nerdexam
CompTIA

CAS-003 · Question #455

While conducting a BIA for a proposed acquisition, the IT integration team found that both companies outsource CRM services to competing and incompatible third-party cloud services. The decision has…

The correct answer is A. Data remnants D. Storage encryption. When migrating CRM data from cloud providers to an in-house solution, the CISO must focus on eliminating data remnants left on cloud storage and ensuring encryption of data at rest in the new environment.

Risk Management

Question

While conducting a BIA for a proposed acquisition, the IT integration team found that both companies outsource CRM services to competing and incompatible third-party cloud services. The decision has been made to bring the CRM service in-house, and the IT team has chosen a future solution. With which of the following should the Chief Information Security Officer (CISO) be MOST concerned? (Choose two.)

Options

  • AData remnants
  • BSovereignty
  • CCompatible services
  • DStorage encryption
  • EData migration
  • FChain of custody

How the community answered

(36 responses)
  • A
    75% (27)
  • B
    6% (2)
  • C
    3% (1)
  • E
    3% (1)
  • F
    14% (5)

Why each option

When migrating CRM data from cloud providers to an in-house solution, the CISO must focus on eliminating data remnants left on cloud storage and ensuring encryption of data at rest in the new environment.

AData remnantsCorrect

Data remnants are residual pieces of sensitive customer data that remain on cloud provider storage infrastructure after the migration is complete; without verified data destruction or sanitization, the provider or future tenants could potentially access that data, creating a significant confidentiality risk.

BSovereignty

Data sovereignty concerns apply primarily to cross-border data storage restrictions and are less critical when an organization is bringing data in-house within the same jurisdiction.

CCompatible services

Compatible services is a technical integration concern for the IT migration team and does not represent a security risk that falls within the CISO's primary responsibility.

DStorage encryptionCorrect

Storage encryption ensures that CRM data is protected at rest in the new in-house environment, so that even if physical or logical storage controls are bypassed, the data remains unreadable to unauthorized parties.

EData migration

Data migration is a logistics and process concern for the IT team; the CISO's security focus centers on protecting data confidentiality and integrity before, during, and after migration rather than the migration process itself.

FChain of custody

Chain of custody is a forensic evidence concept applicable to legal investigations and is not directly relevant to a CRM cloud-to-on-premises migration scenario.

Concept tested: Data remnants and storage encryption in cloud-to-on-premises migration

Source: https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final

Topics

#cloud migration#data remnants#storage encryption#BIA

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice