nerdexam
CompTIA

CAS-003 · Question #560

A vendor develops a mobile application for global customers. The mobile application supports advanced encryption of data between the source (the mobile device) and the destination (the…

The correct answer is A. Mobile tokenization. The provided answer is A (Mobile tokenization). However, given the specific context-a vendor serving global customers using advanced encryption-Export Controls (B) is arguably more applicable. Encryption products are subject to export control regulations (such as the U.S…

Risk Management

Question

A vendor develops a mobile application for global customers. The mobile application supports advanced encryption of data between the source (the mobile device) and the destination (the organization's ERP system). As part of the vendor's compliance program, which of the following would be important to take into account?

Options

  • AMobile tokenization
  • BExport controls
  • CDevice containerization
  • DPrivacy policies

How the community answered

(37 responses)
  • A
    84% (31)
  • B
    5% (2)
  • C
    8% (3)
  • D
    3% (1)

Explanation

The provided answer is A (Mobile tokenization). However, given the specific context-a vendor serving global customers using advanced encryption-Export Controls (B) is arguably more applicable. Encryption products are subject to export control regulations (such as the U.S. Export Administration Regulations and the Wassenaar Arrangement), which restrict the export of strong cryptography to certain countries. A global vendor must assess these legal restrictions as part of its compliance program. Mobile tokenization replaces sensitive data with non-sensitive tokens and is a valid data protection technique, but it is not the primary compliance concern for a vendor distributing encryption technology globally. If the exam intends A, the rationale would be that tokenizing sensitive data in the ERP integration reduces the sensitivity of data exposed in transit.

Topics

#export controls#encryption compliance#mobile application#cryptography regulations

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice