CAS-002 · Question #655
In order for a company to boost profits by implementing cost savings on non-core business activities, the IT manager has sought approval for the corporate email system to be hosted in the cloud. The…
The correct answer is C. Data provisioning, processing, in transit, at rest, and de-provisioning. When migrating corporate email to the cloud, the compliance officer must account for the complete data lifecycle covering every state data passes through, from initial creation to final destruction.
Question
In order for a company to boost profits by implementing cost savings on non-core business activities, the IT manager has sought approval for the corporate email system to be hosted in the cloud. The compliance officer has been tasked with ensuring that data lifecycle issues are taken into account. Which of the following BEST covers the data lifecycle end-to-end?
Options
- ACreation and secure destruction of mail accounts, emails, and calendar items
- BInformation classification, vendor selection, and the RFP process
- CData provisioning, processing, in transit, at rest, and de-provisioning
- DSecuring virtual environments, appliances, and equipment that handle email
How the community answered
(63 responses)- A8% (5)
- B16% (10)
- C73% (46)
- D3% (2)
Why each option
When migrating corporate email to the cloud, the compliance officer must account for the complete data lifecycle covering every state data passes through, from initial creation to final destruction.
Creation and secure destruction address only the first and last stages of the lifecycle, omitting critical intermediate states such as data in transit and data at rest.
Information classification, vendor selection, and the RFP process describe procurement and vendor management activities, not the stages of the data lifecycle itself.
Data provisioning, processing, in transit, at rest, and de-provisioning represents the full end-to-end data lifecycle framework recognized in cloud security standards. This option ensures compliance obligations are addressed at every phase - from when data is created and processed, to how it is secured during transmission and storage, to how it is properly destroyed at end of life. No other choice covers all these states.
Securing virtual environments and appliances describes infrastructure security controls rather than the data lifecycle phases a compliance officer must track end-to-end.
Concept tested: Cloud data lifecycle management for compliance
Source: https://cloudsecurityalliance.org/research/guidance
Topics
Community Discussion
No community discussion yet for this question.