nerdexam
CompTIA

CAS-002 · Question #655

In order for a company to boost profits by implementing cost savings on non-core business activities, the IT manager has sought approval for the corporate email system to be hosted in the cloud. The…

The correct answer is C. Data provisioning, processing, in transit, at rest, and de-provisioning. When migrating corporate email to the cloud, the compliance officer must account for the complete data lifecycle covering every state data passes through, from initial creation to final destruction.

Integration of Computing, Communications and Business Disciplines

Question

In order for a company to boost profits by implementing cost savings on non-core business activities, the IT manager has sought approval for the corporate email system to be hosted in the cloud. The compliance officer has been tasked with ensuring that data lifecycle issues are taken into account. Which of the following BEST covers the data lifecycle end-to-end?

Options

  • ACreation and secure destruction of mail accounts, emails, and calendar items
  • BInformation classification, vendor selection, and the RFP process
  • CData provisioning, processing, in transit, at rest, and de-provisioning
  • DSecuring virtual environments, appliances, and equipment that handle email

How the community answered

(63 responses)
  • A
    8% (5)
  • B
    16% (10)
  • C
    73% (46)
  • D
    3% (2)

Why each option

When migrating corporate email to the cloud, the compliance officer must account for the complete data lifecycle covering every state data passes through, from initial creation to final destruction.

ACreation and secure destruction of mail accounts, emails, and calendar items

Creation and secure destruction address only the first and last stages of the lifecycle, omitting critical intermediate states such as data in transit and data at rest.

BInformation classification, vendor selection, and the RFP process

Information classification, vendor selection, and the RFP process describe procurement and vendor management activities, not the stages of the data lifecycle itself.

CData provisioning, processing, in transit, at rest, and de-provisioningCorrect

Data provisioning, processing, in transit, at rest, and de-provisioning represents the full end-to-end data lifecycle framework recognized in cloud security standards. This option ensures compliance obligations are addressed at every phase - from when data is created and processed, to how it is secured during transmission and storage, to how it is properly destroyed at end of life. No other choice covers all these states.

DSecuring virtual environments, appliances, and equipment that handle email

Securing virtual environments and appliances describes infrastructure security controls rather than the data lifecycle phases a compliance officer must track end-to-end.

Concept tested: Cloud data lifecycle management for compliance

Source: https://cloudsecurityalliance.org/research/guidance

Topics

#data lifecycle#cloud security#compliance#SaaS email

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice