nerdexam
Isaca

CDPSE · Question #77

A software development organization with remote personnel has implemented a third-party virtualized workspace to allow the teams to collaborate. Which of the following should be of GREATEST concern?

The correct answer is B. Personal data could potentially be exfiltrated through the virtual workspace. When using a third-party virtual workspace, the greatest privacy concern is that personal data processed or stored within it could be exfiltrated by the provider or through the platform.

Privacy Architecture

Question

A software development organization with remote personnel has implemented a third-party virtualized workspace to allow the teams to collaborate. Which of the following should be of GREATEST concern?

Options

  • AThe third-party workspace is hosted in a highly regulated jurisdiction.
  • BPersonal data could potentially be exfiltrated through the virtual workspace.
  • CThe organization's products are classified as intellectual property.
  • DThere is a lack of privacy awareness and training among remote personnel.

How the community answered

(48 responses)
  • A
    15% (7)
  • B
    52% (25)
  • C
    6% (3)
  • D
    27% (13)

Why each option

When using a third-party virtual workspace, the greatest privacy concern is that personal data processed or stored within it could be exfiltrated by the provider or through the platform.

AThe third-party workspace is hosted in a highly regulated jurisdiction.

A highly regulated hosting jurisdiction may actually provide stronger legal protections for data rather than representing a privacy concern.

BPersonal data could potentially be exfiltrated through the virtual workspace.Correct

Third-party virtual workspaces may process, transmit, or cache personal data, creating a risk that sensitive information could be exfiltrated by unauthorized actors or the provider itself. This represents a direct privacy threat to data subjects and potential regulatory liability for the organization that cannot be easily controlled once data leaves its environment.

CThe organization's products are classified as intellectual property.

Intellectual property classification is a business and legal concern, but is separate from personal data privacy protection obligations.

DThere is a lack of privacy awareness and training among remote personnel.

Lack of privacy training is an addressable organizational gap, whereas data exfiltration through the platform is an immediate and harder-to-control technical risk.

Concept tested: Third-party data processor - personal data exfiltration risk

Source: https://www.enisa.europa.eu/topics/cloud-and-big-data/cloud-security

Topics

#Data Exfiltration#Virtual Workspace Security#Third-Party Risk#Privacy Breach

Community Discussion

No community discussion yet for this question.

Full CDPSE Practice