nerdexam
CompTIA

SY0-301 · Question #905

Acme Corp has selectively outsourced proprietary business processes to ABC Services. Due to some technical issues, ABC services wants to send some of Acme Corp's debug data to a third party vendor…

The correct answer is C. This may violate data ownership and non-disclosure agreements. When a vendor wants to share a client's data with a sub-vendor, the original contractual agreements governing data ownership and confidentiality must be reviewed first.

Security program management and oversight

Question

Acme Corp has selectively outsourced proprietary business processes to ABC Services. Due to some technical issues, ABC services wants to send some of Acme Corp's debug data to a third party vendor for problem resolution. Which of the following MUST be considered prior to sending data to a third party?

Options

  • AThe data should be encrypted prior to transport
  • BThis would not constitute unauthorized data sharing
  • CThis may violate data ownership and non-disclosure agreements
  • DAcme Corp should send the data to ABC Services' vendor instead

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    3% (1)
  • C
    74% (26)
  • D
    9% (3)

Why each option

When a vendor wants to share a client's data with a sub-vendor, the original contractual agreements governing data ownership and confidentiality must be reviewed first.

AThe data should be encrypted prior to transport

Encrypting data in transit is a security best practice but does not address the underlying legal question of whether sharing the data with a third party is permitted at all.

BThis would not constitute unauthorized data sharing

Sharing a client's proprietary data with an unauthorized third party without explicit permission can absolutely constitute unauthorized data sharing under most contractual and regulatory frameworks.

CThis may violate data ownership and non-disclosure agreementsCorrect

Outsourcing agreements typically include non-disclosure agreements (NDAs) and data ownership clauses that restrict how the primary vendor can handle or share the client's data. Forwarding Acme Corp's debug data to a third party without Acme Corp's consent could violate these contractual obligations. This constitutes a legal and compliance concern that must be addressed before any data transfer occurs.

DAcme Corp should send the data to ABC Services' vendor instead

Having Acme Corp send the data directly does not resolve the core issue of whether the third-party disclosure is permissible under the existing agreements.

Concept tested: Third-party data sharing and NDA compliance

Source: https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final

Topics

#data ownership#NDA#third-party risk#data governance

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice