nerdexam
CompTIA

CAS-002 · Question #233

The organization has an IT driver on cloud computing to improve delivery times for IT solution provisioning. Separate to this initiative, a business case has been approved for replacing the existing…

The correct answer is C. There may be regulatory restrictions with credit cards being processed out of country or. When evaluating cloud adoption for credit card processing, regulatory and data residency restrictions under PCI DSS must be assessed before approving cloud hosting for that workload.

Integration of Computing, Communications and Business Disciplines

Question

The organization has an IT driver on cloud computing to improve delivery times for IT solution provisioning. Separate to this initiative, a business case has been approved for replacing the existing banking platform for credit card processing with a newer offering. It is the security practitioner's responsibility to evaluate whether the new credit card processing platform can be hosted within a cloud environment. Which of the following BEST balances the security risk and IT drivers for cloud computing?

Options

  • AA third-party cloud computing platform makes sense for new IT solutions.
  • BUsing a third-party cloud computing environment should be endorsed going forward.
  • CThere may be regulatory restrictions with credit cards being processed out of country or
  • DCloud computing should rarely be considered an option for any processes that need to be

How the community answered

(62 responses)
  • A
    6% (4)
  • B
    3% (2)
  • C
    76% (47)
  • D
    15% (9)

Why each option

When evaluating cloud adoption for credit card processing, regulatory and data residency restrictions under PCI DSS must be assessed before approving cloud hosting for that workload.

AA third-party cloud computing platform makes sense for new IT solutions.

This statement is unconditionally broad - not all new IT solutions are appropriate for third-party cloud environments without first evaluating regulatory requirements and data sensitivity classifications.

BUsing a third-party cloud computing environment should be endorsed going forward.

Broadly endorsing third-party cloud without evaluating the specific compliance constraints applicable to credit card processing is irresponsible and potentially non-compliant with PCI DSS.

CThere may be regulatory restrictions with credit cards being processed out of country orCorrect

Credit card data processing is governed by PCI DSS, which imposes strict controls on where and how cardholder data is processed; additionally, many jurisdictions enforce data sovereignty laws that prohibit processing payment data outside specific national boundaries, making regulatory review essential before endorsing cloud hosting for this use case.

DCloud computing should rarely be considered an option for any processes that need to be

Categorically avoiding cloud for any sensitive process is overly restrictive and fails to balance the legitimate organizational IT driver for cloud adoption with a proportionate risk assessment.

Concept tested: Cloud adoption risk assessment for regulated payment data

Source: https://www.pcisecuritystandards.org/document_library/

Topics

#cloud computing#PCI DSS#regulatory compliance#risk assessment

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice