nerdexam
CompTIA

CAS-003 · Question #761

During the migration of a company's human resources application to a PaaS provider, the Chief Privacy Officer (CPO) expresses concern the vendor's staff may be able to access data within the…

The correct answer is A. Execute non-disclosure agreements and background checks on vendor staff. The stated answer A is an administrative control that does not technically prevent vendor staff from reading data - it only creates legal liability after the fact. The CPO's concern is technical access, which requires a technical control. A CASB (Cloud Access Security Broker)…

Enterprise Security Architecture

Question

During the migration of a company's human resources application to a PaaS provider, the Chief Privacy Officer (CPO) expresses concern the vendor's staff may be able to access data within the migrating applications. The application stack includes a multitier architecture and uses commercially available, vendor- supported software packages. Which of the following BEST addresses the CPO's concerns?

Options

  • AExecute non-disclosure agreements and background checks on vendor staff.
  • BEnsure the platform vendor implement date-at-rest encryption on its storage.
  • CEnable MFA to the vendor's tier of the architecture.
  • DImpalement a CASB that tokenizes company data in transit to the migrated applications.

How the community answered

(17 responses)
  • A
    82% (14)
  • C
    6% (1)
  • D
    12% (2)

Explanation

The stated answer A is an administrative control that does not technically prevent vendor staff from reading data - it only creates legal liability after the fact. The CPO's concern is technical access, which requires a technical control. A CASB (Cloud Access Security Broker) configured to tokenize data in transit (D) replaces sensitive values with non-sensitive tokens before data ever reaches the PaaS provider's infrastructure. Even if a vendor employee has full system access, they see only meaningless tokens - the actual data never leaves the organization's control boundary.

Topics

#PaaS security#CASB#data privacy#cloud vendor risk

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice