CS0-003 · Question #231
An organization has deployed a cloud-based storage system for shared data that is in phase two of the data life cycle. Which of the following controls should the security team ensure are addressed? (C
The correct answer is D. Encryption F. Access controls. An organization deployed a cloud-based storage system for shared data in phase two of the data life cycle, and the security team needs to address relevant controls.
Question
An organization has deployed a cloud-based storage system for shared data that is in phase two of the data life cycle. Which of the following controls should the security team ensure are addressed? (Choose two.)
Options
- AData classification
- BData destruction
- CData loss prevention
- DEncryption
- EBackups
- FAccess controls
How the community answered
(39 responses)- A3% (1)
- B5% (2)
- C10% (4)
- D79% (31)
- E3% (1)
Why each option
An organization deployed a cloud-based storage system for shared data in phase two of the data life cycle, and the security team needs to address relevant controls.
Data classification typically occurs in phase one (creation/collection) to categorize data sensitivity, guiding subsequent control applications, not as a primary control for data already in phase two (storage/usage).
Data destruction (or purging) is part of the final phase (disposition) of the data life cycle, dealing with the secure removal of data when it is no longer needed.
Data Loss Prevention (DLP) is a broader set of tools and policies to prevent sensitive data from leaving the organization's control; while relevant to data security, it's a higher-level strategy rather than a direct technical control on the data in storage itself like encryption or access controls.
Encryption protects data at rest within the cloud storage system and data in transit, ensuring confidentiality and integrity, which is crucial for shared data during its active storage and use.
Backups are critical for data availability and recovery, but the question focuses on controls for the data *in* storage during its active life cycle phase, where encryption and access controls directly address confidentiality and integrity.
Access controls are essential to manage who can access, modify, or delete the shared data, ensuring that only authorized users or systems can interact with it, which is critical for the integrity and confidentiality of shared data in a shared storage system.
Concept tested: Data life cycle security controls
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/data-lifecycle-management-overview?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.