nerdexam
CompTIA

DA0-002 · Question #10

A data analyst is following up on a recent, company-wide data audit of customer invoice data. Which of the following is the best option for the analyst to use?

The correct answer is B. GDPR. When auditing company-wide customer invoice data, GDPR is the most relevant regulation to use, as it governs the processing of personal data for individuals within the EU, which commonly includes details found in customer invoices.

Data Governance

Question

A data analyst is following up on a recent, company-wide data audit of customer invoice data. Which of the following is the best option for the analyst to use?

Options

  • APCI DSS
  • BGDPR
  • CISO
  • DPII

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    71% (30)
  • C
    10% (4)
  • D
    14% (6)

Why each option

When auditing company-wide customer invoice data, GDPR is the most relevant regulation to use, as it governs the processing of personal data for individuals within the EU, which commonly includes details found in customer invoices.

APCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is a standard for organizations that handle branded credit cards, focusing specifically on cardholder data security, not broader personal data privacy like GDPR.

BGDPRCorrect

GDPR (General Data Protection Regulation) is a comprehensive data protection and privacy law that applies to all companies processing the personal data of individuals residing in the European Union, regardless of the company's location. Customer invoice data frequently contains personal information that falls under GDPR's scope, making it critical for a data audit.

CISO

ISO (International Organization for Standardization) refers to a body that develops various international standards (e.g., ISO 27001 for information security), not a specific data privacy regulation that directly governs customer invoice data in the context of an audit.

DPII

PII (Personally Identifiable Information) is a type of data (information that can identify an individual), not a regulation or standard to 'use' for an audit; the audit would be concerned with data classified as PII under regulations like GDPR.

Concept tested: Data privacy regulations, GDPR

Source: https://gdpr-info.eu/

Topics

#Data privacy#Data regulations#GDPR#Compliance

Community Discussion

No community discussion yet for this question.

Full DA0-002 Practice