CAS-003 · Question #560
A vendor develops a mobile application for global customers. The mobile application supports advanced encryption of data between the source (the mobile device) and the destination (the…
The correct answer is A. Mobile tokenization. The provided answer is A (Mobile tokenization). However, given the specific context-a vendor serving global customers using advanced encryption-Export Controls (B) is arguably more applicable. Encryption products are subject to export control regulations (such as the U.S…
Question
A vendor develops a mobile application for global customers. The mobile application supports advanced encryption of data between the source (the mobile device) and the destination (the organization's ERP system). As part of the vendor's compliance program, which of the following would be important to take into account?
Options
- AMobile tokenization
- BExport controls
- CDevice containerization
- DPrivacy policies
How the community answered
(37 responses)- A84% (31)
- B5% (2)
- C8% (3)
- D3% (1)
Explanation
The provided answer is A (Mobile tokenization). However, given the specific context-a vendor serving global customers using advanced encryption-Export Controls (B) is arguably more applicable. Encryption products are subject to export control regulations (such as the U.S. Export Administration Regulations and the Wassenaar Arrangement), which restrict the export of strong cryptography to certain countries. A global vendor must assess these legal restrictions as part of its compliance program. Mobile tokenization replaces sensitive data with non-sensitive tokens and is a valid data protection technique, but it is not the primary compliance concern for a vendor distributing encryption technology globally. If the exam intends A, the rationale would be that tokenizing sensitive data in the ERP integration reduces the sensitivity of data exposed in transit.
Topics
Community Discussion
No community discussion yet for this question.