nerdexam
CSA

CCSK · Question #165

What is the most important reason for knowing where the cloud service provider will host the data?

The correct answer is A. Such knowledge is a prerequisite to implementing the required measures to ensure compliance. Knowing the physical location of hosted data is the foundational prerequisite that determines which compliance frameworks, data protection laws, and security controls must be applied. Without this knowledge, no compliance program can be properly designed or implemented.

Legal, Risk, and Compliance

Question

What is the most important reason for knowing where the cloud service provider will host the data?

Options

  • ASuch knowledge is a prerequisite to implementing the required measures to ensure compliance
  • BEnable the data controller to register with the local Data Protection Officer(s), where appropriate.
  • CTo facilitate comprehensive disaster planning.
  • DTo enable data location transparency for the consumer.
  • ETo allow compliance with local laws regarding data privacy and safeguarding.

How the community answered

(27 responses)
  • A
    78% (21)
  • C
    11% (3)
  • D
    7% (2)
  • E
    4% (1)

Why each option

Knowing the physical location of hosted data is the foundational prerequisite that determines which compliance frameworks, data protection laws, and security controls must be applied. Without this knowledge, no compliance program can be properly designed or implemented.

ASuch knowledge is a prerequisite to implementing the required measures to ensure complianceCorrect

Data location determines jurisdiction, which in turn dictates which legal and regulatory frameworks apply - such as GDPR in the EU or CCPA in California. Knowing the hosting location is therefore the prerequisite action that enables all subsequent compliance measures, including legal registration, data transfer agreements, and technical controls. All other options in this list are downstream actions that depend on first satisfying this prerequisite.

BEnable the data controller to register with the local Data Protection Officer(s), where appropriate.

Registering with a local Data Protection Officer is a specific compliance action that only becomes relevant after the hosting location is already known, making it a consequence of A rather than the primary reason.

CTo facilitate comprehensive disaster planning.

Disaster recovery planning benefits from knowing data location, but this is an operational concern secondary to the legal and regulatory compliance imperative.

DTo enable data location transparency for the consumer.

Data location transparency for the consumer is a customer-facing benefit and a compliance output, not the most important underlying reason for needing to know the location.

ETo allow compliance with local laws regarding data privacy and safeguarding.

Complying with local laws is a valid reason but is narrower in scope than A - option A encompasses this and all other compliance measures, making it the more complete and important answer.

Concept tested: Cloud data residency and compliance prerequisites

Source: https://www.enisa.europa.eu/publications/cloud-computing-risk-assessment

Topics

#data residency#compliance#data location#regulatory requirements

Community Discussion

No community discussion yet for this question.

Full CCSK Practice