nerdexam
CSA

CCSK · Question #90

The key concern of data location is:

The correct answer is D. Data is stored only in geographic locations permitted by regulations. The primary concern of data location in regulated environments is ensuring that data is stored only in geographic regions that comply with applicable laws and regulations, not in any prohibited jurisdiction.

Cloud Data Security

Question

The key concern of data location is:

Options

  • AAssurance that all data requested by legal authorities has been retrieved
  • BAssurance that prohibited locations cannot access the data
  • CData is located only on redundant storage subsystems with high MTBF (mean time between
  • DData is stored only in geographic locations permitted by regulations
  • EData should not be commingled with other customers

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    4% (2)
  • D
    81% (39)
  • E
    10% (5)

Why each option

The primary concern of data location in regulated environments is ensuring that data is stored only in geographic regions that comply with applicable laws and regulations, not in any prohibited jurisdiction.

AAssurance that all data requested by legal authorities has been retrieved

Retrieving data for legal authorities addresses legal hold and e-discovery obligations, which is a separate compliance concern from data location.

BAssurance that prohibited locations cannot access the data

Preventing prohibited parties from accessing data is an access control concern, not a data location concern.

CData is located only on redundant storage subsystems with high MTBF (mean time between

Storage redundancy and high MTBF relate to availability and reliability engineering, not to regulatory data location requirements.

DData is stored only in geographic locations permitted by regulationsCorrect

Regulations such as GDPR, HIPAA, and national data sovereignty laws specify where certain categories of data may and may not be stored. The key concern of data location is therefore ensuring that data at rest resides only in geographically and legally permissible locations. Violations can occur simply by storing data in a non-compliant region, regardless of whether it is accessed or disclosed.

EData should not be commingled with other customers

Data commingling with other customers is a multi-tenancy and data isolation concern, distinct from the regulatory question of where data is geographically stored.

Concept tested: Regulatory data location and geographic storage compliance

Source: https://www.nist.gov/privacy-framework

Topics

#data location#data sovereignty#regulatory compliance#data residency

Community Discussion

No community discussion yet for this question.

Full CCSK Practice