driver on cloud computing to improve delivery times for IT solution provisioning. Separate to this initiative, a business case has been approved for replacing the existing banking platform for credit card processing with a newer offering. It is the security practitioner's responsibility to evaluate whether the new credit card processing platform can be hosted within a cloud environment. Which of the following BEST balances the security risk and IT drivers for cloud computing?
Options
- AA third-party cloud computing platform makes sense for new IT solutions.
- BUsing a third-party cloud computing environment should be endorsed going forward.
- CThere may be regulatory restrictions with credit cards being processed out of country or processed by
- DCloud computing should rarely be considered an option for any processes that need to be significantly
How the community answered
(27 responses)- A4% (1)
- B7% (2)
- C70% (19)
- D19% (5)
Explanation
While cloud computing is beneficial for many IT workloads, credit card processing is subject to strict regulatory requirements - most notably PCI DSS (Payment Card Industry Data Security Standard). Answer C is correct because it identifies the critical concern: regulatory restrictions around where cardholder data can be processed (data sovereignty / cross-border data transfer laws) and who can process it (third-party liability, shared responsibility model under PCI DSS). Moving card processing to a third-party cloud introduces compliance complexity including auditing requirements, contractual obligations, and potential violations of local data residency laws. Option A and B are too broadly permissive without acknowledging compliance risk. Option D is overly restrictive as a blanket rule.
Topics
Community Discussion
No community discussion yet for this question.