nerdexam
CompTIA

CAS-003 · Question #15

A business is growing and starting to branch out into other locations. In anticipation of opening an office in a different country, the Chief Information Security Officer (CISO) and legal team agree…

The correct answer is B. Data retention policy E. Data sovereignty policy H. Encryption standard. Meeting data lifecycle, geographic, and encryption requirements for a new international office requires a combination of retention, sovereignty, and encryption policies working together.

Risk Management

Question

A business is growing and starting to branch out into other locations. In anticipation of opening an office in a different country, the Chief Information Security Officer (CISO) and legal team agree they need to meet the following criteria regarding data to open the new office:

Store taxation-related documents for five years Store customer addresses in an encrypted format Destroy customer information after one year Keep data only in the customer's home country Which of the following should the CISO implement to BEST meet these requirements? (Choose three.)

Options

  • ACapacity planning policy
  • BData retention policy
  • CData classification standard
  • DLegal compliance policy
  • EData sovereignty policy
  • FBackup policy
  • GAcceptable use policy
  • HEncryption standard

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    66% (21)
  • C
    9% (3)
  • F
    3% (1)
  • G
    19% (6)

Why each option

Meeting data lifecycle, geographic, and encryption requirements for a new international office requires a combination of retention, sovereignty, and encryption policies working together.

ACapacity planning policy

Capacity planning policy addresses storage and compute resource allocation, not data handling lifecycle, geographic residency, or encryption requirements.

BData retention policyCorrect

A data retention policy directly addresses the requirements to store taxation documents for five years and destroy customer information after one year by defining mandatory data lifecycle rules.

CData classification standard

A data classification standard categorizes data by sensitivity level but does not specify retention periods, geographic restrictions, or encryption implementation requirements.

DLegal compliance policy

A legal compliance policy is a broad governance document and does not provide the specific operational controls needed for retention schedules, data sovereignty, or encryption.

EData sovereignty policyCorrect

A data sovereignty policy mandates that data remain within a specific country or jurisdiction, directly satisfying the requirement to keep data only in the customer's home country.

FBackup policy

A backup policy governs how and when data backups are created and stored, not the lifecycle, geographic location, or encryption requirements for primary data.

GAcceptable use policy

An acceptable use policy governs how employees and users interact with organizational systems and data, not data management, retention, or encryption requirements.

HEncryption standardCorrect

An encryption standard defines the required algorithms, key lengths, and implementation methods to ensure customer addresses are stored in an encrypted format as required.

Concept tested: Data governance policies for international compliance requirements

Source: https://csrc.nist.gov/publications/detail/sp/800-188/final

Topics

#data sovereignty#data retention#encryption standards#international compliance

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice