CAS-001 · Question #441
For companies seeking to move to cloud services, variances in regulation between jurisdictions can be addressed in which of the following ways?
The correct answer is D. Tagging VMs to ensure they are only run in certain geographic regions. Data sovereignty and compliance regulations (e.g., GDPR, HIPAA, local data residency laws) vary significantly by country and region. The core requirement is ensuring data and workloads remain within jurisdictions whose laws the company complies with. Tagging VMs to ensure they…
Question
For companies seeking to move to cloud services, variances in regulation between jurisdictions can be addressed in which of the following ways?
Options
- AEnsuring the cloud service provides high availability spanning multiple regions.
- BUsing an international private cloud model as opposed to public IaaS.
- CEncrypting all data moved to or processed in a cloud-based service.
- DTagging VMs to ensure they are only run in certain geographic regions.
How the community answered
(40 responses)- A3% (1)
- B10% (4)
- C5% (2)
- D83% (33)
Explanation
Data sovereignty and compliance regulations (e.g., GDPR, HIPAA, local data residency laws) vary significantly by country and region. The core requirement is ensuring data and workloads remain within jurisdictions whose laws the company complies with. Tagging VMs to ensure they only run in certain geographic regions (D) directly addresses this by enforcing data residency - workloads tagged for, say, EU-only regions will not be provisioned outside the EU, satisfying local regulations. High availability across multiple regions (A) could actually worsen compliance by spreading data to non-compliant jurisdictions. An international private cloud (B) does not inherently resolve which jurisdiction's law applies. Encryption (C) protects data confidentiality but does not address which legal jurisdiction governs where data is processed or stored.
Topics
Community Discussion
No community discussion yet for this question.