CDPSE · Question #77
A software development organization with remote personnel has implemented a third-party virtualized workspace to allow the teams to collaborate. Which of the following should be of GREATEST concern?
The correct answer is B. Personal data could potentially be exfiltrated through the virtual workspace. When using a third-party virtual workspace, the greatest privacy concern is that personal data processed or stored within it could be exfiltrated by the provider or through the platform.
Question
A software development organization with remote personnel has implemented a third-party virtualized workspace to allow the teams to collaborate. Which of the following should be of GREATEST concern?
Options
- AThe third-party workspace is hosted in a highly regulated jurisdiction.
- BPersonal data could potentially be exfiltrated through the virtual workspace.
- CThe organization's products are classified as intellectual property.
- DThere is a lack of privacy awareness and training among remote personnel.
How the community answered
(48 responses)- A15% (7)
- B52% (25)
- C6% (3)
- D27% (13)
Why each option
When using a third-party virtual workspace, the greatest privacy concern is that personal data processed or stored within it could be exfiltrated by the provider or through the platform.
A highly regulated hosting jurisdiction may actually provide stronger legal protections for data rather than representing a privacy concern.
Third-party virtual workspaces may process, transmit, or cache personal data, creating a risk that sensitive information could be exfiltrated by unauthorized actors or the provider itself. This represents a direct privacy threat to data subjects and potential regulatory liability for the organization that cannot be easily controlled once data leaves its environment.
Intellectual property classification is a business and legal concern, but is separate from personal data privacy protection obligations.
Lack of privacy training is an addressable organizational gap, whereas data exfiltration through the platform is an immediate and harder-to-control technical risk.
Concept tested: Third-party data processor - personal data exfiltration risk
Source: https://www.enisa.europa.eu/topics/cloud-and-big-data/cloud-security
Topics
Community Discussion
No community discussion yet for this question.